CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2012-3990

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the IME State Manager implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors, related to the nsIContent::GetNameSpaceID function.

    Published: 9 Oct 2012
    4.3
    Medium

    CVE-2012-3992

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly manage history data, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive POST content via vectors involving a location.hash write operation and history navigation that triggers the loading of a URL into the history object.

    Published: 9 Oct 2012
    4.3
    Medium

    CVE-2012-3994

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allow remote attackers to conduct cross-site scripting (XSS) attacks via a binary plugin that uses Object.defineProperty to shadow the top object, and leverages the relationship between top.location and the location property.

    Published: 9 Oct 2012
    9.3
    Critical

    CVE-2012-4179

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the nsHTMLCSSUtils::CreateCSSPropertyTxn function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

    Published: 9 Oct 2012
    9.3
    Critical

    CVE-2012-4180

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the nsHTMLEditor::IsPrevCharInNodeWhitespace function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 9 Oct 2012
    9.3
    Critical

    CVE-2012-4182

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the nsTextEditRules::WillInsert function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

    Published: 9 Oct 2012
    9.3
    Critical

    CVE-2012-4183

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the DOMSVGTests::GetRequiredFeatures function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

    Published: 9 Oct 2012
    9.3
    Critical

    CVE-2012-4187

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly manage a certain insPos variable, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and assertion failure) via unspecified vectors.

    Published: 9 Oct 2012
    3.6
    Low

    CVE-2012-4518

    Last Modified: 11 Apr 2025

    ibacm 1.0.7 creates files with world-writable permissions, which allows local users to overwrite the ib_acm daemon log or ibacm.port file.

    Published: 9 Oct 2012
    9.3
    Critical

    CVE-2012-3982

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 9 Oct 2012
    6.8
    Medium

    CVE-2012-3984

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly handle navigation away from a web page that has a SELECT element's menu active, which allows remote attackers to spoof page content via vectors involving absolute positioning and scrolling.

    Published: 9 Oct 2012
    9.3
    Critical

    CVE-2012-3993

    Last Modified: 11 Apr 2025

    The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not properly interact with failures of InstallTrigger methods, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site, related to an "XrayWrapper pollution" issue.

    Published: 9 Oct 2012
    9.3
    Critical

    CVE-2012-3995

    Last Modified: 11 Apr 2025

    The IsCSSWordSpacingSpace function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 9 Oct 2012
    9.3
    Critical

    CVE-2012-4181

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the nsSMILAnimationController::DoSample function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

    Published: 9 Oct 2012
    4.3
    Medium

    CVE-2012-4184

    Last Modified: 11 Apr 2025

    The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not prevent access to properties of a prototype for a standard class, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site.

    Published: 9 Oct 2012
    9.3
    Critical

    CVE-2012-4186

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the nsWaveReader::DecodeAudioData function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 9 Oct 2012
    7.8
    High

    CVE-2012-5166

    Last Modified: 11 Apr 2025

    ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to cause a denial of service (named daemon hang) via unspecified combinations of resource records.

    Published: 9 Oct 2012
    6.8
    Medium

    CVE-2012-5354

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly handle navigation away from a web page that has multiple menus of SELECT elements active, which allows remote attackers to conduct clickjacking attacks via vectors involving an XPI file, the window.open method, and the Geolocation API, a different vulnerability than CVE-2012-3984.

    Published: 9 Oct 2012
    4.3
    Medium

    CVE-2012-5330

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in asaanCart 0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to calc.php, (2) chat.php, (3) register.php, or (4) index.php in libs/smarty_ajax/; or the (5) page parameter to libs/smarty_ajax/index.php.

    Published: 8 Oct 2012
    6.8
    Medium

    CVE-2012-5331

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in asaanCart 0.9 allows remote attackers to include arbitrary local files via a .. (dot dot) in the page parameter to index.php.

    Published: 8 Oct 2012
    5
    Medium

    CVE-2012-5332

    Last Modified: 11 Apr 2025

    at32 Reverse Proxy 1.060.310 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a long string in an HTTP header field, as demonstrated using the If-Unmodified-Since field.

    Published: 8 Oct 2012
    7.5
    High

    CVE-2012-5333

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in page.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 8 Oct 2012
    7.5
    High

    CVE-2012-5334

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in product_desc.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the pid parameter.

    Published: 8 Oct 2012
    4
    Medium

    CVE-2012-5335

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Tiny Server 1.1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the URI of an HTTP request.

    Published: 8 Oct 2012
    4
    Medium

    CVE-2012-5329

    Last Modified: 11 Apr 2025

    Buffer overflow in TYPSoft FTP Server 1.1 allows remote authenticated users to cause a denial of service (application crash) via a long string in an APPE command.

    Published: 8 Oct 2012
    6.8
    Medium

    CVE-2012-1671

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in index.php in phpPaleo 4.8b155 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

    Published: 8 Oct 2012
    4.3
    Medium

    CVE-2012-0846

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar 1.2.4 allows remote attackers to inject arbitrary web script or HTML via the Location variable.

    Published: 8 Oct 2012
    9.3
    Critical

    CVE-2012-5324

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in the Pdf Printer Preferences ActiveX Control in pdfxctrl.dll in Tracker Software PDF-XChange 3.60.0128 allow remote attackers to execute arbitrary code via a long string in the (1) sub_path parameter to the StoreInRegistry function or (2) sub_key parameter to the InitFromRegistry function.

    Published: 8 Oct 2012
    2.1
    Low

    CVE-2012-5325

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the scr_do_redirect function in scr.php in the Shortcode Redirect plugin 1.0.01 and earlier for WordPress allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via the (1) url or (2) sec attributes in a redirect tag.

    Published: 8 Oct 2012
    6.8
    Medium

    CVE-2012-5326

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in admin/function.php in IDevSpot iSupport 1.x allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via an administrators action.

    Published: 8 Oct 2012
    6.5
    Medium

    CVE-2012-5327

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in fs-admin/fs-admin.php in the Mingle Forum plugin 1.0.32.1 and other versions before 1.0.33 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) delete_usrgrp[] parameter in a delete_usergroups action, (2) usergroup parameter in an add_user_togroup action, or (3) add_forum_group_id parameter in an add_forum_submit action.

    Published: 8 Oct 2012
    6.5
    Medium

    CVE-2012-5328

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in the Mingle Forum plugin 1.0.32.1 and other versions before 1.0.33 for WordPress might allow remote authenticated users to execute arbitrary SQL commands via the (1) memberid or (2) groupid parameters in a removemember action or (3) id parameter to fs-admin/fs-admin.php, or (4) edit_forum_id parameter in an edit_save_forum action to fs-admin/wpf-edit-forum-group.php.

    Published: 8 Oct 2012
    7.5
    High

    CVE-2011-4342

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in wp_xml_export.php in the BackWPup plugin before 1.7.2 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpabs parameter.

    Published: 8 Oct 2012
    4
    Medium

    CVE-2011-4927

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the bazaar repository adapter in Redmine 1.0.x before 1.0.5 allows remote authenticated users to obtain sensitive information via unknown vectors.

    Published: 8 Oct 2012
    4.3
    Medium

    CVE-2011-4928

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the textile formatter in Redmine before 1.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 8 Oct 2012
    7.5
    High

    CVE-2011-4929

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitrary commands via unknown vectors.

    Published: 8 Oct 2012
    9.3
    Critical

    CVE-2012-1189

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in modules/graphic/ssgraph/grsound.cpp in The Open Racing Car Simulator (TORCS) before 1.3.3 and Speed Dreams allows user-assisted remote attackers to execute arbitrary code via a long file name in an engine sample attribute in an xml configuration file.

    Published: 8 Oct 2012
    6.8
    Medium

    CVE-2012-1308

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in redpass.cgi in D-Link DSL-2640B Firmware EU_4.00 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the sysPassword parameter.

    Published: 8 Oct 2012
    6.8
    Medium

    CVE-2012-1416

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in SocialCMS 1.0.2 allow remote attackers to hijack the authentication of administrators for requests that (1) add administrator accounts via a member_new action to my_admin/admin1_members.php or (2) modify the default site title via a save action to my_admin/admin1_configuration.php.

    Published: 8 Oct 2012
    6.8
    Medium

    CVE-2012-5319

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in setup/security.cgi in D-Link DCS-900, DCS-2000, and DCS-5300 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the rootpass parameter.

    Published: 8 Oct 2012
    4.3
    Medium

    CVE-2012-5322

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Xavi X7968 allow remote attackers to inject arbitrary web script or HTML via the (1) pvcName parameter to webconfig/wan/confirm.html/confirm or (2) host_name_txtbox parameter to webconfig/lan/lan_config.html/local_lan_config.

    Published: 8 Oct 2012
    6.8
    Medium

    CVE-2012-5323

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in webconfig/admin_passwd/passwd.html/admin_passwd in Xavi X7968 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the sysUserName, sysPassword, and sysCfmPwd parameters.

    Published: 8 Oct 2012
    5
    Medium

    CVE-2011-5208

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in the BackWPup plugin before 1.4.1 for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the wpabs parameter to (1) app/options-view_log-iframe.php or (2) app/options-runnow-iframe.php.

    Published: 8 Oct 2012
    6.8
    Medium

    CVE-2012-5320

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in password.cgi in Sagem F@ST 2604 253180972B allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the sysPassword parameter.

    Published: 8 Oct 2012
    5.8
    Medium

    CVE-2012-5321

    Last Modified: 11 Apr 2025

    tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks via the url parameter, aka "frame injection."

    Published: 8 Oct 2012
    7.5
    High

    CVE-2012-5310

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the WP e-Commerce plugin before 3.8.7.6 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 8 Oct 2012
    Unknown

    CVE-2012-5311

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-0227. Reason: This candidate is a duplicate of CVE-2012-0227. Notes: All CVE users should reference CVE-2012-0227 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 8 Oct 2012
    4.3
    Medium

    CVE-2012-5314

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in ViewGit 0.0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the f parameter.

    Published: 8 Oct 2012
    3.5
    Low

    CVE-2012-5316

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Barracuda Spam & Virus Firewall 600 Firmware 4.0.1.009 and earlier allow remote authenticated users to inject arbitrary web script or HTML via (1) Troubleshooting in the Trace route Device module or (2) LDAP Username in the LDAP Configuration module.

    Published: 8 Oct 2012
    7.5
    High

    CVE-2012-5317

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in main_bigware_43.php in Bigware Shop before 2.1.5 allows remote attackers to execute arbitrary SQL commands via the lastname parameter in a process action.

    Published: 8 Oct 2012