CVE Feed

    Dashboard / CVE

    6.6
    Medium

    CVE-2012-4467

    Last Modified: 11 Apr 2025

    The (1) do_siocgstamp and (2) do_siocgstampns functions in net/socket.c in the Linux kernel before 3.5.4 use an incorrect argument order, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (system crash) via a crafted ioctl call.

    Published: 10 Oct 2012
    6.5
    Medium

    CVE-2012-4465

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the substr function in parsing.c in cgit 0.9.0.3 and earlier allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via an empty username in the "Author" field in a commit.

    Published: 10 Oct 2012
    4.3
    Medium

    CVE-2012-3040

    Last Modified: 23 May 2025

    Cross-site scripting (XSS) vulnerability in the web server on Siemens SIMATIC S7-1200 PLCs 2.x through 3.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.

    Published: 10 Oct 2012
    2.1
    Low

    CVE-2012-4899

    Last Modified: 11 Apr 2025

    WellinTech KingView 6.5.3 and earlier uses a weak password-hashing algorithm, which makes it easier for local users to discover credentials by reading an unspecified file.

    Published: 10 Oct 2012
    3.3
    Low

    CVE-2012-5355

    Last Modified: 11 Apr 2025

    welcome.py in xdiagnose before 2.5.2ubuntu0.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.

    Published: 10 Oct 2012
    5.8
    Medium

    CVE-2012-5356

    Last Modified: 11 Apr 2025

    The apt-add-repository tool in Ubuntu Software Properties 0.75.x before 0.75.10.3, 0.80.x before 0.80.9.2, 0.81.x before 0.81.13.5, 0.82.x before 0.82.7.3, and 0.92.x before 0.92.8 does not properly check PPA GPG keys imported from a keyserver, which allows remote attackers to install arbitrary package repository GPG keys via a man-in-the-middle (MITM) attack.

    Published: 10 Oct 2012
    4
    Medium

    CVE-2012-3987

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 16.0 on Android assigns chrome privileges to Reader Mode pages, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site.

    Published: 10 Oct 2012
    7.5
    High

    CVE-2012-5195

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the Perl_repeatcpy function in util.c in Perl 5.12.x before 5.12.5, 5.14.x before 5.14.3, and 5.15.x before 15.15.5 allows context-dependent attackers to cause a denial of service (memory consumption and crash) or possibly execute arbitrary code via the 'x' string repeat operator.

    Published: 10 Oct 2012
    10
    Critical

    CVE-2012-4504

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the url::get_pac function in url.cpp in libproxy 0.4.x before 0.4.9 allows remote servers to have an unspecified impact via a large proxy.pac file.

    Published: 10 Oct 2012
    4.3
    Medium

    CVE-2012-4529

    Last Modified: 11 Apr 2025

    The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain the session id (1) via a man-in-the-middle attack or (2) by reading a log.

    Published: 10 Oct 2012
    7.8
    High

    CVE-2012-3549

    Last Modified: 11 Apr 2025

    The SCTP implementation in FreeBSD 8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted ASCONF chunk.

    Published: 9 Oct 2012
    5
    Medium

    CVE-2012-3505

    Last Modified: 11 Apr 2025

    Tinyproxy 1.8.3 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via (1) a large number of headers or (2) a large number of forged headers that trigger hash collisions predictably. bucket.

    Published: 9 Oct 2012
    6.8
    Medium

    CVE-2012-4002

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in GLPI-PROJECT GLPI before 0.83.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 9 Oct 2012
    4.3
    Medium

    CVE-2012-4003

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in GLPI-PROJECT GLPI before 0.83.3 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 9 Oct 2012
    7.5
    High

    CVE-2012-4399

    Last Modified: 11 Apr 2025

    The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

    Published: 9 Oct 2012
    5.8
    Medium

    CVE-2012-5353

    Last Modified: 11 Apr 2025

    Eduserv OpenAthens SP 2.0 for Java allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack."

    Published: 9 Oct 2012
    9.3
    Critical

    CVE-2012-2528

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; Word Automation Services on Microsoft SharePoint Server 2010; and Office Web Apps 2010 SP1 allows remote attackers to execute arbitrary code via a crafted RTF document, aka "RTF File listid Use-After-Free Vulnerability."

    Published: 9 Oct 2012
    5
    Medium

    CVE-2012-2551

    Last Modified: 11 Apr 2025

    The server in Kerberos in Microsoft Windows Server 2008 R2 and R2 SP1, and Windows 7 Gold and SP1, allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a crafted session request, aka "Kerberos NULL Dereference Vulnerability."

    Published: 9 Oct 2012
    4.3
    Medium

    CVE-2012-2552

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the SQL Server Report Manager in Microsoft SQL Server 2000 Reporting Services SP2 and SQL Server 2005 SP4, 2008 SP2 and SP3, 2008 R2 SP1, and 2012 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Reflected XSS Vulnerability."

    Published: 9 Oct 2012
    4.3
    Medium

    CVE-2012-2520

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Microsoft InfoPath 2007 SP2 and SP3 and 2010 SP1, Communicator 2007 R2, Lync 2010 and 2010 Attendee, SharePoint Server 2007 SP2 and SP3 and 2010 SP1, Groove Server 2010 SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted string, aka "HTML Sanitization Vulnerability."

    Published: 9 Oct 2012
    9.3
    Critical

    CVE-2012-2550

    Last Modified: 11 Apr 2025

    Microsoft Works 9 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted Word .doc file, aka "Works Heap Vulnerability."

    Published: 9 Oct 2012
    9.3
    Critical

    CVE-2012-0182

    Last Modified: 11 Apr 2025

    Microsoft Word 2007 SP2 and SP3 does not properly handle memory during the parsing of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Word PAPX Section Corruption Vulnerability."

    Published: 9 Oct 2012
    7.2
    High

    CVE-2012-2529

    Last Modified: 11 Apr 2025

    Integer overflow in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Windows Kernel Integer Overflow Vulnerability."

    Published: 9 Oct 2012
    5
    Medium

    CVE-2012-3436

    Last Modified: 11 Apr 2025

    OpenTTD 0.6.0 through 1.2.1 does not properly validate requests to clear a water tile, which allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a certain sequence of steps related to "the water/coast aspect of tiles which also have railtracks on one half."

    Published: 9 Oct 2012
    4.3
    Medium

    CVE-2011-5209

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in search/ in GraphicsClone Script, possibly 1.11, allows remote attackers to inject arbitrary web script or HTML via the term parameter.

    Published: 9 Oct 2012
    6.8
    Medium

    CVE-2011-5210

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in admin/preview.php in Limny 3.0.0 allows remote attackers to read arbitrary files via a ..%2F (encoded dot dot slash) in the theme parameter.

    Published: 9 Oct 2012
    4.3
    Medium

    CVE-2012-5341

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in statistik.php in Otterware StatIt 4 allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter, (2) show parameter in a stat_tld action, or (3) order parameter in a stat_abfragen action.

    Published: 9 Oct 2012
    7.5
    High

    CVE-2012-5342

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in SenseSites CommonSense CMS allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) special.php, (2) article.php, or (3) cat2.php.

    Published: 9 Oct 2012
    4.3
    Medium

    CVE-2012-5343

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/login.php in Limny 3.0.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO, related to the "PHP_SELF" variable.

    Published: 9 Oct 2012
    5
    Medium

    CVE-2012-5344

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the WebServer (Thttpd.bat) in IpTools (aka Tiny TCP/IP server) 0.1.4 allows remote attackers to read arbitrary files via a .. (dot dot) in a HTTP request.

    Published: 9 Oct 2012
    7.5
    High

    CVE-2012-5347

    Last Modified: 11 Apr 2025

    TinyWebGallery 1.8.3 allows remote attackers to execute arbitrary code via shell metacharacters in the command parameter to (1) inc/filefunctions.inc or (2) info.php.

    Published: 9 Oct 2012
    6.8
    Medium

    CVE-2012-5348

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in MangosWeb Enhanced 3.0.3 allows remote attackers to execute arbitrary SQL commands via the login parameter in a login action to index.php.

    Published: 9 Oct 2012
    2.6
    Low

    CVE-2012-5349

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in pay.php in the Pay With Tweet plugin before 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) link, (2) title, or (3) dl parameter.

    Published: 9 Oct 2012
    6
    Medium

    CVE-2012-5350

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Pay With Tweet plugin before 1.2 for WordPress allows remote authenticated users with certain permissions to execute arbitrary SQL commands via the id parameter in a paywithtweet shortcode.

    Published: 9 Oct 2012
    4.3
    Medium

    CVE-2012-5346

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in wp-live.php in the WP Live.php module 1.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter. NOTE: some of these details are obtained from third party information.

    Published: 9 Oct 2012
    5
    Medium

    CVE-2012-5345

    Last Modified: 11 Apr 2025

    Buffer overflow in the Remote command server (Rcmd.bat) in IpTools (aka Tiny TCP/IP server) 0.1.4 allows remote attackers to cause a denial of service (crash) via a long string to TCP port 23.

    Published: 9 Oct 2012
    5
    Medium

    CVE-2012-5110

    Last Modified: 11 Apr 2025

    The compositor in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 9 Oct 2012
    7.5
    High

    CVE-2012-5111

    Last Modified: 11 Apr 2025

    Google Chrome before 22.0.1229.92 does not monitor for crashes of Pepper plug-ins, which has unspecified impact and remote attack vectors.

    Published: 9 Oct 2012
    7.5
    High

    CVE-2012-2900

    Last Modified: 11 Apr 2025

    Skia, as used in Google Chrome before 22.0.1229.92, does not properly render text, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors.

    Published: 9 Oct 2012
    9.3
    Critical

    CVE-2012-5108

    Last Modified: 11 Apr 2025

    Race condition in Google Chrome before 22.0.1229.92 allows remote attackers to execute arbitrary code via vectors related to audio devices.

    Published: 9 Oct 2012
    10
    Critical

    CVE-2012-3983

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 9 Oct 2012
    9.3
    Critical

    CVE-2012-3991

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict JSAPI access to the GetProperty function, which allows remote attackers to bypass the Same Origin Policy and possibly have unspecified other impact via a crafted web site.

    Published: 9 Oct 2012
    9.3
    Critical

    CVE-2012-4185

    Last Modified: 11 Apr 2025

    Buffer overflow in the nsCharTraits::length function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

    Published: 9 Oct 2012
    9.3
    Critical

    CVE-2012-4188

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 9 Oct 2012
    5
    Medium

    CVE-2012-5055

    Last Modified: 11 Apr 2025

    DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.

    Published: 9 Oct 2012
    4.9
    Medium

    CVE-2012-0957

    Last Modified: 11 Apr 2025

    The override_release function in kernel/sys.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive information from kernel stack memory via a uname system call in conjunction with a UNAME26 personality.

    Published: 9 Oct 2012
    4.3
    Medium

    CVE-2012-3985

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly implement the HTML5 Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging initial-origin access after document.domain has been set.

    Published: 9 Oct 2012
    4.3
    Medium

    CVE-2012-3986

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict calls to DOMWindowUtils (aka nsDOMWindowUtils) methods, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code.

    Published: 9 Oct 2012
    9.3
    Critical

    CVE-2012-3988

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 might allow user-assisted remote attackers to execute arbitrary code via vectors involving use of mozRequestFullScreen to enter full-screen mode, and use of the history.back method for backwards history navigation.

    Published: 9 Oct 2012
    9.3
    Critical

    CVE-2012-3989

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly perform a cast of an unspecified variable during use of the instanceof operator on a JavaScript object, which allows remote attackers to execute arbitrary code or cause a denial of service (assertion failure) via a crafted web site.

    Published: 9 Oct 2012