CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2012-6472

    Last Modified: 11 Apr 2025

    Opera before 12.12 on UNIX uses weak permissions for the profile directory, which allows local users to obtain sensitive information by reading a (1) cache file, (2) password file, or (3) configuration file, or (4) possibly gain privileges by modifying or overwriting a configuration file.

    Published: 2 Jan 2013
    5
    Medium

    CVE-2013-0721

    Last Modified: 11 Apr 2025

    wp-php-widget.php in the WP PHP widget plugin 1.0.2 for WordPress allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.

    Published: 2 Jan 2013
    4.3
    Medium

    CVE-2012-6467

    Last Modified: 11 Apr 2025

    Opera before 12.10 follows Internet shortcuts that are referenced by a (1) IMG element or (2) other inline element, which makes it easier for remote attackers to conduct phishing attacks via a crafted web site, as exploited in the wild in November 2012.

    Published: 2 Jan 2013
    4.3
    Medium

    CVE-2012-6093

    Last Modified: 11 Apr 2025

    The QSslSocket::sslErrors function in Qt before 4.6.5, 4.7.x before 4.7.6, 4.8.x before 4.8.5, when using certain versions of openSSL, uses an "incompatible structure layout" that can read memory from the wrong location, which causes Qt to report an incorrect error when certificate validation fails and might cause users to make unsafe security decisions to accept a certificate.

    Published: 2 Jan 2013
    5
    Medium

    CVE-2012-6084

    Last Modified: 11 Apr 2025

    modules/m_capab.c in (1) ircd-ratbox before 3.0.8 and (2) Charybdis before 3.4.2 does not properly support capability negotiation during server handshakes, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed request.

    Published: 1 Jan 2013
    4.3
    Medium

    CVE-2012-6459

    Last Modified: 11 Apr 2025

    ConnMan 1.3 on Tizen continues to list the bluetooth service after offline mode has been enabled, which might allow remote attackers to obtain sensitive information via Bluetooth packets.

    Published: 1 Jan 2013
    7.5
    High

    CVE-2012-6426

    Last Modified: 28 May 2025

    LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended access-control restrictions via crafted SAML data.

    Published: 1 Jan 2013
    4.3
    Medium

    CVE-2012-4970

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web management interface on Polycom HDX Video End Points with UC APL software before 2.7.1.1_J, and commercial software before 3.0.5, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 Jan 2013
    5
    Medium

    CVE-2012-5573

    Last Modified: 11 Apr 2025

    The connection_edge_process_relay_cell function in or/relay.c in Tor before 0.2.3.25 maintains circuits even if an unexpected SENDME cell arrives, which might allow remote attackers to cause a denial of service (memory consumption or excessive cell reception rate) or bypass intended flow-control restrictions via a RELAY_COMMAND_SENDME command.

    Published: 1 Jan 2013
    5.8
    Medium

    CVE-2012-5769

    Last Modified: 11 Apr 2025

    IBM SPSS Modeler 14.0, 14.1, 14.2 through FP3, and 15.0 before FP2 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference.

    Published: 1 Jan 2013
    5
    Medium

    CVE-2013-0189

    Last Modified: 11 Apr 2025

    cachemgr.cgi in Squid 3.1.x and 3.2.x, possibly 3.1.22, 3.2.4, and other versions, allows remote attackers to cause a denial of service (resource consumption) via a crafted request. NOTE: this issue is due to an incorrect fix for CVE-2012-5643, possibly involving an incorrect order of arguments or incorrect comparison.

    Published: 1 Jan 2013
    3.3
    Low

    CVE-2012-6371

    Last Modified: 11 Apr 2025

    The WPA2 implementation on the Belkin N900 F9K1104v1 router establishes a WPS PIN based on 6 digits of the LAN/WLAN MAC address, which makes it easier for remote attackers to obtain access to a Wi-Fi network by reading broadcast packets, a different vulnerability than CVE-2012-4366.

    Published: 31 Dec 2012
    5.8
    Medium

    CVE-2011-5251

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in forum/login.php in vBulletin 4.1.3 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter in a lostpw action.

    Published: 31 Dec 2012
    7.5
    High

    CVE-2012-4688

    Last Modified: 10 Jul 2025

    The Central application in i-GEN opLYNX before 2.01.9 allows remote attackers to bypass authentication via vectors involving the disabling of browser JavaScript support.

    Published: 31 Dec 2012
    7.5
    High

    CVE-2012-5642

    Last Modified: 11 Apr 2025

    server/action.py in Fail2ban before 0.8.8 does not properly handle the content of the matches tag, which might allow remote attackers to trigger unsafe behavior in a custom action file via unspecified symbols in this content.

    Published: 31 Dec 2012
    2.9
    Low

    CVE-2012-6334

    Last Modified: 11 Apr 2025

    The Track My Mobile feature in the SamsungDive subsystem for Android on Samsung Galaxy devices does not properly implement Location APIs, which allows physically proximate attackers to provide arbitrary location data via a "commonly available simple GPS location spoofer."

    Published: 31 Dec 2012
    3.3
    Low

    CVE-2012-6335

    Last Modified: 11 Apr 2025

    The Anti-theft service in AVG AntiVirus for Android allows physically proximate attackers to provide arbitrary location data via a "commonly available simple GPS location spoofer."

    Published: 31 Dec 2012
    3.3
    Low

    CVE-2012-6336

    Last Modified: 11 Apr 2025

    The Missing Device feature in Lookout allows physically proximate attackers to provide arbitrary location data via a "commonly available simple GPS location spoofer."

    Published: 31 Dec 2012
    3.3
    Low

    CVE-2012-6337

    Last Modified: 11 Apr 2025

    The Track My Mobile feature in the SamsungDive subsystem for Android on Samsung Galaxy devices shows the activation of remote tracking, which might allow physically proximate attackers to defeat a product-recovery effort by tampering with this feature or its location data.

    Published: 31 Dec 2012
    4.3
    Medium

    CVE-2012-6339

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface in Cerberus FTP Server before 5.0.6.0 allow (1) remote attackers to inject arbitrary web script or HTML via a log entry that is not properly handled within the Log Manager component, and might allow (2) remote authenticated administrators to inject arbitrary web script or HTML via a Messages field to the servermanager program.

    Published: 31 Dec 2012
    4.3
    Medium

    CVE-2012-6453

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the RSS Reader extension before 0.2.6 for MediaWiki allows remote attackers to inject arbitrary web script or HTML via a crafted feed.

    Published: 31 Dec 2012
    2.1
    Low

    CVE-2013-0222

    Last Modified: 11 Apr 2025

    The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the uniq command, which triggers a stack-based buffer overflow in the alloca function.

    Published: 31 Dec 2012
    8.8
    High

    CVE-2012-4792

    Last Modified: 22 Apr 2026

    Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and exploited in the wild in December 2012.

    Published: 30 Dec 2012
    5.8
    Medium

    CVE-2012-6085

    Last Modified: 11 Apr 2025

    The read_block function in g10/import.c in GnuPG 1.4.x before 1.4.13 and 2.0.x through 2.0.19, when importing a key, allows remote attackers to corrupt the public keyring database or cause a denial of service (application crash) via a crafted length field of an OpenPGP packet.

    Published: 29 Dec 2012
    5.8
    Medium

    CVE-2012-0738

    Last Modified: 11 Apr 2025

    IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during scanning, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary certificate.

    Published: 28 Dec 2012
    5.8
    Medium

    CVE-2012-0741

    Last Modified: 11 Apr 2025

    IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during use of the Manual Explore Proxy feature, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary certificate.

    Published: 28 Dec 2012
    3.5
    Low

    CVE-2012-3870

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in objects/createobject.php in Open Constructor 3.12.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) name or (2) description parameter.

    Published: 28 Dec 2012
    6.8
    Medium

    CVE-2012-5445

    Last Modified: 11 Apr 2025

    The kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software before 9.3.1-ES10 does not properly validate unspecified system calls, which allows attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a crafted binary.

    Published: 28 Dec 2012
    4.3
    Medium

    CVE-2012-6369

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Troubleshooting Reporting System feature in AgileBits 1Password 3.9.9 might allow remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header that is not properly handled in a View Troubleshooting Report action.

    Published: 28 Dec 2012
    4.3
    Medium

    CVE-2012-3872

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Open Constructor 3.12.0 allow remote attackers to inject arbitrary web script or HTML via (1) the result parameter to data/file/edit.php, (2) the q parameter to confirm.php, or (3) the keyword parameter to users/users.php.

    Published: 28 Dec 2012
    3.5
    Low

    CVE-2012-3871

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in data/hybrid/i_hybrid.php in Open Constructor 3.12.0 allows remote authenticated users to inject arbitrary web script or HTML via the header parameter.

    Published: 28 Dec 2012
    6.5
    Medium

    CVE-2012-3873

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Open Constructor 3.12.0 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) data/gallery/edit.php, (2) data/guestbook/edit.php, (3) data/file/edit.php, (4) data/htmltext/edit.php, (5) data/publication/edit.php, or (6) data/event/edit.php.

    Published: 28 Dec 2012
    5
    Medium

    CVE-2012-4528

    Last Modified: 11 Apr 2025

    The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.

    Published: 28 Dec 2012
    4.3
    Medium

    CVE-2012-4932

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in SimpleInvoices before stable-2012-1-CIS3000 allow remote attackers to inject arbitrary web script or HTML via (1) the having parameter in a manage action to index.php; (2) the Email field in an Add User action; (3) the Customer Name field in an Add Customer action; the (4) Street address, (5) Street address 2, (6) City, (7) Zip code, (8) State, (9) Country, (10) Mobile Phone, (11) Phone, (12) Fax, (13) Email, (14) PayPal business name, (15) PayPal notify url, (16) PayPal return url, (17) Eway customer ID, (18) Custom field 1, (19) Custom field 2, (20) Custom field 3, or (21) Custom field 4 field in an Add Biller action; (22) the Customer field in an Add Invoice action; the (23) Invoice or (24) Notes field in a Process Payment action; (25) the Payment type description field in a Payment Types action; (26) the Description field in an Invoice Preferences action; (27) the Description field in a Manage Products action; or (28) the Description field in a Tax Rates action.

    Published: 28 Dec 2012
    6.4
    Medium

    CVE-2012-6431

    Last Modified: 11 Apr 2025

    Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, which allows remote attackers to bypass intended URI restrictions via a doubly encoded string.

    Published: 27 Dec 2012
    6.8
    Medium

    CVE-2012-6432

    Last Modified: 11 Apr 2025

    Symfony 2.0.x before 2.0.20, 2.1.x before 2.1.5, and 2.2-dev, when the internal routes configuration is enabled, allows remote attackers to access arbitrary services via vectors involving a URI beginning with a /_internal substring.

    Published: 27 Dec 2012
    2.6
    Low

    CVE-2012-5868

    Last Modified: 11 Apr 2025

    WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.

    Published: 27 Dec 2012
    4.4
    Medium

    CVE-2013-3302

    Last Modified: 11 Apr 2025

    Race condition in the smb_send_rqst function in fs/cifs/transport.c in the Linux kernel before 3.7.2 allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via vectors involving a reconnection event.

    Published: 27 Dec 2012
    4.7
    Medium

    CVE-2013-2015

    Last Modified: 11 Apr 2025

    The ext4_orphan_del function in fs/ext4/namei.c in the Linux kernel before 3.7.3 does not properly handle orphan-list entries for non-journal filesystems, which allows physically proximate attackers to cause a denial of service (system hang) via a crafted filesystem on removable media, as demonstrated by the e2fsprogs tests/f_orphan_extents_inode/image.gz test.

    Published: 27 Dec 2012
    4.3
    Medium

    CVE-2012-0958

    Last Modified: 11 Apr 2025

    content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted webpage.

    Published: 26 Dec 2012
    2.1
    Low

    CVE-2012-0961

    Last Modified: 11 Apr 2025

    Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x before 0.8.16~exp12ubuntu10.7, and 0.9.7.5ubuntu5.x before 0.9.7.5ubuntu5.2, as used in Ubuntu, uses world-readable permissions for /var/log/apt/term.log, which allows local users to obtain sensitive shell information by reading the log file.

    Published: 26 Dec 2012
    4.3
    Medium

    CVE-2012-0962

    Last Modified: 11 Apr 2025

    Aptdaemon 0.43 in Ubuntu 11.10 and 12.04 LTS uses short IDs when importing PPA GPG keys from a keyserver, which allows remote attackers to install arbitrary package repository GPG keys via a man-in-the-middle (MITM) attack.

    Published: 26 Dec 2012
    9.3
    Critical

    CVE-2012-5161

    Last Modified: 11 Apr 2025

    The XML Service interface in Citrix XenApp 6.5 and 6.5 Feature Pack 1 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 26 Dec 2012
    5
    Medium

    CVE-2012-6314

    Last Modified: 11 Apr 2025

    Citrix XenDesktop Virtual Desktop Agent (VDA) 5.6.x before 5.6.200, when making changes to the server-side policy that control USB redirection, does not propagate changes to the VDA, which allows authenticated users to retain access to the USB device.

    Published: 26 Dec 2012
    5
    Medium

    CVE-2012-4616

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Web UI in EMC Data Protection Advisor (DPA) 5.6 through SP1, 5.7 through SP1, and 5.8 through SP4 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 26 Dec 2012
    10
    Critical

    CVE-2012-6298

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in CA IdentityMinder r12.0 through CR16, r12.5 before SP15, and r12.6 GA allows remote attackers to execute arbitrary commands or modify data via unknown vectors.

    Published: 26 Dec 2012
    10
    Critical

    CVE-2012-6299

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in CA IdentityMinder r12.0 through CR16, r12.5 before SP15, and r12.6 GA allows remote attackers to bypass intended access restrictions via unknown vectors.

    Published: 26 Dec 2012
    7.2
    High

    CVE-2012-5951

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in IBM Tivoli NetView 1.4, 5.1 through 5.4, and 6.1 on z/OS allows local users to gain privileges by leveraging access to the normal Unix System Services (USS) security level.

    Published: 26 Dec 2012
    7.5
    High

    CVE-2012-4816

    Last Modified: 11 Apr 2025

    IBM Rational Automation Framework (RAF) 3.x through 3.0.0.5 allows remote attackers to bypass intended Env Gen Wizard (aka Environment Generation Wizard) access restrictions by visiting context roots in HTTP sessions on port 8080.

    Published: 26 Dec 2012
    2.1
    Low

    CVE-2012-5179

    Last Modified: 11 Apr 2025

    The Boat Browser application before 4.2 and Boat Browser Mini application before 3.9 for Android do not properly implement the WebView class, which allows attackers to obtain sensitive information via a crafted application.

    Published: 26 Dec 2012