CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2012-2887

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving onclick events.

    Published: 26 Sept 2012
    7.5
    High

    CVE-2012-2888

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG text references.

    Published: 26 Sept 2012
    4.3
    Medium

    CVE-2012-2889

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to inject arbitrary web script or HTML via vectors involving frames, aka "Universal XSS (UXSS)."

    Published: 26 Sept 2012
    6.8
    Medium

    CVE-2012-2890

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the PDF functionality in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.

    Published: 26 Sept 2012
    5
    Medium

    CVE-2012-2892

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to bypass the pop-up blocker via unknown vectors.

    Published: 26 Sept 2012
    6.8
    Medium

    CVE-2012-2894

    Last Modified: 11 Apr 2025

    Google Chrome before 22.0.1229.79 does not properly handle graphics-context data structures, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors.

    Published: 26 Sept 2012
    6.8
    Medium

    CVE-2012-2895

    Last Modified: 11 Apr 2025

    The PDF functionality in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger out-of-bounds write operations.

    Published: 26 Sept 2012
    7.5
    High

    CVE-2012-2896

    Last Modified: 11 Apr 2025

    Integer overflow in the WebGL implementation in Google Chrome before 22.0.1229.79 on Mac OS X allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 26 Sept 2012
    5
    Medium

    CVE-2012-2877

    Last Modified: 11 Apr 2025

    The extension system in Google Chrome before 22.0.1229.79 does not properly handle modal dialogs, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

    Published: 26 Sept 2012
    7.8
    High

    CVE-2012-2897

    Last Modified: 11 Apr 2025

    The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT, as used by Google Chrome before 22.0.1229.79 and other programs, do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a crafted TrueType font file, aka "Windows Font Parsing Vulnerability" or "TrueType Font Parsing Vulnerability."

    Published: 26 Sept 2012
    7.5
    High

    CVE-2012-2876

    Last Modified: 11 Apr 2025

    Buffer overflow in the SSE2 optimization functionality in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 26 Sept 2012
    7.5
    High

    CVE-2012-2880

    Last Modified: 11 Apr 2025

    Race condition in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the plug-in paint buffer.

    Published: 26 Sept 2012
    5
    Medium

    CVE-2012-2884

    Last Modified: 11 Apr 2025

    Skia, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 26 Sept 2012
    5
    Medium

    CVE-2012-2891

    Last Modified: 11 Apr 2025

    The IPC implementation in Google Chrome before 22.0.1229.79 allows attackers to obtain potentially sensitive information about memory addresses via unspecified vectors.

    Published: 26 Sept 2012
    4.3
    Medium

    CVE-2012-1117

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Joomla! 2.5.0 and 2.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Sept 2012
    4.3
    Medium

    CVE-2012-1188

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before 3.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) type or (2) querystring parameters to private/en/error or (3) name parameter to private/en/locale/index.

    Published: 26 Sept 2012
    6.4
    Medium

    CVE-2012-1617

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in combine.php in OSClass before 2.3.6 allows remote attackers to read and write arbitrary files via a .. (dot dot) in the type parameter. NOTE: this vulnerability can be leveraged to upload arbitrary files.

    Published: 26 Sept 2012
    6.5
    Medium

    CVE-2012-5162

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in oc-admin/ajax/ajax.php in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) edit_category_post or (2) enable_category action to index.php.

    Published: 26 Sept 2012
    4.3
    Medium

    CVE-2012-5163

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in oc-admin/ajax/ajax.php in OSClass before 2.3.5 allows remote attackers to inject arbitrary web script or HTML via the id parameter in an enable_category action to index.php.

    Published: 26 Sept 2012
    7.5
    High

    CVE-2012-6612

    Last Modified: 11 Apr 2025

    The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, different vectors than CVE-2013-6407.

    Published: 26 Sept 2012
    6.4
    Medium

    CVE-2013-6407

    Last Modified: 11 Apr 2025

    The UpdateRequestHandler for XML in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 26 Sept 2012
    7.5
    High

    CVE-2012-1116

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Joomla! 1.7.x and 2.5.x before 2.5.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 26 Sept 2012
    4.3
    Medium

    CVE-2012-5164

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before 3.2.7 allow remote attackers to inject arbitrary web script or HTML via the term parameter to (1) autocomplete.php, (2) search/ajax/autosuggest.php, (3) livesuggest.php, or (4) save.php in frontend/modules/search/ajax.

    Published: 26 Sept 2012
    4.3
    Medium

    CVE-2012-0869

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in fup in Frams' Fast File EXchange (F*EX, aka fex) before 20120215 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 25 Sept 2012
    4.3
    Medium

    CVE-2012-0974

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the getParam function in oc-includes/osclass/core/Params.php in OSClass before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) sCity, (2) sPattern, (3) sPriceMax, and (4) sPriceMin parameters in a search action to index.php.

    Published: 25 Sept 2012
    4.3
    Medium

    CVE-2012-1103

    Last Modified: 11 Apr 2025

    emacs/notmuch-mua.el in Notmuch before 0.11.1, when using the Emacs interface, allows user-assisted remote attackers to read arbitrary files via crafted MML tags, which are not properly quoted in an email reply cna cause the files to be attached to the message.

    Published: 25 Sept 2012
    4.3
    Medium

    CVE-2012-1293

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in fup in Frams' Fast File EXchange (F*EX, aka fex) before 20111129-2 allow remote attackers to inject arbitrary web script or HTML via the (1) to or (2) from parameters.

    Published: 25 Sept 2012
    4.3
    Medium

    CVE-2012-1646

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the FAQ module 6.x-1.x before 6.x-1.13 and 7.x-1.x-rc1 for Drupal allow remote authenticated users to inject arbitrary web script or HTML via the (1) title parameter in faq.admin.inc or (2) detailed_question parameter in faq.module.

    Published: 25 Sept 2012
    7.5
    High

    CVE-2012-0973

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the sCategory parameter to index.php, which is not properly handled by the (1) osc_search_category_id function in oc-includes/osclass/helpers/hSearch.php and (2) findBySlug function oc-includes/osclass/model/Category.php. NOTE: some of these details are obtained from third party information.

    Published: 25 Sept 2012
    7.5
    High

    CVE-2012-0209

    Last Modified: 11 Apr 2025

    Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, contains an externally introduced modification (Trojan Horse) in templates/javascript/open_calendar.js, which allows remote attackers to execute arbitrary PHP code.

    Published: 25 Sept 2012
    7.5
    High

    CVE-2012-5159

    Last Modified: 11 Apr 2025

    phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modification (Trojan Horse) in server_sync.php, which allows remote attackers to execute arbitrary PHP code via an eval injection attack.

    Published: 25 Sept 2012
    6.8
    Medium

    CVE-2012-3304

    Last Modified: 11 Apr 2025

    The Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to hijack sessions via unspecified vectors.

    Published: 25 Sept 2012
    6.4
    Medium

    CVE-2012-3305

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to overwrite arbitrary files via a crafted application file.

    Published: 25 Sept 2012
    9
    Critical

    CVE-2012-3334

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 11.50 before 11.50.xC9W2 and 11.70 before 11.70.xC5 allows remote authenticated users to execute arbitrary code via crafted arguments in a SET COLLATION statement.

    Published: 25 Sept 2012
    10
    Critical

    CVE-2012-3298

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the REST services framework in IBM WebSphere Commerce 7.0 Feature Pack 4 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unspecified vectors.

    Published: 25 Sept 2012
    3.3
    Low

    CVE-2012-3311

    Last Modified: 11 Apr 2025

    IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 on z/OS, in certain configurations involving Federated Repositories for IIOP connections and Optimized Local Adapters, does not perform CBIND checks, which allows local users to bypass intended access restrictions, and read or modify application data, via unspecified vectors.

    Published: 25 Sept 2012
    5
    Medium

    CVE-2012-2187

    Last Modified: 11 Apr 2025

    IBM Remote Supervisor Adapter II firmware for System x3650, x3850 M2, and x3950 M2 1.13 and earlier generates weak RSA keys, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors.

    Published: 25 Sept 2012
    5
    Medium

    CVE-2012-2199

    Last Modified: 11 Apr 2025

    The server message channel agent in the queue manager in the server in IBM WebSphere MQ 7.0.1 before 7.0.1.9, 7.1, and 7.5 on Solaris allows remote attackers to cause a denial of service (invalid address alignment exception and daemon crash) via vectors involving a multiplexed channel.

    Published: 25 Sept 2012
    2.6
    Low

    CVE-2012-3300

    Last Modified: 11 Apr 2025

    IBM WebSphere Commerce 7.0 before 7.0.0.6, when persistent sessions and personalization IDs are enabled, allows remote attackers to cause a denial of service (resource consumption) via unspecified vectors.

    Published: 25 Sept 2012
    6.8
    Medium

    CVE-2012-3306

    Last Modified: 11 Apr 2025

    IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1, when multi-domain support is configured, does not purge password data from the authentication cache, which has unspecified impact and remote attack vectors.

    Published: 25 Sept 2012
    9
    Critical

    CVE-2012-3324

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the UTL_FILE module in IBM DB2 and DB2 Connect 10.1 before FP1 on Windows allows remote authenticated users to modify, delete, or read arbitrary files via a pathname in the file field.

    Published: 25 Sept 2012
    10
    Critical

    CVE-2012-3259

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1461.

    Published: 25 Sept 2012
    10
    Critical

    CVE-2012-3261

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1463.

    Published: 25 Sept 2012
    10
    Critical

    CVE-2012-3262

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1464.

    Published: 25 Sept 2012
    10
    Critical

    CVE-2012-3263

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1465.

    Published: 25 Sept 2012
    7.5
    High

    CVE-2012-3264

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1472.

    Published: 25 Sept 2012
    4.3
    Medium

    CVE-2012-4015

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the management screen in myLittleTools myLittleAdmin for SQL Server 2000 allows remote attackers to inject arbitrary web script or HTML via vectors that trigger a crafted database entry.

    Published: 25 Sept 2012
    8.5
    High

    CVE-2012-2287

    Last Modified: 11 Apr 2025

    The authentication functionality in EMC RSA Authentication Agent 7.1 and RSA Authentication Client 3.5 on Windows XP and Windows Server 2003, when an unspecified configuration exists, allows remote authenticated users to bypass an intended token-authentication step, and establish a login session to a remote host, by leveraging Windows credentials for that host.

    Published: 25 Sept 2012
    4.3
    Medium

    CVE-2012-3037

    Last Modified: 23 May 2025

    The Siemens SIMATIC S7-1200 2.x PLC does not properly protect the private key of the SIMATIC CONTROLLER Certification Authority certificate, which allows remote attackers to spoof the S7-1200 web server by using this key to create a forged certificate.

    Published: 25 Sept 2012
    7.8
    High

    CVE-2012-3011

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the web server in Fultek WinTr Scada 4.0.5 and earlier allows remote attackers to read arbitrary files via a crafted request.

    Published: 25 Sept 2012