CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2012-5611

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.1.66, and MariaDB 5.5.2.x before 5.5.28a, 5.3.x before 5.3.11, 5.2.x before 5.2.13 and 5.1.x before 5.1.66, allows remote authenticated users to execute arbitrary code via a long argument to the GRANT FILE command.

    Published: 29 Nov 2012
    5
    Medium

    CVE-2012-5372

    Last Modified: 11 Apr 2025

    Rubinius computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against the MurmurHash3 algorithm.

    Published: 28 Nov 2012
    7.5
    High

    CVE-2012-4964

    Last Modified: 11 Apr 2025

    The Samsung printer firmware before 20121031 has a hardcoded read-write SNMP community, which makes it easier for remote attackers to obtain administrative access via an SNMP request.

    Published: 28 Nov 2012
    5
    Medium

    CVE-2012-5130

    Last Modified: 11 Apr 2025

    Skia, as used in Google Chrome before 23.0.1271.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 28 Nov 2012
    7.5
    High

    CVE-2012-5131

    Last Modified: 11 Apr 2025

    Google Chrome before 23.0.1271.91 on Mac OS X does not properly mitigate improper rendering behavior in the Intel GPU driver, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 28 Nov 2012
    5
    Medium

    CVE-2012-5132

    Last Modified: 11 Apr 2025

    Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service (application crash) via a response with chunked transfer coding.

    Published: 28 Nov 2012
    7.5
    High

    CVE-2012-5133

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG filters.

    Published: 28 Nov 2012
    7.5
    High

    CVE-2012-5135

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to printing.

    Published: 28 Nov 2012
    6.8
    Medium

    CVE-2012-5136

    Last Modified: 11 Apr 2025

    Google Chrome before 23.0.1271.91 does not properly perform a cast of an unspecified variable during handling of the INPUT element, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted HTML document.

    Published: 28 Nov 2012
    5
    Medium

    CVE-2012-6061

    Last Modified: 11 Apr 2025

    The dissect_wtp_common function in epan/dissectors/packet-wtp.c in the WTP dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 uses an incorrect data type for a certain length field, which allows remote attackers to cause a denial of service (integer overflow and infinite loop) via a crafted value in a packet.

    Published: 28 Nov 2012
    Unknown

    CVE-2011-5370

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-5370. Reason: This candidate is a duplicate of CVE-2012-5370. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2012-5370 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Nov 2012
    Unknown

    CVE-2011-5371

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-5371. Reason: This candidate is a duplicate of CVE-2012-5371. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2012-5371 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Nov 2012
    Unknown

    CVE-2011-5373

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-5373. Reason: This candidate is a duplicate of CVE-2012-5373. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2012-5373 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Nov 2012
    4
    Medium

    CVE-2012-5563

    Last Modified: 11 Apr 2025

    OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by creating new tokens through token chaining. NOTE: this issue exists because of a CVE-2012-3426 regression.

    Published: 28 Nov 2012
    2.1
    Low

    CVE-2012-5592

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-6052. Reason: This candidate is a reservation duplicate of CVE-2012-6052. Notes: All CVE users should reference CVE-2012-6052 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 28 Nov 2012
    4.3
    Medium

    CVE-2012-5593

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-6053. Reason: This candidate is a reservation duplicate of CVE-2012-6053. Notes: All CVE users should reference CVE-2012-6053 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 28 Nov 2012
    4.3
    Medium

    CVE-2012-5594

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-6054. Reason: This candidate is a reservation duplicate of CVE-2012-6054. Notes: All CVE users should reference CVE-2012-6054 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 28 Nov 2012
    4.3
    Medium

    CVE-2012-5597

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-6059. Reason: This candidate is a reservation duplicate of CVE-2012-6059. Notes: All CVE users should reference CVE-2012-6059 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 28 Nov 2012
    4.3
    Medium

    CVE-2012-5598

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-6060. Reason: This candidate is a reservation duplicate of CVE-2012-6060. Notes: All CVE users should reference CVE-2012-6060 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 28 Nov 2012
    4.3
    Medium

    CVE-2012-5599

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-6061. Reason: This candidate is a reservation duplicate of CVE-2012-6061. Notes: All CVE users should reference CVE-2012-6061 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 28 Nov 2012
    4.3
    Medium

    CVE-2012-5600

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-6062. Reason: This candidate is a reservation duplicate of CVE-2012-6062. Notes: All CVE users should reference CVE-2012-6062 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 28 Nov 2012
    4.3
    Medium

    CVE-2012-5601

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-6055. Reason: This candidate is a reservation duplicate of CVE-2012-6055. Notes: All CVE users should reference CVE-2012-6055 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 28 Nov 2012
    4.3
    Medium

    CVE-2012-5602

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-6058. Reason: This candidate is a reservation duplicate of CVE-2012-6058. Notes: All CVE users should reference CVE-2012-6058 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Nov 2012
    5
    Medium

    CVE-2012-6052

    Last Modified: 11 Apr 2025

    Wireshark 1.8.x before 1.8.4 allows remote attackers to obtain sensitive hostname information by reading pcap-ng files.

    Published: 28 Nov 2012
    5
    Medium

    CVE-2012-6055

    Last Modified: 11 Apr 2025

    epan/dissectors/packet-3g-a11.c in the 3GPP2 A11 dissector in Wireshark 1.8.x before 1.8.4 allows remote attackers to cause a denial of service (infinite loop) via a zero value in a sub-type length field.

    Published: 28 Nov 2012
    5
    Medium

    CVE-2012-6056

    Last Modified: 11 Apr 2025

    Integer overflow in the dissect_sack_chunk function in epan/dissectors/packet-sctp.c in the SCTP dissector in Wireshark 1.8.x before 1.8.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted Duplicate TSN count.

    Published: 28 Nov 2012
    5
    Medium

    CVE-2012-6060

    Last Modified: 11 Apr 2025

    Integer overflow in the dissect_iscsi_pdu function in epan/dissectors/packet-iscsi.c in the iSCSI dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

    Published: 28 Nov 2012
    4.3
    Medium

    CVE-2012-5596

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-6057. Reason: This candidate is a reservation duplicate of CVE-2012-6057. Notes: All CVE users should reference CVE-2012-6057 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 28 Nov 2012
    5
    Medium

    CVE-2012-6053

    Last Modified: 11 Apr 2025

    epan/dissectors/packet-usb.c in the USB dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 relies on a length field to calculate an offset value, which allows remote attackers to cause a denial of service (infinite loop) via a zero value for this field.

    Published: 28 Nov 2012
    5
    Medium

    CVE-2012-6058

    Last Modified: 11 Apr 2025

    Integer overflow in the dissect_icmpv6 function in epan/dissectors/packet-icmpv6.c in the ICMPv6 dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted Number of Sources value.

    Published: 28 Nov 2012
    5
    Medium

    CVE-2012-6062

    Last Modified: 11 Apr 2025

    The dissect_rtcp_app function in epan/dissectors/packet-rtcp.c in the RTCP dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.

    Published: 28 Nov 2012
    5.9
    Medium

    CVE-2012-6709

    Last Modified: 21 Nov 2024

    ELinks 0.12 and Twibright Links 2.3 have Missing SSL Certificate Validation.

    Published: 28 Nov 2012
    5.4
    Medium

    CVE-2012-5571

    Last Modified: 7 Apr 2026

    A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authorization restrictions. This occurs because OpenStack Keystone does not properly handle EC2 (Elastic Compute Cloud) tokens when a user's role has been removed from a tenant. An attacker can leverage a token associated with a removed user role to gain unauthorized access.

    Published: 28 Nov 2012
    Unknown

    CVE-2011-5372

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-5372. Reason: This candidate is a duplicate of CVE-2012-5372. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2012-5372 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Nov 2012
    4.3
    Medium

    CVE-2012-5595

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-6056. Reason: This candidate is a reservation duplicate of CVE-2012-6056. Notes: All CVE users should reference CVE-2012-6056 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 28 Nov 2012
    5
    Medium

    CVE-2012-6054

    Last Modified: 11 Apr 2025

    The dissect_sflow_245_address_type function in epan/dissectors/packet-sflow.c in the sFlow dissector in Wireshark 1.8.x before 1.8.4 does not properly handle length calculations for an invalid IP address type, which allows remote attackers to cause a denial of service (infinite loop) via a packet that is neither IPv4 nor IPv6.

    Published: 28 Nov 2012
    5
    Medium

    CVE-2012-6057

    Last Modified: 11 Apr 2025

    The dissect_eigrp_metric_comm function in epan/dissectors/packet-eigrp.c in the EIGRP dissector in Wireshark 1.8.x before 1.8.4 uses the wrong data type for a certain offset value, which allows remote attackers to cause a denial of service (integer overflow and infinite loop) via a malformed packet.

    Published: 28 Nov 2012
    5
    Medium

    CVE-2012-6059

    Last Modified: 11 Apr 2025

    The dissect_isakmp function in epan/dissectors/packet-isakmp.c in the ISAKMP dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 uses an incorrect data structure to determine IKEv2 decryption parameters, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

    Published: 28 Nov 2012
    4.3
    Medium

    CVE-2012-4611

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Adaptive Authentication On-Premise (AAOP) before 7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 Nov 2012
    9.3
    Critical

    CVE-2012-4614

    Last Modified: 11 Apr 2025

    The default configuration of EMC Smarts Network Configuration Manager (NCM) before 9.1 does not require authentication for database access, which allows remote attackers to have an unspecified impact via a network session.

    Published: 27 Nov 2012
    2.1
    Low

    CVE-2012-4615

    Last Modified: 11 Apr 2025

    EMC Smarts Network Configuration Manager (NCM) before 9.1 uses a hardcoded encryption key for the storage of credentials, which allows local users to obtain sensitive information via unspecified vectors.

    Published: 27 Nov 2012
    10
    Critical

    CVE-2012-6046

    Last Modified: 11 Apr 2025

    Static code injection vulnerability in admin/banners.php in PHP Enter allows remote attackers to inject arbitrary PHP code into horad.php via the code parameter.

    Published: 27 Nov 2012
    6.8
    Medium

    CVE-2012-6047

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in X7 Chat 2.0.5.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that add a user to an arbitrary group via the users page in an adminpanel action to index.php.

    Published: 27 Nov 2012
    5
    Medium

    CVE-2012-6048

    Last Modified: 11 Apr 2025

    Guitar Pro 6.1.1 r10791 allows remote attackers to cause a denial of service (crash) via a long string in a gpx file.

    Published: 27 Nov 2012
    6.4
    Medium

    CVE-2012-6050

    Last Modified: 11 Apr 2025

    The winbox service in MikroTik RouterOS 5.15 and earlier allows remote attackers to cause a denial of service (CPU consumption), read the router version, and possibly have other impacts via a request to download the router's DLLs or plugins, as demonstrated by roteros.dll.

    Published: 27 Nov 2012
    4.3
    Medium

    CVE-2012-6045

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in gb/user/index.php in Ramui Forum, possibly 1.0 Beta, allows remote attackers to inject arbitrary web script or HTML via the query parameter.

    Published: 27 Nov 2012
    5
    Medium

    CVE-2012-6049

    Last Modified: 11 Apr 2025

    Open Solution Quick.Cart 5.0 allows remote attackers to obtain sensitive information via (1) a long string or (2) invalid characters in a cookie, which reveals the installation path in an error message.

    Published: 27 Nov 2012
    4.3
    Medium

    CVE-2012-6662

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title attribute, which is not properly handled in the autocomplete combo box demo.

    Published: 27 Nov 2012
    6.8
    Medium

    CVE-2012-5134

    Last Modified: 11 Apr 2025

    Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.

    Published: 27 Nov 2012
    2.1
    Low

    CVE-2012-6108

    Last Modified: 11 Apr 2025

    HP Linux Imaging and Printing (HPLIP) before 3.13.2 uses world-writable permissions for /var/log/hp and /var/log/hp/tmp, which allows local users to delete log files via standard filesystem operations.

    Published: 27 Nov 2012