CVE-2012-0676
published 2012-05-11CVE-2012-0676: WebKit in Apple Safari before 5.1.7 does not properly track state information during the processing of form input, which allows remote attackers to fill in…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
2.08%
79.7th percentile
WebKit in Apple Safari before 5.1.7 does not properly track state information during the processing of form input, which allows remote attackers to fill in form fields on the pages of arbitrary web sites via unspecified vectors.
Affected
76 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | <= 5.1.6 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rq8p-47fw-3qqv: WebKit in Apple Safari before 5
ghsa_unreviewed·2022-05-17
CVE-2012-0676 [MEDIUM] CWE-20 GHSA-rq8p-47fw-3qqv: WebKit in Apple Safari before 5
WebKit in Apple Safari before 5.1.7 does not properly track state information during the processing of form input, which allows remote attackers to fill in form fields on the pages of arbitrary web sites via unspecified vectors.
Red Hat
kernel: kvm: irqchip_in_kernel() and vcpu->arch.apic inconsistency
vendor_redhat·2012-02-07·CVSS 4.9
CVE-2012-1601 [MEDIUM] kernel: kvm: irqchip_in_kernel() and vcpu->arch.apic inconsistency
kernel: kvm: irqchip_in_kernel() and vcpu->arch.apic inconsistency
The KVM implementation in the Linux kernel before 3.3.6 allows host OS users to cause a denial of service (NULL pointer dereference and host OS crash) by making a KVM_CREATE_IRQCHIP ioctl call after a virtual CPU already exists.
Statement: This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise MRG as they did not provide support for the KVM subsystem. This has been addressed in Red Hat Enterprise Linux 6 via https://rhn.redhat.com/errata/RHSA-2012-0571.html. This has been addressed in Red Hat Enterprise Linux 5 via RHSA-2012:0676 https://rhn.redhat.com/errata/RHSA-2012-0676.html.
Package: kvm (Red Hat Enterprise Linux 5) - Affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) -
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2012/May/msg00002.htmlhttp://osvdb.org/81787http://secunia.com/advisories/47292http://support.apple.com/kb/HT5282http://www.securitytracker.com/id?1027053https://exchange.xforce.ibmcloud.com/vulnerabilities/75474http://lists.apple.com/archives/security-announce/2012/May/msg00002.htmlhttp://osvdb.org/81787http://secunia.com/advisories/47292http://support.apple.com/kb/HT5282http://www.securitytracker.com/id?1027053https://exchange.xforce.ibmcloud.com/vulnerabilities/75474
2012-05-11
Published