CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2009-2899

    Last Modified: 11 Apr 2025

    The monitor perl script in the Sybase database plug-in in SpringSource Hyperic HQ before 4.3 allows local users to obtain the database password by listing the process and its arguments.

    Published: 5 Dec 2012
    6.9
    Medium

    CVE-2012-3317

    Last Modified: 11 Apr 2025

    IBM WebSphere Message Broker 6.1 before 6.1.0.11, 7.0 before 7.0.0.5, and 8.0 before 8.0.0.2 has incorrect ownership of certain uninstaller Java Runtime Environment (JRE) files, which might allow local users to gain privileges by leveraging access to uid 501 or gid 300.

    Published: 5 Dec 2012
    6.8
    Medium

    CVE-2012-4608

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the web interface in EMC RSA NetWitness Informer before 2.0.5.6 allows remote attackers to hijack the authentication of arbitrary users.

    Published: 5 Dec 2012
    4.3
    Medium

    CVE-2012-4609

    Last Modified: 11 Apr 2025

    The web interface in EMC RSA NetWitness Informer before 2.0.5.6 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

    Published: 5 Dec 2012
    5.8
    Medium

    CVE-2012-4982

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the a parameter.

    Published: 5 Dec 2012
    4.3
    Medium

    CVE-2012-4983

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities on the Forescout CounterACT NAC device before 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the a parameter to assets/login or (2) the query parameter to assets/rangesearch.

    Published: 5 Dec 2012
    4.3
    Medium

    CVE-2012-4985

    Last Modified: 11 Apr 2025

    The Forescout CounterACT NAC device 6.3.4.1 does not block ARP and ICMP traffic from unrecognized clients, which allows remote attackers to conduct ARP poisoning attacks via crafted packets.

    Published: 5 Dec 2012
    5
    Medium

    CVE-2012-4347

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in the management console in Symantec Messaging Gateway (SMG) 9.5.x allow remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) logFile parameter in a logs action to brightmail/export or (2) localBackupFileSelection parameter in an APPLIANCE restoreSource action to brightmail/admin/restore/download.do.

    Published: 5 Dec 2012
    2.1
    Low

    CVE-2012-4862

    Last Modified: 11 Apr 2025

    The Host Connect emulator in IBM Rational Developer for System z 7.1 through 8.5.1 does not properly store the SSL certificate password, which allows local users to obtain sensitive information via unspecified vectors.

    Published: 5 Dec 2012
    9.3
    Critical

    CVE-2012-6066

    Last Modified: 11 Apr 2025

    freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demonstrated by an OpenSSH client with modified versions of ssh.c and sshconnect2.c.

    Published: 4 Dec 2012
    10
    Critical

    CVE-2012-6067

    Last Modified: 11 Apr 2025

    freeFTPd.exe in freeFTPd through 1.0.11 allows remote attackers to bypass authentication via a crafted SFTP session, as demonstrated by an OpenSSH client with modified versions of ssh.c and sshconnect2.c.

    Published: 4 Dec 2012
    9.3
    Critical

    CVE-2012-5975

    Last Modified: 11 Apr 2025

    The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6.2.5, and 6.3.0 through 6.3.2 on UNIX and Linux, when old-style password authentication is enabled, allows remote attackers to bypass authentication via a crafted session involving entry of blank passwords, as demonstrated by a root login session from a modified OpenSSH client with an added input_userauth_passwd_changereq call in sshconnect2.c.

    Published: 4 Dec 2012
    10
    Critical

    CVE-2012-5137

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 23.0.1271.95 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the Media Source API.

    Published: 4 Dec 2012
    10
    Critical

    CVE-2012-5138

    Last Modified: 11 Apr 2025

    Google Chrome before 23.0.1271.95 does not properly handle file paths, which has unspecified impact and attack vectors.

    Published: 4 Dec 2012
    3.7
    Low

    CVE-2011-4316

    Last Modified: 11 Apr 2025

    Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, in certain unspecified conditions, does not lock the desktop screen between SPICE sessions, which allows local users with access to a virtual machine to gain access to other users' desktop sessions via unspecified vectors.

    Published: 4 Dec 2012
    3.3
    Low

    CVE-2012-3538

    Last Modified: 11 Apr 2025

    Pulp in Red Hat CloudForms before 1.1 logs administrative passwords in a world-readable file, which allows local users to read pulp administrative passwords by reading production.log.

    Published: 4 Dec 2012
    2.6
    Low

    CVE-2012-4534

    Last Modified: 11 Apr 2025

    org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response.

    Published: 4 Dec 2012
    2.1
    Low

    CVE-2012-4574

    Last Modified: 11 Apr 2025

    Pulp in Red Hat CloudForms before 1.1 uses world-readable permissions for pulp.conf, which allows local users to read the administrative password by reading this file.

    Published: 4 Dec 2012
    2.1
    Low

    CVE-2012-5605

    Last Modified: 11 Apr 2025

    Grinder in Red Hat CloudForms before 1.1 uses world-writable permissions for /var/lib/pulp/cache/grinder/, which allows local users to modify grinder cache files.

    Published: 4 Dec 2012
    7.8
    High

    CVE-2012-5688

    Last Modified: 11 Apr 2025

    ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.

    Published: 4 Dec 2012
    6.2
    Medium

    CVE-2012-0860

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, allow local users to gain privileges via a Trojan horse (1) deployUtil.py or (2) vds_bootstrap.py Python module in /tmp/.

    Published: 4 Dec 2012
    6.8
    Medium

    CVE-2012-0861

    Last Modified: 11 Apr 2025

    The vds_installer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, uses the -k curl parameter when downloading deployUtil.py and vds_bootstrap.py, which prevents SSL certificates from being validated and allows remote attackers to execute arbitrary Python code via a man-in-the-middle attack.

    Published: 4 Dec 2012
    2.7
    Low

    CVE-2012-2696

    Last Modified: 11 Apr 2025

    The backend in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1 does not properly check privileges, which allows remote authenticated users to query arbitrary information via a (1) SOAP or (2) GWT request.

    Published: 4 Dec 2012
    4.3
    Medium

    CVE-2012-3546

    Last Modified: 11 Apr 2025

    org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.

    Published: 4 Dec 2012
    2.1
    Low

    CVE-2012-5516

    Last Modified: 11 Apr 2025

    Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when moving disks between storage domains, does not properly wipe-after-delete, which prevents disks from being securely deleted and might allow local users to obtain sensitive information via unspecified vectors.

    Published: 4 Dec 2012
    5.5
    Medium

    CVE-2012-5603

    Last Modified: 11 Apr 2025

    proxies_controller.rb in Katello in Red Hat CloudForms before 1.1 does not properly check permissions, which allows remote authenticated users to read consumer certificates or change arbitrary users' settings via unspecified vectors related to the "consumer UUID" of a system.

    Published: 4 Dec 2012
    4.3
    Medium

    CVE-2012-5604

    Last Modified: 11 Apr 2025

    The ldap_fluff gem for Ruby, as used in Red Hat CloudForms 1.1, when using Active Directory for authentication, allows remote attackers to bypass authentication via unspecified vectors.

    Published: 4 Dec 2012
    7.5
    High

    CVE-2012-6329

    Last Modified: 11 Apr 2025

    The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly handle backslashes and fully qualified method names during compilation of bracket notation, which allows context-dependent attackers to execute arbitrary commands via crafted input to an application that accepts translation strings from users, as demonstrated by the TWiki application before 5.1.3, and the Foswiki application 1.0.x through 1.0.10 and 1.1.x through 1.1.6.

    Published: 4 Dec 2012
    4.3
    Medium

    CVE-2012-4431

    Last Modified: 11 Apr 2025

    org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.

    Published: 4 Dec 2012
    4.3
    Medium

    CVE-2012-5541

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Twitter Pull module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.0-rc3 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "data coming from Twitter."

    Published: 3 Dec 2012
    6
    Medium

    CVE-2012-5367

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in OrangeHRM 2.7.1 RC 1 allow remote authenticated administrators to execute arbitrary SQL commands via the sortField parameter to (1) viewCustomers, (2) viewPayGrades, or (3) viewSystemUsers in symfony/web/index.php/admin/, as demonstrated using cross-site request forgery (CSRF) attacks.

    Published: 3 Dec 2012
    7.5
    High

    CVE-2012-5534

    Last Modified: 11 Apr 2025

    The hook_process function in the plugin API for WeeChat 0.3.0 through 0.3.9.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a command from a plugin, related to "shell expansion."

    Published: 3 Dec 2012
    6
    Medium

    CVE-2012-5537

    Last Modified: 11 Apr 2025

    The Simplenews Scheduler module 6.x-2.x before 6.x-2.4 for Drupal allows remote authenticated users with the "send scheduled newsletters" permission to inject arbitrary PHP code into the scheduling form, which is later executed by cron.

    Published: 3 Dec 2012
    2.1
    Low

    CVE-2012-5538

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the FileField Sources module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.6 for Drupal, when the field has "Reference existing" source enabled, allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file.

    Published: 3 Dec 2012
    4.3
    Medium

    CVE-2012-5543

    Last Modified: 11 Apr 2025

    The Feeds module 7.x-2.x before 7.x-2.0-alpha6 for Drupal, when a field is mapped to the node's author, does not properly check permissions, which allows remote attackers to create arbitrary nodes via a crafted source feed.

    Published: 3 Dec 2012
    4
    Medium

    CVE-2012-5544

    Last Modified: 11 Apr 2025

    The Mandrill module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users to obtain password reset links by reading the logs in the Mandrill dashboard.

    Published: 3 Dec 2012
    6.8
    Medium

    CVE-2012-5547

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Search API module 7.x-1.x before 7.x-1.3 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable a server via a server action or (2) enable a search index via an enable index action.

    Published: 3 Dec 2012
    4.3
    Medium

    CVE-2012-5551

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the MailChimp module 7.x-2.x before 7.x-2.7 for Drupal allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) a predictable "webhook URL key" and (2) improper sanitization of "Webhook variables from POST requests."

    Published: 3 Dec 2012
    5
    Medium

    CVE-2012-5552

    Last Modified: 11 Apr 2025

    The Password policy module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to obtain password hashes by sniffing the network, related to "client-side password history checks."

    Published: 3 Dec 2012
    2.1
    Low

    CVE-2012-5553

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the OM Maximenu module 6.x-1.x before 6.x-1.44 and 7.x-1.x before 7.x-1.44 for Drupal allow remote authenticated users with the "administer OM Maximenu" permission to inject arbitrary web script or HTML via the (1) Menu Title (2) Link Title, (3) Path Query, (4) Anchor, or (5) vocabulary names.

    Published: 3 Dec 2012
    5
    Medium

    CVE-2012-5554

    Last Modified: 11 Apr 2025

    The default configuration for the Webform CiviCRM Integration module 7.x-3.x before 7.x-3.2 has "Enforce Permissions" disabled, which allows remote attackers to obtain contact information by reading webforms.

    Published: 3 Dec 2012
    2.6
    Low

    CVE-2012-5559

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the page manager node view task in the Chaos tool suite (ctools) module 6.x-1.x before 6.x-1.10 for Drupal allows remote authenticated users with permissions to submit or edit nodes to inject arbitrary web script or HTML via the page title.

    Published: 3 Dec 2012
    4.3
    Medium

    CVE-2012-5569

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via a (1) page title or (2) crafted email message.

    Published: 3 Dec 2012
    7.5
    High

    CVE-2012-1598

    Last Modified: 11 Apr 2025

    Joomla! 1.5.x before 1.5.26 has unspecified impact and attack vectors related to "insufficient randomness" and a "password reset vulnerability."

    Published: 3 Dec 2012
    5
    Medium

    CVE-2012-1599

    Last Modified: 11 Apr 2025

    Joomla! 1.5.x before 1.5.26 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end information" via unknown vectors. NOTE: this might be a duplicate of CVE-2012-1611.

    Published: 3 Dec 2012
    3.5
    Low

    CVE-2012-5539

    Last Modified: 11 Apr 2025

    The Organic Groups (OG) module 7.x-1.x before 7.x-1.5 for Drupal does not properly maintain pending group memberships, which allows remote authenticated users to post to arbitrary groups by modifying their own account while a pending membership is waiting to be approved.

    Published: 3 Dec 2012
    6.8
    Medium

    CVE-2012-5542

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Commerce Extra Panes module 7.x-1.x before 7.x-1.1 in Drupal allows remote attackers to hijack the authentication of administrators for requests that enable or disable a Commerce extra panes pane via unspecified vectors related to "the link to reorder items."

    Published: 3 Dec 2012
    4.3
    Medium

    CVE-2012-5548

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 Dec 2012
    7.5
    High

    CVE-2012-5550

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 3 Dec 2012
    6.8
    Medium

    CVE-2012-5556

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.1 and 7.x-2.x before 7.x-2.0-alpha3 for Drupal allow remote attackers to hijack the authentication of arbitrary users via unknown vectors.

    Published: 3 Dec 2012