CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2012-4833

    Last Modified: 11 Apr 2025

    fuser in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly restrict the -k option, which allows local users to kill arbitrary processes via a crafted command line.

    Published: 1 Oct 2012
    5
    Medium

    CVE-2012-4830

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11 and 7.0 through 7.0.0.6 allows remote attackers to obtain users' personal data via unknown vectors.

    Published: 1 Oct 2012
    7.5
    High

    CVE-2012-4415

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long protocol name.

    Published: 1 Oct 2012
    7.5
    High

    CVE-2012-4432

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in opngreduc.c in OptiPNG Hg and 0.7.x before 0.7.3 might allow remote attackers to execute arbitrary code via unspecified vectors related to "palette reduction."

    Published: 1 Oct 2012
    4.3
    Medium

    CVE-2012-4437

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the SmartyException class in Smarty (aka smarty-php) before 3.1.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors that trigger a Smarty exception.

    Published: 1 Oct 2012
    6.8
    Medium

    CVE-2012-4427

    Last Modified: 11 Apr 2025

    The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extensions from extensions.gnome.org via a crafted web page.

    Published: 1 Oct 2012
    4.3
    Medium

    CVE-2011-4551

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in tiki-cookie-jar.php in TikiWiki CMS/Groupware before 8.2 and LTS before 6.5 allows remote attackers to inject arbitrary web script or HTML via arbitrary parameters.

    Published: 1 Oct 2012
    3.5
    Low

    CVE-2012-1588

    Last Modified: 11 Apr 2025

    Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via a long email address.

    Published: 1 Oct 2012
    5
    Medium

    CVE-2012-1591

    Last Modified: 11 Apr 2025

    The image module in Drupal 7.x before 7.14 does not properly check permissions when caching derivative image styles of private images, which allows remote attackers to read private image styles.

    Published: 1 Oct 2012
    7.5
    High

    CVE-2012-2240

    Last Modified: 11 Apr 2025

    scripts/dscverify.pl in devscripts before 2.12.3 allows remote attackers to execute arbitrary commands via unspecified vectors related to "arguments to external commands."

    Published: 1 Oct 2012
    5
    Medium

    CVE-2012-2241

    Last Modified: 11 Apr 2025

    scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete arbitrary files via a crafted (1) .dsc or (2) .changes file, probably related to a NULL byte in a filename.

    Published: 1 Oct 2012
    6.8
    Medium

    CVE-2012-2242

    Last Modified: 11 Apr 2025

    scripts/dget.pl in devscripts before 2.10.73 allows remote attackers to execute arbitrary commands via a crafted (1) .dsc or (2) .changes file, related to "arguments to external commands" that are not properly escaped, a different vulnerability than CVE-2012-2240.

    Published: 1 Oct 2012
    4
    Medium

    CVE-2012-1590

    Last Modified: 11 Apr 2025

    The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post title via the forum overview page.

    Published: 1 Oct 2012
    4
    Medium

    CVE-2012-2153

    Last Modified: 11 Apr 2025

    Drupal 7.x before 7.14 does not properly restrict access to nodes in a list when using a "contributed node access module," which allows remote authenticated users with the "Access the content overview page" permission to read all published nodes by accessing the admin/content page.

    Published: 1 Oct 2012
    5
    Medium

    CVE-2012-1833

    Last Modified: 11 Apr 2025

    VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allow remote attackers to bypass intended access restrictions and modify arbitrary object properties via a crafted request parameter to an application.

    Published: 28 Sept 2012
    6.8
    Medium

    CVE-2012-4448

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that modify an RSS URL via a dashboard_incoming_links edit action.

    Published: 28 Sept 2012
    6.8
    Medium

    CVE-2012-0956

    Last Modified: 11 Apr 2025

    ubiquity-slideshow-ubuntu before 58.2, during installation, allows remote man-in-the-middle attackers to execute arbitrary web script or HTML and read arbitrary files via a crafted attribute in the <a> tag of a Twitter feed.

    Published: 28 Sept 2012
    9.3
    Critical

    CVE-2012-0418

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the client in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 on Windows allows user-assisted remote attackers to execute arbitrary code via a crafted file.

    Published: 28 Sept 2012
    5
    Medium

    CVE-2012-0419

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the agent HTTP interfaces in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to read arbitrary files via directory traversal sequences in a request.

    Published: 28 Sept 2012
    4.3
    Medium

    CVE-2012-4017

    Last Modified: 11 Apr 2025

    The jigbrowser+ application before 1.5.0 for Android does not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application.

    Published: 28 Sept 2012
    4.3
    Medium

    CVE-2012-4912

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to inject arbitrary web script or HTML via a crafted signature in an HTML e-mail message.

    Published: 28 Sept 2012
    7.8
    High

    CVE-2012-5048

    Last Modified: 11 Apr 2025

    APIFTP Server in Optimalog Optima PLC 1.5.2 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted packet.

    Published: 28 Sept 2012
    10
    Critical

    CVE-2012-0417

    Last Modified: 11 Apr 2025

    Integer overflow in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 28 Sept 2012
    7.5
    High

    CVE-2012-2998

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the ad hoc query module in Trend Micro Control Manager (TMCM) before 5.5.0.1823 and 6.0 before 6.0.0.1449 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 28 Sept 2012
    4.3
    Medium

    CVE-2012-4016

    Last Modified: 11 Apr 2025

    The ATOK application before 1.0.4 for Android allows remote attackers to read the learning information file, and obtain sensitive input-string information, via a crafted application.

    Published: 28 Sept 2012
    6.8
    Medium

    CVE-2012-4051

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in editAccount.html in the JAMF Software Server (JSS) interface in JAMF Casper Suite before 8.61 allow remote attackers to hijack the authentication of administrators for requests that (1) create user accounts or (2) change passwords via a Save action.

    Published: 28 Sept 2012
    7.8
    High

    CVE-2012-5049

    Last Modified: 11 Apr 2025

    APIFTP Server in Optimalog Optima PLC 1.5.2 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

    Published: 28 Sept 2012
    4.3
    Medium

    CVE-2012-4462

    Last Modified: 11 Apr 2025

    aviary/jobcontrol.py in Condor, as used in Red Hat Enterprise MRG 2.3, when removing a job, allows remote attackers to cause a denial of service (condor_schedd restart) via square brackets in the cproc option.

    Published: 28 Sept 2012
    5.1
    Medium

    CVE-2012-4463

    Last Modified: 11 Apr 2025

    Midnight Commander (mc) 4.8.5 does not properly handle the (1) MC_EXT_SELECTED or (2) MC_EXT_ONLYTAGGED environment variables when multiple files are selected, which allows user-assisted remote attackers to execute arbitrary commands via a crafted file name.

    Published: 28 Sept 2012
    5
    Medium

    CVE-2012-4464

    Last Modified: 11 Apr 2025

    Ruby 1.9.3 before patchlevel 286 and 2.0 before revision r37068 allows context-dependent attackers to bypass safe-level restrictions and modify untainted strings via the (1) exc_to_s or (2) name_err_to_s API function, which marks the string as tainted, a different vulnerability than CVE-2012-4466. NOTE: this issue might exist because of a CVE-2011-1005 regression.

    Published: 28 Sept 2012
    7.8
    High

    CVE-2012-4618

    Last Modified: 11 Apr 2025

    The SIP ALG feature in the NAT implementation in Cisco IOS 12.2, 12.4, and 15.0 through 15.2 allows remote attackers to cause a denial of service (device reload) via transit IP packets, aka Bug ID CSCtn76183.

    Published: 27 Sept 2012
    7.8
    High

    CVE-2012-4619

    Last Modified: 11 Apr 2025

    The NAT implementation in Cisco IOS 12.2, 12.4, and 15.0 through 15.2 allows remote attackers to cause a denial of service (device reload) via transit IP packets, aka Bug ID CSCtr46123.

    Published: 27 Sept 2012
    7.8
    High

    CVE-2012-4623

    Last Modified: 11 Apr 2025

    The DHCPv6 server in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x, 3.1.xS before 3.1.4S, 3.1.xSG and 3.2.xSG before 3.2.5SG, 3.2.xS, 3.2.xXO, 3.3.xS, and 3.3.xSG before 3.3.1SG allows remote attackers to cause a denial of service (device reload) via a malformed DHCPv6 packet, aka Bug ID CSCto57723.

    Published: 27 Sept 2012
    7.8
    High

    CVE-2012-3949

    Last Modified: 11 Apr 2025

    The SIP implementation in Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su5, 8.x before 8.5(1)su4, and 8.6 before 8.6(2a)su1; Cisco IOS 12.2 through 12.4 and 15.0 through 15.2; and Cisco IOS XE 3.3.xSG before 3.3.1SG, 3.4.xS, and 3.5.xS allows remote attackers to cause a denial of service (service crash or device reload) via a crafted SIP message containing an SDP session description, aka Bug IDs CSCtw66721, CSCtj33003, and CSCtw84664.

    Published: 27 Sept 2012
    2.1
    Low

    CVE-2012-4453

    Last Modified: 11 Apr 2025

    dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.

    Published: 27 Sept 2012
    7.1
    High

    CVE-2012-4617

    Last Modified: 11 Apr 2025

    The BGP implementation in Cisco IOS 15.2, IOS XE 3.5.xS before 3.5.2S, and IOS XR 4.1.0 through 4.2.2 allows remote attackers to cause a denial of service (multiple connection resets) by leveraging a peer relationship and sending a malformed attribute, aka Bug IDs CSCtt35379, CSCty58300, CSCtz63248, and CSCtz62914.

    Published: 27 Sept 2012
    7.8
    High

    CVE-2012-4621

    Last Modified: 11 Apr 2025

    The Device Sensor feature in Cisco IOS 15.0 through 15.2 allows remote attackers to cause a denial of service (device reload) via a DHCP packet, aka Bug ID CSCty96049.

    Published: 27 Sept 2012
    7.1
    High

    CVE-2012-3950

    Last Modified: 11 Apr 2025

    The Intrusion Prevention System (IPS) feature in Cisco IOS 12.3 through 12.4 and 15.0 through 15.2, in certain configurations of enabled categories and missing signatures, allows remote attackers to cause a denial of service (device reload) via DNS packets, aka Bug ID CSCtw55976.

    Published: 27 Sept 2012
    2.1
    Low

    CVE-2012-4452

    Last Modified: 11 Apr 2025

    MySQL 5.0.88, and possibly other versions and platforms, allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of a CVE-2009-4030 regression, which was not omitted in other packages and versions such as MySQL 5.0.95 in Red Hat Enterprise Linux 6.

    Published: 27 Sept 2012
    7.8
    High

    CVE-2012-4620

    Last Modified: 11 Apr 2025

    Cisco IOS 12.2 and 15.0 through 15.2 on Cisco 10000 series routers, when a tunnel interface exists, allows remote attackers to cause a denial of service (interface queue wedge) via tunneled (1) GRE/IP, (2) IPIP, or (3) IPv6 in IPv4 packets, aka Bug ID CSCts66808.

    Published: 27 Sept 2012
    7.1
    High

    CVE-2012-4622

    Last Modified: 11 Apr 2025

    Cisco IOS XE 03.02.00.XO.15.0(2)XO on Catalyst 4500E series switches, when a Supervisor Engine 7L-E card is installed, allows remote attackers to cause a denial of service (card reload) via malformed packets that trigger uncorrected ECC error messages, aka Bug ID CSCty88456.

    Published: 27 Sept 2012
    7.5
    High

    CVE-2012-2874

    Last Modified: 11 Apr 2025

    Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation, a different vulnerability than CVE-2012-2883.

    Published: 26 Sept 2012
    6.8
    Medium

    CVE-2012-2875

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the PDF functionality in Google Chrome before 22.0.1229.79 allow remote attackers to have an unknown impact via a crafted document.

    Published: 26 Sept 2012
    7.5
    High

    CVE-2012-2878

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to plug-in handling.

    Published: 26 Sept 2012
    4.3
    Medium

    CVE-2012-2879

    Last Modified: 11 Apr 2025

    Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service (DOM topology corruption) via a crafted document.

    Published: 26 Sept 2012
    7.5
    High

    CVE-2012-2881

    Last Modified: 11 Apr 2025

    Google Chrome before 22.0.1229.79 does not properly handle plug-ins, which allows remote attackers to cause a denial of service (DOM tree corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 26 Sept 2012
    6.8
    Medium

    CVE-2012-2882

    Last Modified: 11 Apr 2025

    FFmpeg, as used in Google Chrome before 22.0.1229.79, does not properly handle OGG containers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors, related to a "wild pointer" issue.

    Published: 26 Sept 2012
    7.5
    High

    CVE-2012-2883

    Last Modified: 11 Apr 2025

    Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation, a different vulnerability than CVE-2012-2874.

    Published: 26 Sept 2012
    7.5
    High

    CVE-2012-2885

    Last Modified: 11 Apr 2025

    Double free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to application exit.

    Published: 26 Sept 2012
    4.3
    Medium

    CVE-2012-2886

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to inject arbitrary web script or HTML via vectors related to the Google V8 bindings, aka "Universal XSS (UXSS)."

    Published: 26 Sept 2012