CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2012-5182

    Last Modified: 11 Apr 2025

    The Loctouch application 3.4.6 and earlier for Android does not properly handle implicit intents, which allows attackers to obtain sensitive information about logged locations via a crafted application.

    Published: 26 Dec 2012
    2.6
    Low

    CVE-2012-5183

    Last Modified: 11 Apr 2025

    The Loctouch application 3.4.6 and earlier for Android allows attackers to obtain sensitive information about logged locations via a crafted application that leverages read permission for system log files.

    Published: 26 Dec 2012
    4.3
    Medium

    CVE-2012-5584

    Last Modified: 11 Apr 2025

    The Table of Contents module 6.x-3.x before 6.x-3.8 for Drupal does not properly check node permissions, which allows remote attackers to read a node's headers by accessing a table of contents block.

    Published: 26 Dec 2012
    2.1
    Low

    CVE-2012-5585

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Mixpanel module 6.x-1.x before 6.x-1.1 in Drupal allows remote authenticated users with the "access administration pages" permission to inject arbitrary web script or HTML via the Maxpanel token.

    Published: 26 Dec 2012
    2.1
    Low

    CVE-2012-5586

    Last Modified: 11 Apr 2025

    The Services module 6.x-3.x before 6.x-3.3 and 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "access user profiles" permission to access arbitrary users' emails via vectors related to the "user index method" and "the path to the user resource."

    Published: 26 Dec 2012
    4.3
    Medium

    CVE-2012-5587

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Email Field module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the mailto link.

    Published: 26 Dec 2012
    7.5
    High

    CVE-2012-5590

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Webmail Plus module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 26 Dec 2012
    4.3
    Medium

    CVE-2012-5180

    Last Modified: 11 Apr 2025

    The Opera Mobile application before 12.1 and Opera Mini application before 7.5 for Android do not properly implement the WebView class, which allows attackers to obtain sensitive information via a crafted application.

    Published: 26 Dec 2012
    3.5
    Low

    CVE-2012-5589

    Last Modified: 11 Apr 2025

    The MultiLink module 6.x-2.x before 6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal does not properly check node permissions when generating an in-content link, which allows remote authenticated users with text-editing permissions to read arbitrary node titles via a generated link.

    Published: 26 Dec 2012
    2.6
    Low

    CVE-2012-5588

    Last Modified: 11 Apr 2025

    The Email Field module 6.x-1.x before 6.x-1.3 for Drupal, when using a field permission module and the field contact field formatter is set to the full or teaser display mode, does not properly check permissions, which allows remote attackers to email the stored address via unspecified vectors.

    Published: 26 Dec 2012
    4.3
    Medium

    CVE-2012-5591

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Zero Point module 6.x-1.x before 6.x-1.18 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via the path aliases.

    Published: 26 Dec 2012
    4
    Medium

    CVE-2012-0429

    Last Modified: 11 Apr 2025

    dhost in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 on Windows allows remote authenticated users to cause a denial of service (daemon crash) via crafted characters in an HTTP request.

    Published: 25 Dec 2012
    10
    Critical

    CVE-2012-0432

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an unspecified impact via unknown vectors.

    Published: 25 Dec 2012
    4.3
    Medium

    CVE-2012-0428

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Dec 2012
    6.4
    Medium

    CVE-2012-0430

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 on Windows allows remote attackers to obtain an administrator cookie and bypass authorization checks via unknown vectors.

    Published: 25 Dec 2012
    10
    Critical

    CVE-2012-0411

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Novell iPrint Client before 5.82 allows remote attackers to execute arbitrary code via an op-client-interface-version action.

    Published: 24 Dec 2012
    3.3
    Low

    CVE-2012-4046

    Last Modified: 11 Apr 2025

    The D-Link DCS-932L camera with firmware 1.02 allows remote attackers to discover the password via a UDP broadcast packet, as demonstrated by running the D-Link Setup Wizard and reading the _paramR["P"] value.

    Published: 24 Dec 2012
    6.4
    Medium

    CVE-2012-5930

    Last Modified: 11 Apr 2025

    The pa_modify_accounts function in auth.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 does not require authentication for the modifyAccounts method, which allows remote attackers to change the passwords of administrative accounts via a crafted application/x-amf request.

    Published: 24 Dec 2012
    5.5
    Medium

    CVE-2012-5931

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the set_log_config function in regclnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 allows remote authenticated users to create or overwrite arbitrary files via directory traversal sequences in a log pathname.

    Published: 24 Dec 2012
    10
    Critical

    CVE-2012-5932

    Last Modified: 11 Apr 2025

    Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 allows remote attackers to execute arbitrary Perl code via a crafted application/x-amf request.

    Published: 24 Dec 2012
    10
    Critical

    CVE-2012-6428

    Last Modified: 1 Jul 2025

    The Carlo Gavazzi EOS-Box stores hard-coded passwords in the PHP file of the device. By using the hard-coded passwords, attackers can log into the device with administrative privileges. This could allow the attacker to have unauthorized access.

    Published: 23 Dec 2012
    4.3
    Medium

    CVE-2012-4698

    Last Modified: 11 Apr 2025

    Siemens RuggedCom Rugged Operating System (ROS) before 3.12, ROX I OS through 1.14.5, ROX II OS through 2.3.0, and RuggedMax OS through 4.2.1.4621.22 use hardcoded private keys for SSL and SSH communication, which makes it easier for man-in-the-middle attackers to spoof servers and decrypt network traffic by leveraging the availability of these keys within ROS files at all customer installations.

    Published: 23 Dec 2012
    7.8
    High

    CVE-2012-6427

    Last Modified: 1 Jul 2025

    The Carlo Gavazzi EOS-Box does not check the validity of the data before executing queries. By accessing the SQL table of certain pages that do not require authentication, attackers can leak information from the device. This could allow the attacker to compromise confidentiality.

    Published: 23 Dec 2012
    4.7
    Medium

    CVE-2013-2058

    Last Modified: 11 Apr 2025

    The host_start function in drivers/usb/chipidea/host.c in the Linux kernel before 3.7.4 does not properly support a certain non-streaming option, which allows local users to cause a denial of service (system crash) by sending a large amount of network traffic through a USB/Ethernet adapter.

    Published: 22 Dec 2012
    4.4
    Medium

    CVE-2012-5667

    Last Modified: 11 Apr 2025

    Multiple integer overflows in GNU Grep before 2.11 might allow context-dependent attackers to execute arbitrary code via vectors involving a long input line that triggers a heap-based buffer overflow.

    Published: 22 Dec 2012
    5.3
    Medium

    CVE-2017-7829

    Last Modified: 21 Nov 2024

    It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not displayed if preceded by a null character in the display string. This vulnerability affects Thunderbird < 52.5.2.

    Published: 22 Dec 2012
    4
    Medium

    CVE-2012-6324

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 and 5.1 before Patch 1 allows remote authenticated users to read arbitrary files via unspecified vectors.

    Published: 21 Dec 2012
    4.3
    Medium

    CVE-2012-5181

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in concrete5 Japanese 5.5.1 through 5.5.2.1 and concrete5 English 5.5.0 through 5.6.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 21 Dec 2012
    4
    Medium

    CVE-2012-6325

    Last Modified: 11 Apr 2025

    VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 does not properly parse XML documents, which allows remote authenticated users to read arbitrary files via unspecified vectors.

    Published: 21 Dec 2012
    10
    Critical

    CVE-2012-3002

    Last Modified: 11 Apr 2025

    The web interface on (1) Foscam and (2) Wansview IP cameras allows remote attackers to bypass authentication, and perform administrative functions or read the admin password, via a direct request to an unspecified URL.

    Published: 21 Dec 2012
    7.2
    High

    CVE-2012-4859

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in IBM Tivoli Storage Manager for Space Management (aka TSM HSM) before 6.2.5.0 and 6.3.x before 6.3.1.0 allows local users to read or modify file system objects via unknown vectors.

    Published: 21 Dec 2012
    6.4
    Medium

    CVE-2012-5954

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in IBM Tivoli Storage Manager for Space Management (aka TSM HSM) before 6.2.5.0 and 6.3.x before 6.3.1.0 allows remote attackers to read or modify HSM-managed file system objects via unknown vectors.

    Published: 21 Dec 2012
    10
    Critical

    CVE-2012-1712

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Liferay component in Oracle Sun GlassFish Web Space Server before 10.0 Update 7 Patch 2 has unknown impact and attack vectors.

    Published: 21 Dec 2012
    10
    Critical

    CVE-2012-1714

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in a TList 6 ActiveX control in Oracle Hyperion Financial Management 11.1.1.4 and 11.1.2.1.104 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 21 Dec 2012
    6.8
    Medium

    CVE-2012-3133

    Last Modified: 11 Apr 2025

    Buffer overflow in the DataDirect ODBC driver, as used in Oracle Hyperion Interactive Reporting 11.1.2.1 and 11.1.2.2, Essbase Server 11.1.2.1 and 11.1.2.2, Production Reporting Server 11.1.2.1 and 11.1.2.2, and Integration Services Server 11.1.2.1 and 11.1.2.2 has unknown impact and attack vectors.

    Published: 21 Dec 2012
    6.4
    Medium

    CVE-2012-5664

    Last Modified: 13 Feb 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-6496, CVE-2012-6497. Reason: this candidate was intended for one issue, but the candidate was publicly used to label concerns about multiple products. Notes: All CVE users should consult CVE-2012-6496 and CVE-2012-6497 to determine which ID is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 21 Dec 2012
    7.5
    High

    CVE-2012-6089

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in the canoniseFileName function in os/pl-os.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted filename.

    Published: 21 Dec 2012
    7.5
    High

    CVE-2012-6090

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in the expand function in os/pl-glob.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted filename.

    Published: 21 Dec 2012
    7.5
    High

    CVE-2012-6496

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types in certain find_by_ method calls.

    Published: 21 Dec 2012
    9.8
    Critical

    CVE-2012-6094

    Last Modified: 21 Nov 2024

    cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system

    Published: 21 Dec 2012
    4.3
    Medium

    CVE-2012-4839

    Last Modified: 11 Apr 2025

    The OSLC interface in the Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows remote attackers to conduct phishing attacks via a FRAME element.

    Published: 20 Dec 2012
    7.9
    High

    CVE-2012-4856

    Last Modified: 11 Apr 2025

    The Service Processor in the IBM Power 5 91##-### and 940#-### before SF240_418_382 does not ensure that firewall code is executed, which allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 20 Dec 2012
    7.5
    High

    CVE-2012-5469

    Last Modified: 11 Apr 2025

    The Portable phpMyAdmin plugin before 1.3.1 for WordPress allows remote attackers to bypass authentication and obtain phpMyAdmin console access via a direct request to wp-content/plugins/portable-phpmyadmin/wp-pma-mod.

    Published: 20 Dec 2012
    5
    Medium

    CVE-2012-5765

    Last Modified: 11 Apr 2025

    The Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a SQL error message.

    Published: 20 Dec 2012
    10
    Critical

    CVE-2012-5955

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the IBM HTTP Server component 5.3 in IBM WebSphere Application Server (WAS) for z/OS allows remote attackers to execute arbitrary commands via unknown vectors.

    Published: 20 Dec 2012
    9.3
    Critical

    CVE-2012-6271

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player through 11.6.8.638 allows remote attackers to trigger installation of arbitrary signed Xtras via a Shockwave movie that contains an Xtra URL, as demonstrated by a URL for an outdated Xtra.

    Published: 20 Dec 2012
    9.3
    Critical

    CVE-2012-6270

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player through 11.6.8.638 allows remote attackers to trigger installation of a Shockwave Player 10.4.0.025 compatibility feature via a crafted HTML document that references Shockwave content with a certain compatibility parameter, related to a "downgrading" attack.

    Published: 20 Dec 2012
    3.3
    Low

    CVE-2012-3329

    Last Modified: 11 Apr 2025

    IBM Advanced Settings Utility (ASU) through 3.62 and 3.70 through 9.21 and Bootable Media Creator (BoMC) through 2.30 and 3.00 through 9.21 on Linux allow local users to overwrite arbitrary files via a symlink attack on a (1) temporary file or (2) log file.

    Published: 19 Dec 2012
    4.3
    Medium

    CVE-2012-5177

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Welcart plugin before 1.2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 19 Dec 2012
    9.3
    Critical

    CVE-2012-5691

    Last Modified: 11 Apr 2025

    Buffer overflow in RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via a crafted RealMedia file.

    Published: 19 Dec 2012