CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2012-4351

    Last Modified: 11 Apr 2025

    Integer overflow in pgpwded.sys in Symantec PGP Desktop 10.x and Encryption Desktop 10.3.0 before MP1 allows local users to gain privileges via a crafted application.

    Published: 18 Feb 2013
    4.3
    Medium

    CVE-2012-4352

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Stoneware webNetwork 6.1 before SP1 allow remote attackers to inject arbitrary web script or HTML via the blogName parameter to (1) community/blog.jsp or (2) community/blogSearch.jsp, the (3) calendarType or (4) monthNumber parameter to community/calendar.jsp, or the (5) flag parameter to swDashboard/ajax/setAppFlag.jsp.

    Published: 18 Feb 2013
    4.4
    Medium

    CVE-2012-6533

    Last Modified: 11 Apr 2025

    Buffer overflow in pgpwded.sys in Symantec PGP Desktop 10.x and Encryption Desktop 10.3.0 before MP1 on Windows XP and Server 2003 allows local users to gain privileges via a crafted application.

    Published: 18 Feb 2013
    6.8
    Medium

    CVE-2013-0288

    Last Modified: 11 Apr 2025

    nss-pam-ldapd before 0.7.18 and 0.8.x before 0.8.11 allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code by performing a name lookup on an application with a large number of open file descriptors, which triggers a stack-based buffer overflow related to incorrect use of the FD_SET macro.

    Published: 18 Feb 2013
    4.3
    Medium

    CVE-2013-1808

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in ZeroClipboard.swf and ZeroClipboard10.swf in ZeroClipboard before 1.0.8, as used in em-shorty, RepRapCalculator, Fulcrum, Django, aCMS, and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this is might be the same vulnerability as CVE-2013-1463. If so, it is likely that CVE-2013-1463 will be REJECTed.

    Published: 18 Feb 2013
    4.3
    Medium

    CVE-2012-3499

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in the (1) mod_imagemap, (2) mod_info, (3) mod_ldap, (4) mod_proxy_ftp, and (5) mod_status modules.

    Published: 18 Feb 2013
    4.3
    Medium

    CVE-2012-4558

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer module in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via a crafted string.

    Published: 18 Feb 2013
    2.1
    Low

    CVE-2013-2237

    Last Modified: 11 Apr 2025

    The key_notify_policy_flush function in net/key/af_key.c in the Linux kernel before 3.9 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory by reading a broadcast message from the notify_policy interface of an IPSec key_socket.

    Published: 18 Feb 2013
    4
    Medium

    CVE-2013-0330

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Jenkins before 1.502 and LTS before 1.480.3 allows remote authenticated users with write access to build arbitrary jobs via unknown attack vectors.

    Published: 17 Feb 2013
    6.8
    Medium

    CVE-2013-0327

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Jenkins master in Jenkins before 1.502 and LTS before 1.480.3 allows remote attackers to hijack the authentication of users via unknown vectors.

    Published: 17 Feb 2013
    4
    Medium

    CVE-2013-0331

    Last Modified: 11 Apr 2025

    Jenkins before 1.502 and LTS before 1.480.3 allows remote authenticated users with write access to cause a denial of service via a crafted payload.

    Published: 17 Feb 2013
    4.3
    Medium

    CVE-2013-0328

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Jenkins before 1.502 and LTS before 1.480.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Feb 2013
    7.5
    High

    CVE-2013-0329

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Jenkins before 1.502 and LTS before 1.480.3 allows remote attackers to bypass the CSRF protection mechanism via unknown attack vectors.

    Published: 17 Feb 2013
    7.5
    High

    CVE-2012-6135

    Last Modified: 21 Nov 2024

    RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.

    Published: 17 Feb 2013
    6.5
    Medium

    CVE-2012-3286

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP ArcSight Connector Appliance 6.3 and earlier and ArcSight Logger 5.2 and earlier allows remote authenticated users to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.

    Published: 16 Feb 2013
    6.8
    Medium

    CVE-2012-5199

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP ArcSight Connector Appliance 6.3 and earlier and ArcSight Logger 5.2 and earlier allows remote authenticated users to execute arbitrary code via unknown vectors.

    Published: 16 Feb 2013
    5
    Medium

    CVE-2012-5198

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP ArcSight Connector Appliance before 6.3 and ArcSight Logger 5.2 and earlier allows remote attackers to obtain sensitive information via unknown vectors.

    Published: 16 Feb 2013
    7.6
    High

    CVE-2012-4694

    Last Modified: 11 Apr 2025

    Moxa EDR-G903 series routers with firmware before 2.11 do not use a sufficient source of entropy for (1) SSH and (2) SSL keys, which makes it easier for man-in-the-middle attackers to spoof a device or modify a client-server data stream by leveraging knowledge of a key from a product installation elsewhere.

    Published: 15 Feb 2013
    9.3
    Critical

    CVE-2012-4701

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Tridium Niagara AX 3.5, 3.6, and 3.7 allows remote attackers to read sensitive files, and consequently execute arbitrary code, by leveraging (1) valid credentials or (2) the guest feature.

    Published: 15 Feb 2013
    10
    Critical

    CVE-2012-4711

    Last Modified: 11 Apr 2025

    Buffer overflow in kingMess.exe 65.20.2003.10300 in WellinTech KingView 6.52, kingMess.exe 65.20.2003.10400 in KingView 6.53, and kingMess.exe 65.50.2011.18049 in KingView 6.55 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted packet.

    Published: 15 Feb 2013
    5
    Medium

    CVE-2012-4712

    Last Modified: 11 Apr 2025

    Moxa EDR-G903 series routers with firmware before 2.11 have a hardcoded account, which allows remote attackers to obtain unspecified device access via unknown vectors.

    Published: 15 Feb 2013
    10
    Critical

    CVE-2013-0658

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in RFManagerService.exe in Schneider Electric Accutech Manager 2.00.1 and earlier allows remote attackers to execute arbitrary code via a crafted HTTP request.

    Published: 15 Feb 2013
    4.3
    Medium

    CVE-2013-0703

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in imgboard.com imgboard before 1.22R6.1 u and 20xx before 2010u allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Feb 2013
    4.3
    Medium

    CVE-2013-0704

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the GREE application before 1.3.3 for Android allows remote attackers to obtain sensitive information via a crafted URL, which is not properly handled during interaction with other applications.

    Published: 15 Feb 2013
    5
    Medium

    CVE-2013-0705

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in LSI 3ware Disk Manager (3DM) before 2 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 15 Feb 2013
    4.3
    Medium

    CVE-2013-1123

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the server in Cisco Unified MeetingPlace 7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCuc65411 and CSCue18706.

    Published: 15 Feb 2013
    6.8
    Medium

    CVE-2013-1128

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the server in Cisco Unified MeetingPlace before 7.1(2.2000) allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCuc64903. NOTE: some of these details are obtained from third party information.

    Published: 15 Feb 2013
    10
    Critical

    CVE-2013-1405

    Last Modified: 11 Apr 2025

    VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 before Update 3a, VMware VI-Client 2.5, VMware ESXi 3.5 through 4.1, and VMware ESX 3.5 through 4.1 do not properly implement the management authentication protocol, which allow remote servers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 15 Feb 2013
    5
    Medium

    CVE-2012-1016

    Last Modified: 11 Apr 2025

    The pkinit_server_return_padata function in plugins/preauth/pkinit/pkinit_srv.c in the PKINIT implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.4 attempts to find an agility KDF identifier in inappropriate circumstances, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted Draft 9 request.

    Published: 15 Feb 2013
    6.9
    Medium

    CVE-2013-0871

    Last Modified: 11 Apr 2025

    Race condition in the ptrace functionality in the Linux kernel before 3.7.5 allows local users to gain privileges via a PTRACE_SETREGS ptrace system call in a crafted application, as demonstrated by ptrace_death.

    Published: 15 Feb 2013
    5
    Medium

    CVE-2013-1415

    Last Modified: 11 Apr 2025

    The pkinit_check_kdc_pkid function in plugins/preauth/pkinit/pkinit_crypto_openssl.c in the PKINIT implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.4 and 1.11.x before 1.11.1 does not properly handle errors during extraction of fields from an X.509 certificate, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed KRB5_PADATA_PK_AS_REQ AS-REQ request.

    Published: 15 Feb 2013
    3.3
    Low

    CVE-2012-5564

    Last Modified: 11 Apr 2025

    android-tools 4.1.1 in Android Debug Bridge (ADB) allows local users to overwrite arbitrary files via a symlink attack on /tmp/adb.log.

    Published: 14 Feb 2013
    Unknown

    CVE-2012-6127

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This was originally reported as an issue in jakarta-commons-httpclient involving wildcard matching in the SSL hostname verifier, but further investigation showed that it was not a security issue. Notes: none

    Published: 14 Feb 2013
    5
    Medium

    CVE-2013-1402

    Last Modified: 11 Apr 2025

    DigiLIBE 3.4 and possibly other versions sends a redirect but does not exit, which allows remote attackers to obtain sensitive configuration information via a direct request to configuration/general_configuration.html.

    Published: 14 Feb 2013
    6
    Medium

    CVE-2013-0701

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Cybozu Garoon 2.5.0 through 3.5.3 allows remote authenticated users to execute arbitrary SQL commands by leveraging a logging privilege.

    Published: 14 Feb 2013
    4.3
    Medium

    CVE-2013-0702

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cybozu Garoon 2.0.0 through 3.5.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Feb 2013
    10
    Critical

    CVE-2012-5188

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in mora Downloader before 1.0.0.1 allows remote attackers to trigger the launch of a .exe file via unspecified vectors.

    Published: 14 Feb 2013
    4.3
    Medium

    CVE-2013-4204

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the JUnit files in the GWTTestCase in Google Web Toolkit (GWT) before 2.5.1 RC1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Feb 2013
    7.2
    High

    CVE-2013-0292

    Last Modified: 11 Apr 2025

    The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, which allows local users to gain privileges via a spoofed signal.

    Published: 14 Feb 2013
    4.3
    Medium

    CVE-2013-0281

    Last Modified: 11 Apr 2025

    Pacemaker 1.1.10, when remote Cluster Information Base (CIB) configuration or resource management is enabled, does not limit the duration of connections to the blocking sockets, which allows remote attackers to cause a denial of service (connection blocking).

    Published: 14 Feb 2013
    4.3
    Medium

    CVE-2013-1114

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unity Express before 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCud87527.

    Published: 13 Feb 2013
    5.4
    Medium

    CVE-2013-1100

    Last Modified: 11 Apr 2025

    The HTTP server in Cisco IOS on Catalyst switches does not properly handle TCP socket events, which allows remote attackers to cause a denial of service (device crash) via crafted packets on TCP port (1) 80 or (2) 443, aka Bug ID CSCuc53853.

    Published: 13 Feb 2013
    9
    Critical

    CVE-2013-1111

    Last Modified: 11 Apr 2025

    The Cisco ATA 187 Analog Telephone Adaptor with firmware 9.2.1.0 and 9.2.3.1 before ES build 4 does not properly implement access control, which allows remote attackers to execute operating-system commands via vectors involving a session on TCP port 7870, aka Bug ID CSCtz67038.

    Published: 13 Feb 2013
    5
    Medium

    CVE-2013-1122

    Last Modified: 11 Apr 2025

    Cisco NX-OS on the Nexus 7000, when a certain Overlay Transport Virtualization (OTV) configuration is used, allows remote attackers to cause a denial of service (M1-Series module reload) via crafted packets, aka Bug ID CSCud15673.

    Published: 13 Feb 2013
    6.4
    Medium

    CVE-2013-1131

    Last Modified: 11 Apr 2025

    Cisco Small Business Wireless Access Points WAP200, WAP2000, WAP200E, and WET200 allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted SSID that is not properly handled during a site survey, aka Bug IDs CSCua86182, CSCua91196, CSCud36155, and CSCua86190.

    Published: 13 Feb 2013
    6.3
    Medium

    CVE-2012-3280

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities on HP NonStop Servers H06.x and J06.x allow remote authenticated users to obtain sensitive information, modify data, or cause a denial of service via an OSS Remote Operation over an Expand connection.

    Published: 13 Feb 2013
    10
    Critical

    CVE-2013-0635

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 12.0.0.112 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 13 Feb 2013
    10
    Critical

    CVE-2013-0636

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Adobe Shockwave Player before 12.0.0.112 allows attackers to execute arbitrary code via unspecified vectors.

    Published: 13 Feb 2013
    6.4
    Medium

    CVE-2012-6531

    Last Modified: 11 Apr 2025

    (1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 do not properly handle SimpleXMLElement classes, which allow remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack, a different vulnerability than CVE-2012-3363.

    Published: 13 Feb 2013
    9.1
    Critical

    CVE-2012-3363

    Last Modified: 11 Apr 2025

    Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.

    Published: 13 Feb 2013