CVE Feed

    Dashboard / CVE

    3.6
    Low

    CVE-2012-3738

    Last Modified: 11 Apr 2025

    The Emergency Dialer screen in the Passcode Lock implementation in Apple iOS before 6 does not properly limit the dialing methods, which allows physically proximate attackers to bypass intended access restrictions and make FaceTime calls through Voice Dialing, or obtain sensitive contact information by attempting to make a FaceTime call and reading the contact suggestions.

    Published: 20 Sept 2012
    5
    Medium

    CVE-2012-3743

    Last Modified: 11 Apr 2025

    The System Logs implementation in Apple iOS before 6 does not restrict /var/log access by sandboxed apps, which allows remote attackers to obtain sensitive information via a crafted app that reads log files.

    Published: 20 Sept 2012
    5
    Medium

    CVE-2012-3744

    Last Modified: 11 Apr 2025

    Telephony in Apple iOS before 6 uses an SMS message's return address as the displayed sender address, which allows remote attackers to spoof text communication via a message in which the return address does not match the originating address.

    Published: 20 Sept 2012
    5
    Medium

    CVE-2012-3745

    Last Modified: 11 Apr 2025

    Off-by-one error in Telephony in Apple iOS before 6 allows remote attackers to cause a denial of service (buffer overflow and connectivity outage) via a crafted user-data header in an SMS message.

    Published: 20 Sept 2012
    5
    Medium

    CVE-2012-3724

    Last Modified: 11 Apr 2025

    CFNetwork in Apple iOS before 6 does not properly identify the host portion of a URL, which allows remote attackers to obtain sensitive information by leveraging the construction of an HTTP request with an incorrect hostname derived from a malformed URL.

    Published: 20 Sept 2012
    1.9
    Low

    CVE-2012-3729

    Last Modified: 11 Apr 2025

    The Berkeley Packet Filter (BPF) interpreter implementation in the kernel in Apple iOS before 6 accesses uninitialized memory locations, which allows local users to obtain sensitive information about the layout of kernel memory via a crafted program that uses a BPF interface.

    Published: 20 Sept 2012
    6.4
    Medium

    CVE-2012-3732

    Last Modified: 11 Apr 2025

    Mail in Apple iOS before 6 uses an S/MIME message's From address as the displayed sender address, which allows remote attackers to spoof signed content via an e-mail message in which the From field does not match the signer's identity.

    Published: 20 Sept 2012
    2.1
    Low

    CVE-2012-3740

    Last Modified: 11 Apr 2025

    The Passcode Lock implementation in Apple iOS before 6 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement via unspecified vectors.

    Published: 20 Sept 2012
    1.9
    Low

    CVE-2012-3741

    Last Modified: 11 Apr 2025

    The Restrictions (aka Parental Controls) implementation in Apple iOS before 6 does not properly handle purchase attempts after a Disable Restrictions action, which allows local users to bypass an intended Apple ID authentication step via an app that performs purchase transactions.

    Published: 20 Sept 2012
    5
    Medium

    CVE-2012-3742

    Last Modified: 11 Apr 2025

    Safari in Apple iOS before 6 does not properly restrict use of an unspecified Unicode character that looks similar to the https lock indicator, which allows remote attackers to spoof https connections by placing this character in the TITLE element of a web page.

    Published: 20 Sept 2012
    6.8
    Medium

    CVE-2012-3747

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Sept 2012
    2.1
    Low

    CVE-2012-3739

    Last Modified: 11 Apr 2025

    The Passcode Lock implementation in Apple iOS before 6 allows physically proximate attackers to bypass an intended passcode requirement via vectors involving use of the camera.

    Published: 20 Sept 2012
    7.5
    High

    CVE-2012-0650

    Last Modified: 11 Apr 2025

    Buffer overflow in the DirectoryService Proxy in DirectoryService in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.

    Published: 20 Sept 2012
    4.3
    Medium

    CVE-2012-3714

    Last Modified: 11 Apr 2025

    The Form Autofill feature in Apple Safari before 6.0.1 does not restrict the filled fields to the set of fields contained in an Autofill popover, which allows remote attackers to obtain the Me card from an Address Book via a crafted web site.

    Published: 20 Sept 2012
    4.6
    Medium

    CVE-2012-3723

    Last Modified: 11 Apr 2025

    Apple Mac OS X before 10.7.5 does not properly handle the bNbrPorts field of a USB hub descriptor, which allows physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption and system crash) by attaching a USB device.

    Published: 20 Sept 2012
    3.3
    Low

    CVE-2012-3725

    Last Modified: 11 Apr 2025

    The DNAv4 protocol implementation in the DHCP component in Apple iOS before 6 sends Wi-Fi packets containing a MAC address of a host on a previously used network, which might allow remote attackers to obtain sensitive information about previous device locations by sniffing an unencrypted Wi-Fi network for these packets.

    Published: 20 Sept 2012
    2.1
    Low

    CVE-2012-3731

    Last Modified: 11 Apr 2025

    Mail in Apple iOS before 6 does not properly implement the Data Protection feature for e-mail attachments, which allows physically proximate attackers to bypass an intended passcode requirement via unspecified vectors.

    Published: 20 Sept 2012
    4.3
    Medium

    CVE-2012-3746

    Last Modified: 11 Apr 2025

    UIWebView in UIKit in Apple iOS before 6 does not properly use the Data Protection feature, which allows context-dependent attackers to obtain cleartext file content by leveraging direct access to a device's filesystem.

    Published: 20 Sept 2012
    4.3
    Medium

    CVE-2011-5178

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in netmri/config/userAdmin/login.tdf in Infoblox NetMRI 6.0.2.42, 6.1.2, 6.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) eulaAccepted or (2) mode parameter.

    Published: 20 Sept 2012
    4.3
    Medium

    CVE-2011-5181

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in clickdesk.php in ClickDesk Live Support - Live Chat plugin 2.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cdwidgetid parameter. NOTE: some of these details are obtained from third party information.

    Published: 20 Sept 2012
    4.3
    Medium

    CVE-2011-5184

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node Manager i 9.10 allow remote attackers to inject arbitrary web script or HTML via the (1) node parameter to nnm/mibdiscover; (2) nodename parameter to nnm/protected/configurationpoll.jsp, (3) nnm/protected/ping.jsp, (4) nnm/protected/statuspoll.jsp, or (5) nnm/protected/traceroute.jsp; or (6) field parameter to nmm/validate. NOTE: this might be a duplicate of CVE-2011-4155 or CVE-2011-4156.

    Published: 20 Sept 2012
    4.3
    Medium

    CVE-2011-5185

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in video_comments.php in Online Subtitles Workshop before 2.0 rev 131 allows remote attackers to inject arbitrary web script or HTML via the comment parameter.

    Published: 20 Sept 2012
    2.1
    Low

    CVE-2011-5187

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Support Ticketing System module 6.x-1.x before 6.x-1.7 for Drupal allows remote authenticated users with the "administer support projects" permission to inject arbitrary web script or HTML via unspecified vectors.

    Published: 20 Sept 2012
    4.3
    Medium

    CVE-2011-5190

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Social Book Facebook Clone 2010 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO parameter to (1) signup.php, (2) lostpass.php, (3) login.php, (4) index.php, (5) help_tos.php, (6) help_contact.php, or (7) help.php.

    Published: 20 Sept 2012
    4.3
    Medium

    CVE-2011-5180

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in wp-1pluginjquery.php in the ZooEffect plugin 1.01 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter. NOTE: some of these details are obtained from third party information. NOTE: this has been disputed by a third party.

    Published: 20 Sept 2012
    7.5
    High

    CVE-2011-5183

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in OrderSys 1.6.4 and earlier allow remote attackers to execute arbitrary SQL commands via the where_clause parameter to (1) index.php, (2) index_long.php, or (3) index_short.php in ordering/interface_creator/.

    Published: 20 Sept 2012
    2.1
    Low

    CVE-2011-5189

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Webform Validation module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with permissions to "update Webform nodes" to inject arbitrary web script or HTML via unspecified vectors.

    Published: 20 Sept 2012
    2.1
    Low

    CVE-2011-5188

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Support Timer module 6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users with the "track time spent" permission to inject arbitrary web script or HTML via unspecified vectors.

    Published: 20 Sept 2012
    4.3
    Medium

    CVE-2011-5177

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in admin/controller.php in eSyndiCat Pro 2.3.05 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to the admins (2) blocks, (3) articles, or (4) suggest-category; or (5) sort parameter to the search page.

    Published: 20 Sept 2012
    4.3
    Medium

    CVE-2011-5179

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in skysa-official/skysa.php in Skysa App Bar Integration plugin, possibly before 1.04, for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit parameter.

    Published: 20 Sept 2012
    4.3
    Medium

    CVE-2011-5182

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in lanoba-social-plugin/index.php in the Lanoba Social plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the vendor disputes this issue, stating "Lanoba's plug in does sanitize user input, and because that input is never sent to the browser, an attacker has no way of executing script or code on a user's behalf.

    Published: 20 Sept 2012
    4.3
    Medium

    CVE-2011-5186

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in jbshop.php in the jbShop plugin for e107 7 allows remote attackers to inject arbitrary web script or HTML via the item_id parameter.

    Published: 20 Sept 2012
    6
    Medium

    CVE-2012-1626

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the conversion form for Events in the Date module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer Date Tools" privilege to execute arbitrary SQL commands via unspecified vectors.

    Published: 20 Sept 2012
    3.5
    Low

    CVE-2012-1628

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the SuperCron module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 20 Sept 2012
    2.1
    Low

    CVE-2012-1629

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Taxotouch module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.

    Published: 20 Sept 2012
    2.1
    Low

    CVE-2012-1630

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Taxonomy Navigator module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.

    Published: 20 Sept 2012
    6
    Medium

    CVE-2012-1625

    Last Modified: 11 Apr 2025

    Eval injection vulnerability in the fillpdf_form_export_decode function in fillpdf.admin.inc in the Fill PDF module 6.x-1.x before 6.x-1.16 and 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with administer PDFs privileges to execute arbitrary PHP code via unspecified vectors. NOTE: Some of these details are obtained from third party information.

    Published: 20 Sept 2012
    6.8
    Medium

    CVE-2012-1631

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Admin:hover module for Drupal allows remote attackers to hijack the authentication of administrators for requests that unpublish all nodes, and possibly other actions, via unspecified vectors.

    Published: 20 Sept 2012
    5
    Medium

    CVE-2012-5007

    Last Modified: 11 Apr 2025

    The Fill PDF module 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to write to arbitrary PDF files via unspecified vectors related to the fillpdf_merge_pdf function and incorrect arguments, a different vulnerability than CVE-2012-1625. NOTE: some of these details are obtained from third party information.

    Published: 20 Sept 2012
    4.3
    Medium

    CVE-2012-0988

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in config/dmsDefaults.php in KnowledgeTree 3.7.0.2 and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) login.php, (2) admin.php, or (3) preferences.php.

    Published: 20 Sept 2012
    3.5
    Low

    CVE-2012-1627

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in vud_term.module in the Vote Up/Down module 6.x-2.x before 6.x-2.8 and 6.x-3.x before 6.x-3.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via taxonomy terms.

    Published: 20 Sept 2012
    2.1
    Low

    CVE-2012-1632

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in password_policy.admin.inc in the Password Policy module before 6.x-1.4 and 7.x-1.0 beta3 for Drupal allows remote authenticated users with administer policies permissions to inject arbitrary web script or HTML via the name parameter.

    Published: 20 Sept 2012
    2.1
    Low

    CVE-2012-6536

    Last Modified: 11 Apr 2025

    net/xfrm/xfrm_user.c in the Linux kernel before 3.6 does not verify that the actual Netlink message length is consistent with a certain header field, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability and providing a (1) new or (2) updated state.

    Published: 20 Sept 2012
    6.8
    Medium

    CVE-2012-1633

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Password Policy module before 6.x-1.4 and 7.x-1.0 beta3 for Drupal allows remote attackers to hijack the authentication of administrative users for requests that unblock a user.

    Published: 20 Sept 2012
    6
    Medium

    CVE-2012-1638

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Search Autocomplete module before 7.x-2.1 for Drupal allows remote authenticated users with the "use search_autocomplete" permission to execute arbitrary SQL commands via unspecified vectors.

    Published: 19 Sept 2012
    2.1
    Low

    CVE-2012-1640

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Managesite module 6.x-1.x before 6.1-1.1 for Drupal allow remote authenticated users with "administer managesite" permissions to inject arbitrary web script or HTML via the title parameter when (1) adding or (2) updating a category.

    Published: 19 Sept 2012
    6.8
    Medium

    CVE-2012-5003

    Last Modified: 11 Apr 2025

    nxapplet.jar in No Machine NX Web Companion 3.x and earlier does not properly verify the authenticity of updates, which allows user-assisted remote attackers to execute arbitrary code via a crafted (1) SiteUrl or (2) RedirectUrl parameter that points to a Trojan Horse client.zip update file.

    Published: 19 Sept 2012
    6.8
    Medium

    CVE-2012-5004

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Parallels H-Sphere 3.3 Patch 1 allow remote attackers to hijack the authentication of admins for requests that (1) add group plans via admin/group_plans.html or (2) add extra packages via admin/extra_packs/create_extra_pack.html.

    Published: 19 Sept 2012
    6.8
    Medium

    CVE-2012-5005

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in admin/admin_options.php in VR GPub 4.0 allows remote attackers to hijack the authentication of admins for requests that add admin accounts via an add action.

    Published: 19 Sept 2012
    9.3
    Critical

    CVE-2012-5006

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in npdjvu.dll in Caminova DjVu Browser Plug-in 6.1.4 Build 27351 and other versions before 6.1.4.27993 allows remote attackers to execute arbitrary code via a crafted Sjbz chunk in a djvu file.

    Published: 19 Sept 2012