Show filters
115 Total Results
Displaying 71-80 of 115
Sort by:
Attacker Value
Unknown

CVE-2012-3867

Disclosure Date: August 06, 2012 (last updated October 04, 2023)
lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Request (CSR), which makes it easier for user-assisted remote attackers to trick administrators into signing a crafted agent certificate via ANSI control sequences.
0
Attacker Value
Unknown

CVE-2012-3954

Disclosure Date: July 25, 2012 (last updated October 04, 2023)
Multiple memory leaks in ISC DHCP 4.1.x and 4.2.x before 4.2.4-P1 and 4.1-ESV before 4.1-ESV-R6 allow remote attackers to cause a denial of service (memory consumption) by sending many requests.
0
Attacker Value
Unknown

CVE-2012-3571

Disclosure Date: July 25, 2012 (last updated October 04, 2023)
ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed client identifier.
0
Attacker Value
Unknown

CVE-2012-0876

Disclosure Date: July 03, 2012 (last updated October 04, 2023)
The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.
0
Attacker Value
Unknown

CVE-2012-0950

Disclosure Date: June 19, 2012 (last updated October 04, 2023)
The Apport hook (DistUpgradeApport.py) in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uploads the /var/log/dist-upgrade directory when reporting bugs to Launchpad, which allows remote attackers to read repository credentials by viewing a public bug report. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0949.
0
Attacker Value
Unknown

CVE-2011-3193

Disclosure Date: June 16, 2012 (last updated October 04, 2023)
Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.
0
Attacker Value
Unknown

CVE-2011-4409

Disclosure Date: June 16, 2012 (last updated October 04, 2023)
The Ubuntu One Client for Ubuntu 10.04 LTS, 11.04, 11.10, and 12.04 LTS does not properly validate SSL certificates, which allows remote attackers to spoof a server and modify or read sensitive information via a man-in-the-middle (MITM) attack.
0
Attacker Value
Unknown

CVE-2011-4408

Disclosure Date: June 16, 2012 (last updated October 04, 2023)
The Single Sign On Client (ubuntu-sso-client) for Ubuntu 11.04 and 11.10 does not properly validate SSL certificates when using HTTPS, which allows remote attackers to spoof a server and modify or read sensitive data via a man-in-the-middle (MITM) attack.
0
Attacker Value
Unknown

CVE-2012-0948

Disclosure Date: June 07, 2012 (last updated October 04, 2023)
DistUpgrade/DistUpgradeMain.py in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uses weak permissions for (1) apt-clone_system_state.tar.gz and (2) system_state.tar.gz, which allows local users to obtain repository credentials.
0
Attacker Value
Unknown

CVE-2012-0259

Disclosure Date: June 05, 2012 (last updated October 04, 2023)
The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a zero value in the component count of an EXIF XResolution tag in a JPEG file, which triggers an out-of-bounds read.