CVE Feed

    Dashboard / CVE

    3.5
    Low

    CVE-2012-1651

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Submenu Tree module before 6.x-1.5 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 19 Sept 2012
    2.1
    Low

    CVE-2012-1652

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Hierarchical Select module 6.x-3.x before 6.x-3.8 for Drupal allows remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML via unspecified vectors related to "the vocabulary's help text."

    Published: 19 Sept 2012
    3.5
    Low

    CVE-2012-1653

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Taxonomy Views Integrator (TVI) module 6.x-1.x before 6.x-1.3 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, related to "views pages."

    Published: 19 Sept 2012
    7.5
    High

    CVE-2012-2105

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in login.php in Timesheet Next Gen 1.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.

    Published: 19 Sept 2012
    5
    Medium

    CVE-2012-2991

    Last Modified: 11 Apr 2025

    The PayPal (aka MODULE_PAYMENT_PAYPAL_STANDARD) module before 1.1 in osCommerce Online Merchant before 2.3.4 allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self.

    Published: 19 Sept 2012
    4.3
    Medium

    CVE-2012-3373

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.21 and 1.5.x before 1.5.8 allows remote attackers to inject arbitrary web script or HTML via vectors involving a %00 sequence in an Ajax link URL associated with a Wicket app.

    Published: 19 Sept 2012
    9
    Critical

    CVE-2012-4992

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in FlashFXP.exe in FlashFXP 4.2 allow remote authenticated users to execute arbitrary code via a long unicode string to (1) TListbox or (2) TComboBox.

    Published: 19 Sept 2012
    7.5
    High

    CVE-2012-4993

    Last Modified: 11 Apr 2025

    torrent_functions.php in RivetTracker 1.03 and earlier does not properly restrict access, which allows remote attackers to have an unspecified impact.

    Published: 19 Sept 2012
    6.5
    Medium

    CVE-2012-4994

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in admin/admin.php in LimeSurvey before 1.91+ Build 120224 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a browse action. NOTE: some of these details are obtained from third party information.

    Published: 19 Sept 2012
    4.3
    Medium

    CVE-2012-4995

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/userrighthandling.php in LimeSurvey before 1.91+ Build 120224 allows remote attackers to inject arbitrary web script or HTML via the full_name parameter in a moduser action to admin/admin.php. NOTE: some of these details are obtained from third party information.

    Published: 19 Sept 2012
    7.5
    High

    CVE-2012-4996

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in RivetTracker 1.03 and earlier allow remote attackers to execute arbitrary SQL commands via the hash parameter to (1) dltorrent.php or (2) torrent_functions.php.

    Published: 19 Sept 2012
    7.5
    High

    CVE-2012-4997

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in acp/index.php in AneCMS allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter.

    Published: 19 Sept 2012
    4.3
    Medium

    CVE-2012-4998

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in starCMS allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Published: 19 Sept 2012
    7.5
    High

    CVE-2012-5001

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Hitachi JP1/Cm2/Network Node Manager i before 09-50-03 allow remote attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors.

    Published: 19 Sept 2012
    6.8
    Medium

    CVE-2012-5002

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file name option is enabled, allows remote attackers to execute arbitrary code via a long USER FTP command.

    Published: 19 Sept 2012
    6.1
    Medium

    CVE-2012-4999

    Last Modified: 11 Apr 2025

    Mercury MR804 Router 8.0 3.8.1 Build 101220 Rel.53006nB allows remote attackers to cause a denial of service (service hang) via a crafted string in HTTP header fields such as (1) If-Modified-Since, (2) If-None-Match, or (3) If-Unmodified-Since. NOTE: some of these details are obtained from third party information.

    Published: 19 Sept 2012
    7.5
    High

    CVE-2012-5000

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in jokes/index.php in the Witze addon 0.9 for deV!L'z Clanportal allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action.

    Published: 19 Sept 2012
    4.3
    Medium

    CVE-2011-3827

    Last Modified: 11 Apr 2025

    The iCalendar component in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to cause a denial of service (out-of-bounds read and daemon crash) via a crafted date-time string in a .ics attachment.

    Published: 19 Sept 2012
    10
    Critical

    CVE-2012-0271

    Last Modified: 11 Apr 2025

    Integer overflow in the WebConsole component in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before 8.0.3 HP1 and 2012 before SP1 might allow remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow, as demonstrated by a request with -1 in the Content-Length HTTP header.

    Published: 19 Sept 2012
    4.3
    Medium

    CVE-2012-0272

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to inject arbitrary web script or HTML via the merge parameter.

    Published: 19 Sept 2012
    4.3
    Medium

    CVE-2012-2578

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in SmarterMail 9.2 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a JavaScript alert function used in conjunction with the fromCharCode method, (2) a SCRIPT element, (3) a Cascading Style Sheets (CSS) expression property in the STYLE attribute of an arbitrary element, or (4) an innerHTML attribute within an XML document.

    Published: 19 Sept 2012
    4.3
    Medium

    CVE-2012-2586

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Mailtraq 2.17.3.3150 allow remote attackers to inject arbitrary web script or HTML via an e-mail message subject with (1) a JavaScript alert function used in conjunction with the fromCharCode method or (2) a SCRIPT element; an e-mail message body with (3) a crafted SRC attribute of an IFRAME element, (4) a data: URL in the CONTENT attribute of an HTTP-EQUIV="refresh" META element, or (5) a Cascading Style Sheets (CSS) expression property in the STYLE attribute of an IMG element; or an e-mail message Date header with (6) a JavaScript alert function used in conjunction with the fromCharCode method, (7) a SCRIPT element, (8) a CSS expression property in the STYLE attribute of an arbitrary element, (9) a crafted SRC attribute of an IFRAME element, or (10) a data: URL in the CONTENT attribute of an HTTP-EQUIV="refresh" META element.

    Published: 19 Sept 2012
    4
    Medium

    CVE-2012-4400

    Last Modified: 11 Apr 2025

    repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field.

    Published: 19 Sept 2012
    4
    Medium

    CVE-2012-4401

    Last Modified: 11 Apr 2025

    Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities.

    Published: 19 Sept 2012
    4.9
    Medium

    CVE-2012-4402

    Last Modified: 11 Apr 2025

    webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token intended for only one service.

    Published: 19 Sept 2012
    5
    Medium

    CVE-2012-4407

    Last Modified: 11 Apr 2025

    lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file.

    Published: 19 Sept 2012
    5.5
    Medium

    CVE-2012-4408

    Last Modified: 11 Apr 2025

    course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, which allows remote authenticated users to bypass intended access restrictions via a reset operation.

    Published: 19 Sept 2012
    5
    Medium

    CVE-2012-4403

    Last Modified: 11 Apr 2025

    theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response.

    Published: 19 Sept 2012
    10
    Critical

    CVE-2012-3258

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Operations Orchestration 9.0 before 9.03 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 19 Sept 2012
    7.5
    High

    CVE-2012-2684

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in the get_sample_filters_by_signature function in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow remote attackers to execute arbitrary SQL commands via the (1) agent or (2) object id.

    Published: 19 Sept 2012
    4
    Medium

    CVE-2012-2685

    Last Modified: 11 Apr 2025

    Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allows remote authenticated users to cause a denial of service (memory consumption) via a large size in an image request.

    Published: 19 Sept 2012
    6.8
    Medium

    CVE-2012-2734

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow remote attackers to hijack the authentication of arbitrary users for requests that execute commands via unspecified vectors.

    Published: 19 Sept 2012
    4.9
    Medium

    CVE-2012-2735

    Last Modified: 11 Apr 2025

    Session fixation vulnerability in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allows remote attackers to hijack web sessions via a crafted session cookie.

    Published: 19 Sept 2012
    4.9
    Medium

    CVE-2012-3459

    Last Modified: 11 Apr 2025

    Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allows remote authenticated users to modify Condor attributes and possibly gain privileges via crafted additional parameters in an HTTP POST request, which triggers a job attribute change request to Condor.

    Published: 19 Sept 2012
    8.8
    High

    CVE-2012-3490

    Last Modified: 21 Nov 2024

    The (1) my_popenv_impl and (2) my_spawnv functions in src/condor_utils/my_popen.cpp and the (3) systemCommand function in condor_vm-gahp/vmgahp_common.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the return value of setuid calls, which might cause a subprocess to be created with root privileges and allow remote attackers to gain privileges via unspecified vectors.

    Published: 19 Sept 2012
    5.8
    Medium

    CVE-2012-3493

    Last Modified: 11 Apr 2025

    The command_give_request_ad function in condor_startd.V6/command.cpp Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 allows remote attackers to obtain sensitive information, and possibly control or start arbitrary jobs, via a ClassAd request to the condor_startd port, which leaks the ClaimId.

    Published: 19 Sept 2012
    10
    Critical

    CVE-2012-5196

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 have unknown impact and attack vectors.

    Published: 19 Sept 2012
    1.9
    Low

    CVE-2012-6538

    Last Modified: 11 Apr 2025

    The copy_to_user_auth function in net/xfrm/xfrm_user.c in the Linux kernel before 3.6 uses an incorrect C library function for copying a string, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability.

    Published: 19 Sept 2012
    5
    Medium

    CVE-2012-2680

    Last Modified: 11 Apr 2025

    Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, does not properly restrict access to resources, which allows remote attackers to obtain sensitive information via unspecified vectors related to (1) "web pages," (2) "export functionality," and (3) "image viewing."

    Published: 19 Sept 2012
    4.3
    Medium

    CVE-2012-2683

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) "error message displays" or (2) "in source HTML on certain pages."

    Published: 19 Sept 2012
    4.3
    Medium

    CVE-2012-3451

    Last Modified: 11 Apr 2025

    Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.

    Published: 19 Sept 2012
    6.4
    Medium

    CVE-2012-3492

    Last Modified: 11 Apr 2025

    The filesystem authentication (condor_io/condor_auth_fs.cpp) in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 uses authentication directories even when they have weak permissions, which allows remote attackers to impersonate users by renaming a user's authentication directory.

    Published: 19 Sept 2012
    1.9
    Low

    CVE-2012-6537

    Last Modified: 11 Apr 2025

    net/xfrm/xfrm_user.c in the Linux kernel before 3.6 does not initialize certain structures, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability.

    Published: 19 Sept 2012
    5.8
    Medium

    CVE-2012-2681

    Last Modified: 11 Apr 2025

    Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, uses predictable random numbers to generate session keys, which makes it easier for remote attackers to guess the session key.

    Published: 19 Sept 2012
    4
    Medium

    CVE-2012-3491

    Last Modified: 11 Apr 2025

    src/condor_schedd.V6/schedd.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the permissions of jobs, which allows remote authenticated users to remove arbitrary idle jobs via unspecified vectors.

    Published: 19 Sept 2012
    10
    Critical

    CVE-2012-5197

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 have unknown impact and attack vectors related to "error checking of system calls."

    Published: 19 Sept 2012
    2.1
    Low

    CVE-2012-1654

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Data module 6.x-1.x before 6.x-1.0 and 7.x-1.x before 7.x-1.0-alpha3 for Drupal allow remote authenticated users with the administer data tables permission to inject arbitrary web script or HTML via the title parameter in (1) data.views.inc and (2) data_ui/data_ui.admin.inc.

    Published: 18 Sept 2012
    4
    Medium

    CVE-2012-1655

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the UC PayDutchGroup / WeDeal payment module 6.x-1.0 for Drupal allows remote authenticated users to obtain account credentials via unknown attack vectors.

    Published: 18 Sept 2012
    2.1
    Low

    CVE-2012-1657

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in block_class.module in the Block Class module before 7.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the class name.

    Published: 18 Sept 2012
    2.1
    Low

    CVE-2012-1658

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Read More Link module 6.x-3.x before 6.x-3.1 for Drupal allows remote authenticated users with the access administration pages permission to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Sept 2012