CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2012-5285

    Last Modified: 11 Apr 2025

    Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4.0.2710; and Adobe AIR SDK before 3.4.0.2710 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than other Flash Player buffer overflow CVEs listed in APSB12-22.

    Published: 8 Oct 2012
    2.6
    Low

    CVE-2011-4363

    Last Modified: 11 Apr 2025

    ProcessTable.pm in the Proc::ProcessTable module 0.45 for Perl, when TTY information caching is enabled, allows local users to overwrite arbitrary files via a symlink attack on /tmp/TTYDEVS.

    Published: 7 Oct 2012
    5
    Medium

    CVE-2011-4911

    Last Modified: 11 Apr 2025

    Joomla! before 1.5.12 does not perform a JEXEC check in unspecified files, which allows remote attackers to obtain the installation path via unspecified vectors.

    Published: 7 Oct 2012
    6.8
    Medium

    CVE-2012-1414

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in manager/news.php in Plume CMS 1.2.4 and earlier allows remote attackers to hijack the authentication of administrators for requests that create News pages via a publish action.

    Published: 7 Oct 2012
    4.3
    Medium

    CVE-2011-4909

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.5.12 allow remote attackers to inject arbitrary web script or HTML via the HTTP_REFERER header to (1) components/com_content/views/article/tmpl/form.php, (2) components/com_user/controller.php, (3) plugins/system/legacy/html.php, or (4) templates/beez/html/com_content/article/form.php.

    Published: 7 Oct 2012
    4.3
    Medium

    CVE-2011-4910

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Joomla! before 1.5.12 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Published: 7 Oct 2012
    4.3
    Medium

    CVE-2010-5276

    Last Modified: 11 Apr 2025

    The Memcache module 5.x before 5.x-1.10 and 6.x before 6.x-1.6 for Drupal does not properly handle the $user object in memcache_admin, which might "lead to a role change not being recognized until the user logs in again."

    Published: 7 Oct 2012
    4.9
    Medium

    CVE-2010-5277

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Views Bulk Operations module 6 before 6.x-1.10 for Drupal allows remote authenticated users with user management permissions to bypass intended access restrictions and delete anonymous users (user 0) via unspecified vectors.

    Published: 7 Oct 2012
    4.3
    Medium

    CVE-2010-5275

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in memcache_admin in the Memcache module 5.x before 5.x-1.10 and 6.x before 6.x-1.6 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 7 Oct 2012
    4.3
    Medium

    CVE-2010-5278

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in manager/controllers/default/resource/tvs.php in MODx Revolution 2.0.2-pl, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the class_key parameter. NOTE: some of these details are obtained from third party information.

    Published: 7 Oct 2012
    7.8
    High

    CVE-2011-3918

    Last Modified: 11 Apr 2025

    The Zygote process in Android 4.0.3 and earlier accepts fork requests from processes with arbitrary UIDs, which allows remote attackers to cause a denial of service (reboot loop) via a crafted application.

    Published: 7 Oct 2012
    4.3
    Medium

    CVE-2012-5305

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in CMD_DOMAIN in JBMC Software DirectAdmin 1.403 allows remote attackers to inject arbitrary web script or HTML via the domain parameter.

    Published: 6 Oct 2012
    7.5
    High

    CVE-2012-5304

    Last Modified: 11 Apr 2025

    Static code injection vulnerability in administration/install.php in YVS Image Gallery allows remote attackers to inject arbitrary PHP code into functions/db_connect.php via unspecified vectors. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation.

    Published: 6 Oct 2012
    9.3
    Critical

    CVE-2012-5306

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the SelectDirectory method in DcsCliCtrl.dll in Camera Stream Client ActiveX Control, as used in D-Link DCS-5605 PTZ IP Network Camera, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string argument.

    Published: 6 Oct 2012
    6.8
    Medium

    CVE-2012-1153

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads directory.

    Published: 6 Oct 2012
    4.3
    Medium

    CVE-2012-1564

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in administration/create_album.php in YVS Image Gallery allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Oct 2012
    4.3
    Medium

    CVE-2012-1634

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in video_filter.codecs.inc in the Video Filter module 6.x-2.x and 7.x-2.x for Drupal allows remote attackers to inject arbitrary web script or HTML via the EMBEDLOOKUP parameter for Blip.tv links.

    Published: 6 Oct 2012
    7.5
    High

    CVE-2011-4932

    Last Modified: 11 Apr 2025

    Eval injection vulnerability in ip_cms/modules/standard/content_management/actions.php in ImpressPages CMS 1.0.12 and possibly other versons before 1.0.13 allows remote attackers to execute arbitrary code via the cm_group parameter.

    Published: 6 Oct 2012
    6
    Medium

    CVE-2012-0987

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in edituser.php in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the icmsConfigPlugins[sanitizer_plugins][] parameter.

    Published: 6 Oct 2012
    3.5
    Low

    CVE-2012-1624

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Lingotek module 6.x-1.x before 6.x-1.40 for Drupal allow remote authenticated users to inject arbitrary web script or HTML when (1) creating or (2) editing page content.

    Published: 6 Oct 2012
    4.3
    Medium

    CVE-2012-0986

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) notifications.php, (2) modules/system/admin/images/browser.php, and (3) modules/content/admin/content.php.

    Published: 6 Oct 2012
    7.5
    High

    CVE-2012-1565

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in ez Publish 4.1.4, 4.2, 4.3, 4.4, 4.5, and 4.6 has unknown impact and attack vectors related to an insecure direct object reference.

    Published: 6 Oct 2012
    5
    Medium

    CVE-2012-1623

    Last Modified: 11 Apr 2025

    The Registration Codes module before 6.x-2.4 for Drupal does not restrict access to the registration code list, which might allow remote attackers to bypass intended registration restrictions.

    Published: 6 Oct 2012
    4.7
    Medium

    CVE-2012-4442

    Last Modified: 11 Apr 2025

    Monkey HTTP Daemon 0.9.3 retains the supplementary group IDs of the root account during operations with a non-root effective UID, which might allow local users to bypass intended file-read restrictions by leveraging a race condition in a file-permission check.

    Published: 5 Oct 2012
    6.9
    Medium

    CVE-2012-5303

    Last Modified: 11 Apr 2025

    Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file, as demonstrated by a pathname different from the default /var/run/monkey.pid pathname.

    Published: 5 Oct 2012
    6.9
    Medium

    CVE-2012-4897

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in the installer in VMware Movie Decoder before 9.0 allows local users to gain privileges via a Trojan horse executable file in the installer directory.

    Published: 5 Oct 2012
    4.3
    Medium

    CVE-2012-5050

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the server in VMware vCenter Operations (aka vCOps) before 5.0.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Oct 2012
    5
    Medium

    CVE-2012-5051

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in VMware CapacityIQ 1.5.x allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 5 Oct 2012
    6.9
    Medium

    CVE-2012-4443

    Last Modified: 11 Apr 2025

    Monkey HTTP Daemon 0.9.3 uses a real UID of root and a real GID of root during execution of CGI scripts, which might allow local users to gain privileges by leveraging cgi-bin write access.

    Published: 5 Oct 2012
    9.3
    Critical

    CVE-2012-4894

    Last Modified: 11 Apr 2025

    Google SketchUp before 8.0.14346 (aka 8 Maintenance 3) allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted SKP file.

    Published: 5 Oct 2012
    9.3
    Critical

    CVE-2012-4895

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in SumatraPDF before 2.1 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnerability than CVE-2012-4896.

    Published: 5 Oct 2012
    9.3
    Critical

    CVE-2012-4896

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in SumatraPDF before 2.1 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnerability than CVE-2012-4895.

    Published: 5 Oct 2012
    4.3
    Medium

    CVE-2012-4018

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Final Beta Laboratory MyWebSearch before 1.23 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.

    Published: 5 Oct 2012
    4.3
    Medium

    CVE-2012-4481

    Last Modified: 11 Apr 2025

    The safe-level feature in Ruby 1.8.7 allows context-dependent attackers to modify strings via the NameError#to_s method when operating on Ruby objects. NOTE: this issue is due to an incomplete fix for CVE-2011-1005.

    Published: 5 Oct 2012
    4
    Medium

    CVE-2012-5620

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 5 Oct 2012
    6.8
    Medium

    CVE-2012-2999

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in Cerberus FTP Server before 5.0.5.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add a user account or (2) reconfigure the state of the FTP service, as demonstrated by a request to usermanager/users/modify.

    Published: 4 Oct 2012
    5
    Medium

    CVE-2012-5301

    Last Modified: 11 Apr 2025

    The default configuration of Cerberus FTP Server before 5.0.4.0 supports the DES cipher for SSH sessions, which makes it easier for remote attackers to obtain sensitive information by sniffing the network and performing a brute-force attack on the encrypted data.

    Published: 4 Oct 2012
    7.5
    High

    CVE-2011-5203

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in WB/Default.asp in Akiva WebBoard before 8 SR 1 allows remote attackers to execute arbitrary SQL commands via the name parameter. NOTE: some of these details are obtained from third party information.

    Published: 4 Oct 2012
    4.3
    Medium

    CVE-2012-5295

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in login.cfm in FuseTalk Forums 3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the windowed parameter.

    Published: 4 Oct 2012
    7.5
    High

    CVE-2012-5297

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in edit.asp in Mavili Guestbook, as released in November 2007, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 4 Oct 2012
    5
    Medium

    CVE-2012-5298

    Last Modified: 11 Apr 2025

    Mavili Guestbook, as released in November 2007, stores guestbook.mdb under the web root with insufficient access control, which allows remote attackers to read the database via a direct request.

    Published: 4 Oct 2012
    7.5
    High

    CVE-2012-5299

    Last Modified: 11 Apr 2025

    Mavili Guestbook, as released in November 2007, allows remote attackers to edit, delete, and approve arbitrary messages via a direct request to (1) edit.asp, (2) delete.asp, or (3) approve.asp.

    Published: 4 Oct 2012
    7.5
    High

    CVE-2012-5300

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in art_catalogo.php in MyStore Xpress Tienda Virtual 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 4 Oct 2012
    4.3
    Medium

    CVE-2011-5205

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in audl.php in Rapidleech 2.3 rev42 SVN r358, rev43 SVN r397, and earlier allows remote attackers to inject arbitrary web script or HTML via the links parameter.

    Published: 4 Oct 2012
    4.3
    Medium

    CVE-2011-5206

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in notes.php in Rapidleech before 2.3 rev42 SVN r399 allows remote attackers to inject arbitrary web script or HTML via the notes parameter.

    Published: 4 Oct 2012
    1.9
    Low

    CVE-2011-5204

    Last Modified: 11 Apr 2025

    Akiva WebBoard 8.x stores passwords in plaintext, which allows local users to obtain sensitive information by reading from the database.

    Published: 4 Oct 2012
    4.3
    Medium

    CVE-2011-5207

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/OptionsPostsList.php in the TheCartPress plugin for WordPress before 1.1.6 before 2011-12-31 allows remote attackers to inject arbitrary web script or HTML via the tcp_name_post_XXXXX parameter.

    Published: 4 Oct 2012
    7.5
    High

    CVE-2012-5294

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in art_detalle.php in MyStore Xpress Tienda Virtual allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 4 Oct 2012
    4.3
    Medium

    CVE-2012-5296

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Mavili Guestbook, as released in November 2007, allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) approve.asp, (2) delete.asp, (3) edit.asp, or (4) edit2.asp.

    Published: 4 Oct 2012
    7.5
    High

    CVE-2012-5288

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in page.php in phpMyDirectory 1.3.3 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 4 Oct 2012