CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2012-3260

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1462.

    Published: 25 Sept 2012
    7.8
    High

    CVE-2012-4014

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in McAfee Email Anti-virus (formerly WebShield SMTP) allows remote attackers to cause a denial of service via unknown vectors.

    Published: 25 Sept 2012
    7.5
    High

    CVE-2013-1753

    Last Modified: 21 Nov 2024

    The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.

    Published: 25 Sept 2012
    6.8
    Medium

    CVE-2012-2893

    Last Modified: 11 Apr 2025

    Double free vulnerability in libxslt, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XSL transforms.

    Published: 25 Sept 2012
    4.3
    Medium

    CVE-2013-1752

    Last Modified: 7 Nov 2023

    Various versions of Python do not properly restrict readline calls, which allows remote attackers to cause a denial of service (memory consumption) via a long string, related to (1) httplib - fixed in 2.7.4, 2.6.9, and 3.3.3; (2) ftplib - fixed in 2.7.6, 2.6.9, 3.3.3; (3) imaplib - not yet fixed in 2.7.x, fixed in 2.6.9, 3.3.3; (4) nntplib - fixed in 2.7.6, 2.6.9, 3.3.3; (5) poplib - not yet fixed in 2.7.x, fixed in 2.6.9, 3.3.3; and (6) smtplib - not yet fixed in 2.7.x, fixed in 2.6.9, not yet fixed in 3.3.x. NOTE: this was REJECTed because it is incompatible with CNT1 "Independently Fixable" in the CVE Counting Decisions

    Published: 25 Sept 2012
    9.3
    Critical

    CVE-2012-4655

    Last Modified: 11 Apr 2025

    The WebLaunch feature in Cisco Secure Desktop before 3.6.6020 does not properly validate binaries that are received by the downloader process, which allows remote attackers to execute arbitrary code via vectors involving (1) ActiveX or (2) Java components, aka Bug IDs CSCtz76128 and CSCtz78204.

    Published: 24 Sept 2012
    4.9
    Medium

    CVE-2012-6657

    Last Modified: 12 Apr 2025

    The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system crash) by leveraging the ability to create a raw socket.

    Published: 24 Sept 2012
    4.3
    Medium

    CVE-2012-5099

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in list.php in PHPB2B 4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action.

    Published: 23 Sept 2012
    4.3
    Medium

    CVE-2011-5191

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in pretty-bar.php in Pretty Link Lite plugin before 1.5.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the slug parameter, a different vulnerability than CVE-2011-5192.

    Published: 23 Sept 2012
    4.3
    Medium

    CVE-2011-5192

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in pretty-bar.php in Pretty Link Lite plugin before 1.5.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the slug parameter, a different vulnerability than CVE-2011-5191.

    Published: 23 Sept 2012
    2.6
    Low

    CVE-2011-5193

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin 1.4.2.3 for WordPress, when the WHOIS widget is enabled, allows remote attackers to inject arbitrary web script or HTML via the domain parameter to index.php, a different vulnerability than CVE-2011-5194.

    Published: 23 Sept 2012
    4.3
    Medium

    CVE-2011-5194

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin before 1.4.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the domain parameter, a different vulnerability than CVE-2011-5193.

    Published: 23 Sept 2012
    6.8
    Medium

    CVE-2011-5195

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Conference Systems 2.3.4 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload a PHP file.

    Published: 23 Sept 2012
    6.8
    Medium

    CVE-2011-5197

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Harvester Systems 2.3.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload PHP files.

    Published: 23 Sept 2012
    7.5
    High

    CVE-2011-5198

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in search.php in Neturf eCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the SearchFor parameter. NOTE: some of these details are obtained from third party information.

    Published: 23 Sept 2012
    4.3
    Medium

    CVE-2011-5199

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in sign.php in tinyguestbook allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Published: 23 Sept 2012
    7.5
    High

    CVE-2011-5200

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in DeDeCMS, possibly 5.6, allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) list.php, (2) members.php, or (3) book.php.

    Published: 23 Sept 2012
    7.5
    High

    CVE-2011-5201

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in sign.php in tinyguestbook allow remote attackers to execute arbitrary SQL commands via the (1) name and (2) msg parameters. NOTE: some of these details are obtained from third party information.

    Published: 23 Sept 2012
    5
    Medium

    CVE-2012-5100

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in HServer 0.1.1 allows remote attackers to read arbitrary files via a (1) ..%5c (dot dot encoded backslash) or (2) %2e%2e%5c (encoded dot dot backslash) in the PATH_INFO.

    Published: 23 Sept 2012
    7.5
    High

    CVE-2012-5101

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the JExtensions JE Poll component before 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 23 Sept 2012
    4.3
    Medium

    CVE-2012-5102

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in inc/extensions.php in VertrigoServ 2.25 allows remote attackers to inject arbitrary web script or HTML via the ext parameter.

    Published: 23 Sept 2012
    4.3
    Medium

    CVE-2012-5103

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in action/add-submit.php in Ggb Guestbook 0.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url or (2) message parameter.

    Published: 23 Sept 2012
    4.3
    Medium

    CVE-2012-5104

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in forums/ubbthreads.php in UBB.threads 7.5.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the Loginname parameter.

    Published: 23 Sept 2012
    4.3
    Medium

    CVE-2012-5105

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager 1.2.4 allow remote attackers to inject arbitrary web script or HTML via the dbsel parameter to (1) main.php or (2) index.php; or (3) nsextt parameter to index.php.

    Published: 23 Sept 2012
    7.5
    High

    CVE-2012-5098

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Php-X-Links, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to rate.php, (2) cid parameter to view.php, or (3) t parameter to pop.php.

    Published: 23 Sept 2012
    6.8
    Medium

    CVE-2011-5196

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Journal Systems 2.3.6 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload PHP files.

    Published: 23 Sept 2012
    4.3
    Medium

    CVE-2012-3977

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-4930. Reason: This candidate is a duplicate of CVE-2012-4930. Notes: All CVE users should reference CVE-2012-4930 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 22 Sept 2012
    6.8
    Medium

    CVE-2012-4447

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in tif_pixarlog.c in LibTIFF before 4.0.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF image using the PixarLog Compression format.

    Published: 22 Sept 2012
    9.3
    Critical

    CVE-2012-1529

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly initialized or (2) is deleted, aka "OnMove Use After Free Vulnerability."

    Published: 21 Sept 2012
    9.3
    Critical

    CVE-2012-2548

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Layout Use After Free Vulnerability."

    Published: 21 Sept 2012
    9.3
    Critical

    CVE-2012-2557

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "cloneNode Use After Free Vulnerability."

    Published: 21 Sept 2012
    9.3
    Critical

    CVE-2012-2546

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Event Listener Use After Free Vulnerability."

    Published: 21 Sept 2012
    6.4
    Medium

    CVE-2012-3137

    Last Modified: 11 Apr 2025

    The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and makes it easier to conduct brute force password guessing attacks, aka "stealth password cracking vulnerability."

    Published: 21 Sept 2012
    4.3
    Medium

    CVE-2012-3713

    Last Modified: 11 Apr 2025

    Apple Safari before 6.0.1 does not properly handle the Quarantine attribute of HTML documents, which allows user-assisted remote attackers to read arbitrary files by leveraging the presence of a downloaded document.

    Published: 20 Sept 2012
    4.3
    Medium

    CVE-2012-3715

    Last Modified: 11 Apr 2025

    Apple Safari before 6.0.1 makes http requests for https URIs in certain circumstances involving a paste into the address bar, which allows user-assisted remote attackers to obtain sensitive information by sniffing the network.

    Published: 20 Sept 2012
    7.5
    High

    CVE-2012-3716

    Last Modified: 11 Apr 2025

    CoreText in Apple Mac OS X 10.7.x before 10.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write or read) via a crafted text glyph.

    Published: 20 Sept 2012
    2.1
    Low

    CVE-2012-3718

    Last Modified: 11 Apr 2025

    Apple Mac OS X before 10.7.5 and 10.8.x before 10.8.2 allows local users to read passwords entered into Login Window (aka LoginWindow) or Screen Saver Unlock by installing an input method that intercepts keystrokes.

    Published: 20 Sept 2012
    6.8
    Medium

    CVE-2012-3719

    Last Modified: 11 Apr 2025

    Mail in Apple Mac OS X before 10.7.5 does not properly handle embedded web plugins, which allows remote attackers to execute arbitrary plugin code via an e-mail message that triggers the loading of a third-party plugin.

    Published: 20 Sept 2012
    4.3
    Medium

    CVE-2012-3720

    Last Modified: 11 Apr 2025

    Mobile Accounts in Apple Mac OS X before 10.7.5 and 10.8.x before 10.8.2 saves password hashes for external-account use even if external accounts are not enabled, which might allow remote attackers to determine passwords via unspecified access to a mobile account.

    Published: 20 Sept 2012
    5
    Medium

    CVE-2012-3721

    Last Modified: 11 Apr 2025

    Profile Manager in Apple Mac OS X before 10.7.5 does not properly perform authentication for the Device Management private interface, which allows attackers to enumerate managed devices via unspecified vectors.

    Published: 20 Sept 2012
    6.8
    Medium

    CVE-2012-3722

    Last Modified: 11 Apr 2025

    The Sorenson codec in QuickTime in Apple Mac OS X before 10.7.5, and in CoreMedia in iOS before 6, accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with Sorenson encoding.

    Published: 20 Sept 2012
    6.8
    Medium

    CVE-2012-3726

    Last Modified: 11 Apr 2025

    Double free vulnerability in ImageIO in Apple iOS before 6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG image.

    Published: 20 Sept 2012
    6.8
    Medium

    CVE-2012-3727

    Last Modified: 11 Apr 2025

    Buffer overflow in the IPsec component in Apple iOS before 6 allows remote attackers to execute arbitrary code via a crafted racoon configuration file.

    Published: 20 Sept 2012
    6.9
    Medium

    CVE-2012-3728

    Last Modified: 11 Apr 2025

    The kernel in Apple iOS before 6 dereferences invalid pointers during the handling of packet-filter data structures, which allows local users to gain privileges via a crafted program that makes packet-filter ioctl calls.

    Published: 20 Sept 2012
    4.3
    Medium

    CVE-2012-3730

    Last Modified: 11 Apr 2025

    Mail in Apple iOS before 6 does not properly handle reuse of Content-ID header values, which allows remote attackers to spoof attachments via a header value that was also used in a previous e-mail message, as demonstrated by a message from a different sender.

    Published: 20 Sept 2012
    4.3
    Medium

    CVE-2012-3733

    Last Modified: 11 Apr 2025

    Messages in Apple iOS before 6, when multiple iMessage e-mail addresses are configured, does not ensure that a reply's sender address matches the recipient address of the original message, which allows remote attackers to obtain potentially sensitive information about alternate e-mail addresses in opportunistic circumstances by reading a reply.

    Published: 20 Sept 2012
    1.9
    Low

    CVE-2012-3734

    Last Modified: 11 Apr 2025

    Office Viewer in Apple iOS before 6 writes cleartext document data to a temporary file, which might allow local users to bypass a document's intended (1) Data Protection level or (2) encryption state by reading the temporary content.

    Published: 20 Sept 2012
    2.1
    Low

    CVE-2012-3735

    Last Modified: 11 Apr 2025

    The Passcode Lock implementation in Apple iOS before 6 does not properly interact with the "Slide to Power Off" feature, which allows physically proximate attackers to see the most recently used third-party app by watching the device's screen.

    Published: 20 Sept 2012
    4.6
    Medium

    CVE-2012-3736

    Last Modified: 11 Apr 2025

    The Passcode Lock implementation in Apple iOS before 6 allows physically proximate attackers to bypass an intended passcode requirement via vectors related to ending a FaceTime call.

    Published: 20 Sept 2012
    2.1
    Low

    CVE-2012-3737

    Last Modified: 11 Apr 2025

    The Passcode Lock implementation in Apple iOS before 6 does not properly restrict photo viewing, which allows physically proximate attackers to view arbitrary stored photos by spoofing a time value.

    Published: 20 Sept 2012