CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2013-0838

    Last Modified: 11 Apr 2025

    Google Chrome before 24.0.1312.52 on Linux uses weak permissions for shared memory segments, which has unspecified impact and attack vectors.

    Published: 15 Jan 2013
    7.5
    High

    CVE-2012-5148

    Last Modified: 11 Apr 2025

    The hyphenation functionality in Google Chrome before 24.0.1312.52 does not properly validate file names, which has unspecified impact and attack vectors.

    Published: 15 Jan 2013
    5
    Medium

    CVE-2013-0834

    Last Modified: 11 Apr 2025

    Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service (out-of-bounds read) via vectors involving glyphs.

    Published: 15 Jan 2013
    7.5
    High

    CVE-2012-5147

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to DOM handling.

    Published: 15 Jan 2013
    7.5
    High

    CVE-2012-5150

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving seek operations on video data.

    Published: 15 Jan 2013
    7.5
    High

    CVE-2012-5153

    Last Modified: 11 Apr 2025

    Google V8 before 3.14.5.3, as used in Google Chrome before 24.0.1312.52, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers an out-of-bounds access to stack memory.

    Published: 15 Jan 2013
    7.5
    High

    CVE-2012-5154

    Last Modified: 11 Apr 2025

    Integer overflow in Google Chrome before 24.0.1312.52 on Windows allows attackers to cause a denial of service or possibly have unspecified other impact via vectors related to allocation of shared memory.

    Published: 15 Jan 2013
    3.5
    Low

    CVE-2013-0172

    Last Modified: 11 Apr 2025

    Samba 4.0.x before 4.0.1, in certain Active Directory domain-controller configurations, does not properly interpret Access Control Entries that are based on an objectClass, which allows remote authenticated users to bypass intended restrictions on modifying LDAP directory objects by leveraging (1) objectClass access by a user, (2) objectClass access by a group, or (3) write access to an attribute.

    Published: 15 Jan 2013
    4.3
    Medium

    CVE-2013-0221

    Last Modified: 11 Apr 2025

    The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the sort command, when using the (1) -d or (2) -M switch, which triggers a stack-based buffer overflow in the alloca function.

    Published: 15 Jan 2013
    4
    Medium

    CVE-2013-0368

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.

    Published: 15 Jan 2013
    4.3
    Medium

    CVE-2013-0383

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote attackers to affect availability via unknown vectors related to Server Locking.

    Published: 15 Jan 2013
    5
    Medium

    CVE-2012-1702

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier and 5.5.28 and earlier allows remote attackers to affect availability via unknown vectors.

    Published: 15 Jan 2013
    6.8
    Medium

    CVE-2012-5060

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Server component in Oracle MySQL 5.1.65 and earlier and 5.5.27 and earlier allows remote authenticated users to affect availability, related to GIS Extension.

    Published: 15 Jan 2013
    1.9
    Low

    CVE-2013-0223

    Last Modified: 11 Apr 2025

    The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the join command, when using the -i switch, which triggers a stack-based buffer overflow in the alloca function.

    Published: 15 Jan 2013
    4
    Medium

    CVE-2013-0367

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Partition.

    Published: 15 Jan 2013
    4
    Medium

    CVE-2013-0371

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability, related to MyISAM.

    Published: 15 Jan 2013
    6.6
    Medium

    CVE-2013-0385

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows local users to affect confidentiality and integrity via unknown vectors related to Server Replication.

    Published: 15 Jan 2013
    6.8
    Medium

    CVE-2013-0386

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Stored Procedure.

    Published: 15 Jan 2013
    4
    Medium

    CVE-2012-0572

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier and 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.

    Published: 15 Jan 2013
    4
    Medium

    CVE-2012-0574

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote authenticated users to affect availability via unknown vectors.

    Published: 15 Jan 2013
    4
    Medium

    CVE-2012-1705

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier and 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.

    Published: 15 Jan 2013
    5.4
    Medium

    CVE-2013-0375

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.1.28 and earlier, allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Server Replication.

    Published: 15 Jan 2013
    6.8
    Medium

    CVE-2013-0384

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Information Schema.

    Published: 15 Jan 2013
    6.8
    Medium

    CVE-2013-0389

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.

    Published: 15 Jan 2013
    4
    Medium

    CVE-2012-0578

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.

    Published: 15 Jan 2013
    3.5
    Low

    CVE-2012-5096

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users with Server Privileges to affect availability via unknown vectors.

    Published: 15 Jan 2013
    7.5
    High

    CVE-2013-1800

    Last Modified: 11 Apr 2025

    The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156.

    Published: 14 Jan 2013
    5.8
    Medium

    CVE-2013-0751

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 18.0 on Android and SeaMonkey before 2.15 do not restrict a touch event to a single IFRAME element, which allows remote attackers to obtain sensitive information or possibly conduct cross-site scripting (XSS) attacks via a crafted HTML document.

    Published: 13 Jan 2013
    6.5
    Medium

    CVE-2013-0270

    Last Modified: 30 Jul 2026

    A flaw was found in OpenStack Keystone. A remote attacker could exploit this vulnerability by sending a large HTTP request, specifically by providing a long tenant name when requesting a token. This could lead to a denial of service, consuming excessive CPU and memory resources on the affected system.

    Published: 13 Jan 2013
    10
    Critical

    CVE-2012-3174

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java 7 before Update 11 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2013-0422. NOTE: some parties have mapped CVE-2012-3174 to an issue involving recursive use of the Reflection API, but that issue is already covered as part of CVE-2013-0422. This identifier is for a different vulnerability whose details are not public as of 20130114.

    Published: 13 Jan 2013
    5.8
    Medium

    CVE-2011-5252

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in Users/Account/LogOff in Orchard 1.0.x before 1.0.21, 1.1.x before 1.1.31, 1.2.x before 1.2.42, and 1.3.x before 1.3.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the ReturnUrl parameter.

    Published: 12 Jan 2013
    4.3
    Medium

    CVE-2011-5253

    Last Modified: 11 Apr 2025

    Dl Download Ticket Service 0.3 through 0.9 allows remote attackers to login as an arbitrary user by supplying an authorization header.

    Published: 12 Jan 2013
    10
    Critical

    CVE-2011-5254

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Connections plugin before 0.7.1.6 for WordPress has unknown impact and attack vectors.

    Published: 12 Jan 2013
    7.5
    High

    CVE-2012-5874

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in the (1) update_whosonline_reg and (2) update_whosonline_guest functions in Elite Bulletin Board before 2.1.22 allow remote attackers to execute arbitrary SQL commands via the PATH_INFO to (a) checkuser.php, (b) groups.php, (c) index.php, (d) login.php, (e) quicklogin.php, (f) register.php, (g) Search.php, (h) viewboard.php, or (i) viewtopic.php.

    Published: 12 Jan 2013
    5.8
    Medium

    CVE-2012-6499

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in age-verification.php in the Age Verification plugin 0.4 and earlier for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_to parameter.

    Published: 12 Jan 2013
    5
    Medium

    CVE-2012-6500

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in download.lib.php in Pragyan CMS 3.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the fileget parameter in a profile action to index.php.

    Published: 12 Jan 2013
    4.3
    Medium

    CVE-2012-6501

    Last Modified: 11 Apr 2025

    The KillProcess method in the HP PKI ActiveX control (HPPKI.ocx) before 1.2.0.1 allows remote attackers to cause a denial of service (kill process) via the partial or full name of a process.

    Published: 12 Jan 2013
    4.4
    Medium

    CVE-2013-0722

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the scan_load_hosts function in ec_scan.c in Ettercap 0.7.5.1 and earlier might allow local users to gain privileges via a Trojan horse hosts list containing a long line.

    Published: 11 Jan 2013
    Unknown

    CVE-2012-0722

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-0722. Reason: This candidate is a duplicate of CVE-2013-0722. A year-transition issue caused the wrong ID to be used. Notes: All CVE users should reference CVE-2013-0722 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 11 Jan 2013
    4.4
    Medium

    CVE-2012-2251

    Last Modified: 11 Apr 2025

    rssh 2.3.2, as used by Debian, Fedora, and others, when the rsync protocol is enabled, allows local users to bypass intended restricted shell access via a (1) "-e" or (2) "--" command line option.

    Published: 11 Jan 2013
    4.4
    Medium

    CVE-2012-2252

    Last Modified: 11 Apr 2025

    Incomplete blacklist vulnerability in rssh before 2.3.4, when the rsync protocol is enabled, allows local users to bypass intended restricted shell access via the --rsh command line option.

    Published: 11 Jan 2013
    4.3
    Medium

    CVE-2013-0860

    Last Modified: 11 Apr 2025

    The ff_er_frame_end function in libavcodec/error_resilience.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.1 does not properly verify that a frame is fully initialized, which allows remote attackers to trigger a NULL pointer dereference via crafted picture data.

    Published: 11 Jan 2013
    5
    Medium

    CVE-2013-0198

    Last Modified: 11 Apr 2025

    Dnsmasq before 2.66test2, when used with certain libvirt configurations, replies to queries from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via spoofed TCP based DNS queries. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3411.

    Published: 11 Jan 2013
    9.8
    Critical

    CVE-2013-0422

    Last Modified: 21 Apr 2026

    Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServer class to obtain a reference to a private MBeanInstantiator object, then retrieving arbitrary Class references using the findClass method, and (2) using the Reflection API with recursion in a way that bypasses a security check by the java.lang.invoke.MethodHandles.Lookup.checkSecurityManager method due to the inability of the sun.reflect.Reflection.getCallerClass method to skip frames related to the new reflection API, as exploited in the wild in January 2013, as demonstrated by Blackhole and Nuclear Pack, and a different vulnerability than CVE-2012-4681 and CVE-2012-3174. NOTE: some parties have mapped the recursive Reflection API issue to CVE-2012-3174, but CVE-2012-3174 is for a different vulnerability whose details are not public as of 20130114. CVE-2013-0422 covers both the JMX/MBean and Reflection API issues. NOTE: it was originally reported that Java 6 was also vulnerable, but the reporter has retracted this claim, stating that Java 6 is not exploitable because the relevant code is called in a way that does not bypass security checks. NOTE: as of 20130114, a reliable third party has claimed that the findClass/MBeanInstantiator vector was not fixed in Oracle Java 7 Update 11. If there is still a vulnerable condition, then a separate CVE identifier might be created for the unfixed issue.

    Published: 10 Jan 2013
    7.5
    High

    CVE-2013-4118

    Last Modified: 12 Apr 2025

    FreeRDP before 1.1.0-beta1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors.

    Published: 10 Jan 2013
    5
    Medium

    CVE-2013-2014

    Last Modified: 12 Apr 2025

    OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption and crash) via multiple long requests.

    Published: 10 Jan 2013
    7.5
    High

    CVE-2013-4119

    Last Modified: 12 Apr 2025

    FreeRDP before 1.1.0-beta+2013071101 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by disconnecting before authentication has finished.

    Published: 10 Jan 2013
    Unknown

    CVE-2013-0965

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 10 Jan 2013
    Unknown

    CVE-2013-0972

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 10 Jan 2013
    4.3
    Medium

    CVE-2013-1789

    Last Modified: 11 Apr 2025

    splash/Splash.cc in poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to the (1) Splash::arbitraryTransformMask, (2) Splash::blitMask, and (3) Splash::scaleMaskYuXu functions.

    Published: 10 Jan 2013