261621
|
- |
|
layton_technology
|
helpbox
|
Layton Helpbox 4.4.0 allows remote attackers to discover cleartext credentials for the login page by sniffing the network.
|
CWE-310
Cryptographic Issues
|
CVE-2012-4977
|
2012-12-12 20:38 |
2012-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261622
|
- |
|
adobe
|
coldfusion
|
Adobe ColdFusion 9.0 through 9.0.2, and 10, allows local users to bypass intended shared-hosting sandbox permissions via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-5675
|
2012-12-12 20:38 |
2012-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261623
|
- |
|
simple_gmail_login
|
1.1.2 1.1.3
|
simple-gmail-login.php in the Simple Gmail Login plugin before 1.1.4 for WordPress allows remote attackers to obtain sensitive information via a request that lacks a timezone, leading to disclosure o…
|
CWE-200
Information Exposure
|
CVE-2012-6313
|
2012-12-12 03:56 |
2012-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261624
|
- |
|
google
|
android
|
The Browser application in Android 4.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted market: URI in the SRC attribute of an IFRAME element.
|
CWE-20
Improper Input Validation
|
CVE-2012-6301
|
2012-12-11 14:00 |
2012-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261625
|
- |
|
broadwin
|
webaccess
|
webvrpcs.exe in Advantech/BroadWin WebAccess allows remote attackers to execute arbitrary code or obtain a security-code value via a long string in an RPC request to TCP port 4592.
|
CWE-94
Code Injection
|
CVE-2011-4041
|
2012-12-11 13:27 |
2012-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261626
|
- |
|
kent-web
|
access_report
|
Cross-site scripting (XSS) vulnerability in KENT-WEB ACCESS REPORT 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to access-log data.
|
CWE-79
Cross-site Scripting
|
CVE-2012-5175
|
2012-12-6 20:45 |
2012-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261627
|
- |
|
kent-web
|
access_report
|
Cross-site scripting (XSS) vulnerability in KENT-WEB ACCESS REPORT 5.02 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to tag embedding.
|
CWE-79
Cross-site Scripting
|
CVE-2012-5176
|
2012-12-6 20:45 |
2012-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261628
|
- |
|
vmware
|
springsource_spring_security
|
CRLF injection vulnerability in the logout functionality in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 allows remote attackers to inject arbitrary HTTP headers and conduc…
|
CWE-94
Code Injection
|
CVE-2011-2732
|
2012-12-6 14:00 |
2012-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261629
|
- |
|
siemens
|
scalance_s_firmware scalance_s602 scalance_s612 scalance_s613
|
The web server on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with firmware before 2.3.0.3 does not limit the rate of authentication attempts, which makes it easier …
|
CWE-287
Improper Authentication
|
CVE-2012-1799
|
2012-12-6 13:18 |
2012-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261630
|
- |
|
emc
|
rsa_netwitness_informer
|
The web interface in EMC RSA NetWitness Informer before 2.0.5.6 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
|
CWE-20
Improper Input Validation
|
CVE-2012-4609
|
2012-12-6 01:07 |
2012-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|