CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2012-5674

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Adobe ColdFusion 10 before Update 5, when Internet Information Services (IIS) is used, allows attackers to cause a denial of service via unknown vectors.

    Published: 20 Nov 2012
    5
    Medium

    CVE-2012-5703

    Last Modified: 11 Apr 2025

    The vSphere API in VMware ESXi 4.1 and ESX 4.1 allows remote attackers to cause a denial of service (host daemon crash) via an invalid value in a (1) RetrieveProp or (2) RetrievePropEx SOAP request.

    Published: 20 Nov 2012
    Unknown

    CVE-2012-2589

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-4344. Reason: This candidate is a duplicate of CVE-2012-4344. Notes: All CVE users should reference CVE-2012-4344 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Nov 2012
    5
    Medium

    CVE-2011-4612

    Last Modified: 11 Apr 2025

    icecast before 2.3.3 allows remote attackers to inject control characters such as newlines into the error loc (error.log) via a crafted URL.

    Published: 20 Nov 2012
    6.8
    Medium

    CVE-2012-4203

    Last Modified: 11 Apr 2025

    The New Tab page in Mozilla Firefox before 17.0 uses a privileged context for execution of JavaScript code by bookmarklets, which allows user-assisted remote attackers to run arbitrary programs by leveraging a javascript: URL in a bookmark.

    Published: 20 Nov 2012
    9.3
    Critical

    CVE-2012-4213

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the nsEditor::FindNextLeafNode function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

    Published: 20 Nov 2012
    9.3
    Critical

    CVE-2012-4214

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the nsTextEditorState::PrepareEditor function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-5840.

    Published: 20 Nov 2012
    9.3
    Critical

    CVE-2012-4217

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the nsViewManager::ProcessPendingUpdates function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

    Published: 20 Nov 2012
    3.3
    Low

    CVE-2012-4366

    Last Modified: 11 Apr 2025

    Belkin wireless routers Surf N150 Model F7D1301v1, N900 Model F9K1104v1, N450 Model F9K1105V2, and N300 Model F7D2301v1 generate a predictable default WPA2-PSK passphrase based on eight digits of the WAN MAC address, which allows remote attackers to access the network by sniffing the beacon frames.

    Published: 20 Nov 2012
    6.4
    Medium

    CVE-2012-4523

    Last Modified: 11 Apr 2025

    radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to bypass intended access restrictions and spoof clients.

    Published: 20 Nov 2012
    3.5
    Low

    CVE-2012-5529

    Last Modified: 11 Apr 2025

    TraceManager in Firebird 2.5.0 and 2.5.1, when trace is enabled, allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) by preparing an empty dynamic SQL query.

    Published: 20 Nov 2012
    6.8
    Medium

    CVE-2012-5837

    Last Modified: 11 Apr 2025

    The Web Developer Toolbar in Mozilla Firefox before 17.0 executes script with chrome privileges, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.

    Published: 20 Nov 2012
    9.3
    Critical

    CVE-2012-5839

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the gfxShapedWord::CompressedGlyph::IsClusterStart function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 20 Nov 2012
    9.3
    Critical

    CVE-2012-5842

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 20 Nov 2012
    9.3
    Critical

    CVE-2012-5843

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 20 Nov 2012
    3.5
    Low

    CVE-2012-6074

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.447.4.1, and 1.466.x before 1.466.10.1 allows remote authenticated users with write access to inject arbitrary web script or HTML via unspecified vectors.

    Published: 20 Nov 2012
    4.3
    Medium

    CVE-2012-3354

    Last Modified: 11 Apr 2025

    doku.php in DokuWiki, as used in Fedora 16, 17, and 18, when certain PHP error levels are set, allows remote attackers to obtain sensitive information via the prefix parameter, which reveals the installation path in an error message.

    Published: 20 Nov 2012
    4.3
    Medium

    CVE-2012-4201

    Last Modified: 11 Apr 2025

    The evalInSandbox implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 uses an incorrect context during the handling of JavaScript code that sets the location.href property, which allows remote attackers to conduct cross-site scripting (XSS) attacks or read arbitrary files by leveraging a sandboxed add-on.

    Published: 20 Nov 2012
    9.3
    Critical

    CVE-2012-4202

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the image::RasterImage::DrawFrameTo function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code via a crafted GIF image.

    Published: 20 Nov 2012
    9.3
    Critical

    CVE-2012-4204

    Last Modified: 11 Apr 2025

    The str_unescape function in the JavaScript engine in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.

    Published: 20 Nov 2012
    4.3
    Medium

    CVE-2012-4207

    Last Modified: 11 Apr 2025

    The HZ-GB-2312 character-set implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 does not properly handle a ~ (tilde) character in proximity to a chunk delimiter, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document.

    Published: 20 Nov 2012
    4.3
    Medium

    CVE-2012-4209

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 do not prevent use of a "top" frame name-attribute value to access the location property, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a binary plugin.

    Published: 20 Nov 2012
    9.3
    Critical

    CVE-2012-4210

    Last Modified: 11 Apr 2025

    The Style Inspector in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 does not properly restrict the context of HTML markup and Cascading Style Sheets (CSS) token sequences, which allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted stylesheet.

    Published: 20 Nov 2012
    9.3
    Critical

    CVE-2012-4215

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the nsPlaintextEditor::FireClipboardEvent function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

    Published: 20 Nov 2012
    9.3
    Critical

    CVE-2012-4216

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the gfxFont::GetFontEntry function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

    Published: 20 Nov 2012
    10
    Critical

    CVE-2012-4218

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the BuildTextRunsScanner::BreakSink::SetBreaks function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

    Published: 20 Nov 2012
    6.4
    Medium

    CVE-2012-4566

    Last Modified: 11 Apr 2025

    The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to bypass intended access restrictions and spoof clients, a different vulnerability than CVE-2012-4523.

    Published: 20 Nov 2012
    9.3
    Critical

    CVE-2012-5829

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the nsWindow::OnExposeEvent function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 20 Nov 2012
    9.3
    Critical

    CVE-2012-5833

    Last Modified: 11 Apr 2025

    The texImage2D implementation in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 does not properly interact with Mesa drivers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via function calls involving certain values of the level parameter.

    Published: 20 Nov 2012
    10
    Critical

    CVE-2012-5835

    Last Modified: 11 Apr 2025

    Integer overflow in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (invalid write operation) via crafted data.

    Published: 20 Nov 2012
    7.5
    High

    CVE-2012-5836

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving the setting of Cascading Style Sheets (CSS) properties in conjunction with SVG text.

    Published: 20 Nov 2012
    9.3
    Critical

    CVE-2012-5838

    Last Modified: 11 Apr 2025

    The copyTexImage2D implementation in the WebGL subsystem in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via large image dimensions.

    Published: 20 Nov 2012
    9.3
    Critical

    CVE-2012-5840

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the nsTextEditorState::PrepareEditor function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-4214.

    Published: 20 Nov 2012
    4.3
    Medium

    CVE-2012-5841

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 implement cross-origin wrappers with a filtering behavior that does not properly restrict write actions, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site.

    Published: 20 Nov 2012
    5.8
    Medium

    CVE-2012-6073

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.447.4.1, and 1.466.x before 1.466.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 20 Nov 2012
    6.8
    Medium

    CVE-2012-4205

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 assign the system principal, rather than the sandbox principal, to XMLHttpRequest objects created in sandboxes, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks or obtain sensitive information by leveraging a sandboxed add-on.

    Published: 20 Nov 2012
    4.3
    Medium

    CVE-2012-4208

    Last Modified: 11 Apr 2025

    The XrayWrapper implementation in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 does not consider the compartment during property filtering, which allows remote attackers to bypass intended chrome-only restrictions on reading DOM object properties via a crafted web site.

    Published: 20 Nov 2012
    10
    Critical

    CVE-2012-4212

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the XPCWrappedNative::Mark function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

    Published: 20 Nov 2012
    8.8
    High

    CVE-2012-5830

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 on Mac OS X allows remote attackers to execute arbitrary code via an HTML document.

    Published: 20 Nov 2012
    4.3
    Medium

    CVE-2012-6072

    Last Modified: 11 Apr 2025

    CRLF injection vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.447.4.1, and 1.466.x before 1.466.10.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

    Published: 20 Nov 2012
    7.2
    High

    CVE-2012-4225

    Last Modified: 11 Apr 2025

    NVIDIA UNIX graphics driver before 295.71 and before 304.32 allows local users to write to arbitrary physical memory locations and gain privileges by modifying the VGA window using /dev/nvidia0.

    Published: 19 Nov 2012
    7.5
    High

    CVE-2012-5854

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in WeeChat 0.3.6 through 0.3.9 allows remote attackers to cause a denial of service (crash or hang) and possibly execute arbitrary code via crafted IRC colors that are not properly decoded.

    Published: 19 Nov 2012
    4
    Medium

    CVE-2012-5918

    Last Modified: 11 Apr 2025

    razorCMS 1.2 allows remote authenticated users to access administrator directories and files by creating and deleting a directory.

    Published: 19 Nov 2012
    4.3
    Medium

    CVE-2012-5919

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Havalite 1.0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) find or (2) replace fields to havalite/findReplace.php; (3) username parameter to havalite/hava_login.php, (4) the Edit Article module, or (5) hava_post.php in the postAuthor module; (6) postId parameter to hava_post.php; (7) userId parameter to hava_user.php; or (8) linkId parameter to hava_link.php.

    Published: 19 Nov 2012
    4.3
    Medium

    CVE-2012-4541

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Piwik before 1.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 19 Nov 2012
    7.5
    High

    CVE-2012-5535

    Last Modified: 21 Nov 2024

    gnome-system-log polkit policy allows arbitrary files on the system to be read

    Published: 19 Nov 2012
    4.3
    Medium

    CVE-2012-4533

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the "extra" details in the DiffSource._get_row function in lib/viewvc.py in ViewVC 1.0.x before 1.0.13 and 1.1.x before 1.1.16 allows remote authenticated users with repository commit access to inject arbitrary web script or HTML via the "function name" line.

    Published: 19 Nov 2012
    6.8
    Medium

    CVE-2012-4552

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the error function in ssg/ssgParser.cxx in PLIB 1.8.5 allows remote attackers to execute arbitrary code via a crafted 3d model file that triggers a long error message, as demonstrated by a .ase file.

    Published: 18 Nov 2012
    6.8
    Medium

    CVE-2012-4935

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the web interface in Pattern Insight 2.3 allows remote attackers to hijack the authentication of arbitrary users.

    Published: 18 Nov 2012
    6.8
    Medium

    CVE-2012-4936

    Last Modified: 11 Apr 2025

    The web interface in Pattern Insight 2.3 allows remote attackers to conduct clickjacking attacks via a FRAME element.

    Published: 18 Nov 2012