CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2012-6360

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Intelligent Operations Center 1.5.0 allows remote attackers to inject arbitrary web script or HTML via event data fields.

    Published: 18 Jan 2013
    5
    Medium

    CVE-2012-5875

    Last Modified: 11 Apr 2025

    Firefly Media Server 1.0.0.1359 allows remote attackers to cause a denial of service (NULL pointer dereference) via a (1) crafted Connection HTTP header; a return carriage control character in the (2) Accept Language header, (3) User-agent header, (4) Host header, or (5) protocol version; or a (6) crafted HTTP protocol version.

    Published: 18 Jan 2013
    4.3
    Medium

    CVE-2012-6088

    Last Modified: 11 Apr 2025

    The rpmpkgRead function in lib/package.c in RPM 4.10.x before 4.10.2 does not return an error code in certain situations involving an "unparseable signature," which allows remote attackers to bypass RPM signature checks via a crafted package.

    Published: 18 Jan 2013
    5
    Medium

    CVE-2013-0250

    Last Modified: 12 Apr 2025

    The init_nss_hash function in exec/totemcrypto.c in Corosync 2.0 before 2.3 does not properly initialize the HMAC key, which allows remote attackers to cause a denial of service (crash) via a crafted packet.

    Published: 18 Jan 2013
    4
    Medium

    CVE-2013-1774

    Last Modified: 11 Apr 2025

    The chase_port function in drivers/usb/serial/io_ti.c in the Linux kernel before 3.7.4 allows local users to cause a denial of service (NULL pointer dereference and system crash) via an attempted /dev/ttyUSB read or write operation on a disconnected Edgeport USB serial converter.

    Published: 18 Jan 2013
    9.3
    Critical

    CVE-2012-4607

    Last Modified: 11 Apr 2025

    Buffer overflow in nsrindexd in EMC NetWorker 7.5.x and 7.6.x before 7.6.5, and 8.x before 8.0.0.6, allows remote attackers to execute arbitrary code via crafted SunRPC data.

    Published: 17 Jan 2013
    3.5
    Low

    CVE-2012-3310

    Last Modified: 11 Apr 2025

    IBM Tivoli Federated Identity Manager (TFIM) before 6.1.1.14, 6.2.0 before 6.2.0.12, and 6.2.1 before 6.2.1.4 allows context-dependent attackers to discover (1) a cleartext LDAP Bind Password, (2) keystore passwords, (3) a cleartext Basic Authentication password from a client, or (4) a cleartext user password by leveraging a logging configuration with a log trace setting of all.

    Published: 17 Jan 2013
    4.6
    Medium

    CVE-2012-5429

    Last Modified: 11 Apr 2025

    The VPN driver in Cisco VPN Client on Windows does not properly interact with the kernel, which allows local users to cause a denial of service (kernel fault and system crash) via a crafted application, aka Bug ID CSCuc81669.

    Published: 17 Jan 2013
    2.6
    Low

    CVE-2012-5972

    Last Modified: 7 Jul 2025

    Directory traversal vulnerability in the web server in SpecView 2.5 build 853 and earlier allows remote attackers to read arbitrary files via a ... (dot dot dot) in a URI.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2012-4689

    Last Modified: 11 Apr 2025

    Integer overflow in CimWebServer.exe in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to cause a denial of service (daemon crash) via a malformed HTTP request.

    Published: 17 Jan 2013
    6.8
    Medium

    CVE-2013-1109

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in testingLibraryAction.do in the Training Center testing library in Cisco WebEx Training Center allows remote attackers to hijack the authentication of arbitrary users for requests that delete tests, aka Bug ID CSCzu81067.

    Published: 17 Jan 2013
    5
    Medium

    CVE-2012-5444

    Last Modified: 11 Apr 2025

    Cisco TelePresence Video Communication Server (VCS) X7.0.3 does not properly process certain search rules, which allows remote attackers to create conferences via an unspecified Conductor request, aka Bug ID CSCub67989.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2012-6397

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cisco WebEx Social (formerly Cisco Quad) allows remote attackers to inject arbitrary web script or HTML via a crafted RSS service link, aka Bug ID CSCub61977.

    Published: 17 Jan 2013
    7.8
    High

    CVE-2012-5419

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliance (ASA) software 8.7.1 and 8.7.1.1 for the Cisco ASA 1000V Cloud Firewall allows remote attackers to cause a denial of service (device reload) via a malformed H.225 H.323 IPv4 packet, aka Bug IDs CSCuc42812 and CSCuc88741.

    Published: 17 Jan 2013
    10
    Critical

    CVE-2012-6392

    Last Modified: 11 Apr 2025

    Cisco Prime LAN Management Solution (LMS) 4.1 through 4.2.2 on Linux does not properly validate authentication and authorization requests in TCP sessions, which allows remote attackers to execute arbitrary commands via a crafted session, aka Bug ID CSCuc79779.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2013-0355

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 10.2.0.5 and 11.1.0.1, and EM DB Control 11.1.0.7, 11.2.0.2, and 11.2.0.3, allows remote attackers to affect integrity via unknown vectors related to Distributed/Cross DB Features.

    Published: 17 Jan 2013
    2.1
    Low

    CVE-2013-0370

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain Products Suite 9.3.1.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2013-0377

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Client System Analyzer.

    Published: 17 Jan 2013
    2.1
    Low

    CVE-2013-0390

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Bookmarkable Pages.

    Published: 17 Jan 2013
    5
    Medium

    CVE-2013-0417

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Sun Storage Common Array Manager (CAM) component in Oracle Sun Products Suite 6.9.0 allows remote attackers to affect confidentiality, related to Fault Management System (FMS).

    Published: 17 Jan 2013
    6.8
    Medium

    CVE-2013-0418

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 and 8.4 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2013-0393. NOTE: the previous information was obtained from the January 2013 CPU. Oracle has not commented on claims from an independent researcher that this is a heap-based buffer overflow in the Paradox database stream filter (vspdx.dll) that can be triggered using a table header with a crafted "number of fields" value.

    Published: 17 Jan 2013
    3.3
    Low

    CVE-2012-0569

    Last Modified: 11 Apr 2025

    Unspecified vulnerability Oracle Sun Solaris 10 allows local users to affect confidentiality and integrity via unknown vectors related to Install/smpatch.

    Published: 17 Jan 2013
    5
    Medium

    CVE-2012-3170

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Siebel CRM component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect availability via unknown vectors related to Siebel Core - Server Infrastructure, a different vulnerability than CVE-2012-3169.

    Published: 17 Jan 2013
    6.6
    Medium

    CVE-2013-0399

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 9 and 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Utility/Umount.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2012-1677

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via unknown vectors.

    Published: 17 Jan 2013
    4
    Medium

    CVE-2012-1680

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Siebel CRM component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Siebel Apps - Multi-channel Technologies.

    Published: 17 Jan 2013
    4
    Medium

    CVE-2012-1700

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Siebel CRM component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Siebel UI Framework.

    Published: 17 Jan 2013
    5
    Medium

    CVE-2012-1701

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Siebel CRM component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect confidentiality via unknown vectors related to Highly Interactive Web UI.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2012-1755

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Products 8.51 allows remote attackers to affect integrity via vectors related to PeopleBooks - PSOL.

    Published: 17 Jan 2013
    4
    Medium

    CVE-2012-3168

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Siebel CRM component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect availability via unknown vectors related to Siebel Core - Server Infrastructure.

    Published: 17 Jan 2013
    6.4
    Medium

    CVE-2012-3190

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Universal Work Queue component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity, related to UWQ Server Issues.

    Published: 17 Jan 2013
    3.5
    Low

    CVE-2012-3192

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Products 8.51 and 8.52 allows remote authenticated users to affect integrity, related to Rich Text Editor (RTE).

    Published: 17 Jan 2013
    5.5
    Medium

    CVE-2012-3218

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Human Resources component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Security Groups.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2012-3219

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 10.2.0.5 and 11.1.0.1; EM DB Control 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3; and EM Plugin for DB 12.1.0.1 and 12.1.0.2 allows remote attackers to affect integrity via unknown vectors related to Storage Management.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2012-5059

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Products 8.51 and 8.52 allows remote attackers to affect integrity via unknown vectors related to Portal, a different vulnerability than CVE-2013-0392.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2013-0353

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 10.2.0.5 and 11.1.0.1; EM DB Control 11.1.0.7, 11.2.0.2, and 11.2.0.3; and EM Plugin for DB 12.1.0.1 allows remote attackers to affect integrity via unknown vectors related to Enterprise Configuration Management.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2013-0354

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 10.2.0.5, and EM DB Control 11.1.0.7, 11.2.0.2, and 11.2.0.3, allows remote attackers to affect integrity via unknown vectors related to Policy Framework.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2013-0356

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Products 8.51 and 8.52 allows remote attackers to affect integrity, related to PIA Core Technology.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2013-0357

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Products 8.52 allows remote attackers to affect integrity, related to PIA Core Technology.

    Published: 17 Jan 2013
    7.5
    High

    CVE-2013-0359

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the APM - Application Performance Management component in Oracle Enterprise Manager Grid Control 6.5, 11.1, and 12.1.0.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Business Transaction Management.

    Published: 17 Jan 2013
    7.8
    High

    CVE-2013-0362

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2013-0363 and CVE-2013-0364.

    Published: 17 Jan 2013
    7.8
    High

    CVE-2013-0363

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2013-0362 and CVE-2013-0364.

    Published: 17 Jan 2013
    7.8
    High

    CVE-2013-0364

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2013-0362 and CVE-2013-0363.

    Published: 17 Jan 2013
    4
    Medium

    CVE-2013-0365

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Siebel CRM component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.

    Published: 17 Jan 2013
    10
    Critical

    CVE-2013-0366

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2013-0361.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2013-0373

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 10.2.0.5 and 11.1.0.1; EM DB Control 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3; and EM Plugin for DB 12.1.0.1, and 12.1.0.2 allows remote attackers to affect integrity via unknown vectors related to Distributed/Cross DB Features.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2013-0378

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Siebel CRM component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect integrity via unknown vectors related to Siebel Calendar, a different vulnerability than CVE-2013-0379.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2013-0379

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Siebel CRM component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect integrity via unknown vectors related to Siebel Calendar, a different vulnerability than CVE-2013-0378.

    Published: 17 Jan 2013
    6.4
    Medium

    CVE-2013-0382

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Campaign Management.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2013-0387

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Products 8.51 and 8.52 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to PeopleCode.

    Published: 17 Jan 2013