Search Results (24193 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2013-0178 1 Redislabs 1 Redis 2024-11-21 5.5 Medium
Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.
CVE-2013-0165 1 Redhat 1 Openshift 2024-11-21 7.3 High
cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp.
CVE-2012-6341 1 Netgear 4 Wgr614v7, Wgr614v7 Firmware, Wgr614v9 and 1 more 2024-11-21 6.5 Medium
An Information Disclosure vulnerability exists in the my config file in NEtGEAR WGR614 v7 and v9, which could let a malicious user recover all previously used passwords on the device, for both the control panel and WEP/WPA/WPA2, in plaintext. This is a different issue than CVE-2012-6340.
CVE-2012-6135 2 Phusion, Redhat 2 Passenger, Openshift 2024-11-21 7.5 High
RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.
CVE-2012-6125 1 Call-cc 1 Chicken 2024-11-21 9.8 Critical
Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.
CVE-2012-6123 2 Call-cc, Debian 2 Chicken, Debian Linux 2024-11-21 6.5 Medium
Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."
CVE-2012-6111 2 Debian, Gnome 2 Debian Linux, Gnome Keyring 2024-11-21 7.5 High
gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function
CVE-2012-6091 1 Magentocommerce 1 Magento 2024-11-21 7.5 High
Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure vulnerability.
CVE-2012-6079 1 Boldgrid 1 W3 Total Cache 2024-11-21 7.5 High
W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via their hash keys.
CVE-2012-6078 1 Boldgrid 1 W3 Total Cache 2024-11-21 7.5 High
W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.
CVE-2012-6077 1 Boldgrid 1 W3 Total Cache 2024-11-21 7.5 High
W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files.
CVE-2012-6070 1 Falconpl 1 Falconpl 2024-11-21 7.5 High
Falconpl before 0.9.6.9-git20120606 misuses the libcurl API which may allow remote attackers to interfere with security checks.
CVE-2012-5828 1 Blackberry 2 Playbook, Playbook Firmware 2024-11-21 6.5 Medium
BlackBerry PlayBook before 2.1 has an Information Disclosure Vulnerability via a Web browser component error
CVE-2012-5699 1 Babygekko 1 Babygekko 2024-11-21 9.8 Critical
BabyGekko before 1.2.4 allows PHP file inclusion.
CVE-2012-5644 4 Debian, Fedoraproject, Libuser Project and 1 more 4 Debian Linux, Fedora, Libuser and 1 more 2024-11-21 5.5 Medium
libuser has information disclosure when moving user's home directory
CVE-2012-5582 1 Opendnssec 1 Opendnssec 2024-11-21 9.8 Critical
opendnssec misuses libcurl API
CVE-2012-5570 1 Basic Webmail Project 1 Basic Webmail 2024-11-21 4.3 Medium
The Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allows remote authenticated users with the "access basic_webmail" permission to read arbitrary users' email addresses.
CVE-2012-5535 2 Fedoraproject, Gnome 2 Fedora, Gnome-system-log 2024-11-21 7.5 High
gnome-system-log polkit policy allows arbitrary files on the system to be read
CVE-2012-5476 2 Debian, Openstack 2 Debian Linux, Horizon 2024-11-21 5.5 Medium
Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the admin password and token value.
CVE-2012-5360 1 Ffmpeg 1 Ffmpeg 2024-11-21 N/A
Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted QT file.