Show filters
301 Total Results
Displaying 211-220 of 301
Sort by:
Attacker Value
Unknown

CVE-2012-5953

Disclosure Date: February 20, 2013 (last updated October 05, 2023)
IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2, when the Parse Query Strings option is enabled on an HTTPInput node, allows remote attackers to cause a denial of service (infinite loop) via a crafted query string.
0
Attacker Value
Unknown

CVE-2012-5952

Disclosure Date: February 20, 2013 (last updated October 05, 2023)
IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2 does not validate Basic Authentication credentials before proceeding to WS-Addressing and WS-Security operations, which allows remote attackers to trigger transmission of unauthenticated messages via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-3317

Disclosure Date: December 05, 2012 (last updated October 05, 2023)
IBM WebSphere Message Broker 6.1 before 6.1.0.11, 7.0 before 7.0.0.5, and 8.0 before 8.0.0.2 has incorrect ownership of certain uninstaller Java Runtime Environment (JRE) files, which might allow local users to gain privileges by leveraging access to uid 501 or gid 300.
0
Attacker Value
Unknown

CVE-2012-5792

Disclosure Date: November 04, 2012 (last updated October 05, 2023)
The Sage Pay Direct module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0
Attacker Value
Unknown

CVE-2012-0303

Disclosure Date: July 05, 2012 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Brightmail Control Center in Symantec Message Filter 6.3 allow remote attackers to hijack the authentication of arbitrary users for requests that (1) execute application commands or (2) create admin accounts.
0
Attacker Value
Unknown

CVE-2012-0300

Disclosure Date: July 05, 2012 (last updated October 04, 2023)
Brightmail Control Center in Symantec Message Filter 6.3 does not properly restrict establishment of sessions to the listening port, which allows remote attackers to obtain potentially sensitive version information via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-0301

Disclosure Date: July 05, 2012 (last updated October 04, 2023)
Session fixation vulnerability in Brightmail Control Center in Symantec Message Filter 6.3 allows remote attackers to hijack web sessions via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-0302

Disclosure Date: July 05, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Brightmail Control Center in Symantec Message Filter 6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-1483

Disclosure Date: March 15, 2012 (last updated October 04, 2023)
Unspecified vulnerability in the Message Forwarder (com.gmail.zbnetium) application 1.12.20110409.1 for Android has unknown impact and attack vectors.
0
Attacker Value
Unknown

CVE-2012-1407

Disclosure Date: March 07, 2012 (last updated October 04, 2023)
Unspecified vulnerability in the GO Message Widget (com.gau.go.launcherex.gowidget.smswidget) application 1.9, 2.1, and 2.3 for Android has unknown impact and attack vectors.
0