CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2012-5116

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of SVG filters.

    Published: 7 Nov 2012
    7.5
    High

    CVE-2012-5117

    Last Modified: 11 Apr 2025

    Google Chrome before 23.0.1271.64 does not properly restrict the loading of an SVG subresource in the context of an IMG element, which has unspecified impact and remote attack vectors.

    Published: 7 Nov 2012
    6.8
    Medium

    CVE-2012-5119

    Last Modified: 11 Apr 2025

    Race condition in Pepper, as used in Google Chrome before 23.0.1271.64, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to buffers.

    Published: 7 Nov 2012
    7.5
    High

    CVE-2012-5120

    Last Modified: 11 Apr 2025

    Google V8 before 3.13.7.5, as used in Google Chrome before 23.0.1271.64, on 64-bit Linux platforms allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers an out-of-bounds access to an array.

    Published: 7 Nov 2012
    7.5
    High

    CVE-2012-5121

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to video layout.

    Published: 7 Nov 2012
    7.5
    High

    CVE-2012-5122

    Last Modified: 11 Apr 2025

    Google Chrome before 23.0.1271.64 does not properly perform a cast of an unspecified variable during handling of input, which allows remote attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 7 Nov 2012
    5
    Medium

    CVE-2012-5123

    Last Modified: 11 Apr 2025

    Skia, as used in Google Chrome before 23.0.1271.64, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 7 Nov 2012
    7.5
    High

    CVE-2012-5124

    Last Modified: 11 Apr 2025

    Google Chrome before 23.0.1271.64 does not properly handle textures, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 7 Nov 2012
    7.5
    High

    CVE-2012-5125

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of extension tabs.

    Published: 7 Nov 2012
    7.5
    High

    CVE-2012-5126

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of plug-in placeholders.

    Published: 7 Nov 2012
    7.5
    High

    CVE-2012-5128

    Last Modified: 11 Apr 2025

    Google V8 before 3.13.7.5, as used in Google Chrome before 23.0.1271.64, does not properly perform write operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 7 Nov 2012
    7.5
    High

    CVE-2012-5127

    Last Modified: 11 Apr 2025

    Integer overflow in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted WebP image.

    Published: 7 Nov 2012
    7.5
    High

    CVE-2012-5118

    Last Modified: 11 Apr 2025

    Google Chrome before 23.0.1271.64 on Mac OS X does not properly validate an integer value during the handling of GPU command buffers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 7 Nov 2012
    6.8
    Medium

    CVE-2012-4540

    Last Modified: 11 Apr 2025

    Off-by-one error in the invoke function in IcedTeaScriptablePluginObject.cc in IcedTea-Web 1.1.x before 1.1.7, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.x before 1.4.1 allows remote attackers to obtain sensitive information, cause a denial of service (crash), or possibly execute arbitrary code via a crafted webpage that triggers a heap-based buffer overflow, related to an error message and a "triggering event attached to applet." NOTE: the 1.4.x versions were originally associated with CVE-2013-4349, but that entry has been MERGED with this one.

    Published: 7 Nov 2012
    5.5
    Medium

    CVE-2012-4573

    Last Modified: 11 Apr 2025

    The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.

    Published: 7 Nov 2012
    5.8
    Medium

    CVE-2011-5236

    Last Modified: 11 Apr 2025

    Moneris eSelectPlus 2.03 PHP API does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 6 Nov 2012
    5.8
    Medium

    CVE-2011-5238

    Last Modified: 11 Apr 2025

    google-checkout-php-sample-code before 1.3.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 6 Nov 2012
    5.8
    Medium

    CVE-2011-5239

    Last Modified: 11 Apr 2025

    CiviCRM 4.0.5 and 4.1.1 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 6 Nov 2012
    5.8
    Medium

    CVE-2011-5240

    Last Modified: 11 Apr 2025

    Magento 1.5 and 1.6.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 6 Nov 2012
    5.8
    Medium

    CVE-2011-5242

    Last Modified: 11 Apr 2025

    tmhOAuth before 0.61 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 6 Nov 2012
    5.8
    Medium

    CVE-2011-5243

    Last Modified: 11 Apr 2025

    TwitterOAuth does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 6 Nov 2012
    5.8
    Medium

    CVE-2011-5237

    Last Modified: 11 Apr 2025

    PayPal WPS ToolKit does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 6 Nov 2012
    5.8
    Medium

    CVE-2011-5241

    Last Modified: 11 Apr 2025

    Services_Twitter 0.6.3 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 6 Nov 2012
    1.9
    Low

    CVE-2012-4461

    Last Modified: 11 Apr 2025

    The KVM subsystem in the Linux kernel before 3.6.9, when running on hosts that use qemu userspace without XSAVE, allows local users to cause a denial of service (kernel OOPS) by using the KVM_SET_SREGS ioctl to set the X86_CR4_OSXSAVE bit in the guest cr4 register, then calling the KVM_RUN ioctl.

    Published: 6 Nov 2012
    10
    Critical

    CVE-2012-5275

    Last Modified: 11 Apr 2025

    Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-5274, CVE-2012-5276, CVE-2012-5277, and CVE-2012-5280.

    Published: 6 Nov 2012
    10
    Critical

    CVE-2012-5278

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600 allow attackers to bypass intended access restrictions and execute arbitrary code via unspecified vectors.

    Published: 6 Nov 2012
    10
    Critical

    CVE-2012-5279

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 6 Nov 2012
    10
    Critical

    CVE-2012-5280

    Last Modified: 11 Apr 2025

    Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-5274, CVE-2012-5275, CVE-2012-5276, and CVE-2012-5277.

    Published: 6 Nov 2012
    6.8
    Medium

    CVE-2012-5485

    Last Modified: 12 Apr 2025

    registerConfiglet.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via unspecified vectors, related to the admin interface.

    Published: 6 Nov 2012
    6.4
    Medium

    CVE-2012-5486

    Last Modified: 12 Apr 2025

    ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character.

    Published: 6 Nov 2012
    8.5
    High

    CVE-2012-5487

    Last Modified: 12 Apr 2025

    The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privileges to bypass the Python sandbox restriction and execute arbitrary Python code via vectors related to importing.

    Published: 6 Nov 2012
    5
    Medium

    CVE-2012-5488

    Last Modified: 12 Apr 2025

    python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to createObject.

    Published: 6 Nov 2012
    6.5
    Medium

    CVE-2012-5489

    Last Modified: 12 Apr 2025

    The App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21 and 3.13.x before 2.13.11, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote authenticated users to gain access to restricted attributes via unspecified vectors.

    Published: 6 Nov 2012
    4.3
    Medium

    CVE-2012-5491

    Last Modified: 12 Apr 2025

    z3c.form, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain the default form field values by leveraging knowledge of the form location and the element id.

    Published: 6 Nov 2012
    5
    Medium

    CVE-2012-5492

    Last Modified: 12 Apr 2025

    uid_catalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to obtain metadata about hidden objects via a crafted URL.

    Published: 6 Nov 2012
    8.5
    High

    CVE-2012-5493

    Last Modified: 12 Apr 2025

    gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain permissions to bypass the Python sandbox and execute arbitrary Python code via unspecified vectors.

    Published: 6 Nov 2012
    4.3
    Medium

    CVE-2012-5494

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to "{u,}translate."

    Published: 6 Nov 2012
    5
    Medium

    CVE-2012-5495

    Last Modified: 12 Apr 2025

    python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to "go_back."

    Published: 6 Nov 2012
    5
    Medium

    CVE-2012-5496

    Last Modified: 12 Apr 2025

    kupu_spellcheck.py in Kupu in Plone before 4.0 allows remote attackers to cause a denial of service (ZServer thread lock) via a crafted URL.

    Published: 6 Nov 2012
    5
    Medium

    CVE-2012-5497

    Last Modified: 12 Apr 2025

    membership_tool.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to enumerate user account names via a crafted URL.

    Published: 6 Nov 2012
    5
    Medium

    CVE-2012-5498

    Last Modified: 12 Apr 2025

    queryCatalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to bypass caching and cause a denial of service via a crafted request to a collection.

    Published: 6 Nov 2012
    5
    Medium

    CVE-2012-5501

    Last Modified: 12 Apr 2025

    at_download.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read arbitrary BLOBs (Files and Images) stored on custom content types via a crafted URL.

    Published: 6 Nov 2012
    3.5
    Low

    CVE-2012-5502

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in safe_html.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with permissions to edit content to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Nov 2012
    5
    Medium

    CVE-2012-5503

    Last Modified: 12 Apr 2025

    ftp.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read hidden folder contents via unspecified vectors.

    Published: 6 Nov 2012
    4.3
    Medium

    CVE-2012-5504

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in widget_traversal.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Nov 2012
    5
    Medium

    CVE-2012-5505

    Last Modified: 12 Apr 2025

    atat.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read private data structures via a request for a view without a name.

    Published: 6 Nov 2012
    5
    Medium

    CVE-2012-5506

    Last Modified: 12 Apr 2025

    python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to cause a denial of service (infinite loop) via an RSS feed request for a folder the user does not have permission to access.

    Published: 6 Nov 2012
    5
    Medium

    CVE-2012-6661

    Last Modified: 12 Apr 2025

    Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it easier for remote attackers to guess the value via unspecified vectors. NOTE: this issue was SPLIT from CVE-2012-5508 due to different vulnerability types (ADT2).

    Published: 6 Nov 2012
    10
    Critical

    CVE-2012-5277

    Last Modified: 11 Apr 2025

    Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-5274, CVE-2012-5275, CVE-2012-5276, and CVE-2012-5280.

    Published: 6 Nov 2012
    5
    Medium

    CVE-2012-5499

    Last Modified: 12 Apr 2025

    python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to cause a denial of service (memory consumption) via a large value, related to formatColumns.

    Published: 6 Nov 2012