CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2010-5255

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in UltraISO 9.3.6.2750 allows local users to gain privileges via a Trojan horse daemon.dll file in the current working directory, as demonstrated by a directory that contains a .iso file. NOTE: some of these details are obtained from third party information.

    Published: 7 Sept 2012
    6.9
    Medium

    CVE-2010-5263

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Sothink SWF Decompiler 6.0 Build 610 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .flv file. NOTE: some of these details are obtained from third party information.

    Published: 7 Sept 2012
    6.9
    Medium

    CVE-2010-5271

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Altova MapForce 2011 Enterprise Edition SP1 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .mfd file. NOTE: some of these details are obtained from third party information.

    Published: 7 Sept 2012
    10
    Critical

    CVE-2012-3013

    Last Modified: 11 Apr 2025

    WAGO I/O System 758 model 758-870, 758-874, 758-875, and 758-876 Industrial PC (IPC) devices have default passwords for unspecified Web Based Management accounts, which makes it easier for remote attackers to obtain administrative access via a TCP session.

    Published: 7 Sept 2012
    6.4
    Medium

    CVE-2012-4416

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality and integrity via unknown vectors related to Hotspot.

    Published: 7 Sept 2012
    2.9
    Low

    CVE-2012-4454

    Last Modified: 11 Apr 2025

    openCryptoki before 2.4.1, when using spinlocks, allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) .pkapi_xpk or (2) .pkcs11spinloc file in /tmp.

    Published: 7 Sept 2012
    6.2
    Medium

    CVE-2012-4455

    Last Modified: 11 Apr 2025

    openCryptoki 2.4.1 allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) LCK..opencryptoki or (2) LCK..opencryptoki_stdll file in /var/lock/.

    Published: 7 Sept 2012
    10
    Critical

    CVE-2012-4879

    Last Modified: 11 Apr 2025

    The Linux Console on the WAGO I/O System 758 model 758-870, 758-874, 758-875, and 758-876 Industrial PC (IPC) devices has a default password of wago for the (1) root and (2) admin accounts, (3) a default password of user for the user account, and (4) a default password of guest for the guest account, which makes it easier for remote attackers to obtain login access via a TELNET session, a different vulnerability than CVE-2012-3013.

    Published: 7 Sept 2012
    7.5
    High

    CVE-2012-4420

    Last Modified: 21 Nov 2024

    An information disclosure flaw was found in the way the Java Virtual Machine (JVM) implementation of Java SE 7 as provided by OpenJDK 7 incorrectly initialized integer arrays after memory allocation (in certain circumstances they had nonzero elements right after the allocation). A remote attacker could use this flaw to obtain potentially sensitive information.

    Published: 7 Sept 2012
    4.3
    Medium

    CVE-2012-4872

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Tickets/Submit in Kayako Fusion before 4.40.985 allows remote attackers to inject arbitrary web script or HTML via certain vectors, possibly a crafted ticket description.

    Published: 6 Sept 2012
    4.3
    Medium

    CVE-2012-4873

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the file_download function in GNUBoard before 4.34.21 allows remote attackers to inject arbitrary web script or HTML via the filename parameter.

    Published: 6 Sept 2012
    6.5
    Medium

    CVE-2012-1467

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in the iBrowser plugin library, as used in Open Journal Systems before 2.3.7, allow remote authenticated users to (1) delete or (2) rename arbitrary files via a .. (dot dot) in the param parameter to lib/pkp/lib/tinymce/jscripts/tiny_mce/plugins/ibrowser/scripts/rfiles.php.

    Published: 6 Sept 2012
    6
    Medium

    CVE-2012-1468

    Last Modified: 11 Apr 2025

    Incomplete blacklist vulnerability in Open Journal Systems before 2.3.7 allows remote authenticated users with the Author Role permission to execute arbitrary code by uploading a file with an executable extension that is not ".php", then accessing it via a direct request to the file in submission/original/ in the associated article directory, as demonstrated using .pHp, .asp, and other extensions.

    Published: 6 Sept 2012
    5
    Medium

    CVE-2012-1611

    Last Modified: 11 Apr 2025

    Joomla! 2.5.x before 2.5.4 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end" information via unknown attack vectors. NOTE: this might be a duplicate of CVE-2012-1599.

    Published: 6 Sept 2012
    4.3
    Medium

    CVE-2012-1612

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the update manager in Joomla! 2.5.x before 2.5.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Sept 2012
    10
    Critical

    CVE-2012-4874

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Another WordPress Classifieds Plugin before 2.0 for WordPress has unknown impact and attack vectors related to "image uploads."

    Published: 6 Sept 2012
    9.3
    Critical

    CVE-2012-4875

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in gdevwpr2.c in Ghostscript 9.04, when processing the OutputFile device parameter, allows user-assisted remote attackers to execute arbitrary code via a long file name in a PostScript document. NOTE: as of 20120314, the developer was not able to reproduce the issue and disputed it

    Published: 6 Sept 2012
    10
    Critical

    CVE-2012-4876

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the UltraMJCam ActiveX Control in TRENDnet SecurView TV-IP121WN Wireless Internet Camera allows remote attackers to execute arbitrary code via a long string to the OpenFileDlg method.

    Published: 6 Sept 2012
    6.8
    Medium

    CVE-2012-4877

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in controlcenter.php in FlatnuX CMS 2011 08.09.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that add user accounts.

    Published: 6 Sept 2012
    5
    Medium

    CVE-2012-4878

    Last Modified: 11 Apr 2025

    Absolute path traversal vulnerability in controlcenter.php in FlatnuX CMS 2011 08.09.2 allows remote administrators to read arbitrary files via a full pathname in the dir parameter in a contents/Files action.

    Published: 6 Sept 2012
    4.3
    Medium

    CVE-2012-1469

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Open Journal Systems before 2.3.7 allow remote attackers and remote authenticated users to inject arbitrary web script or HTML via the (1) editor or (2) callback parameters to lib/pkp/lib/tinymce/jscripts/tiny_mce/plugins/ibrowser/ibrowser.php in the iBrowser plugin, (3) authors[][url] parameter to index.php, or (4) Bio Statement or (5) Abstract of Submission fields to the stripUnsafeHtml function in lib/pkp/classes/core/String.inc.php.

    Published: 6 Sept 2012
    4.3
    Medium

    CVE-2012-4871

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in service/graph_html.php in the administrator panel in LiteSpeed Web Server 4.1.11 allows remote attackers to inject arbitrary web script or HTML via the gtitle parameter.

    Published: 6 Sept 2012
    7.5
    High

    CVE-2006-7247

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Weblinks (com_weblinks) component for Joomla! and Mambo 1.0.9 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter.

    Published: 6 Sept 2012
    4.3
    Medium

    CVE-2012-0820

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0822.

    Published: 6 Sept 2012
    5
    Medium

    CVE-2012-0835

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Joomla! 1.7.x before 1.7.5 and 2.5.x before 2.5.1 allows attackers to obtain sensitive information via unknown vectors related to "administrator."

    Published: 6 Sept 2012
    5
    Medium

    CVE-2012-0836

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Joomla! 1.7.x before 1.7.5 allows attackers to read the error log via unknown vectors.

    Published: 6 Sept 2012
    4.3
    Medium

    CVE-2012-0822

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Joomla! 1.6 and 1.7.x before 1.7.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0820.

    Published: 6 Sept 2012
    5
    Medium

    CVE-2012-0819

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2012-0821.

    Published: 6 Sept 2012
    5
    Medium

    CVE-2012-0821

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2012-0819.

    Published: 6 Sept 2012
    5
    Medium

    CVE-2012-0837

    Last Modified: 11 Apr 2025

    Joomla! 1.7.x before 1.7.5 and 2.5.x before 2.5.1 allows attackers to obtain the installation path via unspecified vectors related to "administrator."

    Published: 6 Sept 2012
    6.8
    Medium

    CVE-2012-1112

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Open-Realty CMS 2.5.8 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the select_users_template parameter to index.php.

    Published: 6 Sept 2012
    4.3
    Medium

    CVE-2012-1110

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Etano 1.22 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user, (2) email, (3) email2, (4) f17_zip, or (5) agree parameter to join.php; (6) PATH_INFO, (7) st, (8) f17_city, (9) f17_country, (10) f17_state, (11) f17_zip, (12) f19, (13) wphoto, (14) search, or (15) v parameter to search.php; (16) PATH_INFO or (17) st parameter to photo_search.php; or (18) return parameter to photo_view.php.

    Published: 6 Sept 2012
    6.8
    Medium

    CVE-2012-2069

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Wishlist module 6.x-2.x before 6.x-2.6 and 7.x-2.x before 7.x-2.6 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) sequences via the (1) wl_reveal or (2) q parameters.

    Published: 6 Sept 2012
    7.5
    High

    CVE-2012-2740

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in public_html/lists/admin in phpList before 2.10.18 allows remote attackers to execute arbitrary SQL commands via the sortby parameter in a find action.

    Published: 6 Sept 2012
    9.3
    Critical

    CVE-2012-4864

    Last Modified: 11 Apr 2025

    Oreans WinLicense 2.1.8.0 allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via a crafted xml file.

    Published: 6 Sept 2012
    9.3
    Critical

    CVE-2012-4865

    Last Modified: 11 Apr 2025

    Buffer overflow in Oreans Themida 2.1.8.0 allows remote attackers to execute arbitrary code via a crafted .TMD file.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2012-4866

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Xtreme RAT 3.5 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as the current working directory. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    5
    Medium

    CVE-2012-4867

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in modules/com_vtiger_workflow/sortfieldsjson.php in vtiger CRM 5.1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the module_name parameter.

    Published: 6 Sept 2012
    7.5
    High

    CVE-2012-4868

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in news.php in the Kunena component 1.7.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 6 Sept 2012
    4.3
    Medium

    CVE-2012-2741

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in public_html/lists/admin/ in phpList before 2.10.18 allows remote attackers to inject arbitrary web script or HTML via the num parameter in a reconcileusers action.

    Published: 6 Sept 2012
    7.5
    High

    CVE-2012-4869

    Last Modified: 11 Apr 2025

    The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attackers to execute arbitrary commands via the callmenum parameter in a c action.

    Published: 6 Sept 2012
    4.3
    Medium

    CVE-2012-4870

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) context parameter to panel/index_amp.php or (2) panel/dhtml/index.php; (3) clid or (4) clidname parameters to panel/flash/mypage.php; (5) PATH_INFO to admin/views/freepbx_reload.php; or (6) login parameter to recordings/index.php.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5195

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Roxio MyDVD 9 allows local users to gain privileges via a Trojan horse HomeUtils9.dll file in the current working directory, as demonstrated by a directory that contains a .dmsd or .dmsm file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5197

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Pixia 4.70j allows local users to gain privileges via a Trojan horse wintab32.dll file in the current working directory, as demonstrated by a directory that contains a .pxa file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5198

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in Intuit QuickBooks 2010 allow local users to gain privileges via a Trojan horse (1) dbicudtx11.dll, (2) mfc90enu.dll, or (3) mfc90loc.dll file in the current working directory, as demonstrated by a directory that contains a .des, .qbo, or .qpg file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5199

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in PhotoImpact X3 13.00.0000.0 allows local users to gain privileges via a Trojan horse bwsconst.dll file in the current working directory, as demonstrated by a directory that contains a .ufp or .ufo file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5200

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in KeePass Password Safe before 1.18 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .kdb file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5201

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in MAGIX Samplitude Producer 11 allows local users to gain privileges via a Trojan horse PlayRIplA6.dll file in the current working directory, as demonstrated by a directory that contains a .vip file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5202

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in JetAudio 8.0.7.1000 Basic allows local users to gain privileges via a Trojan horse WNASPI32.DLL file in the current working directory, as demonstrated by a directory that contains a .mp3 file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5205

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in e-press ONE Office Author allow local users to gain privileges via a Trojan horse (1) java_msci.dll or (2) msci_java.dll file in the current working directory, as demonstrated by a directory that contains a .psw file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012