CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2012-3051

    Last Modified: 11 Apr 2025

    Cisco NX-OS 5.2 and 6.1 on Nexus 7000 series switches allows remote attackers to cause a denial of service (process crash or packet loss) via a large number of ARP packets, aka Bug ID CSCtr44822.

    Published: 16 Sept 2012
    4
    Medium

    CVE-2012-3096

    Last Modified: 11 Apr 2025

    Cisco Unity Connection (UC) 7.1, 8.0, and 8.5 allows remote authenticated users to cause a denial of service (resource consumption and administration outage) via extended use of the product, aka Bug ID CSCtd79132.

    Published: 16 Sept 2012
    6.8
    Medium

    CVE-2012-3908

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the ISE Administrator user interface (aka the Apache Tomcat interface) on Cisco Identity Services Engine (ISE) 3300 series appliances before 1.1.0.665 Cumulative Patch 1 allow remote attackers to hijack the authentication of administrators, aka Bug ID CSCty46684.

    Published: 16 Sept 2012
    5
    Medium

    CVE-2012-3094

    Last Modified: 11 Apr 2025

    The VPN downloader in the download_install component in Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495 on Linux accepts arbitrary X.509 server certificates without user interaction, which allows remote attackers to obtain sensitive information via vectors involving an invalid certificate, aka Bug ID CSCua11967.

    Published: 16 Sept 2012
    6.3
    Medium

    CVE-2012-3895

    Last Modified: 11 Apr 2025

    Cisco IOS 15.0 through 15.3 allows remote authenticated users to cause a denial of service (device crash) via an MVPNv6 update, aka Bug ID CSCty89224.

    Published: 16 Sept 2012
    5
    Medium

    CVE-2012-3901

    Last Modified: 11 Apr 2025

    The updateTime function in sensorApp on Cisco IPS 4200 series sensors 7.0 and 7.1 allows remote attackers to cause a denial of service (process crash and traffic-inspection outage) via network traffic, aka Bug ID CSCta96144.

    Published: 16 Sept 2012
    9.3
    Critical

    CVE-2011-5162

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in GOM Player 2.1.33.5071 allows user-assisted remote attackers to execute arbitrary code via a .ASX file with a long URI in the "ref href" tag. NOTE: this issue exists because of a CVE-2007-0707 regression.

    Published: 15 Sept 2012
    9.3
    Critical

    CVE-2011-5164

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in VanDyke Software AbsoluteFTP 1.9.6 through 2.2.10 allows remote FTP servers to execute arbitrary code via a crafted file name in a LIST command response.

    Published: 15 Sept 2012
    9.3
    Critical

    CVE-2011-5165

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted .wav file.

    Published: 15 Sept 2012
    9.3
    Critical

    CVE-2011-5167

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the SetDevNames method of the Tidestone Formula One ActiveX control (TTF16.ocx) 6.3.5 Build 1 in Oracle Hyperion Strategic Finance 12.x and possibly earlier allows remote attackers to execute arbitrary code via a long string to the DriverName parameter.

    Published: 15 Sept 2012
    7.5
    High

    CVE-2011-5168

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in user.php in Banana Dance before B.1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 15 Sept 2012
    7.5
    High

    CVE-2011-5169

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in sgms/reports/scheduledreports/configure/scheduleProps.jsp in SonicWall ViewPoint 6.0 SP2 allows remote attackers to execute arbitrary SQL commands via the scheduleID parameter.

    Published: 15 Sept 2012
    9.3
    Critical

    CVE-2011-5170

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Castillo Bueno Systems CCMPlayer 1.5 allows remote attackers to execute arbitrary code via a long track name in an m3u playlist.

    Published: 15 Sept 2012
    6.8
    Medium

    CVE-2011-5173

    Last Modified: 11 Apr 2025

    Buffer overflow in Bugbear Entertainment FlatOut 2005 allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the title field in a bed file.

    Published: 15 Sept 2012
    7.5
    High

    CVE-2011-5175

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in search.php in Banana Dance, possibly B.1.5 and earlier, allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Published: 15 Sept 2012
    4.3
    Medium

    CVE-2011-5176

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in search.php in Banana Dance, possibly B.1.5 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) q or (2) category parameter.

    Published: 15 Sept 2012
    4.3
    Medium

    CVE-2012-3233

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in __swift/thirdparty/PHPExcel/PHPExcel/Shared/JAMA/docs/download.php in Kayako Fusion 4.40.1148, and possibly before 4.50.1581, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Published: 15 Sept 2012
    7.5
    High

    CVE-2012-4925

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in approve.php in Img Pals Photo Host 1.0 allow remote attackers to execute arbitrary SQL commands via the u parameter in a (1) app0 or (2) app1 action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 15 Sept 2012
    6.4
    Medium

    CVE-2012-4926

    Last Modified: 11 Apr 2025

    approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activation of administrators via the u parameter in an (1) app0 (disable) or (2) app1 (enable) action.

    Published: 15 Sept 2012
    7.5
    High

    CVE-2012-4927

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Limesurvey (a.k.a PHPSurveyor) before 1.91+ Build 120224 and earlier allows remote attackers to execute arbitrary SQL commands via the fieldnames parameter to index.php.

    Published: 15 Sept 2012
    4.3
    Medium

    CVE-2012-4928

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in ow_updates/index.php in Oxwall 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the plugin parameter.

    Published: 15 Sept 2012
    7.5
    High

    CVE-2011-5166

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in KnFTP 1.0.0 allow remote attackers to execute arbitrary code via a long string to the (1) USER, (2) PASS, (3) REIN, (4) QUIT, (5) PORT, (6) PASV, (7) TYPE, (8) STRU, (9) MODE, (10) RETR, (11) STOR, (12) APPE, (13) ALLO, (14) REST, (15) RNFR, (16) RNTO, (17) ABOR, (18) DELE, (19) CWD, (20) LIST, (21) NLST, (22) SITE, (23) STST, (24) HELP, (25) NOOP, (26) MKD, (27) RMD, (28) PWD, (29) CDUP, (30) STOU, (31) SNMT, (32) SYST, and (33) XPWD commands.

    Published: 15 Sept 2012
    9.3
    Critical

    CVE-2011-5172

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in StoryBoard Quick 6 Build 3786, and possibly StoryBoard Artist and StoryBoard Studio, allows remote attackers to execute arbitrary code via a long string in the string element field in a frame xml file.

    Published: 15 Sept 2012
    7.2
    High

    CVE-2011-5174

    Last Modified: 11 Apr 2025

    Buffer overflow in Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) in Intel Q67 Express, C202, C204, C206 Chipsets, and Mobile Intel QM67, and QS67 Chipset before 2nd_gen_i5_i7_SINIT_51.BIN Express; Intel Q57, 3450 Chipsets and Mobile Intel QM57 and QS57 Express Chipset before i5_i7_DUAL_SINIT_51.BIN and i7_QUAD_SINIT_51.BIN; Mobile Intel GM45, GS45, and PM45 Express Chipset before GM45_GS45_PM45_SINIT_51.BIN; Intel Q35 Express Chipsets before Q35_SINIT_51.BIN; and Intel 5520, 5500, X58, and 7500 Chipsets before SINIT ACM 1.1 allows local users to bypass the Trusted Execution Technology protection mechanism and perform other unspecified SINIT ACM functions via unspecified vectors.

    Published: 15 Sept 2012
    4.3
    Medium

    CVE-2012-4336

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Flogr 2.5.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO or (2) an arbitrary parameter.

    Published: 15 Sept 2012
    4.3
    Medium

    CVE-2012-4923

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Endian Firewall 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) createrule parameter to dnat.cgi, (2) addrule parameter to dansguardian.cgi, or (3) PATH_INFO to openvpn_users.cgi.

    Published: 15 Sept 2012
    9.3
    Critical

    CVE-2012-4924

    Last Modified: 11 Apr 2025

    Buffer overflow in the CxDbgPrint function in the ipswcom.dll ActiveX component 1.0.0.1 for ASUS Net4Switch 1.0.0020 allows remote attackers to execute arbitrary code via a long parameter to the Alert method.

    Published: 15 Sept 2012
    4.6
    Medium

    CVE-2011-5163

    Last Modified: 11 Apr 2025

    Buffer overflow in an unspecified third-party component in the Batch module for Schneider Electric CitectSCADA before 7.20 and Mitsubishi MX4 SCADA before 7.20 allows local users to execute arbitrary code via a long string in a login sequence.

    Published: 15 Sept 2012
    9.3
    Critical

    CVE-2011-5171

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in CyberLink Power2Go 7 (build 196) and 8 (build 1031) allow remote attackers to execute arbitrary code via the (1) src and (2) name parameters in a p2g project file.

    Published: 15 Sept 2012
    6.8
    Medium

    CVE-2012-2275

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in TestLink 1.9.3 and earlier allow remote attackers to hijack the authentication of users for requests that add, delete, or modify sensitive information, as demonstrated by changing the administrator's email via an editUser action to lib/usermanagement/userInfo.php.

    Published: 15 Sept 2012
    4.3
    Medium

    CVE-2012-4360

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the mod_pagespeed module 0.10.19.1 through 0.10.22.4 for the Apache HTTP Server allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Sept 2012
    5
    Medium

    CVE-2012-4001

    Last Modified: 11 Apr 2025

    The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger HTTP requests to arbitrary hosts via unspecified vectors, as demonstrated by requests to intranet servers.

    Published: 15 Sept 2012
    9.8
    Critical

    CVE-2013-1591

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in libpixman, as used in Pale Moon before 15.4 and possibly other products, has unspecified impact and context-dependent attack vectors. NOTE: this issue might be resultant from an integer overflow in the fast_composite_scaled_bilinear function in pixman-inlines.h, which triggers an infinite loop.

    Published: 15 Sept 2012
    5
    Medium

    CVE-2012-4817

    Last Modified: 11 Apr 2025

    The NFSv4 client implementation in IBM AIX 5.3, 6.1, and 7.1, and VIOS before 2.2.1.4-FP-25 SP-02, does not properly handle GID values, which allows remote attackers to cause a denial of service via unspecified vectors.

    Published: 14 Sept 2012
    4.3
    Medium

    CVE-2012-4013

    Last Modified: 11 Apr 2025

    The WebView class in the Cybozu KUNAI Browser for Remote Service application beta for Android allows remote attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that places this code into a local file associated with a file: URL.

    Published: 14 Sept 2012
    5
    Medium

    CVE-2012-4683

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in bitcoind and Bitcoin-Qt allows attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2012-4682.

    Published: 14 Sept 2012
    5
    Medium

    CVE-2012-4682

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in bitcoind and Bitcoin-Qt allows attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2012-4683.

    Published: 14 Sept 2012
    3.5
    Low

    CVE-2012-4422

    Last Modified: 11 Apr 2025

    wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.

    Published: 14 Sept 2012
    4
    Medium

    CVE-2012-4421

    Last Modified: 11 Apr 2025

    The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.

    Published: 14 Sept 2012
    6.5
    Medium

    CVE-2010-5106

    Last Modified: 11 Apr 2025

    The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the Author or Contributor role.

    Published: 14 Sept 2012
    5
    Medium

    CVE-2012-4419

    Last Modified: 11 Apr 2025

    The compare_tor_addr_to_addr_policy function in or/policies.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.21-rc, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a zero-valued port field that is not properly handled during policy comparison.

    Published: 14 Sept 2012
    5
    Medium

    CVE-2012-4922

    Last Modified: 11 Apr 2025

    The tor_timegm function in common/util.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.22-rc, does not properly validate time values, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed directory object, a different vulnerability than CVE-2012-4419.

    Published: 14 Sept 2012
    5
    Medium

    CVE-2012-4903

    Last Modified: 11 Apr 2025

    Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by obtaining credential data, a different vulnerability than CVE-2012-4906.

    Published: 13 Sept 2012
    4.3
    Medium

    CVE-2012-4905

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inject arbitrary web script or HTML via an extra in an Intent object, aka "Universal XSS (UXSS)."

    Published: 13 Sept 2012
    7.5
    High

    CVE-2012-4908

    Last Modified: 11 Apr 2025

    Google Chrome before 18.0.1025308 on Android allows remote attackers to bypass the Same Origin Policy and obtain access to local files via vectors involving a symlink.

    Published: 13 Sept 2012
    4.3
    Medium

    CVE-2012-4909

    Last Modified: 11 Apr 2025

    Google Chrome before 18.0.1025308 on Android allows remote attackers to obtain cookie information via a crafted application.

    Published: 13 Sept 2012
    4.3
    Medium

    CVE-2012-4904

    Last Modified: 11 Apr 2025

    Cross-application scripting vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inject arbitrary web script via unspecified vectors, as demonstrated by "Universal XSS (UXSS)" attacks against the current tab.

    Published: 13 Sept 2012
    9.3
    Critical

    CVE-2012-4907

    Last Modified: 11 Apr 2025

    Google Chrome before 18.0.1025308 on Android does not properly restrict access from JavaScript code to Android APIs, which allows remote attackers to have an unspecified impact via a crafted web page.

    Published: 13 Sept 2012
    5
    Medium

    CVE-2012-4906

    Last Modified: 11 Apr 2025

    Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by obtaining credential data, a different vulnerability than CVE-2012-4903.

    Published: 13 Sept 2012
    6.8
    Medium

    CVE-2012-3598

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.

    Published: 13 Sept 2012