CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2010-5206

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in e-press ONE Office E-NoteTaker and E-Zip allow local users to gain privileges via a Trojan horse (1) mfc71enu.dll or (2) mfc71loc.dll file in the current working directory, as demonstrated by a directory that contains a .txt, .rar, or .tar file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5207

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in CelFrame Office 2008 Standard Edition allow local users to gain privileges via a Trojan horse (1) java_msci.dll or (2) msci_java.dll file in the current working directory, as demonstrated by a directory that contains a .doc, .xls, or .odg file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5208

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in the (1) Presentation, (2) Writer, and (3) Spreadsheets components in Kingsoft Office 2010 6.6.0.2477 allow local users to gain privileges via a Trojan horse plgpf.dll file in the current working directory, as demonstrated by a directory that contains a .xls, .ppt, .rtf, or .doc file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5209

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in Nuance PDF Reader 6.0 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) exceptiondumpdll.dll file in the current working directory, as demonstrated by a directory that contains a .pdf file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5214

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Fotobook Editor 5.0 2.8.0.1 allows local users to gain privileges via a Trojan horse Fwpuclnt.dll file in the current working directory, as demonstrated by a directory that contains a .dtp file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5215

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in SWiSH Max3 3.0 2009.11.30 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) SWiSHmax3res.dll file in the current working directory, as demonstrated by a directory that contains a .swi file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5216

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in LINGO 11.0.1.6 and 12.0.2.20 allows local users to gain privileges via a Trojan horse myuser.dll file in the current working directory, as demonstrated by a directory that contains a .ltf file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5218

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Dupehunter 9.0.0.3911 allows local users to gain privileges via a Trojan horse Fwpuclnt.dll file in the current working directory, as demonstrated by a directory that contains a .dhjb file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5219

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in SmartFTP 4.0.1140.0 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .txt, .html, or .mpg file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5220

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in MEO Encryption Software 2.02 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .meo or .cry file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5221

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in STDU Explorer 1.0.201 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5222

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Ease Jukebox 1.40 allows local users to gain privileges via a Trojan horse wmaudsdk.dll file in the current working directory, as demonstrated by a directory that contains a .mp3 or .wav file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5223

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in Phoenix Project Manager 2.1.0.8 allow local users to gain privileges via a Trojan horse (1) wbtrv32.dll or (2) w3btrv7.dll file in the current working directory, as demonstrated by a directory that contains a .ppx file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5224

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Cool iPhone Ringtone Maker 2.2.3 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .mp3 file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2011-5151

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in ACDSee Picture Frame Manager 1.0 Build 81 allows local users to gain privileges via a Trojan horse ShellIntMgrPFMU.dll file in the current working directory, as demonstrated by a directory that contains a .jpg file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2011-5152

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in ACDSee Photo Editor 2008 5.x build 291 allow local users to gain privileges via a Trojan horse (1) Wintab32.dll or (2) CV11-DialogEditor.dll file in the current working directory, as demonstrated by a directory that contains a .apd file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2011-5157

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Attachmate Reflection before 14.1 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, a related issue to CVE-2011-0107. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.3
    Medium

    CVE-2012-4754

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in MindManager 2012 10.0.493 allow local users to gain privileges via a Trojan horse (1) ssgp.dll or (2) dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .mmap file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2012-4755

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in SciTools Understand before 2.6 build 600 allows local users to gain privileges via a Trojan horse wintab32.dll file in the current working directory, as demonstrated by a directory that contains a .udb file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2012-4758

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in CyberLink PowerProducer 5.5.3.2325 allow local users to gain privileges via a Trojan horse (1) mfc71loc.dll or (2) mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .ppp or .rdf file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2012-4759

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in facebook_plugin.fpi in the Facebook plug-in in Foxit Reader 5.3.1.0606 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .pdf file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5204

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in IBM Lotus Symphony 1.3.0 20090908.0900 allow local users to gain privileges via a Trojan horse (1) eclipse_1114.dll or (2) emser645mi.dll file in the current working directory, as demonstrated by a directory that contains a .odm, .odt, .otp, .stc, .stw, .sxg, or .sxw file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5212

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Adobe LiveCycle Designer ES2 9.0.0.20091029.1.612548 allows local users to gain privileges via a Trojan horse objectassisten_US.dll file in the current working directory, as demonstrated by a directory that contains a .tds file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5213

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Adobe LiveCycle Designer 8.2.1.3144.1.471865 allows local users to gain privileges via a Trojan horse .dll file in the current working directory, as demonstrated by a directory that contains a .tds file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5217

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in TuneUp Utilities 2009 8.0.3310 and 2010 9.0.4600 allow local users to gain privileges via a Trojan horse (1) wscapi.dll or (2) vclib32.dll file in the current working directory, as demonstrated by a directory that contains a .tvs file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2011-5154

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in (1) SAPGui.exe and (2) BExAnalyzer.exe in SAP GUI 6.4 through 7.2 allow local users to gain privileges via a Trojan horse MFC80LOC.DLL file in the current working directory, as demonstrated by a directory that contains a .sap file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.3
    Medium

    CVE-2011-5155

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Help & Manual 5.5.1 Build 1296 allows local users to gain privileges via a Trojan horse ijl15.dll file in the current working directory, as demonstrated by a directory that contains a .hmxz, .hmxp, .hmskin, .hmx, .hm3, .hpj, .hlp, or .chm file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2011-5156

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Effective File Search 6.7 allows local users to gain privileges via a Trojan horse ztvunrar36.dll file in the current working directory, as demonstrated by a directory that contains a .efs file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2012-4757

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in CyberLink StreamAuthor 4.0 build 3308 allow local users to gain privileges via a Trojan horse (1) mfc71loc.dll or (2) mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .sta or .stp file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5196

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in KeePass Password Safe before 2.13 allows local users to gain privileges via a Trojan horse DwmApi.dll file in the current working directory, as demonstrated by a directory that contains a .kdbx file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5203

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in NCP Secure Enterprise Client before 9.21 Build 68, Secure Entry Client before 9.23 Build 18, and Secure Client - Juniper Edition before 9.23 Build 18 allow local users to gain privileges via a Trojan horse (1) dvccsabase002.dll, (2) conman.dll, (3) kmpapi32.dll, or (4) ncpmon2.dll file in the current working directory, as demonstrated by a directory that contains a .pcf or .spd file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5210

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Sorax Reader 2.0.3129.70 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .pdf file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5211

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in ALSee 6.20.0.1 allows local users to gain privileges via a Trojan horse patchani.dll file in the current working directory, as demonstrated by a directory that contains a .ani, .bmp, .cal, .hdp, .jpe, .mac, .pbm, .pcx, .pgm, .png, .psd, .ras, .tga, or .tiff file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2010-5225

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Babylon 8.1.0 r16 allows local users to gain privileges via a Trojan horse BESExtension.dll file in the current working directory, as demonstrated by a directory that contains a .bgl file. NOTE: some of these details are obtained from third party information.

    Published: 6 Sept 2012
    6.3
    Medium

    CVE-2011-5153

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in FotoSlate 4.0 Build 146 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .plp file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Sept 2012
    6.9
    Medium

    CVE-2012-4756

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in CyberLink LabelPrint 2.5.3602 allow local users to gain privileges via a Trojan horse (1) mfc71loc.dll or (2) mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .lpp file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Sept 2012
    5.1
    Medium

    CVE-2012-4424

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string that triggers a malloc failure and use of the alloca function.

    Published: 6 Sept 2012
    4.6
    Medium

    CVE-2012-4411

    Last Modified: 11 Apr 2025

    The graphical console in Xen 4.0, 4.1 and 4.2 allows local OS guest administrators to obtain sensitive host resource information via the qemu monitor. NOTE: this might be a duplicate of CVE-2007-0998.

    Published: 6 Sept 2012
    3.5
    Low

    CVE-2012-3528

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the backend in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allow remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Sept 2012
    3.5
    Low

    CVE-2012-3529

    Last Modified: 11 Apr 2025

    The configuration module in the backend in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to obtain the encryption key via unspecified vectors.

    Published: 5 Sept 2012
    4.3
    Medium

    CVE-2012-3531

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Install Tool in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Sept 2012
    4.6
    Medium

    CVE-2012-3537

    Last Modified: 11 Apr 2025

    The Crowbar Ohai plugin (chef/cookbooks/ohai/files/default/plugins/crowbar.rb) in the Deployer Barclamp in Crowbar, possibly 1.4 and earlier, allows local users to execute arbitrary shell commands via vectors related to "insecure handling of tmp files" and predictable file names.

    Published: 5 Sept 2012
    4
    Medium

    CVE-2012-4390

    Last Modified: 11 Apr 2025

    (1) apps/calendar/appinfo/remote.php and (2) apps/contacts/appinfo/remote.php in ownCloud before 4.0.7 allows remote authenticated users to enumerate the registered users via unspecified vectors.

    Published: 5 Sept 2012
    6.8
    Medium

    CVE-2012-4391

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in core/ajax/appconfig.php in ownCloud before 4.0.7 allows remote attackers to hijack the authentication of administrators for requests that edit the app configurations.

    Published: 5 Sept 2012
    7.5
    High

    CVE-2012-4392

    Last Modified: 11 Apr 2025

    index.php in ownCloud 4.0.7 does not properly validate the oc_token cookie, which allows remote attackers to bypass authentication via a crafted oc_token cookie value.

    Published: 5 Sept 2012
    4.3
    Medium

    CVE-2012-4394

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in apps/files/js/filelist.js in ownCloud before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via the file parameter.

    Published: 5 Sept 2012
    4.3
    Medium

    CVE-2012-4395

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in ownCloud before 4.0.3 allows remote attackers to inject arbitrary web script or HTML via the redirect_url parameter.

    Published: 5 Sept 2012
    5
    Medium

    CVE-2012-4752

    Last Modified: 11 Apr 2025

    appconfig.php in ownCloud before 4.0.6 does not properly restrict access, which allows remote authenticated users to edit app configurations via unspecified vectors. NOTE: this can be leveraged by unauthenticated remote attackers using CVE-2012-4393.

    Published: 5 Sept 2012
    6.8
    Medium

    CVE-2012-4753

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud before 4.0.5 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 5 Sept 2012
    5
    Medium

    CVE-2012-3526

    Last Modified: 11 Apr 2025

    The reverse proxy add forward module (mod_rpaf) 0.5 and 0.6 for the Apache HTTP Server allows remote attackers to cause a denial of service (server or application crash) via multiple X-Forwarded-For headers in a request.

    Published: 5 Sept 2012