CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2012-5500

    Last Modified: 12 Apr 2025

    The batch id change script (renameObjectsByPaths.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to change the titles of content items by leveraging a valid CSRF token in a crafted request.

    Published: 6 Nov 2012
    5
    Medium

    CVE-2012-5508

    Last Modified: 12 Apr 2025

    The error pages in Plone before 4.2.3 and 4.3 before beta 1 allow remote attackers to obtain random numbers and derive the PRNG state for password resets via unspecified vectors. NOTE: this identifier was SPLIT per ADT2 due to different vulnerability types. CVE-2012-6661 was assigned for the PRNG reseeding issue in Zope.

    Published: 6 Nov 2012
    10
    Critical

    CVE-2012-5274

    Last Modified: 11 Apr 2025

    Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-5275, CVE-2012-5276, CVE-2012-5277, and CVE-2012-5280.

    Published: 6 Nov 2012
    10
    Critical

    CVE-2012-5276

    Last Modified: 11 Apr 2025

    Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-5274, CVE-2012-5275, CVE-2012-5277, and CVE-2012-5280.

    Published: 6 Nov 2012
    4.3
    Medium

    CVE-2012-5490

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in kssdevel.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Nov 2012
    4.3
    Medium

    CVE-2012-5507

    Last Modified: 12 Apr 2025

    AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain passwords via vectors involving timing discrepancies in password validation.

    Published: 6 Nov 2012
    5
    Medium

    CVE-2012-5886

    Last Modified: 11 Apr 2025

    The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to bypass authentication via vectors related to the session ID.

    Published: 5 Nov 2012
    5
    Medium

    CVE-2012-2733

    Last Modified: 11 Apr 2025

    java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not properly restrict the request-header size, which allows remote attackers to cause a denial of service (memory consumption) via a large amount of header data.

    Published: 5 Nov 2012
    0
    Low

    CVE-2012-3439

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-5885, CVE-2012-5886, CVE-2012-5887. Reason: This candidate is a duplicate of CVE-2012-5885, CVE-2012-5886, and CVE-2012-5887. Notes: All CVE users should reference one or more of CVE-2012-5885, CVE-2012-5886, and CVE-2012-5887 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 5 Nov 2012
    7.5
    High

    CVE-2012-4433

    Last Modified: 11 Apr 2025

    Multiple integer overflows in operations/external/ppm-load.c in GEGL (Generic Graphics Library) 0.2.0 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a large (1) width or (2) height value in a Portable Pixel Map (ppm) image, which triggers a heap-based buffer overflow.

    Published: 5 Nov 2012
    8.8
    High

    CVE-2012-5631

    Last Modified: 21 Nov 2024

    ipa 3.0 does not properly check server identity before sending credential containing cookies

    Published: 5 Nov 2012
    5
    Medium

    CVE-2012-5885

    Last Modified: 11 Apr 2025

    The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka server nonce) and nc (aka nonce-count) values, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, a different vulnerability than CVE-2011-1184.

    Published: 5 Nov 2012
    5
    Medium

    CVE-2012-5887

    Last Modified: 30 Oct 2025

    The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests.

    Published: 5 Nov 2012
    5.8
    Medium

    CVE-2012-5780

    Last Modified: 11 Apr 2025

    The Amazon merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5781

    Last Modified: 11 Apr 2025

    Amazon Elastic Load Balancing API Tools does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to overriding the default JDK X509TrustManager.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5782

    Last Modified: 11 Apr 2025

    Amazon Flexible Payments Service (FPS) PHP Library does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to misinterpretation of a certain "true" value.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5787

    Last Modified: 11 Apr 2025

    The PayPal merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5789

    Last Modified: 11 Apr 2025

    PayPal Payments Standard PHP Library before 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to intentional disabling of certificate-validation checks through a "FALSE" value.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5790

    Last Modified: 11 Apr 2025

    PayPal Payments Standard PHP Library 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to misinterpretation of a certain TRUE value.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5795

    Last Modified: 11 Apr 2025

    The PayPal Express module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5797

    Last Modified: 11 Apr 2025

    The PayPal Pro PayFlow module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5798

    Last Modified: 11 Apr 2025

    The PayPal Pro PayFlow EC module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5800

    Last Modified: 11 Apr 2025

    The eBay module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5801

    Last Modified: 11 Apr 2025

    The PayPal module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5802

    Last Modified: 11 Apr 2025

    The PayPal module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5803

    Last Modified: 11 Apr 2025

    The Authorize.Net module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5804

    Last Modified: 11 Apr 2025

    The CyberSource module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5805

    Last Modified: 11 Apr 2025

    The PayPal IPN functionality in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, a different vulnerability than CVE-2012-5806.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5808

    Last Modified: 11 Apr 2025

    The LinkPoint module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5809

    Last Modified: 11 Apr 2025

    The Groupon Redemptions application for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    5.9
    Medium

    CVE-2012-5810

    Last Modified: 11 Apr 2025

    The Chase mobile banking application for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to overriding the default X509TrustManager. NOTE: this vulnerability was fixed in the summer of 2012, but the version number was not changed or is not known.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5811

    Last Modified: 11 Apr 2025

    The Breezy application for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5812

    Last Modified: 11 Apr 2025

    The ACRA library for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5814

    Last Modified: 11 Apr 2025

    Weberknecht, as used in GitHub Gaug.es and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5815

    Last Modified: 11 Apr 2025

    The Rackspace app 2.1.5 for iOS does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5816

    Last Modified: 11 Apr 2025

    AOL Instant Messenger (AIM) 1.0.1.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    7.4
    High

    CVE-2012-5817

    Last Modified: 11 Apr 2025

    Codehaus XFire 1.2.6 and earlier, as used in the Amazon EC2 API Tools Java library and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5818

    Last Modified: 11 Apr 2025

    ElephantDrive does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    7.4
    High

    CVE-2012-5819

    Last Modified: 11 Apr 2025

    FilesAnywhere does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    7.4
    High

    CVE-2012-5822

    Last Modified: 11 Apr 2025

    The contribution feature in Zamboni does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the Python urllib2 library.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5823

    Last Modified: 11 Apr 2025

    Open Source Classifieds does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5824

    Last Modified: 11 Apr 2025

    Trillian 5.1.0.19 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, a different vulnerability than CVE-2009-4831.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5825

    Last Modified: 11 Apr 2025

    Tweepy does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the Python httplib library.

    Published: 4 Nov 2012
    5.9
    Medium

    CVE-2012-3446

    Last Modified: 11 Apr 2025

    Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5788

    Last Modified: 11 Apr 2025

    The PayPal IPN utility does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5793

    Last Modified: 11 Apr 2025

    The Authorize.Net module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5806

    Last Modified: 11 Apr 2025

    The PayPal Payments Pro module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function, a different vulnerability than CVE-2012-5805.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5807

    Last Modified: 11 Apr 2025

    The Authorize.Net eCheck module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5791

    Last Modified: 11 Apr 2025

    PayPal Invoicing does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5792

    Last Modified: 11 Apr 2025

    The Sage Pay Direct module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012