CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2013-0758

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allow remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging improper interaction between plugin objects and SVG elements.

    Published: 8 Jan 2013
    9.3
    Critical

    CVE-2013-0761

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the mozilla::TrackUnionStream::EndTrack implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

    Published: 8 Jan 2013
    9.3
    Critical

    CVE-2013-0763

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to Mesa drivers and a resized WebGL canvas.

    Published: 8 Jan 2013
    9.3
    Critical

    CVE-2013-0768

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the Canvas implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via an HTML document that specifies invalid width and height values.

    Published: 8 Jan 2013
    9.3
    Critical

    CVE-2013-0771

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the gfxTextRun::ShrinkToLigatureBoundaries function in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via a crafted document.

    Published: 8 Jan 2013
    10
    Critical

    CVE-2013-1376

    Last Modified: 11 Apr 2025

    Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0606, CVE-2013-0612, CVE-2013-0615, CVE-2013-0617, and CVE-2013-0621.

    Published: 8 Jan 2013
    1.8
    Low

    CVE-2013-7290

    Last Modified: 11 Apr 2025

    The do_item_get function in items.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (segmentation fault) via a request to delete a key, which does not account for the lack of a null terminator in the key and triggers a buffer over-read when printing to stderr, a different vulnerability than CVE-2013-0179.

    Published: 8 Jan 2013
    1.8
    Low

    CVE-2013-7291

    Last Modified: 11 Apr 2025

    memcached before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (crash) via a request that triggers an "unbounded key print" during logging, related to an issue that was "quickly grepped out of the source tree," a different vulnerability than CVE-2013-0179 and CVE-2013-7290.

    Published: 8 Jan 2013
    5.8
    Medium

    CVE-2012-5647

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in node-util/www/html/restorer.php in Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the PATH_INFO.

    Published: 8 Jan 2013
    4.9
    Medium

    CVE-2012-2697

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in autofs, as used in Red Hat Enterprise Linux (RHEL) 5, allows local users to cause a denial of service (autofs crash and delayed mounts) or prevent "mount expiration" via unspecified vectors related to "using an LDAP-based automount map."

    Published: 7 Jan 2013
    3.7
    Low

    CVE-2012-3359

    Last Modified: 12 Apr 2025

    Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac session cookie, which allows attackers to gain privileges by accessing this cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2013-7347 for the incorrect enforcement of a user timeout.

    Published: 7 Jan 2013
    2.1
    Low

    CVE-2013-0160

    Last Modified: 11 Apr 2025

    The Linux kernel through 3.7.9 allows local users to obtain sensitive information about keystroke timing by using the inotify API on the /dev/ptmx device.

    Published: 7 Jan 2013
    4.3
    Medium

    CVE-2012-5531

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the GateIn Portal in JBoss Enterprise Portal Platform 5.2.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 7 Jan 2013
    5
    Medium

    CVE-2013-0183

    Last Modified: 11 Apr 2025

    multipart/parser.rb in Rack 1.3.x before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (memory consumption and out-of-memory error) via a long string in a Multipart HTTP packet.

    Published: 7 Jan 2013
    3.7
    Low

    CVE-2013-7347

    Last Modified: 12 Apr 2025

    Luci in Red Hat Conga does not properly enforce the user session timeout, which might allow attackers to gain access to the session by reading the __ac session cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2012-3359 for the base64-encoded storage of the user and password in a cookie.

    Published: 7 Jan 2013
    2.1
    Low

    CVE-2013-0157

    Last Modified: 11 Apr 2025

    (a) mount and (b) umount in util-linux 2.14.1, 2.17.2, and probably other versions allow local users to determine the existence of restricted directories by (1) using the --guess-fstype command-line option or (2) attempting to mount a non-existent device, which generates different error messages depending on whether the directory exists.

    Published: 5 Jan 2013
    10
    Critical

    CVE-2011-3937

    Last Modified: 11 Apr 2025

    The H.263 codec (libavcodec/h263dec.c) in FFmpeg 0.7.x before 0.7.12, 0.8.x before 0.8.11, and unspecified versions before 0.10, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 has unspecified impact and attack vectors related to "width/height changing with frame threads."

    Published: 5 Jan 2013
    5
    Medium

    CVE-2012-6330

    Last Modified: 11 Apr 2025

    The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to cause a denial of service (memory consumption) via a large integer in a %MAKETEXT% macro.

    Published: 4 Jan 2013
    3.3
    Low

    CVE-2012-6348

    Last Modified: 11 Apr 2025

    Centrify Deployment Manager 2.1.0.283, as distributed in Centrify Suite before 2012.5, allows local users to (1) overwrite arbitrary files via a symlink attack on the adcheckDMoutput temporary file, or (2) overwrite arbitrary files and consequently gain privileges via a symlink attack on the centrify.cmd.0 temporary file.

    Published: 4 Jan 2013
    4.3
    Medium

    CVE-2012-5977

    Last Modified: 11 Apr 2025

    Asterisk Open Source 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2; Certified Asterisk 1.8.11 before 1.8.11-cert10; and Asterisk Digiumphones 10.x-digiumphones before 10.11.1-digiumphones, when anonymous calls are enabled, allow remote attackers to cause a denial of service (resource consumption) by making anonymous calls from multiple sources and consequently adding many entries to the device state cache.

    Published: 4 Jan 2013
    5
    Medium

    CVE-2012-5976

    Last Modified: 11 Apr 2025

    Multiple stack consumption vulnerabilities in Asterisk Open Source 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2; Certified Asterisk 1.8.11 before 1.8.11-cert10; and Asterisk Digiumphones 10.x-digiumphones before 10.11.1-digiumphones allow remote attackers to cause a denial of service (daemon crash) via TCP data using the (1) SIP, (2) HTTP, or (3) XMPP protocol.

    Published: 4 Jan 2013
    5
    Medium

    CVE-2012-6497

    Last Modified: 11 Apr 2025

    The Authlogic gem for Ruby on Rails, when used with certain versions before 3.2.10, makes potentially unsafe find_by_id method calls, which might allow remote attackers to conduct CVE-2012-6496 SQL injection attacks via a crafted parameter in environments that have a known secret_token value, as demonstrated by a value contained in secret_token.rb in an open-source product.

    Published: 4 Jan 2013
    1.9
    Low

    CVE-2013-0154

    Last Modified: 11 Apr 2025

    The get_page_type function in xen/arch/x86/mm.c in Xen 4.2, when debugging is enabled, allows local PV or HVM guest administrators to cause a denial of service (assertion failure and hypervisor crash) via unspecified vectors related to a hypercall.

    Published: 4 Jan 2013
    2.6
    Low

    CVE-2013-0158

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Jenkins before 1.498, Jenkins LTS before 1.480.2, and Jenkins Enterprise 1.447.x before 1.447.6.1 and 1.466.x before 1.466.12.1, when a slave is attached and anonymous read access is enabled, allows remote attackers to obtain the master cryptographic key via unknown vectors.

    Published: 4 Jan 2013
    6.8
    Medium

    CVE-2012-6434

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in e107_admin/download.php in e107 1.0.2 allow remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the (1) download_url, (2) download_url_extended, (3) download_author_email, (4) download_author_website, (5) download_image, (6) download_thumb, (7) download_visible, or (8) download_class parameter.

    Published: 3 Jan 2013
    6.8
    Medium

    CVE-2012-6433

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in e107_admin/newspost.php in e107 1.0.1 allows remote attackers to hijack the authentication of administrators for requests that conduct XSS attacks via the news_title parameter in a create action.

    Published: 3 Jan 2013
    6
    Medium

    CVE-2012-6495

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users with write permissions to overwrite arbitrary files via unspecified vectors. NOTE: this can be leveraged with CVE-2012-6081 to execute arbitrary code.

    Published: 3 Jan 2013
    5
    Medium

    CVE-2012-5651

    Last Modified: 11 Apr 2025

    Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search results.

    Published: 3 Jan 2013
    5
    Medium

    CVE-2012-5652

    Last Modified: 11 Apr 2025

    Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result.

    Published: 3 Jan 2013
    4.3
    Medium

    CVE-2012-5654

    Last Modified: 11 Apr 2025

    The Nodewords: D6 Meta Tags module before 6.x-1.14 for Drupal, when configured to automatically generate description meta tags from node text, does not properly filter node content when creating tags, which might allow remote attackers to obtain sensitive information by reading the (1) description, (2) dc.description or (3) og:description meta tags.

    Published: 3 Jan 2013
    5
    Medium

    CVE-2012-5655

    Last Modified: 11 Apr 2025

    The Context module 6.x-3.x before 6.x-3.1 and 7.x-3.x before 7.x-3.0-beta6 for Drupal does not properly restrict access to block content, which allows remote attackers to obtain sensitive information via a crafted request.

    Published: 3 Jan 2013
    4.3
    Medium

    CVE-2012-5665

    Last Modified: 11 Apr 2025

    ownCloud 4.0.x before 4.0.10 and 4.5.x before 4.5.5 does not properly restrict access to settings.php, which allows remote attackers to edit app configurations of user_webdavauth and user_ldap by editing this file.

    Published: 3 Jan 2013
    4.3
    Medium

    CVE-2012-6082

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the rsslink function in theme/__init__.py in MoinMoin 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the page name in a rss link.

    Published: 3 Jan 2013
    6.4
    Medium

    CVE-2012-6080

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the _do_attachment_move function in the AttachFile action (action/AttachFile.py) in MoinMoin 1.9.3 through 1.9.5 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a file name.

    Published: 3 Jan 2013
    6
    Medium

    CVE-2012-6081

    Last Modified: 11 Apr 2025

    Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users with write permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, as exploited in the wild in July 2012.

    Published: 3 Jan 2013
    6
    Medium

    CVE-2012-5653

    Last Modified: 11 Apr 2025

    The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name.

    Published: 3 Jan 2013
    4.3
    Medium

    CVE-2012-5666

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in bookmarks/js/bookmarks.js in ownCloud 4.0.x before 4.0.10 and 4.5.x before 4.5.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to apps/bookmark/index.php.

    Published: 3 Jan 2013
    4.3
    Medium

    CVE-2013-0743

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA at the suggestion of the CVE project team. The candidate had been associated with a correct report of a security problem, but not a problem that is categorized as a vulnerability within CVE. Compromised or unauthorized SSL certificates are not within CVE's scope. Notes: none

    Published: 3 Jan 2013
    2.1
    Low

    CVE-2012-5561

    Last Modified: 11 Apr 2025

    script/katello-generate-passphrase in Katello 1.1 uses world-readable permissions for /etc/katello/secure/passphrase, which allows local users to obtain the passphrase by reading the file.

    Published: 3 Jan 2013
    5
    Medium

    CVE-2012-6460

    Last Modified: 11 Apr 2025

    Opera before 11.67 and 12.x before 12.02 allows remote attackers to cause truncation of a dialog, and possibly trigger downloading and execution of arbitrary programs, via a crafted web site.

    Published: 2 Jan 2013
    5
    Medium

    CVE-2012-6461

    Last Modified: 11 Apr 2025

    The X.509 certificate-validation functionality in the https implementation in Opera before 12.10 allows remote attackers to trigger a false indication of successful revocation-status checking by causing a failure of a single checking service.

    Published: 2 Jan 2013
    5
    Medium

    CVE-2012-6462

    Last Modified: 11 Apr 2025

    Opera before 12.10 does not properly implement the Cross-Origin Resource Sharing (CORS) specification, which allows remote attackers to bypass intended page-content restrictions via a crafted request.

    Published: 2 Jan 2013
    4.3
    Medium

    CVE-2012-6463

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Opera before 12.10 allows remote attackers to inject arbitrary web script or HTML via vectors involving an unspecified sequence of loading of documents and loading of data: URLs.

    Published: 2 Jan 2013
    4.3
    Medium

    CVE-2012-6464

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Opera before 12.10 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript code that overrides methods of unspecified native objects in documents that have different origins.

    Published: 2 Jan 2013
    9.3
    Critical

    CVE-2012-6465

    Last Modified: 11 Apr 2025

    Opera before 12.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed SVG image.

    Published: 2 Jan 2013
    5
    Medium

    CVE-2012-6466

    Last Modified: 11 Apr 2025

    Opera before 12.10 does not properly handle incorrect size data in a WebP image, which allows remote attackers to obtain potentially sensitive information from process memory by using a crafted image as the fill pattern for a canvas.

    Published: 2 Jan 2013
    5
    Medium

    CVE-2012-6469

    Last Modified: 11 Apr 2025

    Opera before 12.11 allows remote attackers to determine the existence of arbitrary local files via vectors involving web script in an error page.

    Published: 2 Jan 2013
    9.3
    Critical

    CVE-2012-6470

    Last Modified: 11 Apr 2025

    Opera before 12.12 does not properly allocate memory for GIF images, which allows remote attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a malformed image.

    Published: 2 Jan 2013
    5
    Medium

    CVE-2012-6471

    Last Modified: 11 Apr 2025

    Opera before 12.12 allows remote attackers to spoof the address field via a high rate of HTTP requests.

    Published: 2 Jan 2013
    9.3
    Critical

    CVE-2012-6468

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Opera before 12.11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a long HTTP response.

    Published: 2 Jan 2013