CVE Feed

    Dashboard / CVE

    3.6
    Low

    CVE-2012-5557

    Last Modified: 11 Apr 2025

    The User Read-Only module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.4 for Drupal, does not properly assign roles when there are more than three roles on the site and certain unspecified configurations, which might allow remote authenticated users to gain privileges by performing certain operations, as demonstrated by changing a password.

    Published: 3 Dec 2012
    5
    Medium

    CVE-2012-5859

    Last Modified: 11 Apr 2025

    Samsung Kies Air 2.1.207051 and 2.1.210161 allows remote attackers to cause a denial of service (crash) via a crafted request to www/apps/KiesAir/jws/ssd.php.

    Published: 3 Dec 2012
    4.6
    Medium

    CVE-2012-6065

    Last Modified: 11 Apr 2025

    The OM Maximenu module 6.x-1.43 and earlier for Drupal, when the "Title has PHP" option is enabled, allows remote authenticated users with the "Administer OM Maximenu" permission to execute arbitrary PHP code via a "Link Title," a different vulnerability than CVE-2012-5553.

    Published: 3 Dec 2012
    6.8
    Medium

    CVE-2012-5450

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in lib/filemanager/imagemanager/images.php in CMS Made Simple (CMSMS) 1.11.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary files via the deld parameter.

    Published: 3 Dec 2012
    4.3
    Medium

    CVE-2012-5540

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Hostip module 6.x-2.x before 6.x-2.2 and 7.x-2.x before 7.x-2.2 for Drupal allow remote attackers with control of hostip.info to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 Dec 2012
    2.1
    Low

    CVE-2012-5545

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the ShareThis module 7.x-2.x before 7.x-2.5 for Drupal allow remote authenticated users with the "administer sharethis" permission to inject arbitrary web script or HTML via unspecified vectors related to "JavaScript settings."

    Published: 3 Dec 2012
    6.8
    Medium

    CVE-2012-5549

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 3 Dec 2012
    4.3
    Medium

    CVE-2012-5858

    Last Modified: 11 Apr 2025

    Samsung Kies Air 2.1.207051 and 2.1.210161 relies on the IP address for authentication, which allows remote man-in-the-middle attackers to read arbitrary phone contents by spoofing or controlling the IP address.

    Published: 3 Dec 2012
    3.5
    Low

    CVE-2012-6064

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in lib/filemanager/imagemanager/images.php in CMS Made Simple (CMSMS) before 1.11.2.1 allows remote authenticated administrators to delete arbitrary files via a .. (dot dot) in the deld parameter. NOTE: this can be leveraged using CSRF (CVE-2012-5450) to allow remote attackers to delete arbitrary files.

    Published: 3 Dec 2012
    Unknown

    CVE-2012-5579

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-5611. Reason: This candidate is a duplicate of CVE-2012-5611. Notes: All CVE users should reference CVE-2012-5611 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 3 Dec 2012
    4.7
    Medium

    CVE-2012-5510

    Last Modified: 11 Apr 2025

    Xen 4.x, when downgrading the grant table version, does not properly remove the status page from the tracking list when freeing the page, which allows local guest OS administrators to cause a denial of service (hypervisor crash) via unspecified vectors.

    Published: 3 Dec 2012
    3.2
    Low

    CVE-2012-5512

    Last Modified: 11 Apr 2025

    Array index error in the HVMOP_set_mem_access handler in Xen 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) or obtain sensitive information via unspecified vectors.

    Published: 3 Dec 2012
    4.7
    Medium

    CVE-2012-5514

    Last Modified: 11 Apr 2025

    The guest_physmap_mark_populate_on_demand function in Xen 4.2 and earlier does not properly unlock the subject GFNs when checking if they are in use, which allows local guest HVM administrators to cause a denial of service (hang) via unspecified vectors.

    Published: 3 Dec 2012
    4.7
    Medium

    CVE-2012-5525

    Last Modified: 11 Apr 2025

    The get_page_from_gfn hypercall function in Xen 4.2 allows local PV guest OS administrators to cause a denial of service (crash) via a crafted GFN that triggers a buffer over-read.

    Published: 3 Dec 2012
    4
    Medium

    CVE-2012-5627

    Last Modified: 11 Apr 2025

    Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.

    Published: 3 Dec 2012
    4.7
    Medium

    CVE-2012-6333

    Last Modified: 11 Apr 2025

    Multiple HVM control operations in Xen 3.4 through 4.2 allow local HVM guest OS administrators to cause a denial of service (physical CPU consumption) via a large input.

    Published: 3 Dec 2012
    4.7
    Medium

    CVE-2012-5511

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the dirty video RAM tracking functionality in Xen 3.4 through 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) via a large bitmap image.

    Published: 3 Dec 2012
    6.9
    Medium

    CVE-2012-5513

    Last Modified: 11 Apr 2025

    The XENMEM_exchange handler in Xen 4.2 and earlier does not properly check the memory address, which allows local PV guest OS administrators to cause a denial of service (crash) or possibly gain privileges via unspecified vectors that overwrite memory in the hypervisor reserved range.

    Published: 3 Dec 2012
    4.7
    Medium

    CVE-2012-5515

    Last Modified: 11 Apr 2025

    The (1) XENMEM_decrease_reservation, (2) XENMEM_populate_physmap, and (3) XENMEM_exchange hypercalls in Xen 4.2 and earlier allow local guest administrators to cause a denial of service (long loop and hang) via a crafted extent_order value.

    Published: 3 Dec 2012
    4
    Medium

    CVE-2012-5614

    Last Modified: 11 Apr 2025

    Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with a large number of unique, nested elements.

    Published: 1 Dec 2012
    5
    Medium

    CVE-2012-5615

    Last Modified: 11 Apr 2025

    Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames.

    Published: 1 Dec 2012
    6
    Medium

    CVE-2012-5613

    Last Modified: 11 Apr 2025

    MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who should not have administrative privileges, allows remote authenticated users to gain privileges by leveraging the FILE privilege to create files as the MySQL administrator. NOTE: the vendor disputes this issue, stating that this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation. NOTE: it could be argued that this should not be included in CVE because it is a configuration issue.

    Published: 1 Dec 2012
    6.5
    Medium

    CVE-2012-5612

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Oracle MySQL 5.5.19 and other versions through 5.5.28, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code, as demonstrated using certain variations of the (1) USE, (2) SHOW TABLES, (3) DESCRIBE, (4) SHOW FIELDS FROM, (5) SHOW COLUMNS FROM, (6) SHOW INDEX FROM, (7) CREATE TABLE, (8) DROP TABLE, (9) ALTER TABLE, (10) DELETE FROM, (11) UPDATE, and (12) SET PASSWORD commands.

    Published: 1 Dec 2012
    4.3
    Medium

    CVE-2012-4468

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Privatemsg module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via a user name in a private message.

    Published: 30 Nov 2012
    7.5
    High

    CVE-2012-4470

    Last Modified: 11 Apr 2025

    The Listhandler module 6.x-1.x before 6.x-1.1 for Drupal does not properly check permissions when importing emails, which allows remote comment authors to bypass access restrictions and possibly have other unspecified impact.

    Published: 30 Nov 2012
    5
    Medium

    CVE-2012-4471

    Last Modified: 11 Apr 2025

    The Search Autocomplete module 7.x-2.x before 7.x-2.4 for Drupal does not properly restrict access to the module admin page, which allows remote attackers to disable an autocompletion or change the priority order via unspecified vectors.

    Published: 30 Nov 2012
    3.5
    Low

    CVE-2012-4473

    Last Modified: 11 Apr 2025

    The Restrict node page view module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "view any node page" or "view any node {type} page" permission to access unpublished nodes via a direct request.

    Published: 30 Nov 2012
    5
    Medium

    CVE-2012-4475

    Last Modified: 11 Apr 2025

    The Security Questions module for Drupal 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.1 does not properly restrict access, which allows remote attackers to edit an arbitrary user's questions and answers via unspecified vectors.

    Published: 30 Nov 2012
    4.3
    Medium

    CVE-2012-4476

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 30 Nov 2012
    5
    Medium

    CVE-2012-4477

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to bypass access restrictions via unknown attack vectors.

    Published: 30 Nov 2012
    6.8
    Medium

    CVE-2012-4478

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to hijack the authentication of administrators.

    Published: 30 Nov 2012
    7.5
    High

    CVE-2012-4479

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 30 Nov 2012
    7.5
    High

    CVE-2012-4551

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in libunity-webapps before 2.4.1 allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via a crafted web site, related to "certain hash tables."

    Published: 30 Nov 2012
    6.8
    Medium

    CVE-2012-4559

    Last Modified: 11 Apr 2025

    Multiple double free vulnerabilities in the (1) agent_sign_data function in agent.c, (2) channel_request function in channels.c, (3) ssh_userauth_pubkey function in auth.c, (4) sftp_parse_attr_3 function in sftp.c, and (5) try_publickey_from_file function in keyfiles.c in libssh before 0.5.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

    Published: 30 Nov 2012
    7.5
    High

    CVE-2012-4560

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in libssh before 0.5.3 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors.

    Published: 30 Nov 2012
    5
    Medium

    CVE-2012-4561

    Last Modified: 11 Apr 2025

    The (1) publickey_make_dss, (2) publickey_make_rsa, (3) signature_from_string, (4) ssh_do_sign, and (5) ssh_sign_session_id functions in keys.c in libssh before 0.5.3 free "an invalid pointer on an error path," which might allow remote attackers to cause a denial of service (crash) via unspecified vectors.

    Published: 30 Nov 2012
    7.5
    High

    CVE-2012-4562

    Last Modified: 11 Apr 2025

    Multiple integer overflows in libssh before 0.5.3 allow remote attackers to cause a denial of service (infinite loop or crash) and possibly execute arbitrary code via unspecified vectors, which triggers a buffer overflow, infinite loop, or possibly some other unspecified vulnerabilities.

    Published: 30 Nov 2012
    7.5
    High

    CVE-2012-6063

    Last Modified: 11 Apr 2025

    Double free vulnerability in the sftp_mkdir function in sftp.c in libssh before 0.5.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors, a different vector than CVE-2012-4559.

    Published: 30 Nov 2012
    2.6
    Low

    CVE-2012-4469

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Hashcash module 6.x-2.x before 6.x-2.6 and 7.x-2.x before 7.x-2.2 for Drupal, when "Log failed hashcash" is enabled, allows remote attackers to inject arbitrary web script or HTML via an invalid token, which is not properly handled when administrators use the Database logging module.

    Published: 30 Nov 2012
    5.1
    Medium

    CVE-2012-4472

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in upload.php in the Drag & Drop Gallery module 6.x-1.5 and earlier for Drupal allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the directory specified by the filedir parameter.

    Published: 30 Nov 2012
    4.3
    Medium

    CVE-2012-4474

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Colorbox Node module 7.x-2.x before 7.x-2.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.

    Published: 30 Nov 2012
    5
    Medium

    CVE-2012-4834

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in LayerLoader.jsp in the theme component in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF19 and 8.0 before CF03 allows remote attackers to read arbitrary files via a crafted URI.

    Published: 30 Nov 2012
    6.8
    Medium

    CVE-2012-4221

    Last Modified: 11 Apr 2025

    Integer overflow in diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver for Android 2.3 through 4.2 allows attackers to execute arbitrary code or cause a denial of service via an application that uses crafted arguments in a local diagchar_ioctl call.

    Published: 30 Nov 2012
    4.3
    Medium

    CVE-2012-4222

    Last Modified: 11 Apr 2025

    drivers/gpu/msm/kgsl.c in the Qualcomm Innovation Center (QuIC) Graphics KGSL kernel-mode driver for Android 2.3 through 4.2 allows attackers to cause a denial of service (NULL pointer dereference) via an application that uses crafted arguments in a local kgsl_ioctl call.

    Published: 30 Nov 2012
    6.8
    Medium

    CVE-2012-4220

    Last Modified: 11 Apr 2025

    diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver for Android 2.3 through 4.2 allows attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference) via an application that uses crafted arguments in a local diagchar_ioctl call.

    Published: 30 Nov 2012
    7.8
    High

    CVE-2012-5174

    Last Modified: 11 Apr 2025

    The KYOCERA AH-K3001V, AH-K3002V, WX300K, WX310K, WX320K, and WX320KR devices allow remote attackers to cause a denial of service (persistent reboot) via an e-mail message in an invalid format.

    Published: 30 Nov 2012
    7.5
    High

    CVE-2012-5129

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the WebGL subsystem in Google Chrome OS before 23.0.1271.94 allows remote attackers to cause a denial of service (GPU process crash) or possibly have unspecified other impact via unknown vectors.

    Published: 30 Nov 2012
    4.3
    Medium

    CVE-2012-5624

    Last Modified: 11 Apr 2025

    The XMLHttpRequest object in Qt before 4.8.4 enables http redirection to the file scheme, which allows man-in-the-middle attackers to force the read of arbitrary local files and possibly obtain sensitive information via a file: URL to a QML application.

    Published: 30 Nov 2012
    5
    Medium

    CVE-2012-4841

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Tivoli Endpoint Manager for Remote Control Broker 8.2 before 8.2.1-TIV-TEMRC821-IF0002 allows remote attackers to cause a denial of service (resource consumption) via unknown vectors.

    Published: 29 Nov 2012
    9.3
    Critical

    CVE-2012-3271

    Last Modified: 11 Apr 2025

    Unspecified vulnerability on the HP Integrated Lights-Out 3 (aka iLO3) with firmware before 1.50 and Integrated Lights-Out 4 (aka iLO4) with firmware before 1.13 allows remote attackers to obtain sensitive information via unknown vectors.

    Published: 29 Nov 2012