CVE Feed

    Dashboard / CVE

    4
    Medium

    CVE-2012-4430

    Last Modified: 11 Apr 2025

    The dump_resource function in dird/dird_conf.c in Bacula before 5.2.11 does not properly enforce ACL rules, which allows remote authenticated users to obtain resource dump information via unspecified vectors.

    Published: 13 Sept 2012
    2.6
    Low

    CVE-2012-4930

    Last Modified: 11 Apr 2025

    The SPDY protocol 3 and earlier, as used in Mozilla Firefox, Google Chrome, and other products, can perform TLS encryption of compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.

    Published: 13 Sept 2012
    6.2
    Medium

    CVE-2013-1826

    Last Modified: 11 Apr 2025

    The xfrm_state_netlink function in net/xfrm/xfrm_user.c in the Linux kernel before 3.5.7 does not properly handle error conditions in dump_one_state function calls, which allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability.

    Published: 13 Sept 2012
    7.5
    High

    CVE-2012-4428

    Last Modified: 21 Nov 2024

    openslp: SLPIntersectStringList()' Function has a DoS vulnerability

    Published: 13 Sept 2012
    2.6
    Low

    CVE-2012-4929

    Last Modified: 11 Apr 2025

    The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.

    Published: 13 Sept 2012
    7.8
    High

    CVE-2012-3935

    Last Modified: 11 Apr 2025

    Cisco Unified Presence (CUP) before 8.6(3) and Jabber Extensible Communications Platform (aka Jabber XCP) before 5.3 allow remote attackers to cause a denial of service (process crash) via a crafted XMPP stream header, aka Bug ID CSCtu32832.

    Published: 12 Sept 2012
    7.8
    High

    CVE-2012-4629

    Last Modified: 11 Apr 2025

    The Cisco ASA-CX Context-Aware Security module before 9.0.2-103 for Adaptive Security Appliances (ASA) devices, and Prime Security Manager (aka PRSM) before 9.0.2-103, allows remote attackers to cause a denial of service (disk consumption and application hang) via unspecified IPv4 packets that trigger log entries, aka Bug ID CSCub70603.

    Published: 12 Sept 2012
    5
    Medium

    CVE-2012-2048

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Adobe ColdFusion 10 and earlier allows attackers to cause a denial of service via unknown vectors.

    Published: 12 Sept 2012
    7.5
    High

    CVE-2012-2407

    Last Modified: 11 Apr 2025

    Buffer overflow in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted AAC file that is not properly handled during stream-data unpacking.

    Published: 12 Sept 2012
    6.8
    Medium

    CVE-2012-2408

    Last Modified: 11 Apr 2025

    The AAC SDK in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted AAC file that is not properly handled during decoding.

    Published: 12 Sept 2012
    7.5
    High

    CVE-2012-2409

    Last Modified: 11 Apr 2025

    Buffer overflow in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted RealMedia file, a different vulnerability than CVE-2012-2410.

    Published: 12 Sept 2012
    6.8
    Medium

    CVE-2012-2410

    Last Modified: 11 Apr 2025

    Buffer overflow in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted RealMedia file, a different vulnerability than CVE-2012-2409.

    Published: 12 Sept 2012
    7.5
    High

    CVE-2012-3234

    Last Modified: 11 Apr 2025

    RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 do not properly handle codec frame sizes in RealAudio files, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) or possibly have unspecified other impact via a crafted file.

    Published: 12 Sept 2012
    7.1
    High

    CVE-2012-3955

    Last Modified: 11 Apr 2025

    ISC DHCP 4.1.x before 4.1-ESV-R7 and 4.2.x before 4.2.4-P2 allows remote attackers to cause a denial of service (daemon crash) in opportunistic circumstances by establishing an IPv6 lease in an environment where the lease expiration time is later reduced.

    Published: 12 Sept 2012
    7.8
    High

    CVE-2012-4244

    Last Modified: 11 Apr 2025

    ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P3 allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for a long resource record.

    Published: 12 Sept 2012
    4
    Medium

    CVE-2012-4413

    Last Modified: 11 Apr 2025

    OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.

    Published: 12 Sept 2012
    6.9
    Medium

    CVE-2012-3524

    Last Modified: 11 Apr 2025

    libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: libdbus maintainers state that this is a vulnerability in the applications that do not cleanse environment variables, not in libdbus itself: "we do not support use of libdbus in setuid binaries that do not sanitize their environment before their first call into libdbus."

    Published: 12 Sept 2012
    6.9
    Medium

    CVE-2012-4425

    Last Modified: 11 Apr 2025

    libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: it could be argued that this is a vulnerability in the applications that do not cleanse environment variables, not in libgio itself.

    Published: 12 Sept 2012
    6
    Medium

    CVE-2012-3572

    Last Modified: 11 Apr 2025

    Open Source Competency Center (OSCC) MyMeeting 3.0.1 and earlier, and MyMesyuarat 09b-1, does not properly verify uploaded documents, which allows remote authenticated users to execute arbitrary PHP code via a crafted document.

    Published: 11 Sept 2012
    6.8
    Medium

    CVE-2012-4893

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in file/show.cgi in Webmin 1.590 and earlier allow remote attackers to hijack the authentication of privileged users for requests that (1) read files or execute (2) tar, (3) zip, or (4) gzip commands, a different issue than CVE-2012-2982.

    Published: 11 Sept 2012
    4.3
    Medium

    CVE-2012-1892

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Microsoft Visual Studio Team Foundation Server 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "XSS Vulnerability."

    Published: 11 Sept 2012
    6
    Medium

    CVE-2012-2981

    Last Modified: 11 Apr 2025

    Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary Perl code via a crafted file associated with the type (aka monitor type name) parameter.

    Published: 11 Sept 2012
    6.5
    Medium

    CVE-2012-2982

    Last Modified: 11 Apr 2025

    file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.

    Published: 11 Sept 2012
    5
    Medium

    CVE-2012-2983

    Last Modified: 11 Apr 2025

    file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote attackers to read arbitrary files via the file field.

    Published: 11 Sept 2012
    4.3
    Medium

    CVE-2012-2975

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the traffic overview page on the F5 ASM appliance 10.0.0 through 11.2.0 HF2 allows remote attackers to inject arbitrary web script or HTML via crafted requests that are later listed on a summary page.

    Published: 11 Sept 2012
    4.3
    Medium

    CVE-2012-2536

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Microsoft Systems Management Server 2003 SP3 and System Center Configuration Manager 2007 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Reflected XSS Vulnerability."

    Published: 11 Sept 2012
    6.8
    Medium

    CVE-2012-4405

    Last Modified: 11 Apr 2025

    Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PostScript or (2) PDF file with embedded images, which triggers a heap-based buffer overflow. NOTE: this issue is also described as an array index error.

    Published: 11 Sept 2012
    6.5
    Medium

    CVE-2012-4414

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in the replication code in Oracle MySQL possibly before 5.5.29, and MariaDB 5.1.x through 5.1.62, 5.2.x through 5.2.12, 5.3.x through 5.3.7, and 5.5.x through 5.5.25, allow remote authenticated users to execute arbitrary SQL commands via vectors related to the binary log. NOTE: as of 20130116, Oracle has not commented on claims from a downstream vendor that the fix in MySQL 5.5.29 is incomplete.

    Published: 11 Sept 2012
    8.8
    High

    CVE-2012-5054

    Last Modified: 21 Apr 2026

    Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbitrary code via malformed arguments.

    Published: 11 Sept 2012
    10
    Critical

    CVE-2012-2775

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the read_var_block_data function in libavcodec/alsdec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to a large order and an "out of array write in quant_cof."

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2776

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the decode_cell_data function in libavcodec/indeo3.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unknown impact and attack vectors, related to an "out of picture write."

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2777

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the decode_pic function in libavcodec/cavsdec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to "width/height changing in CAVS," a different vulnerability than CVE-2012-2784.

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2779

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the decode_frame function in libavcodec/indeo5.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to an invalid "gop header" and decoding in a "half initialized context."

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2782

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the decode_slice_header function in libavcodec/h264.c in FFmpeg before 0.11 has unknown impact and attack vectors, related to a "rejected resolution change."

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2783

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in libavcodec/vp56.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, has unknown impact and attack vectors, related to "freeing the returned frame."

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2784

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the decode_pic function in libavcodec/cavsdec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to "width/height changing in CAVS," a different vulnerability than CVE-2012-2777.

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2785

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in libavcodec/wmalosslessdec.c in FFmpeg before 0.11 have unknown impact and attack vectors, related to (1) "some subframes only encode some channels" or (2) a large order value.

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2786

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the decode_wdlt function in libavcodec/dfa.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to an "out of array write."

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2787

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the decode_frame function in libavcodec/indeo4.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unknown impact and attack vectors, related to the "setup width/height."

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2790

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the read_var_block_data function in libavcodec/alsdec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to the "number of decoded samples in first sub-block in BGMC mode."

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2791

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the (1) decode_band_hdr function in indeo4.c and (2) ff_ivi_decode_blocks function in ivi_common.c in libavcodec/ in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, have unknown impact and attack vectors, related to the "transform size."

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2792

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the decode_init function in libavcodec/wmalosslessdec.c in FFmpeg before 0.11 has unknown impact and attack vectors, related to the samples per frame.

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2794

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the decode_mb_info function in libavcodec/indeo5.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors in which the "allocated tile size ... mismatches parameters."

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2797

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the decode_frame_mp3on4 function in libavcodec/mpegaudiodec.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.5 has unknown impact and attack vectors related to a calculation that prevents a frame from being "large enough."

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2798

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the decode_dds1 function in libavcodec/dfa.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to an "out of array write."

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2799

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in libavcodec/wmalosslessdec.c in FFmpeg before 0.11 has unknown impact and attack vectors, related to the "put bit buffer when num_saved_bits is reset."

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2800

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the ff_ivi_process_empty_tile function in libavcodec/ivi_common.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors in which the "tile size ... mismatches parameters" and triggers "writing into a too small array."

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2801

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in libavcodec/avs.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to dimensions and "out of array writes."

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2802

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the ac3_decode_frame function in libavcodec/ac3dec.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unknown impact and attack vectors, related to the "number of output channels" and "out of array writes."

    Published: 10 Sept 2012
    4.3
    Medium

    CVE-2012-4889

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Firewall Analyzer 7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) subTab or (2) tab parameter to createAnomaly.do; (3) url, (4) subTab, or (5) tab parameter to mindex.do; (6) tab parameter to index2.do; or (7) port parameter to syslogViewer.do.

    Published: 10 Sept 2012