CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2012-6518

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in mod.php in DiY-CMS 1.0 allows remote attackers to hijack the authentication of administrators for requests that create a poll via an add action to the poll module.

    Published: 24 Jan 2013
    7.5
    High

    CVE-2012-6519

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in modules/poll/index.php in DIY-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the start parameter to mod.php.

    Published: 24 Jan 2013
    7.5
    High

    CVE-2012-6520

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in the advanced search in Wikidforum 2.10 allow remote attackers to execute arbitrary SQL commands via the (1) select_sort or (2) opt_search_select parameters. NOTE: this issue could not be reproduced by third parties.

    Published: 24 Jan 2013
    4.3
    Medium

    CVE-2012-6513

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php/Admin_Preferences in gpEasy CMS 2.3.3 allows remote attackers to inject arbitrary web script or HTML via the jsoncallback parameter.

    Published: 24 Jan 2013
    4.3
    Medium

    CVE-2012-6506

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Zingiri Web Shop plugin 2.4.0 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in zing.inc.php or (2) notes parameter in fws/pages-front/onecheckout.php.

    Published: 24 Jan 2013
    6.8
    Medium

    CVE-2012-6508

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in NetArt Media Car Portal 3.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change arbitrary user passwords via a nouveau action in the security module to cars/ADMIN/index.php; (2) create a user or (3) create a sub user via a sub_accounts action in the home module to USERS/index.php; or (4) change profile information via an edit action in the profile module to USERS/index.php.

    Published: 24 Jan 2013
    4.3
    Medium

    CVE-2012-6521

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in apps/admin/handlers/versions.php in Elefant CMS 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter to admin/versions.

    Published: 24 Jan 2013
    6.8
    Medium

    CVE-2012-1922

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Sitecom WLM-2501 allow remote attackers to hijack the authentication of administrators for requests that modify settings for (1) Mac Filtering via admin/formFilter, (2) IP/Port Filtering via formFilter, (3) Port Forwarding via formPortFw, (4) Wireless Access Control via admin/formWlAc, (5) Wi-Fi Protected Setup via formWsc, (6) URL Blocking Filter via formURL, (7) Domain Blocking Filter via formDOMAINBLK, and (8) IP Address ACL Filter via admin/formACL in goform/, different vectors than CVE-2012-1921.

    Published: 24 Jan 2013
    4.6
    Medium

    CVE-2012-4542

    Last Modified: 11 Apr 2025

    block/scsi_ioctl.c in the Linux kernel through 3.8 does not properly consider the SCSI device class during authorization of SCSI commands, which allows local users to bypass intended access restrictions via an SG_IO ioctl call that leverages overlapping opcodes.

    Published: 24 Jan 2013
    4.3
    Medium

    CVE-2011-4575

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the JMX console in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 24 Jan 2013
    5.8
    Medium

    CVE-2012-3370

    Last Modified: 11 Apr 2025

    The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 returns the credentials of the previous user when a security context is not provided, which allows remote attackers to gain privileges as other users.

    Published: 24 Jan 2013
    4.9
    Medium

    CVE-2012-5478

    Last Modified: 11 Apr 2025

    The AuthorizationInterceptor in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 does not properly restrict access, which allows remote authenticated users to bypass intended role restrictions and perform arbitrary JMX operations via unspecified vectors.

    Published: 24 Jan 2013
    6.2
    Medium

    CVE-2013-0268

    Last Modified: 11 Apr 2025

    The msr_open function in arch/x86/kernel/msr.c in the Linux kernel before 3.7.6 allows local users to bypass intended capability restrictions by executing a crafted application as root, as demonstrated by msr32.c.

    Published: 24 Jan 2013
    6.8
    Medium

    CVE-2012-0874

    Last Modified: 11 Apr 2025

    The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 do not require authentication by default in certain profiles, which might allow remote attackers to invoke MBean methods and execute arbitrary code via unspecified vectors. NOTE: this issue can only be exploited when the interceptor is not properly configured with a "second layer of authentication," or when used in conjunction with other vulnerabilities that bypass this second layer.

    Published: 24 Jan 2013
    4
    Medium

    CVE-2012-3369

    Last Modified: 11 Apr 2025

    The CallerIdentityLoginModule in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to gain privileges of the previous user via a null password, which causes the previous user's password to be used.

    Published: 24 Jan 2013
    7.1
    High

    CVE-2012-5689

    Last Modified: 11 Apr 2025

    ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA rewrite rule, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for an AAAA record.

    Published: 24 Jan 2013
    7.5
    High

    CVE-2013-0209

    Last Modified: 11 Apr 2025

    lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote attackers to conduct eval injection and SQL injection attacks via crafted parameters, as demonstrated by an eval injection attack against the core_drop_meta_for_table function, leading to execution of arbitrary Perl code.

    Published: 23 Jan 2013
    Unknown

    CVE-2012-6315

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-0209. Reason: This candidate is a reservation duplicate of CVE-2013-0209. Notes: All CVE users should reference CVE-2013-0209 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 23 Jan 2013
    5
    Medium

    CVE-2013-0199

    Last Modified: 12 Apr 2025

    The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes, which allow remote attackers to obtain the Cross-Realm Kerberos Trust key via unspecified vectors.

    Published: 23 Jan 2013
    7.9
    High

    CVE-2012-5484

    Last Modified: 11 Apr 2025

    The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.

    Published: 23 Jan 2013
    3.7
    Low

    CVE-2013-0219

    Last Modified: 11 Apr 2025

    System Security Services Daemon (SSSD) before 1.9.4, when (1) creating, (2) copying, or (3) removing a user home directory tree, allows local users to create, modify, or delete arbitrary files via a symlink attack on another user's files.

    Published: 23 Jan 2013
    5
    Medium

    CVE-2013-0220

    Last Modified: 11 Apr 2025

    The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname function in responder/autofs/autofssrv_cmd.c and the (3) ssh_cmd_parse_request function in responder/ssh/sshsrv_cmd.c in System Security Services Daemon (SSSD) before 1.9.4 allow remote attackers to cause a denial of service (out-of-bounds read, crash, and restart) via a crafted SSSD packet.

    Published: 23 Jan 2013
    5.8
    Medium

    CVE-2012-4918

    Last Modified: 11 Apr 2025

    Call of Duty Elite for iOS 2.0.1 does not properly validate the server SSL certificate, which allows remote attackers to obtain sensitive information via a Man-in-the-Middle (MITM) attack.

    Published: 22 Jan 2013
    1.5
    Low

    CVE-2012-5616

    Last Modified: 11 Apr 2025

    Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf log file, which allows local users to obtain (1) the SSH private key as recorded by the createSSHKeyPair API, (2) the password of an added host as recorded by the AddHost API, or the password of an added VM as recorded by the (3) DeployVM or (4) ResetPasswordForVM API.

    Published: 22 Jan 2013
    5
    Medium

    CVE-2012-3364

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in the Near Field Communication Controller Interface (NCI) in the Linux kernel before 3.4.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via incoming frames with crafted length fields.

    Published: 22 Jan 2013
    7.5
    High

    CVE-2012-6096

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2, 1.7.x before 1.7.4, and 1.8.x before 1.8.4, might allow remote attackers to execute arbitrary code via a long (1) host_name variable (host parameter) or (2) svc_description variable.

    Published: 22 Jan 2013
    2.6
    Low

    CVE-2012-6502

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer before 10 allows remote attackers to obtain sensitive information about the existence of files, and read certain data from files, via a UNC share pathname in the SRC attribute of a SCRIPT element, as demonstrated by reading a name-value pair from a local file via a \\127.0.0.1\C$\ sequence.

    Published: 22 Jan 2013
    4.6
    Medium

    CVE-2013-0151

    Last Modified: 11 Apr 2025

    The do_hvm_op function in xen/arch/x86/hvm/hvm.c in Xen 4.2.x on the x86_32 platform does not prevent HVM_PARAM_NESTEDHVM (aka nested virtualization) operations, which allows guest OS users to cause a denial of service (long-duration page mappings and host OS crash) by leveraging administrative access to an HVM guest in a domain with a large number of VCPUs.

    Published: 22 Jan 2013
    4.7
    Medium

    CVE-2013-0152

    Last Modified: 11 Apr 2025

    Memory leak in Xen 4.2 and unstable allows local HVM guests to cause a denial of service (host memory consumption) by performing nested virtualization in a way that triggers errors that are not properly handled.

    Published: 22 Jan 2013
    7.6
    High

    CVE-2013-0929

    Last Modified: 11 Apr 2025

    Format string vulnerability in the _vsnsprintf function in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote attackers to execute arbitrary code via format string specifiers in a command.

    Published: 21 Jan 2013
    4
    Medium

    CVE-2013-1110

    Last Modified: 11 Apr 2025

    Cisco WebEx Training Center allow remote authenticated users to bypass intended privilege restrictions and (1) enable or (2) disable training-center recordings via a crafted URL, aka Bug ID CSCzu81065.

    Published: 21 Jan 2013
    7.2
    High

    CVE-2012-2291

    Last Modified: 11 Apr 2025

    EMC Avamar Client 4.x, 5.x, and 6.x on HP-UX and Mac OS X, and the EMC Avamar plugin 4.x, 5.x, and 6.x for Oracle, uses world-writable permissions for cache directories, which allows local users to gain privileges via an unspecified symlink attack.

    Published: 21 Jan 2013
    10
    Critical

    CVE-2012-6069

    Last Modified: 2 Jul 2025

    The CoDeSys Runtime Toolkit’s file transfer functionality does not perform input validation, which allows an attacker to access files and directories outside the intended scope. This may allow an attacker to upload and download any file on the device. This could allow the attacker to affect the availability, integrity, and confidentiality of the device.

    Published: 21 Jan 2013
    6.8
    Medium

    CVE-2013-0656

    Last Modified: 11 Apr 2025

    Buffer overflow in a third-party ActiveX component in Siemens SIMATIC RF-MANAGER 2008, and RF-MANAGER Basic 3.0 and earlier, allows remote attackers to execute arbitrary code via a crafted web site.

    Published: 21 Jan 2013
    9.3
    Critical

    CVE-2013-0928

    Last Modified: 11 Apr 2025

    The NetWorker command processor in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote attackers to execute arbitrary commands via a DCP "run command" operation.

    Published: 21 Jan 2013
    4
    Medium

    CVE-2013-1108

    Last Modified: 11 Apr 2025

    Cisco WebEx Training Center allows remote authenticated users to remove hands-on lab-session reservations via a crafted URL, aka Bug ID CSCzu81064.

    Published: 21 Jan 2013
    9.8
    Critical

    CVE-2012-6068

    Last Modified: 2 Jul 2025

    The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service.

    Published: 21 Jan 2013
    9.3
    Critical

    CVE-2013-0655

    Last Modified: 11 Apr 2025

    The client in Schneider Electric Software Update (SESU) Utility 1.0.x and 1.1.x does not ensure that updates have a valid origin, which allows man-in-the-middle attackers to spoof updates, and consequently execute arbitrary code, by modifying the data stream on TCP port 80.

    Published: 21 Jan 2013
    10
    Critical

    CVE-2013-0657

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote attackers to execute arbitrary code by sending TCP port-12397 data that does not comply with a protocol.

    Published: 21 Jan 2013
    2.1
    Low

    CVE-2013-0162

    Last Modified: 11 Apr 2025

    The diff_pp function in lib/gauntlet_rubyparser.rb in the ruby_parser gem 3.1.1 and earlier for Ruby allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.

    Published: 21 Jan 2013
    4.6
    Medium

    CVE-2013-1819

    Last Modified: 11 Apr 2025

    The _xfs_buf_find function in fs/xfs/xfs_buf.c in the Linux kernel before 3.7.6 does not validate block numbers, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the ability to mount an XFS filesystem containing a metadata inode with an invalid extent map.

    Published: 21 Jan 2013
    6.2
    Medium

    CVE-2013-0313

    Last Modified: 11 Apr 2025

    The evm_update_evmxattr function in security/integrity/evm/evm_crypto.c in the Linux kernel before 3.7.5, when the Extended Verification Module (EVM) is enabled, allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an attempted removexattr operation on an inode of a sockfs filesystem.

    Published: 21 Jan 2013
    4.3
    Medium

    CVE-2012-5184

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Olive Toast Documents Pro File Viewer (formerly Files HD) app before 1.11.1 for iOS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 19 Jan 2013
    7.5
    High

    CVE-2012-5185

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Olive Toast Documents Pro File Viewer (formerly Files HD) app before 1.11.1 for iOS allows remote attackers to read or delete files by leveraging guest access.

    Published: 19 Jan 2013
    4.9
    Medium

    CVE-2012-6396

    Last Modified: 11 Apr 2025

    Cisco NX-OS on Nexus 7000 series switches does not properly handle certain line-card replacements, which might allow remote authenticated users to cause a denial of service (memory consumption) via a crafted configuration that references interfaces that do not exist on the new card, aka Bug ID CSCud44300.

    Published: 19 Jan 2013
    7.2
    High

    CVE-2009-4738

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in JustSystems Corporation ATOK 2006 through 2009 and ATOK flat-rate service, and Just Smile 4 with the ATOK Smile module, allows physically proximate users to bypass the screen lock and execute commands with system privileges via unknown vectors related to "launching external applications."

    Published: 18 Jan 2013
    6.8
    Medium

    CVE-2009-5134

    Last Modified: 11 Apr 2025

    Buffer overflow in the "create torrent dialog" functionality in uTorrent 1.8.3 build 15772, and possibly other versions before 1.8.3 (Build 16010), allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a text file containing a large string. NOTE: some of these details are obtained from third party information.

    Published: 18 Jan 2013
    6.3
    Medium

    CVE-2012-5717

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliances (ASA) devices with firmware 8.x through 8.4(1) do not properly manage SSH sessions, which allows remote authenticated users to cause a denial of service (device crash) by establishing multiple sessions, aka Bug ID CSCtc59462.

    Published: 18 Jan 2013
    6.3
    Medium

    CVE-2012-6395

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliances (ASA) devices with firmware 8.4 do not properly validate unspecified input related to UNC share pathnames, which allows remote authenticated users to cause a denial of service (device crash) via unknown vectors, aka Bug ID CSCuc65775.

    Published: 18 Jan 2013
    4.3
    Medium

    CVE-2012-6359

    Last Modified: 11 Apr 2025

    IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.11, 6.2.1 before 6.2.1.3, and 6.2.2 before 6.2.2.2 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.11, 6.2.1 before 6.2.1.3, and 6.2.2 before 6.2.2.2 do not check whether an OpenID attribute is signed in the (1) SREG (aka simple registration extension) and (2) AX (aka attribute exchange extension) cases, which allows man-in-the-middle attackers to spoof OpenID provider data by inserting unsigned attributes.

    Published: 18 Jan 2013