CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2012-5289

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Plogger 1.0 RC1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) index.php or (2) gallery.php.

    Published: 4 Oct 2012
    7.5
    High

    CVE-2012-5291

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in team.php in Posse Softball Director CMS allows remote attackers to execute arbitrary SQL commands via the idteam parameter.

    Published: 4 Oct 2012
    7.5
    High

    CVE-2012-5292

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Atar2b CMS 4.0.1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) gallery_e.php, (2) pageE.php, or (3) pageH.php.

    Published: 4 Oct 2012
    7.5
    High

    CVE-2012-5293

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in SAPID CMS 1.2.3 Stable allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[root_path] parameter to usr/extensions/get_tree.inc.php or (2) root_path parameter to usr/extensions/get_infochannel.inc.php.

    Published: 4 Oct 2012
    7.5
    High

    CVE-2012-5290

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in EasyWebRealEstate allow remote attackers to execute arbitrary SQL commands via the (1) lstid parameter to listings.php or (2) infoid parameter to index.php.

    Published: 4 Oct 2012
    5
    Medium

    CVE-2012-3267

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.20 allows remote attackers to obtain sensitive information via unknown vectors.

    Published: 4 Oct 2012
    5
    Medium

    CVE-2012-3819

    Last Modified: 11 Apr 2025

    Stack consumption vulnerability in dartwebserver.dll 1.9 and earlier, as used in Dart PowerTCP WebServer for ActiveX and other products, allows remote attackers to cause a denial of service (daemon crash) via a long request.

    Published: 4 Oct 2012
    7.5
    High

    CVE-2012-5518

    Last Modified: 21 Nov 2024

    vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate)

    Published: 4 Oct 2012
    7.2
    High

    CVE-2012-0691

    Last Modified: 11 Apr 2025

    CA License (aka CA Licensing) before 1.90.03 does not properly restrict system commands, which allows local users to gain privileges via unspecified vectors.

    Published: 2 Oct 2012
    7.2
    High

    CVE-2012-0692

    Last Modified: 11 Apr 2025

    CA License (aka CA Licensing) before 1.90.03 allows local users to modify or create arbitrary files, and consequently gain privileges, via unspecified vectors.

    Published: 2 Oct 2012
    5
    Medium

    CVE-2012-3266

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in IBRIX 6.1.196 through 6.1.251 on HP IBRIX X9000 Storage allows remote attackers to obtain sensitive information via unknown vectors.

    Published: 2 Oct 2012
    5.8
    Medium

    CVE-2012-3314

    Last Modified: 11 Apr 2025

    IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1, 6.2.0, 6.2.1, and 6.2.2 allow remote attackers to establish sessions via a crafted message that leverages (1) a signature-validation bypass for SAML messages containing unsigned elements, (2) incorrect validation of XML messages, or (3) a certificate-chain validation bypass for an XML signature element that contains the signing certificate.

    Published: 2 Oct 2012
    3.3
    Low

    CVE-2012-5237

    Last Modified: 11 Apr 2025

    The dissect_hsrp function in epan/dissectors/packet-hsrp.c in the HSRP dissector in Wireshark 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

    Published: 2 Oct 2012
    3.3
    Low

    CVE-2012-5238

    Last Modified: 11 Apr 2025

    epan/dissectors/packet-ppp.c in the PPP dissector in Wireshark 1.8.x before 1.8.3 uses incorrect OUI data structures during the decoding of (1) PPP and (2) LCP data, which allows remote attackers to cause a denial of service (assertion failure and application exit) via a malformed packet.

    Published: 2 Oct 2012
    4.3
    Medium

    CVE-2012-5239

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-3548. Reason: This candidate is a reservation duplicate of CVE-2012-3548. Notes: All CVE users should reference CVE-2012-3548 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 2 Oct 2012
    5
    Medium

    CVE-2012-6139

    Last Modified: 11 Apr 2025

    libxslt before 1.1.28 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an (1) empty match attribute in a XSL key to the xsltAddKey function in keys.c or (2) uninitialized variable to the xsltDocumentFunction function in functions.c.

    Published: 2 Oct 2012
    3.6
    Low

    CVE-2012-3504

    Last Modified: 11 Apr 2025

    The nssconfigFound function in genkey.pl in crypto-utils 2.4.1-34 allows local users to overwrite arbitrary files via a symlink attack on the "list" file in the current working directory.

    Published: 2 Oct 2012
    5
    Medium

    CVE-2012-4466

    Last Modified: 11 Apr 2025

    Ruby 1.8.7 before patchlevel 371, 1.9.3 before patchlevel 286, and 2.0 before revision r37068 allows context-dependent attackers to bypass safe-level restrictions and modify untainted strings via the name_err_mesg_to_str API function, which marks the string as tainted, a different vulnerability than CVE-2011-1005.

    Published: 2 Oct 2012
    5.8
    Medium

    CVE-2012-5240

    Last Modified: 11 Apr 2025

    Buffer overflow in the dissect_tlv function in epan/dissectors/packet-ldp.c in the LDP dissector in Wireshark 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a malformed packet.

    Published: 2 Oct 2012
    4.3
    Medium

    CVE-2012-1470

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in code_editor.php in ocPortal before 7.1.6 allow remote attackers to inject arbitrary web script or HTML via the (1) path or (2) line parameters.

    Published: 1 Oct 2012
    5
    Medium

    CVE-2012-1471

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in catalogue_file.php in ocPortal before 7.1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Published: 1 Oct 2012
    7.5
    High

    CVE-2012-1602

    Last Modified: 11 Apr 2025

    user.php in NextBBS 0.6 allows remote attackers to bypass authentication and gain administrator access by setting the userkey cookie to 1.

    Published: 1 Oct 2012
    4.3
    Medium

    CVE-2012-1604

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in NextBBS 0.6 allows remote attackers to inject arbitrary web script or HTML via the do parameter to index.php.

    Published: 1 Oct 2012
    5
    Medium

    CVE-2012-4063

    Last Modified: 11 Apr 2025

    The Apache Santuario configuration in Eucalyptus before 3.1.1 does not properly restrict applying XML Signature transforms to documents, which allows remote attackers to cause a denial of service via unspecified vectors.

    Published: 1 Oct 2012
    6.5
    Medium

    CVE-2012-4064

    Last Modified: 11 Apr 2025

    Eucalyptus before 3.1.1 does not properly restrict the binding of external SOAP web-services messages, which allows remote authenticated users to gain privileges by sending a message to (1) Cloud Controller or (2) Walrus with the internal message format and a modified user id.

    Published: 1 Oct 2012
    3.5
    Low

    CVE-2012-4065

    Last Modified: 11 Apr 2025

    Eucalyptus before 3.1.1 does not properly restrict the binding of external SOAP web-services messages, which allows remote authenticated users to bypass unspecified authorization checks and obtain direct access to a (1) Cloud Controller or (2) Walrus service via a crafted message, as demonstrated by changes to a volume, snapshot, or cloud configuration setting.

    Published: 1 Oct 2012
    4.3
    Medium

    CVE-2012-4242

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the MF Gig Calendar plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the calendar page.

    Published: 1 Oct 2012
    5.8
    Medium

    CVE-2012-5234

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in index.php in ocPortal before 7.1.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter.

    Published: 1 Oct 2012
    7.5
    High

    CVE-2012-1603

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in ajaxserver.php in NextBBS 0.6 allow remote attackers to execute arbitrary SQL commands via the (1) curstr parameter in the findUsers function, (2) id parameter in the isIdAvailable function, or (3) username parameter in the getGreetings function.

    Published: 1 Oct 2012
    4.3
    Medium

    CVE-2012-0989

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in OneOrZero AIMS 2.8.0 Trial Edition build231211 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.

    Published: 1 Oct 2012
    4.3
    Medium

    CVE-2012-1636

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the stickynote module before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of users for requests that delete stickynotes via unspecified vectors.

    Published: 1 Oct 2012
    2.1
    Low

    CVE-2012-5233

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the stickynote module before 7.x-1.1 for Drupal allows remote authenticated users with edit stickynotes privileges to inject arbitrary web script or HTML via unspecified vecotrs.

    Published: 1 Oct 2012
    2.1
    Low

    CVE-2011-5202

    Last Modified: 11 Apr 2025

    BazisVirtualCDBus.sys in WinCDEmu 3.6 allows local users to cause a denial of service (system crash) via the unmount command to batchmnt.exe.

    Published: 1 Oct 2012
    6
    Medium

    CVE-2012-1576

    Last Modified: 11 Apr 2025

    The myuser_delete function in libathemecore/account.c in Atheme 5.x before 5.2.7, 6.x before 6.0.10, and 7.x before 7.0.0-beta2 does not properly clean up CertFP entries when a user is deleted, which allows remote attackers to access a different user account or cause a denial of service (daemon crash) via a login as a deleted user.

    Published: 1 Oct 2012
    6.8
    Medium

    CVE-2012-1897

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Wolf CMS 0.75 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) delete users via the user id number to admin/user/delete; (2) delete pages via the page id number to admin/page/delete; delete the (3) images or (4) themes directory via the directory name to admin/plugin/file_manager/delete, and possibly other directories; or (5) logout the user via a request to admin/login/logout.

    Published: 1 Oct 2012
    4.3
    Medium

    CVE-2012-1898

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in wolfcms/admin/user/add in Wolf CMS 0.75 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user[name], (2) user[email], or (3) user[username] parameters.

    Published: 1 Oct 2012
    4.3
    Medium

    CVE-2012-5225

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in webscr.php in xClick Cart 1.0.1 and 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the shopping_url parameter.

    Published: 1 Oct 2012
    4.3
    Medium

    CVE-2012-5226

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Peel SHOPPING 2.8 and 2.9 allow remote attackers to inject arbitrary web script or HTML via the (1) motclef parameter to achat/recherche.php or (2) PATH_INFO to index.php.

    Published: 1 Oct 2012
    7.5
    High

    CVE-2012-5227

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in administrer/tva.php in Peel SHOPPING 2.8 and 2.9 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 1 Oct 2012
    4.3
    Medium

    CVE-2012-5228

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/index.php in phplist 2.10.9, 2.10.17, and possibly other versions before 2.10.19 allows remote attackers to inject arbitrary web script or HTML via the testtarget parameter. NOTE: some of these details are obtained from third party information.

    Published: 1 Oct 2012
    4.3
    Medium

    CVE-2012-5229

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in css/gallery-css.php in the Slideshow Gallery2 plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the border parameter.

    Published: 1 Oct 2012
    7.5
    High

    CVE-2012-5230

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the JE Story Submit (com_jesubmit) component before 1.9 for Joomla! has unknown impact and attack vectors.

    Published: 1 Oct 2012
    7.5
    High

    CVE-2012-5231

    Last Modified: 11 Apr 2025

    miniCMS 1.0 and 2.0 allows remote attackers to execute arbitrary PHP code via a crafted (1) pagename or (2) area variable containing an executable extension, which is not properly handled by (a) update.php when writing files to content/, or (b) updatenews.php when writing files to content/news/.

    Published: 1 Oct 2012
    3.5
    Low

    CVE-2012-1639

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in product/commerce_product.module in the Drupal Commerce module for Drupal before 7.x-1.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) sku or (2) title parameters.

    Published: 1 Oct 2012
    7.5
    High

    CVE-2012-5223

    Last Modified: 11 Apr 2025

    The proc_deutf function in includes/functions_vbseocp_abstract.php in vBSEO 3.5.0, 3.5.1, 3.5.2, 3.6.0, and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" in the char_repl parameter, which is inserted into a regular expression that is processed by the preg_replace function with the eval switch.

    Published: 1 Oct 2012
    7.5
    High

    CVE-2012-5224

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in vb/includes/vba_cmps_include_bottom.php in vBadvanced CMPS 3.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pages[template] parameter.

    Published: 1 Oct 2012
    4.3
    Medium

    CVE-2012-5232

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Quickl Form component for Joomla! allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 Oct 2012
    6.8
    Medium

    CVE-2012-0748

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified services in IBM Rational Team Concert (RTC) 4.x before 4.0.0.1 allow remote attackers to hijack the authentication of arbitrary users for requests that modify work items.

    Published: 1 Oct 2012
    5
    Medium

    CVE-2012-3035

    Last Modified: 11 Apr 2025

    Buffer overflow in Emerson DeltaV 9.3.1 and 10.3 through 11.3.1 allows remote attackers to cause a denial of service (daemon crash) via a long string to an unspecified port.

    Published: 1 Oct 2012
    5
    Medium

    CVE-2012-3319

    Last Modified: 11 Apr 2025

    IBM Rational Business Developer 8.x before 8.0.1.4 allows remote attackers to obtain potentially sensitive information via a connection to a web service created with the Rational Business Developer product.

    Published: 1 Oct 2012