CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2012-1812

    Last Modified: 11 Apr 2025

    eosfailoverservice.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to obtain sensitive cleartext information via a session on TCP port 12000.

    Published: 13 Nov 2012
    7.8
    High

    CVE-2012-1813

    Last Modified: 11 Apr 2025

    eosfailoverservice.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to cause a denial of service by sending a large amount of data to TCP port 12000.

    Published: 13 Nov 2012
    9.3
    Critical

    CVE-2012-4823

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, allows remote attackers to execute arbitrary code via vectors related to "insecure use of the java.lang.ClassLoder defineClass() method."

    Published: 13 Nov 2012
    5.5
    Medium

    CVE-2012-5476

    Last Modified: 21 Nov 2024

    Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the admin password and token value.

    Published: 13 Nov 2012
    6.5
    Medium

    CVE-2012-5521

    Last Modified: 21 Nov 2024

    quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal

    Published: 13 Nov 2012
    1.9
    Low

    CVE-2012-4535

    Last Modified: 11 Apr 2025

    Xen 3.4 through 4.2, and possibly earlier versions, allows local guest OS administrators to cause a denial of service (Xen infinite loop and physical CPU consumption) by setting a VCPU with an "inappropriate deadline."

    Published: 13 Nov 2012
    2.1
    Low

    CVE-2012-4536

    Last Modified: 11 Apr 2025

    The (1) domain_pirq_to_emuirq and (2) physdev_unmap_pirq functions in Xen 2.2 allows local guest OS administrators to cause a denial of service (Xen crash) via a crafted pirq value that triggers an out-of-bounds read.

    Published: 13 Nov 2012
    2.1
    Low

    CVE-2012-4537

    Last Modified: 11 Apr 2025

    Xen 3.4 through 4.2, and possibly earlier versions, does not properly synchronize the p2m and m2p tables when the set_p2m_entry function fails, which allows local HVM guest OS administrators to cause a denial of service (memory consumption and assertion failure), aka "Memory mapping failure DoS vulnerability."

    Published: 13 Nov 2012
    4.9
    Medium

    CVE-2012-4538

    Last Modified: 11 Apr 2025

    The HVMOP_pagetable_dying hypercall in Xen 4.0, 4.1, and 4.2 does not properly check the pagetable state when running on shadow pagetables, which allows a local HVM guest OS to cause a denial of service (hypervisor crash) via unspecified vectors.

    Published: 13 Nov 2012
    2.1
    Low

    CVE-2012-4539

    Last Modified: 11 Apr 2025

    Xen 4.0 through 4.2, when running 32-bit x86 PV guests on 64-bit hypervisors, allows local guest OS administrators to cause a denial of service (infinite loop and hang or crash) via invalid arguments to GNTTABOP_get_status_frames, aka "Grant table hypercall infinite loop DoS vulnerability."

    Published: 13 Nov 2012
    9.3
    Critical

    CVE-2012-4820

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, when running under a security manager, allows remote attackers to gain privileges by modifying or removing the security manager via vectors related to "insecure use of the java.lang.reflect.Method invoke() method."

    Published: 13 Nov 2012
    9.3
    Critical

    CVE-2012-4822

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, allow remote attackers to execute arbitrary code via vectors related to "insecure use [of] multiple methods in the java.lang.class class."

    Published: 13 Nov 2012
    2.1
    Low

    CVE-2012-5483

    Last Modified: 11 Apr 2025

    tools/sample_data.sh in OpenStack Keystone 2012.1.3, when access to Amazon Elastic Compute Cloud (Amazon EC2) is configured, uses world-readable permissions for /etc/keystone/ec2rc, which allows local users to obtain access to EC2 services by reading administrative access and secret values from this file.

    Published: 13 Nov 2012
    9.3
    Critical

    CVE-2012-4821

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, allow remote attackers to execute arbitrary code via "insecure use" of the (1) java.lang.Class getDeclaredMethods or nd (2) java.lang.reflect.AccessibleObject setAccessible() methods.

    Published: 13 Nov 2012
    5.5
    Medium

    CVE-2012-5474

    Last Modified: 21 Nov 2024

    The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.

    Published: 13 Nov 2012
    5
    Medium

    CVE-2012-5526

    Last Modified: 11 Apr 2025

    CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm.

    Published: 12 Nov 2012
    3.6
    Low

    CVE-2012-4417

    Last Modified: 11 Apr 2025

    GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.

    Published: 12 Nov 2012
    6
    Medium

    CVE-2012-4548

    Last Modified: 11 Apr 2025

    Argument injection vulnerability in syntax-highlighting.sh in cgit 9.0.3 and earlier allows remote authenticated users with permissions to add files to execute arbitrary commands via the --plug-in argument to the highlight command.

    Published: 11 Nov 2012
    6.8
    Medium

    CVE-2012-4553

    Last Modified: 11 Apr 2025

    Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an external database server, related to "transient conditions."

    Published: 11 Nov 2012
    5
    Medium

    CVE-2012-4554

    Last Modified: 11 Apr 2025

    The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE declaration in an XRDS file.

    Published: 11 Nov 2012
    3.5
    Low

    CVE-2012-4730

    Last Modified: 11 Apr 2025

    Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote authenticated users with ModifySelf or AdminUser privileges to inject arbitrary email headers and conduct phishing attacks or obtain sensitive information via unknown vectors.

    Published: 11 Nov 2012
    6.8
    Medium

    CVE-2012-4732

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Request Tracker (RT) 3.8.12 and other versions before 3.8.15, and 4.0.6 and other versions before 4.0.8, allows remote attackers to hijack the authentication of users for requests that toggle ticket bookmarks.

    Published: 11 Nov 2012
    5
    Medium

    CVE-2012-4884

    Last Modified: 11 Apr 2025

    Argument injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to create arbitrary files via unspecified vectors related to the GnuPG client.

    Published: 11 Nov 2012
    4.3
    Medium

    CVE-2012-5827

    Last Modified: 11 Apr 2025

    Joomla! 2.5.x before 2.5.8 and 3.0.x before 3.0.2 allows remote attackers to conduct clickjacking attacks via unspecified vectors involving "Inadequate protection."

    Published: 11 Nov 2012
    Unknown

    CVE-2012-4521

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-4505. Reason: This candidate is a duplicate of CVE-2012-4505. Notes: All CVE users should reference CVE-2012-4505 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 11 Nov 2012
    4
    Medium

    CVE-2012-4731

    Last Modified: 11 Apr 2025

    FAQ manager for Request Tracker (RTFM) before 2.4.5 does not properly check user rights, which allows remote authenticated users to create arbitrary articles in arbitrary classes via unknown vectors.

    Published: 11 Nov 2012
    5
    Medium

    CVE-2012-4734

    Last Modified: 11 Apr 2025

    Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to conduct a "confused deputy" attack to bypass the CSRF warning protection mechanism and cause victims to "modify arbitrary state" via unknown vectors related to a crafted link.

    Published: 11 Nov 2012
    5.5
    Medium

    CVE-2012-5482

    Last Modified: 11 Apr 2025

    The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4573.

    Published: 11 Nov 2012
    6.4
    Medium

    CVE-2012-2455

    Last Modified: 11 Apr 2025

    Advanced Productivity Software DTE Axiom before 12.3.3 does not validate the registration ID, which allows remote attackers to bypass authentication and read or modify data about users, customers, and projects via unspecified vectors.

    Published: 10 Nov 2012
    9.3
    Critical

    CVE-2011-1374

    Last Modified: 11 Apr 2025

    Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted REGION record in a PICT file.

    Published: 9 Nov 2012
    9.3
    Critical

    CVE-2012-3752

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in Apple QuickTime before 7.7.3 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted style element in a QuickTime TeXML file.

    Published: 9 Nov 2012
    9.3
    Critical

    CVE-2012-3753

    Last Modified: 11 Apr 2025

    Buffer overflow in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MIME type.

    Published: 9 Nov 2012
    9.3
    Critical

    CVE-2012-3754

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the Clear method in the ActiveX control in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.

    Published: 9 Nov 2012
    9.3
    Critical

    CVE-2012-3755

    Last Modified: 11 Apr 2025

    Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Targa image.

    Published: 9 Nov 2012
    9.3
    Critical

    CVE-2012-3756

    Last Modified: 11 Apr 2025

    Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted rnet box in an MP4 movie file.

    Published: 9 Nov 2012
    9.3
    Critical

    CVE-2012-3757

    Last Modified: 11 Apr 2025

    Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted PICT file.

    Published: 9 Nov 2012
    9.3
    Critical

    CVE-2012-3758

    Last Modified: 11 Apr 2025

    Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted transform attribute in a text3GTrack element in a QuickTime TeXML file.

    Published: 9 Nov 2012
    9.3
    Critical

    CVE-2012-3751

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML document with a crafted _qtactivex_ parameter in an OBJECT element.

    Published: 9 Nov 2012
    5
    Medium

    CVE-2012-5371

    Last Modified: 11 Apr 2025

    Ruby (aka CRuby) 1.9 before 1.9.3-p327 and 2.0 before r37575 computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against a variant of the MurmurHash2 algorithm, a different vulnerability than CVE-2011-4815.

    Published: 9 Nov 2012
    4
    Medium

    CVE-2012-4020

    Last Modified: 11 Apr 2025

    MosP kintai kanri before 4.1.0 does not enforce privilege requirements, which allows remote authenticated users to read other users' information via unspecified vectors.

    Published: 8 Nov 2012
    5.5
    Medium

    CVE-2012-4021

    Last Modified: 11 Apr 2025

    MosP kintai kanri before 4.1.0 does not properly perform authentication, which allows remote authenticated users to impersonate arbitrary user accounts, and consequently obtain sensitive information or modify settings, via unspecified vectors.

    Published: 8 Nov 2012
    6.4
    Medium

    CVE-2012-4022

    Last Modified: 11 Apr 2025

    Pebble before 2.6.4 allows remote attackers to trigger loss of blog-entry viewability via a crafted comment.

    Published: 8 Nov 2012
    4.3
    Medium

    CVE-2012-4023

    Last Modified: 11 Apr 2025

    CRLF injection vulnerability in Pebble before 2.6.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

    Published: 8 Nov 2012
    5
    Medium

    CVE-2012-5171

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Be Graph BeZIP before 3.10 allows remote attackers to create or overwrite arbitrary files via a crafted archive file.

    Published: 8 Nov 2012
    5
    Medium

    CVE-2012-3315

    Last Modified: 11 Apr 2025

    The Java servlets in the management console in IBM Tivoli Federated Identity Manager (TFIM) through 6.2.2 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) before 6.2.2 do not require authentication for all resource downloads, which allows remote attackers to bypass intended J2EE security constraints, and obtain sensitive information related to (1) federation metadata or (2) a web plugin configuration template, via a crafted request.

    Published: 8 Nov 2012
    7.2
    High

    CVE-2012-5519

    Last Modified: 11 Apr 2025

    CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.

    Published: 8 Nov 2012
    7.5
    High

    CVE-2012-3269

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Performance Insight 5.31, 5.40, and 5.41, when Sybase is used, allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, a different vulnerability than CVE-2012-3270.

    Published: 7 Nov 2012
    5
    Medium

    CVE-2012-5424

    Last Modified: 11 Apr 2025

    Cisco Secure Access Control System (ACS) 5.x before 5.2 Patch 11 and 5.3 before 5.3 Patch 7, when a certain configuration involving TACACS+ and LDAP is used, does not properly validate passwords, which allows remote attackers to bypass authentication by sending a valid username and a crafted password string, aka Bug ID CSCuc65634.

    Published: 7 Nov 2012
    10
    Critical

    CVE-2012-3270

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Performance Insight 5.31, 5.40, and 5.41, when Sybase is used, allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, a different vulnerability than CVE-2012-3269.

    Published: 7 Nov 2012
    7.5
    High

    CVE-2012-5115

    Last Modified: 11 Apr 2025

    Google Chrome before 23.0.1271.64 on Mac OS X does not properly mitigate improper write behavior in graphics drivers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger "wild writes."

    Published: 7 Nov 2012