CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2012-5969

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities on the Huawei E585 device allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the PATH_INFO of an sdcard/ request or (2) modify arbitrary files via a .. (dot dot) in the req_page parameter to en/sms.cgi.

    Published: 19 Dec 2012
    6.1
    Medium

    CVE-2012-5970

    Last Modified: 11 Apr 2025

    The Huawei E585 device allows remote attackers to cause a denial of service (NULL pointer dereference and device outage) via crafted HTTP requests, as demonstrated by unspecified vulnerability-scanning software.

    Published: 19 Dec 2012
    6.8
    Medium

    CVE-2012-5178

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Welcart plugin before 1.2.2 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that complete a purchase.

    Published: 19 Dec 2012
    9.3
    Critical

    CVE-2012-5690

    Last Modified: 11 Apr 2025

    RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allow remote attackers to execute arbitrary code via a RealAudio file that triggers access to an invalid pointer.

    Published: 19 Dec 2012
    4.8
    Medium

    CVE-2012-5968

    Last Modified: 11 Apr 2025

    The Huawei E585 device does not validate the status of admin sessions, which allows remote attackers to obtain sensitive user information and the session ID, and modify data, by leveraging access to the LAN network.

    Published: 19 Dec 2012
    6.8
    Medium

    CVE-2012-5992

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add administrative accounts via screens/aaa/mgmtuser_create.html or (2) insert XSS sequences via the headline parameter to screens/base/web_auth_custom.html, aka Bug ID CSCud50283.

    Published: 19 Dec 2012
    3.5
    Low

    CVE-2012-4848

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Foundations Start before 1.2.2c allow remote authenticated users to inject arbitrary web script or HTML via a Webconfig Users user-attribute field, as demonstrated by the (1) First Name or (2) Last Name field.

    Published: 19 Dec 2012
    4.3
    Medium

    CVE-2012-4846

    Last Modified: 11 Apr 2025

    IBM Lotus Notes 8.5.x before 8.5.3 FP3 does not include the HTTPOnly flag in a Set-Cookie header for a web-application cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, aka SPRs JMAS7TRNLN and SRAO8U3Q68.

    Published: 19 Dec 2012
    6.5
    Medium

    CVE-2012-5967

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in menuXML.php in Centreon 2.3.3 through 2.3.9-4 (fixed in Centreon web 2.6.0) allows remote authenticated users to execute arbitrary SQL commands via the menu parameter.

    Published: 19 Dec 2012
    5
    Medium

    CVE-2012-5978

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in the (1) View Connection Server and (2) View Security Server in VMware View 4.x before 4.6.2 and 5.x before 5.1.2 allow remote attackers to read arbitrary files via unspecified vectors.

    Published: 19 Dec 2012
    6.3
    Medium

    CVE-2012-5991

    Last Modified: 11 Apr 2025

    screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to cause a denial of service (device reload) via a certain buttonClicked value in an internal webauth_type request, aka Bug ID CSCud50209.

    Published: 19 Dec 2012
    4.3
    Medium

    CVE-2012-6007

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to inject arbitrary web script or HTML via the headline parameter, aka Bug ID CSCud65187, a different vulnerability than CVE-2012-5992.

    Published: 19 Dec 2012
    7.2
    High

    CVE-2012-4348

    Last Modified: 11 Apr 2025

    The management console in Symantec Endpoint Protection (SEP) 11.0 before RU7-MP3 and 12.1 before RU2, and Symantec Endpoint Protection Small Business Edition 12.x before 12.1 RU2, does not properly validate input for PHP scripts, which allows remote authenticated users to execute arbitrary code via unspecified vectors.

    Published: 18 Dec 2012
    7.2
    High

    CVE-2012-4350

    Last Modified: 11 Apr 2025

    Multiple unquoted Windows search path vulnerabilities in the (1) Manager and (2) Agent components in Symantec Enterprise Security Manager (ESM) before 11.0 allow local users to gain privileges via unspecified vectors.

    Published: 18 Dec 2012
    3.3
    Low

    CVE-2012-4691

    Last Modified: 23 May 2025

    Memory leak in Siemens Automation License Manager (ALM) 4.x and 5.x before 5.2 allows remote attackers to cause a denial of service (memory consumption) via crafted packets.

    Published: 18 Dec 2012
    1.9
    Low

    CVE-2012-4693

    Last Modified: 11 Apr 2025

    Invensys Wonderware InTouch 2012 R2 and earlier and Siemens ProcessSuite use a weak encryption algorithm for data in Ps_security.ini, which makes it easier for local users to discover passwords by reading this file.

    Published: 18 Dec 2012
    6.1
    Medium

    CVE-2012-4898

    Last Modified: 9 Jul 2025

    Mesh OS before 7.9.1.1 on Tropos wireless mesh routers does not use a sufficient source of entropy for SSH keys, which makes it easier for man-in-the-middle attackers to spoof a device or modify a client-server data stream by leveraging knowledge of a key from a product installation elsewhere.

    Published: 18 Dec 2012
    4.3
    Medium

    CVE-2012-5606

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.9 and 4.5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) file name to apps/files_versions/js/versions.js or (2) apps/files/js/filelist.js; or (3) event title to 3rdparty/fullcalendar/js/fullcalendar.js.

    Published: 18 Dec 2012
    5
    Medium

    CVE-2012-5607

    Last Modified: 11 Apr 2025

    The "Lost Password" reset functionality in ownCloud before 4.0.9 and 4.5.0 does not properly check the security token, which allows remote attackers to change an accounts password via unspecified vectors related to a "Remote Timing Attack."

    Published: 18 Dec 2012
    4.3
    Medium

    CVE-2012-5608

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in apps/user_webdavauth/settings.php in ownCloud 4.5.x before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via arbitrary POST parameters.

    Published: 18 Dec 2012
    6.5
    Medium

    CVE-2012-5609

    Last Modified: 11 Apr 2025

    Incomplete blacklist vulnerability in lib/migrate.php in ownCloud before 4.5.2 allows remote authenticated users to execute arbitrary PHP code by uploading a crafted mount.php file in a ZIP file.

    Published: 18 Dec 2012
    6.5
    Medium

    CVE-2012-5610

    Last Modified: 11 Apr 2025

    Incomplete blacklist vulnerability in lib/filesystem.php in ownCloud before 4.0.9 and 4.5.x before 4.5.2 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a special crafted name.

    Published: 18 Dec 2012
    7.5
    High

    CVE-2012-5468

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in iconvert.c in the bogolexer component in Bogofilter before 1.2.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an email containing a base64 string that is decoded to incomplete multibyte characters.

    Published: 18 Dec 2012
    5
    Medium

    CVE-2012-5574

    Last Modified: 11 Apr 2025

    lib/form/sfForm.class.php in Symfony CMS before 1.4.20 allows remote attackers to read arbitrary files via a crafted upload request.

    Published: 18 Dec 2012
    6.5
    Medium

    CVE-2012-4549

    Last Modified: 14 May 2026

    A flaw was found in JBoss Enterprise Application Platform. The `processInvocation` function within the `org.jboss.as.ejb3.security.AuthorizationInterceptor` component incorrectly authorizes all requests when no roles are defined for an Enterprise Java Beans (EJB) method invocation. This allows attackers to bypass intended access restrictions for EJB methods, leading to unauthorized access to sensitive functionalities.

    Published: 18 Dec 2012
    4.3
    Medium

    CVE-2012-3428

    Last Modified: 11 Apr 2025

    The IronJacamar container before 1.0.12.Final for JBoss Application Server, when allow-multiple-users is enabled in conjunction with a security domain, does not use the credentials supplied in a getConnection function call, which allows remote attackers to obtain access to an arbitrary datasource connection in opportunistic circumstances via an invalid connection attempt.

    Published: 18 Dec 2012
    9.3
    Critical

    CVE-2012-6422

    Last Modified: 11 Apr 2025

    The kernel in Samsung Galaxy S2, Galaxy Note 2, MEIZU MX, and possibly other Android devices, when running an Exynos 4210 or 4412 processor, uses weak permissions (0666) for /dev/exynos-mem, which allows attackers to read or write arbitrary physical memory and gain privileges via a crafted application, as demonstrated by ExynosAbuse.

    Published: 18 Dec 2012
    5
    Medium

    CVE-2012-5643

    Last Modified: 11 Apr 2025

    Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x before 3.1.22, 3.2.x before 3.2.4, and 3.3.x before 3.3.0.2 allow remote attackers to cause a denial of service (memory consumption) via (1) invalid Content-Length headers, (2) long POST requests, or (3) crafted authentication credentials.

    Published: 17 Dec 2012
    5.5
    Medium

    CVE-2012-5656

    Last Modified: 11 Apr 2025

    The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.

    Published: 17 Dec 2012
    2.1
    Low

    CVE-2012-6115

    Last Modified: 11 Apr 2025

    The domain management tool (rhevm-manage-domains) in Red Hat Enterprise Virtualization Manager (RHEV-M) 3.1 and earlier, when the validate action is enabled, logs the administrative password to a world-readable log file, which allows local users to obtain sensitive information by reading this file.

    Published: 17 Dec 2012
    2.1
    Low

    CVE-2012-5658

    Last Modified: 11 Apr 2025

    rhc-chk.rb in Red Hat OpenShift Origin before 1.1, when -d (debug mode) is used, outputs the password and other sensitive information in cleartext, which allows context-dependent attackers to obtain sensitive information, as demonstrated by including log files or Bugzilla reports in support channels.

    Published: 17 Dec 2012
    9.3
    Critical

    CVE-2012-6075

    Last Modified: 11 Apr 2025

    Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.

    Published: 16 Dec 2012
    4.3
    Medium

    CVE-2012-5668

    Last Modified: 11 Apr 2025

    FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to BDF fonts and the improper handling of an "allocation error" in the bdf_free_font function.

    Published: 15 Dec 2012
    4.3
    Medium

    CVE-2012-5670

    Last Modified: 11 Apr 2025

    The _bdf_parse_glyphs function in FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) via vectors related to BDF fonts and an ENCODING field with a negative value.

    Published: 15 Dec 2012
    4.3
    Medium

    CVE-2012-5669

    Last Modified: 11 Apr 2025

    The _bdf_parse_glyphs function in FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to BDF fonts and an incorrect calculation that triggers an out-of-bounds read.

    Published: 15 Dec 2012
    7.5
    High

    CVE-2013-1969

    Last Modified: 11 Apr 2025

    Multiple use-after-free vulnerabilities in libxml2 2.9.0 and possibly other versions might allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to the (1) htmlParseChunk and (2) xmldecl_done functions, as demonstrated by a buffer overflow in the xmlBufGetInputBase function.

    Published: 14 Dec 2012
    2.1
    Low

    CVE-2012-3276

    Last Modified: 11 Apr 2025

    HP OpenVMS 8.3, 8.3-1H1, and 8.4 on the Itanium platform and 7.3-2, 8.2, 8.3, and 8.4 on the Alpha platform does not properly implement the LOGIN and ACME_SERVER ACMELOGIN programs, which allows local users to cause a denial of service via unspecified vectors.

    Published: 13 Dec 2012
    5
    Medium

    CVE-2012-3277

    Last Modified: 11 Apr 2025

    HP OpenVMS 8.3, 8.3-1H1, and 8.4 on the Itanium platform and 7.3-2, 8.2, 8.3, and 8.4 on the Alpha platform does not properly implement the LOGIN and ACME_SERVER ACMELOGIN programs, which allows remote attackers to cause a denial of service via unspecified vectors.

    Published: 13 Dec 2012
    8.5
    High

    CVE-2012-4991

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in Axway SecureTransport 5.1 SP2 and earlier allow remote authenticated users to (1) read, (2) delete, or (3) create files, or (4) list directories, via a ..%5C (encoded dot dot backslash) in a URI.

    Published: 13 Dec 2012
    10
    Critical

    CVE-2012-5680

    Last Modified: 11 Apr 2025

    Buffer overflow in Adobe Photoshop Camera Raw before 7.3 allows attackers to execute arbitrary code via unspecified vectors.

    Published: 13 Dec 2012
    4
    Medium

    CVE-2012-5966

    Last Modified: 11 Apr 2025

    The restricted telnet shell on the D-Link DSL2730U router allows remote authenticated users to bypass intended command restrictions via shell metacharacters that follow a whitelisted command.

    Published: 13 Dec 2012
    7.5
    High

    CVE-2012-5679

    Last Modified: 11 Apr 2025

    Buffer underflow in Adobe Photoshop Camera Raw before 7.3 allows attackers to execute arbitrary code via unspecified vectors.

    Published: 13 Dec 2012
    4
    Medium

    CVE-2012-5374

    Last Modified: 11 Apr 2025

    The CRC32C feature in the Btrfs implementation in the Linux kernel before 3.8-rc1 allows local users to cause a denial of service (extended runtime of kernel code) by creating many different files whose names are associated with the same CRC32C hash value.

    Published: 13 Dec 2012
    4
    Medium

    CVE-2012-5375

    Last Modified: 11 Apr 2025

    The CRC32C feature in the Btrfs implementation in the Linux kernel before 3.8-rc1 allows local users to cause a denial of service (prevention of file creation) by leveraging the ability to write to a directory important to the victim, and creating a file with a crafted name that is associated with a specific CRC32C hash value.

    Published: 13 Dec 2012
    6.5
    Medium

    CVE-2012-5639

    Last Modified: 13 Feb 2025

    LibreOffice and OpenOffice automatically open embedded content

    Published: 13 Dec 2012
    6.5
    Medium

    CVE-2012-4974

    Last Modified: 11 Apr 2025

    Layton Helpbox 4.4.0 allows remote authenticated users to change the login context and gain privileges via a modified (1) loggedinenduser, (2) loggedinendusername, (3) loggedinuserusergroup, (4) loggedinuser, or (5) loggedinusername cookie.

    Published: 12 Dec 2012
    4
    Medium

    CVE-2012-4975

    Last Modified: 11 Apr 2025

    editrequestuser.asp in Layton Helpbox 4.4.0 allows remote authenticated users to change arbitrary support-ticket data via a modified sys_request_id parameter.

    Published: 12 Dec 2012
    10
    Critical

    CVE-2012-5140

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 23.0.1271.97 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the URL loader.

    Published: 12 Dec 2012
    10
    Critical

    CVE-2012-5141

    Last Modified: 11 Apr 2025

    Google Chrome before 23.0.1271.97 does not properly restrict instantiation of the Chromoting client plug-in, which has unspecified impact and attack vectors.

    Published: 12 Dec 2012
    10
    Critical

    CVE-2012-5142

    Last Modified: 11 Apr 2025

    Google Chrome before 23.0.1271.97 does not properly handle history navigation, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.

    Published: 12 Dec 2012