CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2012-5692

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in admin/sources/base/core.php in Invision Power Board (aka IPB or IP.Board) 3.1.x through 3.3.x has unknown impact and remote attack vectors.

    Published: 31 Oct 2012
    3.3
    Low

    CVE-2012-4610

    Last Modified: 11 Apr 2025

    EMC Avamar Client for VMware 6.1 stores the cleartext server root password on the proxy client, which might allow remote attackers to obtain sensitive information by leveraging "network access" to the proxy client.

    Published: 31 Oct 2012
    Unknown

    CVE-2012-5979

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-5079. Reason: This candidate is a duplicate of CVE-2012-5079. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2012-5079 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Oct 2012
    4.3
    Medium

    CVE-2012-4233

    Last Modified: 11 Apr 2025

    LibreOffice 3.5.x before 3.5.7.2 and 3.6.x before 3.6.1, and OpenOffice.org (OOo), allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted (1) odt file to vcllo.dll, (2) ODG (Drawing document) file to svxcorelo.dll, (3) PolyPolygon record in a .wmf (Window Meta File) file embedded in a ppt (PowerPoint) file to tllo.dll, or (4) xls (Excel) file to scfiltlo.dll.

    Published: 31 Oct 2012
    4.7
    Medium

    CVE-2012-4565

    Last Modified: 11 Apr 2025

    The tcp_illinois_info function in net/ipv4/tcp_illinois.c in the Linux kernel before 3.4.19, when the net.ipv4.tcp_congestion_control illinois setting is enabled, allows local users to cause a denial of service (divide-by-zero error and OOPS) by reading TCP stats.

    Published: 31 Oct 2012
    9.3
    Critical

    CVE-2012-0023

    Last Modified: 11 Apr 2025

    Double free vulnerability in the get_chunk_header function in modules/demux/ty.c in VideoLAN VLC media player 0.9.0 through 1.1.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TiVo (TY) file.

    Published: 30 Oct 2012
    6.4
    Medium

    CVE-2013-4497

    Last Modified: 11 Apr 2025

    The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions.

    Published: 30 Oct 2012
    5
    Medium

    CVE-2012-4514

    Last Modified: 11 Apr 2025

    rendering/render_replaced.cpp in Konqueror in KDE before 4.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted web page, related to "trying to reuse a frame with a null part."

    Published: 30 Oct 2012
    6.8
    Medium

    CVE-2012-4515

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by accessing an iframe when it is being updated.

    Published: 30 Oct 2012
    6.4
    Medium

    CVE-2012-4513

    Last Modified: 11 Apr 2025

    khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via large canvas dimensions, which leads to an unexpected sign extension and a heap-based buffer over-read.

    Published: 30 Oct 2012
    8.8
    High

    CVE-2012-4512

    Last Modified: 21 Nov 2024

    The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."

    Published: 30 Oct 2012
    5.1
    Medium

    CVE-2012-4545

    Last Modified: 11 Apr 2025

    The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSS-Negotiate authentication, delegates user credentials through GSSAPI, which allows remote servers to authenticate as the client via the delegated credentials.

    Published: 30 Oct 2012
    7.1
    High

    CVE-2012-4662

    Last Modified: 11 Apr 2025

    The DCERPC inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.3 before 8.3(2.25), 8.4 before 8.4(2.5), and 8.5 before 8.5(1.13) and the Firewall Services Module (FWSM) 4.1 before 4.1(7) in Cisco Catalyst 6500 series switches and 7600 series routers allows remote attackers to cause a denial of service (device reload) via a crafted DCERPC packet, aka Bug IDs CSCtr21376 and CSCtr27524.

    Published: 29 Oct 2012
    7.1
    High

    CVE-2012-4643

    Last Modified: 11 Apr 2025

    The DHCP server on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 7.0 before 7.2(5.8), 7.1 before 7.2(5.8), 7.2 before 7.2(5.8), 8.0 before 8.0(5.28), 8.1 before 8.1(2.56), 8.2 before 8.2(5.27), 8.3 before 8.3(2.31), 8.4 before 8.4(3.10), 8.5 before 8.5(1.9), and 8.6 before 8.6(1.5) does not properly allocate memory for DHCP packets, which allows remote attackers to cause a denial of service (device reload) via a series of crafted IPv4 packets, aka Bug ID CSCtw84068.

    Published: 29 Oct 2012
    7.8
    High

    CVE-2012-4660

    Last Modified: 11 Apr 2025

    The SIP inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.2 before 8.2(5.17), 8.3 before 8.3(2.28), 8.4 before 8.4(2.13), 8.5 before 8.5(1.4), and 8.6 before 8.6(1.5) allows remote attackers to cause a denial of service (device reload) via a crafted SIP media-update packet, aka Bug ID CSCtr63728.

    Published: 29 Oct 2012
    9
    Critical

    CVE-2012-4661

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the DCERPC inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.3 before 8.3(2.34), 8.4 before 8.4(4.4), 8.5 before 8.5(1.13), and 8.6 before 8.6(1.3) and the Firewall Services Module (FWSM) 4.1 before 4.1(9) in Cisco Catalyst 6500 series switches and 7600 series routers might allow remote attackers to execute arbitrary code via a crafted DCERPC packet, aka Bug IDs CSCtr21359 and CSCtr27522.

    Published: 29 Oct 2012
    7.1
    High

    CVE-2012-4659

    Last Modified: 11 Apr 2025

    The AAA functionality in the IPv4 SSL VPN implementations on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.2 before 8.2(5.30) and 8.3 before 8.3(2.34) allows remote attackers to cause a denial of service (device reload) via a crafted authentication response, aka Bug ID CSCtz04566.

    Published: 29 Oct 2012
    7.1
    High

    CVE-2012-4663

    Last Modified: 11 Apr 2025

    The DCERPC inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.3 before 8.3(2.25), 8.4 before 8.4(2.5), and 8.5 before 8.5(1.13) and the Firewall Services Module (FWSM) 4.1 before 4.1(7) in Cisco Catalyst 6500 series switches and 7600 series routers allows remote attackers to cause a denial of service (device reload) via a crafted DCERPC packet, aka Bug IDs CSCtr21346 and CSCtr27521.

    Published: 29 Oct 2012
    10
    Critical

    CVE-2012-4501

    Last Modified: 11 Apr 2025

    Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API calls to delete VMs.

    Published: 26 Oct 2012
    4.3
    Medium

    CVE-2012-5470

    Last Modified: 11 Apr 2025

    libpng_plugin in VideoLAN VLC media player 2.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted PNG file.

    Published: 26 Oct 2012
    4.3
    Medium

    CVE-2012-4019

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in tokyo_bbs.cgi in Come on Girls Interface (CGI) Tokyo BBS allows remote attackers to inject arbitrary web script or HTML via vectors related to the error page.

    Published: 26 Oct 2012
    6.8
    Medium

    CVE-2012-4729

    Last Modified: 11 Apr 2025

    Wing FTP Server before 4.1.1 allows remote authenticated users to cause a denial of service (daemon crash) via two zip commands.

    Published: 26 Oct 2012
    2.1
    Low

    CVE-2012-4544

    Last Modified: 11 Apr 2025

    The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of service (domain 0 memory consumption) via a crafted (a) kernel or (b) ramdisk.

    Published: 26 Oct 2012
    4.3
    Medium

    CVE-2012-4563

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Google Web Toolkit (GWT) 2.4 Beta and release candidates before 2.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Oct 2012
    6.8
    Medium

    CVE-2012-5671

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the dkim_exim_query_dns_txt function in dkim.c in Exim 4.70 through 4.80, when DKIM support is enabled and acl_smtp_connect and acl_smtp_rcpt are not set to "warn control = dkim_disable_verify," allows remote attackers to execute arbitrary code via an email from a malicious DNS server.

    Published: 26 Oct 2012
    4.3
    Medium

    CVE-2012-5920

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Google Web Toolkit (GWT) 2.4 through 2.5 Final, as used in JBoss Operations Network (ON) 3.1.1 and possibly other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2012-4563.

    Published: 26 Oct 2012
    6.4
    Medium

    CVE-2012-4196

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read the Location object via a prototype property-injection attack that defeats certain protection mechanisms for this object.

    Published: 26 Oct 2012
    4.3
    Medium

    CVE-2012-4194

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 do not prevent use of the valueOf method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a plugin.

    Published: 26 Oct 2012
    4.3
    Medium

    CVE-2012-4195

    Last Modified: 11 Apr 2025

    The nsLocation::CheckURL function in Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 does not properly determine the calling document and principal in its return value, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site, and makes it easier for remote attackers to execute arbitrary JavaScript code by leveraging certain add-on behavior.

    Published: 26 Oct 2012
    4.3
    Medium

    CVE-2011-5214

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) modules/admin/admin_module_index.php, or (3) modules/calendar/customise_calendar_times.php; login[] parameter to (4) index.php or (5) pub/clients.php; or framed parameter to (6) licence/index.php or (7) licence/view.php.

    Published: 25 Oct 2012
    7.5
    High

    CVE-2011-5215

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Video Community Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 25 Oct 2012
    7.5
    High

    CVE-2011-5216

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in ajax.php in SCORM Cloud For WordPress plugin before 1.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the active parameter. NOTE: some of these details are obtained from third party information.

    Published: 25 Oct 2012
    7.5
    High

    CVE-2011-5218

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in DotA OpenStats 1.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Published: 25 Oct 2012
    5
    Medium

    CVE-2011-5219

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in examples/show_code.php in mPDF 5.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

    Published: 25 Oct 2012
    7.5
    High

    CVE-2011-5222

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in rub2_w.php in PHP Flirt-Projekt 4.8 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the rub parameter.

    Published: 25 Oct 2012
    4.3
    Medium

    CVE-2011-5223

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in logout.php in Cacti before 0.8.7i allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 25 Oct 2012
    7.5
    High

    CVE-2011-5224

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 25 Oct 2012
    4.3
    Medium

    CVE-2011-5225

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 25 Oct 2012
    6.8
    Medium

    CVE-2011-5226

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to hijack the authentication of an administrator for requests that trigger snapshots.

    Published: 25 Oct 2012
    10
    Critical

    CVE-2011-5227

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the Syslog service (nssyslogd.exe) in Enterasys Network Management Suite (NMS) before 4.1.0.80 allows remote attackers to execute arbitrary code via a long PRIO field in a message to UDP port 514.

    Published: 25 Oct 2012
    4.3
    Medium

    CVE-2011-5228

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Search module (quickstart/search) in appRain CMF 0.1.5 allows remote attackers to inject arbitrary web script or HTML via the ss parameter.

    Published: 25 Oct 2012
    Unknown

    CVE-2011-5231

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-0023. Reason: This candidate is a duplicate of CVE-2012-0023. Notes: All CVE users should reference CVE-2012-0023 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 25 Oct 2012
    Unknown

    CVE-2011-5232

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-0025. Reason: This candidate is a duplicate of CVE-2012-0025. Notes: All CVE users should reference CVE-2012-0025 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 25 Oct 2012
    4.3
    Medium

    CVE-2011-5233

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows Per Strip" and "Samples Per Pixel" values in a TIFF image file.

    Published: 25 Oct 2012
    7.5
    High

    CVE-2011-5234

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in user.php in Social Network Community 2 allows remote attackers to execute arbitrary SQL commands via the userId parameter.

    Published: 25 Oct 2012
    7.5
    High

    CVE-2011-5235

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in mnoGoSearch before 3.3.12 allows remote attackers to execute arbitrary SQL commands via the hostname in a hypertext link.

    Published: 25 Oct 2012
    4.3
    Medium

    CVE-2011-5221

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the getLog function in svnlook.php in WebSVN before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the path parameter to (1) comp.php, (2) diff.php, or (3) revision.php.

    Published: 25 Oct 2012
    7.5
    High

    CVE-2011-5213

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login[username] parameter to index.php, (2) parent_id parameter to modules/Documents/version_list.php, or (3) contact_id parameter to modules/Documents/index.php.

    Published: 25 Oct 2012
    5
    Medium

    CVE-2011-5217

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the PXE Mtftp service in Hitachi JP1/ServerConductor/DeploymentManager before 08-55 Japanese and before 08-51 English allows remote attackers to read arbitrary files via unknown vectors.

    Published: 25 Oct 2012
    4.3
    Medium

    CVE-2011-5220

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in templates/default/Admin/Login.html in PHP-SCMS 1.6.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter to index.php.

    Published: 25 Oct 2012