261311
|
- |
|
redhat
|
freeipa
|
The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedur…
|
CWE-310
Cryptographic Issues
|
CVE-2012-5484
|
2013-02-7 14:01 |
2013-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261312
|
- |
|
cisco
|
webex_social
|
The search function in Cisco Webex Social (formerly Cisco Quad) allows remote authenticated users to read files via unspecified parameters, aka Bug ID CSCud40235.
|
CWE-200
Information Exposure
|
CVE-2013-1107
|
2013-02-7 14:00 |
2013-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261313
|
- |
|
cisco
|
unity_express_software unity_express
|
Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Unity Express with software before 8.0 allow remote attackers to hijack the authentication of unspecified victims via unknown v…
|
CWE-352
Origin Validation Error
|
CVE-2013-1120
|
2013-02-7 14:00 |
2013-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261314
|
- |
|
emc
|
rsa_archer_smartsuite rsa_archer_egrc
|
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer SmartSuite Framework 4.x and RSA Archer GRC 5.x before 5.2SP1 allow remote attackers to inject arbitrary web script or HTML via u…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1064
|
2013-02-7 14:00 |
2013-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261315
|
- |
|
emc
|
rsa_archer_smartsuite rsa_archer_egrc
|
Directory traversal vulnerability in EMC RSA Archer SmartSuite Framework 4.x and RSA Archer GRC 5.x before 5.2SP1 allows remote authenticated users to upload files, and consequently execute arbitrary…
|
CWE-22
Path Traversal
|
CVE-2012-2293
|
2013-02-7 14:00 |
2013-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261316
|
- |
|
novell
|
groupwise
|
Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to inject arbitrary web script…
|
CWE-79
Cross-site Scripting
|
CVE-2012-4912
|
2013-02-7 14:00 |
2012-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261317
|
- |
|
weathernews
|
weathernews_touch
|
The Weathernews Touch application 2.3.2 and earlier for Android allows attackers to obtain sensitive information about logged locations via a crafted application that leverages read permission for sy…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-5187
|
2013-02-7 14:00 |
2013-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261318
|
- |
|
google
|
android
|
The PowerVR SGX driver in Android before 2.3.6 allows attackers to obtain potentially sensitive information from kernel stack memory via an application that uses a crafted length parameter in a reque…
|
CWE-200
Information Exposure
|
CVE-2011-1350
|
2013-02-7 14:00 |
2013-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261319
|
- |
|
digia webkit
|
qt webkit
|
Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r56380, as used in Qt and other products, allows remote webso…
|
CWE-189
Numeric Errors
|
CVE-2010-1766
|
2013-02-7 14:00 |
2010-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261320
|
- |
|
oracle
|
sun_products_suite
|
Unspecified vulnerability in the Directory Server Enterprise Edition component in Oracle Sun Products Suite 6.0, 6.1, 6.2, and 6.3 allows local users to affect confidentiality, integrity, and availab…
|
NVD-CWE-noinfo
|
CVE-2010-3535
|
2013-02-7 14:00 |
2010-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|