CVE Feed

    Dashboard / CVE

    5.8
    Medium

    CVE-2012-5794

    Last Modified: 11 Apr 2025

    The MoneyBookers module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5796

    Last Modified: 11 Apr 2025

    The PayPal Pro module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5799

    Last Modified: 11 Apr 2025

    The Canada Post (aka CanadaPost) module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5813

    Last Modified: 11 Apr 2025

    The Android_Pusher library for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5820

    Last Modified: 11 Apr 2025

    The developer-account sample code in Google AdMob does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 4 Nov 2012
    6.8
    Medium

    CVE-2012-4987

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in RealNetworks RealPlayer 15.0.5.109 allows user-assisted remote attackers to execute arbitrary code via a crafted ZIP file that triggers incorrect processing of long pathnames by the Watch Folders feature.

    Published: 4 Nov 2012
    5.8
    Medium

    CVE-2012-5170

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in Pebble before 2.6.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 4 Nov 2012
    5.1
    Medium

    CVE-2012-3748

    Last Modified: 11 Apr 2025

    Race condition in WebKit in Apple iOS before 6.0.1 and Safari before 6.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript arrays.

    Published: 3 Nov 2012
    5
    Medium

    CVE-2012-3749

    Last Modified: 11 Apr 2025

    The extensions APIs in the kernel in Apple iOS before 6.0.1 provide kernel addresses in responses that contain an OSBundleMachOHeaders key, which makes it easier for remote attackers to bypass the ASLR protection mechanism via a crafted app.

    Published: 3 Nov 2012
    3.6
    Low

    CVE-2012-3750

    Last Modified: 11 Apr 2025

    The Passcode Lock implementation in Apple iOS before 6.0.1 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement and access Passbook passes via unspecified vectors.

    Published: 3 Nov 2012
    6.8
    Medium

    CVE-2012-0025

    Last Modified: 11 Apr 2025

    Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the FlashPix PlugIn 4.2.2.0 for IrfanView, allows remote attackers to cause a denial of service (crash) via a crafted FPX image.

    Published: 2 Nov 2012
    6.8
    Medium

    CVE-2012-4486

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Subuser module before 6.x-1.8 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that switch the user to a subuser via unspecified vectors.

    Published: 2 Nov 2012
    4
    Medium

    CVE-2012-4487

    Last Modified: 11 Apr 2025

    The Subuser module before 6.x-1.8 for Drupal does not properly check "switch subuser" permissions, which allows remote authenticated parent users to change their role by switching to a subuser they created.

    Published: 2 Nov 2012
    2.1
    Low

    CVE-2012-4493

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the administrative interface in the Better Revisions module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer better revisions" permission to inject arbitrary web script or HTML via unspecified vectors.

    Published: 2 Nov 2012
    7.5
    High

    CVE-2012-4498

    Last Modified: 11 Apr 2025

    The Activism module 6.x-2.x before 6.x-2.1 for Drupal does not properly restrict access to the "Campaign" content type, which might allow remote attackers to bypass access restrictions and possibly have other unspecified impact.

    Published: 2 Nov 2012
    2.1
    Low

    CVE-2012-4497

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the "3 slide gallery" in the Elegant Theme module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via a slide URL.

    Published: 2 Nov 2012
    7.8
    High

    CVE-2012-5416

    Last Modified: 11 Apr 2025

    Buffer overflow in Cisco Unified MeetingPlace Web Conferencing before 7.1MR1 Patch 1, 8.0 before 8.0MR1 Patch 1, and 8.5 before 8.5MR3 allows remote attackers to cause a denial of service (daemon hang) via unspecified parameters in a POST request, aka Bug ID CSCua66341.

    Published: 2 Nov 2012
    10
    Critical

    CVE-2012-5417

    Last Modified: 11 Apr 2025

    Cisco Prime Data Center Network Manager (DCNM) before 6.1(1) does not properly restrict access to certain JBoss MainDeployer functionality, which allows remote attackers to execute arbitrary commands via JBoss Application Server Remote Method Invocation (RMI) services, aka Bug ID CSCtz44924.

    Published: 2 Nov 2012
    7.5
    High

    CVE-2012-5576

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.8.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large (1) red, (2) green, or (3) blue color mask in an XWD file.

    Published: 2 Nov 2012
    5
    Medium

    CVE-2012-6551

    Last Modified: 11 Apr 2025

    The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests.

    Published: 2 Nov 2012
    6.4
    Medium

    CVE-2013-3060

    Last Modified: 11 Apr 2025

    The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.

    Published: 2 Nov 2012
    6.8
    Medium

    CVE-2012-4564

    Last Modified: 11 Apr 2025

    ppm2tiff does not check the return value of the TIFFScanlineSize function, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PPM image that triggers an integer overflow, a zero-memory allocation, and a heap-based buffer overflow.

    Published: 2 Nov 2012
    10
    Critical

    CVE-2012-3010

    Last Modified: 11 Apr 2025

    rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remote attackers to cause a denial of service (memory corruption and service crash) or possibly execute arbitrary code via long input data, a different vulnerability than CVE-2012-3021 and CVE-2012-3026.

    Published: 1 Nov 2012
    10
    Critical

    CVE-2012-3021

    Last Modified: 11 Apr 2025

    rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remote attackers to cause a denial of service (memory corruption and service crash) or possibly execute arbitrary code via long input data, a different vulnerability than CVE-2012-3010 and CVE-2012-3026.

    Published: 1 Nov 2012
    10
    Critical

    CVE-2012-3026

    Last Modified: 11 Apr 2025

    rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remote attackers to cause a denial of service (memory corruption and service crash) or possibly execute arbitrary code via long input data, a different vulnerability than CVE-2012-3010 and CVE-2012-3021.

    Published: 1 Nov 2012
    7.8
    High

    CVE-2012-5687

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to the help/ URI.

    Published: 1 Nov 2012
    2.1
    Low

    CVE-2012-5705

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the settings page (admin/settings/hotblocks) in the Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the "administer hotblocks" permission to inject arbitrary web script or HTML via the "block names."

    Published: 1 Nov 2012
    3.5
    Low

    CVE-2012-5704

    Last Modified: 11 Apr 2025

    The Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the "administer hotblocks" permission to cause a denial of service (infinite loop and time out) via a block that references itself.

    Published: 1 Nov 2012
    10
    Critical

    CVE-2012-5409

    Last Modified: 11 Apr 2025

    AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet network, which allows remote attackers to write data to any memory location and consequently execute arbitrary code via crafted messages, as demonstrated by an arbitrary pointer dereference attack or a buffer overflow attack.

    Published: 1 Nov 2012
    2.1
    Low

    CVE-2012-6117

    Last Modified: 11 Apr 2025

    Aeolus Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for /var/log/aeolus-configserver/configserver.log, which allows local users to read plaintext passwords by reading the log file.

    Published: 1 Nov 2012
    4.3
    Medium

    CVE-2012-4939

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface before 3.0-HotFix1 in SolarWinds Orion Network Performance Monitor might allow remote attackers to inject arbitrary web script or HTML via the "Search for an IP address" field.

    Published: 31 Oct 2012
    6.4
    Medium

    CVE-2012-4940

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote attackers to read or delete arbitrary files via a .. (dot dot) in (1) the fileName parameter in a download action to source/loggin/page_log_dwn_file.hsp, or the fileName parameter in (2) an edit action or (3) a delete action to the default URI.

    Published: 31 Oct 2012
    4.3
    Medium

    CVE-2012-4484

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the administrative interface in the Campaign Monitor module before 6.x-2.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this refers to an issue in an independently developed Drupal module, and NOT an issue in the Campaign Monitor software itself (described on the campaignmonitor.com web site).

    Published: 31 Oct 2012
    4.3
    Medium

    CVE-2012-4485

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the galleryformatter_field_formatter_view functiuon in galleryformatter.tpl.php the Gallery formatter module before 7.x-1.2 for Drupal allow remote authenticated users with permissions to create a node or entity to inject arbitrary web script or HTML via the (1) title or (2) alt parameter.

    Published: 31 Oct 2012
    5
    Medium

    CVE-2012-4488

    Last Modified: 11 Apr 2025

    The Location module 6.x before 6.x-3.2 and 7.x before 7.x-3.0-alpha1 for Drupal does not properly check user or node access permissions, which allows remote attackers to read node or user results via the location search page.

    Published: 31 Oct 2012
    4.3
    Medium

    CVE-2012-4490

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Excluded Users module 6.x-1.x before 6.x-1.1 for Drupal allow remote attackers to inject arbitrary web script or HTML via a (1) user name or (2) email address.

    Published: 31 Oct 2012
    5.8
    Medium

    CVE-2012-4491

    Last Modified: 11 Apr 2025

    The Monthly Archive by Node Type module 6.x for Drupal does not properly check permissions defined by node_access modules, which allows remote attackers to access restricted nodes via unspecified vectors.

    Published: 31 Oct 2012
    2.1
    Low

    CVE-2012-4492

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Shorten URLs module 6.x-1.x before 6.x-1.13 and 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors to the (1) report or (2) Custom Services List page.

    Published: 31 Oct 2012
    4.3
    Medium

    CVE-2012-4494

    Last Modified: 11 Apr 2025

    The Shibboleth authentication module 7.x-4.0 for Drupal does not properly check the active status of users, which allows remote blocked users to access bypass intended access restrictions and possibly have other impacts by logging in.

    Published: 31 Oct 2012
    4
    Medium

    CVE-2012-4495

    Last Modified: 11 Apr 2025

    The Mime Mail module 6.x-1.x before 6.x-1.1 for Drupal does not properly restrict access to files outside Drupal's publish files directory, which allows remote authenticated users to send arbitrary files as attachments.

    Published: 31 Oct 2012
    3.5
    Low

    CVE-2012-4500

    Last Modified: 11 Apr 2025

    The Announcements module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users with the "access announcements" permission to bypass node access restrictions and possibly have other unspecified impact.

    Published: 31 Oct 2012
    4.3
    Medium

    CVE-2012-4531

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Joomla! 2.5.x before 2.5.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 31 Oct 2012
    4.3
    Medium

    CVE-2012-4532

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in modules/mod_languages/tmpl/default.php in the Language Switcher module for Joomla! 2.5.x before 2.5.7 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php. NOTE: some of these details are obtained from third party information.

    Published: 31 Oct 2012
    5
    Medium

    CVE-2012-4482

    Last Modified: 11 Apr 2025

    The Ubercart SecureTrading Payment Method module 6.x for Drupal does not properly verify payment notification information, which allows remote attackers to purchase an item without paying via unspecified vectors.

    Published: 31 Oct 2012
    5
    Medium

    CVE-2012-4483

    Last Modified: 11 Apr 2025

    The commons_discussion_views_default_views function in modules/features/commons_discussion/commons_discussion.views_default.inc in the Drupal Commons module 6.x-2.x before 6.x-2.8 for Drupal does not properly enforce intended node access restrictions, which might allow remote attackers to obtain sensitive information via the recent comments listing.

    Published: 31 Oct 2012
    5
    Medium

    CVE-2012-4499

    Last Modified: 11 Apr 2025

    The contact formatter page in the Email Field module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to email the stored address in the entity via unspecified vectors.

    Published: 31 Oct 2012
    5.8
    Medium

    CVE-2012-4489

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in the securelogin_secure_redirect function in the Secure Login module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter.

    Published: 31 Oct 2012
    2.1
    Low

    CVE-2012-4496

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Custom Publishing Options module 6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users with the "administer nodes" permission to inject arbitrary web script or HTML via the status labels parameter.

    Published: 31 Oct 2012
    4.3
    Medium

    CVE-2012-4547

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in awredir.pl in AWStats before 7.1 has unknown impact and attack vectors.

    Published: 31 Oct 2012
    3.5
    Low

    CVE-2012-4934

    Last Modified: 11 Apr 2025

    TomatoCart 1.1.7, when the PayPal Express Checkout module is enabled in sandbox mode, allows remote authenticated users to bypass intended payment requirements by modifying a certain redirection URL.

    Published: 31 Oct 2012