CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2012-1659

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Node Recommendation module 6.x-1.x before 6.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Sept 2012
    2.1
    Low

    CVE-2012-1660

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in components/select.inc in the Webform module 6.x-3.x before 6.x-3.17 and 7.x-3.x before 7.x-3.17 for Drupal, when the "Select (or other)" module is enabled, allow remote authenticated users with the create webform content permission to inject arbitrary web script or HTML via vectors related to (1) checkboxes or (2) radios.

    Published: 18 Sept 2012
    6.8
    Medium

    CVE-2012-1656

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Multisite Search module 6.x-2.2 for Drupal allows remote authenticated users with certain permissions to execute arbitrary SQL commands via the Site table prefix field.

    Published: 18 Sept 2012
    6.8
    Medium

    CVE-2011-4941

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Piwik 1.2 through 1.4 allows remote attackers with the view permission to execute arbitrary code via unknown attack vectors.

    Published: 18 Sept 2012
    6.8
    Medium

    CVE-2012-1901

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in FlexCMS 3.2.1 and earlier allow remote attackers to (1) hijack the authentication of users for requests that change account settings via a request to index.php/profile-edit-save or (2) hijack the authentication of administrators for requests that add a new page via a request to admin/pages-new-save.

    Published: 18 Sept 2012
    4.3
    Medium

    CVE-2012-1183

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the milliwatt_generate function in the Miliwatt application in Asterisk 1.4.x before 1.4.44, 1.6.x before 1.6.2.23, 1.8.x before 1.8.10.1, and 10.x before 10.2.1, when the o option is used and the internal_timing option is off, allows remote attackers to cause a denial of service (application crash) via a large number of samples in an audio packet.

    Published: 18 Sept 2012
    7.5
    High

    CVE-2012-1184

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the ast_parse_digest function in main/utils.c in Asterisk 1.8.x before 1.8.10.1 and 10.x before 10.2.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in an HTTP Digest Authentication header.

    Published: 18 Sept 2012
    6.8
    Medium

    CVE-2012-3028

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to hijack the authentication of arbitrary users for requests that modify data or cause a denial of service.

    Published: 18 Sept 2012
    4.3
    Medium

    CVE-2012-3034

    Last Modified: 11 Apr 2025

    WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to discover a username and password via crafted parameters to unspecified methods in ActiveX controls.

    Published: 18 Sept 2012
    7.5
    High

    CVE-2012-3032

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to execute arbitrary SQL commands via a crafted SOAP message.

    Published: 18 Sept 2012
    5
    Medium

    CVE-2012-3030

    Last Modified: 11 Apr 2025

    WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, stores sensitive information under the web root with insufficient access control, which allows remote attackers to read a (1) log file or (2) configuration file via a direct request.

    Published: 18 Sept 2012
    4.3
    Medium

    CVE-2012-3031

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allow remote attackers to inject arbitrary web script or HTML via a (1) GET parameter, (2) POST parameter, or (3) Referer HTTP header.

    Published: 18 Sept 2012
    8.1
    High

    CVE-2012-4969

    Last Modified: 21 Apr 2026

    Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in September 2012.

    Published: 18 Sept 2012
    7.5
    High

    CVE-2012-2994

    Last Modified: 11 Apr 2025

    The CoSoSys Endpoint Protector 4 appliance establishes an EPProot password based entirely on the appliance serial number, which makes it easier for remote attackers to obtain access via a brute-force attack.

    Published: 18 Sept 2012
    5.9
    Medium

    CVE-2012-2993

    Last Modified: 11 Apr 2025

    Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL server for the (1) POP3, (2) IMAP, or (3) SMTP protocol via an arbitrary valid certificate.

    Published: 18 Sept 2012
    6.4
    Medium

    CVE-2012-2062

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in the Redirecting click bouncer module for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 17 Sept 2012
    4.3
    Medium

    CVE-2012-1899

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in webfolio/admin/users/edit in Webfolio CMS 1.1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) First name, (2) Last name or (3) Email (required) fields.

    Published: 17 Sept 2012
    6.8
    Medium

    CVE-2012-2056

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Content Lock module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 17 Sept 2012
    6.8
    Medium

    CVE-2012-2057

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Ubercart Bulk Stock Updater module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors related to formAPI.

    Published: 17 Sept 2012
    5
    Medium

    CVE-2012-2058

    Last Modified: 11 Apr 2025

    The Ubercart Payflow module for Drupal does not use a secure token, which allows remote attackers to forge payments via unspecified vectors.

    Published: 17 Sept 2012
    4.3
    Medium

    CVE-2012-2059

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the ticketyboo News Ticker module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Sept 2012
    4.3
    Medium

    CVE-2012-2060

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Admin tools module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Sept 2012
    6.8
    Medium

    CVE-2012-2061

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Admin tools module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors involving "not checking tokens."

    Published: 17 Sept 2012
    4.3
    Medium

    CVE-2010-4822

    Last Modified: 11 Apr 2025

    core/model/MySQLDatabase.php in SilverStripe 2.4.x before 2.4.4, when the site is running in "live mode," allows remote attackers to obtain the SQL queries for a page via the showqueries and ajax parameters.

    Published: 17 Sept 2012
    4.3
    Medium

    CVE-2010-4823

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the httpError method in sapphire/core/control/RequestHandler.php in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4, when custom error handling is not used, allows remote attackers to inject arbitrary web script or HTML via "missing URL actions."

    Published: 17 Sept 2012
    6.8
    Medium

    CVE-2010-4824

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the augmentSQL method in core/model/Translatable.php in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4, when the Translatable extension is enabled, allows remote attackers to execute arbitrary SQL commands via the locale parameter.

    Published: 17 Sept 2012
    5
    Medium

    CVE-2010-5078

    Last Modified: 11 Apr 2025

    SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain version information via a direct request to (1) apphire/silverstripe_version or (2) cms/silverstripe_version.

    Published: 17 Sept 2012
    6
    Medium

    CVE-2011-4961

    Last Modified: 11 Apr 2025

    SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote authenticated users with the EDIT_PERMISSIONS permission to gain administrator privileges via a TreeMultiselectField that includes admin groups when adding a user to the selected groups.

    Published: 17 Sept 2012
    6.8
    Medium

    CVE-2011-4962

    Last Modified: 11 Apr 2025

    code/sitefeatures/PageCommentInterface.php in SilverStripe 2.4.x before 2.4.6 might allow remote attackers to execute arbitrary code via a crafted cookie in a user comment submission, which is not properly handled when it is deserialized.

    Published: 17 Sept 2012
    5
    Medium

    CVE-2010-5079

    Last Modified: 11 Apr 2025

    SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 uses weak entropy when generating tokens for (1) the CSRF protection mechanism, (2) autologin, (3) "forgot password" functionality, and (4) password salts, which makes it easier for remote attackers to bypass intended access restrictions via unspecified vectors.

    Published: 17 Sept 2012
    7.5
    High

    CVE-2011-4960

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Folder::findOrMake method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 17 Sept 2012
    4.3
    Medium

    CVE-2012-4968

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe 2.3.x before 2.3.13 and 2.4.x before 2.4.7 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted string to the AbsoluteLinks, (2) BigSummary, (3) ContextSummary, (4) EscapeXML, (5) FirstParagraph, (6) FirstSentence, (7) Initial, (8) LimitCharacters, (9) LimitSentences, (10) LimitWordCount, (11) LimitWordCountXML, (12) Lower, (13) LowerCase, (14) NoHTML, (15) Summary, (16) Upper, (17) UpperCase, or (18) URL method in a template, different vectors than CVE-2012-0976.

    Published: 17 Sept 2012
    6.8
    Medium

    CVE-2011-4959

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the addslashes method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6, when connected to a MySQL database using far east character encodings, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 17 Sept 2012
    4.3
    Medium

    CVE-2012-2575

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 6.0a4 allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of an IFRAME element in the body of an HTML e-mail message.

    Published: 17 Sept 2012
    4.3
    Medium

    CVE-2012-2995

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_1394 allow remote attackers to inject arbitrary web script or HTML via (1) the wrsApprovedURL parameter to addRuleAttrWrsApproveUrl.imss or (2) the src parameter to initUpdSchPage.imss.

    Published: 17 Sept 2012
    6.8
    Medium

    CVE-2012-2996

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in saveAccountSubTab.imss in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_1394 allows remote attackers to hijack the authentication of administrators for requests that create admin accounts via a saveAuth action.

    Published: 17 Sept 2012
    3.3
    Low

    CVE-2012-6655

    Last Modified: 21 Nov 2024

    An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.

    Published: 17 Sept 2012
    6.1
    Medium

    CVE-2012-4439

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins.

    Published: 17 Sept 2012
    2.1
    Low

    CVE-2012-6120

    Last Modified: 11 Apr 2025

    Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive information such as Puppet log files.

    Published: 17 Sept 2012
    8.8
    High

    CVE-2012-4438

    Last Modified: 21 Nov 2024

    Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins master to insert data and execute arbitrary code.

    Published: 17 Sept 2012
    6.9
    Medium

    CVE-2012-3052

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Cisco VPN Client 5.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka Bug ID CSCua28747.

    Published: 16 Sept 2012
    7.8
    High

    CVE-2012-3060

    Last Modified: 11 Apr 2025

    Cisco Unity Connection (UC) 8.6, 9.0, and 9.5 allows remote attackers to cause a denial of service (CPU consumption) via malformed UDP packets, aka Bug ID CSCtz76269.

    Published: 16 Sept 2012
    7.8
    High

    CVE-2012-3079

    Last Modified: 11 Apr 2025

    Cisco IOS 12.2 allows remote attackers to cause a denial of service (CPU consumption) by establishing many IPv6 neighbors, aka Bug ID CSCtn78957.

    Published: 16 Sept 2012
    9.3
    Critical

    CVE-2012-3088

    Last Modified: 11 Apr 2025

    Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495, and 3.2.x, does not check whether an HTTP request originally contains ScanSafe headers, which allows remote attackers to have an unspecified impact via a crafted request, aka Bug ID CSCua13166.

    Published: 16 Sept 2012
    6.3
    Medium

    CVE-2012-3893

    Last Modified: 11 Apr 2025

    The FlexVPN implementation in Cisco IOS 15.2 and 15.3 allows remote authenticated users to cause a denial of service (spoke crash) via spoke-to-spoke traffic, aka Bug ID CSCtz02622.

    Published: 16 Sept 2012
    5
    Medium

    CVE-2012-3899

    Last Modified: 11 Apr 2025

    sensorApp on Cisco IPS 4200 series sensors 6.0, 6.2, and 7.0 does not properly allocate memory, which allows remote attackers to cause a denial of service (memory corruption and process crash, and traffic-inspection outage) via network traffic, aka Bug ID CSCtn23051.

    Published: 16 Sept 2012
    5
    Medium

    CVE-2012-3915

    Last Modified: 11 Apr 2025

    The DMVPN tunnel implementation in Cisco IOS 15.2 allows remote attackers to cause a denial of service (persistent IKE state) via a large volume of hub-to-spoke traffic, aka Bug ID CSCtq39602.

    Published: 16 Sept 2012
    5
    Medium

    CVE-2012-3919

    Last Modified: 11 Apr 2025

    The Cisco Application Control Engine (ACE) module 3.0 for Cisco Catalyst switches and Cisco routers does not properly monitor Load Balancer (LB) queues, which allows remote attackers to cause a denial of service (incorrect memory access and module reboot) via application traffic, aka Bug ID CSCtw70879.

    Published: 16 Sept 2012
    3.5
    Low

    CVE-2012-3923

    Last Modified: 11 Apr 2025

    The SSLVPN implementation in Cisco IOS 12.4, 15.0, 15.1, and 15.2, when DTLS is not enabled, does not properly handle certain outbound ACL configurations, which allows remote authenticated users to cause a denial of service (device crash) via a session involving a PPP over ATM (PPPoA) interface, aka Bug ID CSCte41827.

    Published: 16 Sept 2012
    3.5
    Low

    CVE-2012-3924

    Last Modified: 11 Apr 2025

    The SSLVPN implementation in Cisco IOS 15.1 and 15.2, when DTLS is enabled, does not properly handle certain outbound ACL configurations, which allows remote authenticated users to cause a denial of service (device crash) via a session involving a PPP over ATM (PPPoA) interface, aka Bug ID CSCty97961.

    Published: 16 Sept 2012