CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2012-6097

    Last Modified: 11 Apr 2025

    File descriptor leak in cronie 1.4.8, when running in certain environments, might allow local users to read restricted files, as demonstrated by reading /etc/crontab.

    Published: 22 Oct 2012
    10
    Critical

    CVE-2012-5390

    Last Modified: 12 Apr 2025

    The standard universe shadow (condor_shadow.std) component in Condor 7.7.3 through 7.7.6, 7.8.0 before 7.8.5, and 7.9.0 does no properly check privileges, which allows remote attackers to gain privileges via a crafted standard universe job.

    Published: 22 Oct 2012
    7.8
    High

    CVE-2012-4933

    Last Modified: 11 Apr 2025

    The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username of Ivanhoe and a hard-coded password of Scott for the (1) GetFile_Password and (2) GetConfigInfo_Password operations, which allows remote attackers to obtain sensitive information via a crafted rtrlet/rtr request for the HandleMaintenanceCalls function.

    Published: 20 Oct 2012
    7.8
    High

    CVE-2012-2167

    Last Modified: 11 Apr 2025

    The IBM XIV Storage System Gen3 before 11.1.0.a allows remote attackers to cause a denial of service (device outage) via TCP packets to unspecified ports.

    Published: 20 Oct 2012
    7.5
    High

    CVE-2012-2971

    Last Modified: 11 Apr 2025

    The server in CA ARCserve Backup r12.5, r15, and r16 on Windows does not properly process RPC requests, which allows remote attackers to execute arbitrary code or cause a denial of service via a crafted request.

    Published: 20 Oct 2012
    5
    Medium

    CVE-2012-2972

    Last Modified: 11 Apr 2025

    The (1) server and (2) agent components in CA ARCserve Backup r12.5, r15, and r16 on Windows do not properly validate RPC requests, which allows remote attackers to cause a denial of service (service crash) via a crafted request.

    Published: 20 Oct 2012
    8.5
    High

    CVE-2012-4826

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the SQL/PSM (aka SQL Persistent Stored Module) Stored Procedure (SP) infrastructure in IBM DB2 9.1, 9.5, 9.7 before FP7, 9.8, and 10.1 might allow remote authenticated users to execute arbitrary code by debugging a stored procedure.

    Published: 20 Oct 2012
    6.8
    Medium

    CVE-2012-4845

    Last Modified: 11 Apr 2025

    The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC environment, which allows attackers to bypass intended file-read restrictions by leveraging the setuid installation of the ftp executable file.

    Published: 20 Oct 2012
    6.8
    Medium

    CVE-2012-0306

    Last Modified: 11 Apr 2025

    Symantec Ghost Solution Suite 2.x through 2.5.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted backup file.

    Published: 18 Oct 2012
    9.3
    Critical

    CVE-2012-2290

    Last Modified: 11 Apr 2025

    The client in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375 allows remote attackers to execute arbitrary code by sending a crafted message over a TCP communication channel.

    Published: 18 Oct 2012
    2.1
    Low

    CVE-2012-2284

    Last Modified: 11 Apr 2025

    The (1) install and (2) upgrade processes in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375, when Exchange Server is used, allow local users to read cleartext administrator credentials via unspecified vectors.

    Published: 18 Oct 2012
    4.3
    Medium

    CVE-2012-6092

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web script or HTML via (1) the refresh parameter to PortfolioPublishServlet.java (aka demo/portfolioPublish or Market Data Publisher), or vectors involving (2) debug logs or (3) subscribe messages in webapp/websocket/chat.js. NOTE: AMQ-4124 is covered by CVE-2012-6551.

    Published: 18 Oct 2012
    6.8
    Medium

    CVE-2012-5581

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in tif_dir.c in LibTIFF before 4.0.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DOTRANGE tag in a TIFF image.

    Published: 18 Oct 2012
    2.1
    Low

    CVE-2012-3217

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7.0 allows context-dependent attackers to affect availability, related to Outside In HTML Export SDK.

    Published: 17 Oct 2012
    2.1
    Low

    CVE-2012-3221

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle VM Virtual Box component in Oracle Virtualization 3.2, 4.0, and 4.1 allows local users to affect availability via unknown vectors related to VirtualBox Core. NOTE: The previous information was obtained from the October 2012 CPU. Oracle has not commented on claims from another vendor that this issue is related to "incorrect interrupt handling."

    Published: 17 Oct 2012
    5
    Medium

    CVE-2012-3222

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle iRecruitment component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect availability via unknown vectors related to Signon.

    Published: 17 Oct 2012
    2.1
    Low

    CVE-2012-3223

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.0.5, 5.1.0, 5.2.0, 5.3.0 through 5.3.4, and 6.0.1 allows remote authenticated users to affect confidentiality, related to BASE.

    Published: 17 Oct 2012
    3.5
    Low

    CVE-2012-3224

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.1.0, 5.2.0, and 5.3.0 through 5.3.4 allows remote authenticated users to affect confidentiality, related to BASE.

    Published: 17 Oct 2012
    3.6
    Low

    CVE-2012-3225

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.3.0 through 5.3.4 allows remote authenticated users to affect confidentiality and integrity, related to BASE.

    Published: 17 Oct 2012
    5.5
    Medium

    CVE-2012-3226

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0, 10.0.2, 10.1.0, 10.2.0, 10.2.2, 10.3.0, 10.5.0, 11.0.0 through 11.4.0, and 12.0.0 allows remote authenticated users to affect confidentiality and integrity, related to BASE.

    Published: 17 Oct 2012
    4
    Medium

    CVE-2012-3229

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Siebel Documentation.

    Published: 17 Oct 2012
    4.3
    Medium

    CVE-2012-3230

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 allows remote attackers to affect confidentiality via unknown vectors related to Portal Framework.

    Published: 17 Oct 2012
    4.3
    Medium

    CVE-2012-5058

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to the Web interface.

    Published: 17 Oct 2012
    4
    Medium

    CVE-2012-5061

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0, 10.0.2, 10.1.0, 10.2.0, 10.2.2, 10.3.0, 10.5.0, 11.0.0 through 11.4.0, and 12.0.0 allows remote authenticated users to affect confidentiality, related to BASE.

    Published: 17 Oct 2012
    5
    Medium

    CVE-2012-5063

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0, 10.0.2, 10.1.0, 10.2.0, 10.2.2, 10.3.0, 10.5.0, 11.0.0 through 11.4.0, and 12.0.0 allows remote attackers to affect integrity, related to BASE.

    Published: 17 Oct 2012
    6.8
    Medium

    CVE-2012-5066

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Central Designer component in Oracle Industry Applications 1.3, 1.4, and 1.4.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 17 Oct 2012
    4
    Medium

    CVE-2012-5090

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Agile PLM for Process component in Oracle Supply Chain Products Suite 5.2.2 and 6.1.0.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Document Reference Library.

    Published: 17 Oct 2012
    4.3
    Medium

    CVE-2012-5091

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Agile Product Supplier Collaboration for Process component in Oracle Supply Chain Products Suite 5.2.2 and 6.1.0.0 allows remote attackers to affect confidentiality via unknown vectors related to Supplier Portal.

    Published: 17 Oct 2012
    5.5
    Medium

    CVE-2012-5092

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Agile PLM for Process component in Oracle Supply Chain Products Suite 5.2.2 and 6.1.0.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Supply Chain Relationship Management.

    Published: 17 Oct 2012
    4.3
    Medium

    CVE-2012-5093

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Agile PLM for Process component in Oracle Supply Chain Products Suite 5.2.2 and 6.1.0.0 allows remote attackers to affect integrity via unknown vectors related to Global Spec Management.

    Published: 17 Oct 2012
    5
    Medium

    CVE-2012-5094

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Agile PLM for Process component in Oracle Supply Chain Products Suite 5.2.2 and 6.1.0.0 allows remote attackers to affect confidentiality via unknown vectors related to User Group Management.

    Published: 17 Oct 2012
    4.4
    Medium

    CVE-2012-5095

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to inetd.

    Published: 17 Oct 2012
    4.9
    Medium

    CVE-2012-3228

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.0.5, 5.1.0, 5.2.0, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect integrity and availability, related to BASE.

    Published: 17 Oct 2012
    2.1
    Low

    CVE-2012-5065

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2, and 11.1.1.6.0 allows local users to affect integrity via unknown vectors related to ImagePicker.

    Published: 17 Oct 2012
    3.5
    Low

    CVE-2012-3227

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0, 10.0.2, 10.1.0, 10.2.0, 10.2.2, 10.3.0, 10.5.0, and 11.0.0 through 11.2.0 allows remote authenticated users to affect integrity, related to BASE, a different vulnerability than CVE-2012-3141.

    Published: 17 Oct 2012
    3.5
    Low

    CVE-2012-5064

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0, 10.0.2, 10.1.0, 10.2.0, 10.2.2, 10.3.0, 10.5.0, and 11.0.0 through 11.2.0 allows remote authenticated users to affect confidentiality, related to BASE.

    Published: 17 Oct 2012
    6.9
    Medium

    CVE-2012-3187

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel.

    Published: 17 Oct 2012
    3.6
    Low

    CVE-2012-3165

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect confidentiality and integrity via unknown vectors related to mailx.

    Published: 17 Oct 2012
    4.3
    Medium

    CVE-2012-3175

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown vectors related to Redirects, a different vulnerability than CVE-2012-0518.

    Published: 17 Oct 2012
    3.5
    Low

    CVE-2012-3176

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52 allows remote authenticated users to affect integrity via unknown vectors related to Panel Processor.

    Published: 17 Oct 2012
    4
    Medium

    CVE-2012-3181

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect availability via unknown vectors related to Security.

    Published: 17 Oct 2012
    4.3
    Medium

    CVE-2012-3182

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52 allows remote attackers to affect integrity, related to PIA Core Technology.

    Published: 17 Oct 2012
    4.3
    Medium

    CVE-2012-3184

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2, and 11.1.1.6.0 allows remote attackers to affect integrity via unknown vectors related to Advanced UI.

    Published: 17 Oct 2012
    4.9
    Medium

    CVE-2012-3185

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2, and 11.1.1.6.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Advanced UI, a different vulnerability than CVE-2012-3183 and CVE-2012-3186.

    Published: 17 Oct 2012
    3.5
    Low

    CVE-2012-3188

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50 and 8.51 allows remote authenticated users to affect integrity, related to PIA Core Technology.

    Published: 17 Oct 2012
    7.8
    High

    CVE-2012-3189

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect availability, related to COMSTAR.

    Published: 17 Oct 2012
    2.1
    Low

    CVE-2012-3191

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect availability via unknown vectors related to Data Mover.

    Published: 17 Oct 2012
    3.5
    Low

    CVE-2012-3193

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 10.3.4.2, 11.1.1.5.0, 11.1.1.6.0, and 11.1.1.6.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Administration.

    Published: 17 Oct 2012
    6.4
    Medium

    CVE-2012-3196

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Human Resources component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and availability, related to PDF generation.

    Published: 17 Oct 2012
    4
    Medium

    CVE-2012-3198

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51 and 8.52 allows remote authenticated users to affect availability via unknown vectors related to Query.

    Published: 17 Oct 2012