CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2012-2862

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the PDF functionality in Google Chrome before 21.0.1180.75 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.

    Published: 9 Aug 2012
    7.5
    High

    CVE-2012-2863

    Last Modified: 11 Apr 2025

    The PDF functionality in Google Chrome before 21.0.1180.75 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger out-of-bounds write operations.

    Published: 9 Aug 2012
    4.9
    Medium

    CVE-2012-3433

    Last Modified: 11 Apr 2025

    Xen 4.0 and 4.1 allows local HVM guest OS kernels to cause a denial of service (domain 0 VCPU hang and kernel panic) by modifying the physical address space in a way that triggers excessive shared page search time during the p2m teardown.

    Published: 9 Aug 2012
    4.3
    Medium

    CVE-2012-3463

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_tag_helper.rb in Ruby on Rails 3.x before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the prompt field to the select_tag helper.

    Published: 9 Aug 2012
    4.3
    Medium

    CVE-2012-3464

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 might allow remote attackers to inject arbitrary web script or HTML via vectors involving a ' (quote) character.

    Published: 9 Aug 2012
    4.3
    Medium

    CVE-2012-3465

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/sanitize_helper.rb in the strip_tags helper in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via malformed HTML markup.

    Published: 9 Aug 2012
    6.8
    Medium

    CVE-2012-2649

    Last Modified: 11 Apr 2025

    The Sleipnir Mobile application 2.2.0 and earlier and Sleipnir Mobile Black Edition application 2.2.0 and earlier for Android allow remote attackers to execute arbitrary Java methods, and obtain sensitive information or execute arbitrary commands, via a crafted web site.

    Published: 8 Aug 2012
    4.3
    Medium

    CVE-2012-4004

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Sleipnir Mobile application 2.2.0 and earlier and Sleipnir Mobile Black Edition application 2.2.0 and earlier for Android allows remote attackers to inject arbitrary web script or HTML via a crafted application that interacts with an unspecified Sleipnir Mobile function.

    Published: 8 Aug 2012
    4.3
    Medium

    CVE-2012-2960

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the import functionality in HP ArcSight Connector appliance 6.2.0.6244.0 and ArcSight Logger appliance 5.2.0.6288.0 allows remote attackers to inject arbitrary web script or HTML via a crafted file.

    Published: 8 Aug 2012
    6.5
    Medium

    CVE-2010-5142

    Last Modified: 11 Apr 2025

    chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI.

    Published: 8 Aug 2012
    2.1
    Low

    CVE-2012-0421

    Last Modified: 11 Apr 2025

    The SUSE Audit Log Keeper daemon before 0.2.1-0.4.6.1 for SUSE Manager and Spacewalk uses world-readable permissions for /etc/auditlog-keeper.conf, which allows local users to obtain passwords by reading this file.

    Published: 8 Aug 2012
    6.5
    Medium

    CVE-2011-5098

    Last Modified: 11 Apr 2025

    chef-server-api/app/controllers/clients.rb in Chef Server in Chef before 0.9.20, and 0.10.x before 0.10.6, does not require administrative privileges for creating admin clients, which allows remote authenticated users to bypass intended access restrictions by leveraging read permission for the validation key and executing a knife client create command with the --admin option.

    Published: 8 Aug 2012
    7.5
    High

    CVE-2012-2203

    Last Modified: 11 Apr 2025

    IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, uses the PKCS #12 file format for certificate objects without enforcing file integrity, which makes it easier for remote attackers to spoof SSL servers via vectors involving insertion of an arbitrary root Certification Authority (CA) certificate.

    Published: 8 Aug 2012
    5.5
    Medium

    CVE-2011-5097

    Last Modified: 11 Apr 2025

    chef-server-api/app/controllers/cookbooks.rb in Chef Server in Chef before 0.9.18, and 0.10.x before 0.10.2, does not require administrative privileges for the update and destroy methods, which allows remote authenticated users to (1) upload cookbooks via a knife cookbook upload command or (2) delete cookbooks via a knife cookbook delete command.

    Published: 8 Aug 2012
    5
    Medium

    CVE-2012-2191

    Last Modified: 11 Apr 2025

    IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, does not properly validate data during execution of a protection mechanism against the Vaudenay SSL CBC timing attack, which allows remote attackers to cause a denial of service (application crash) via crafted values in the TLS Record Layer, a different vulnerability than CVE-2012-2333.

    Published: 8 Aug 2012
    7.5
    High

    CVE-2012-4178

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in spywall/includes/deptUploads_data.php in Symantec Web Gateway 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via the groupid parameter.

    Published: 7 Aug 2012
    4.3
    Medium

    CVE-2012-3438

    Last Modified: 11 Apr 2025

    The Magick_png_malloc function in coders/png.c in GraphicsMagick 6.7.8-6 does not use the proper variable type for the allocation size, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG file that triggers incorrect memory allocation.

    Published: 7 Aug 2012
    3.6
    Low

    CVE-2012-3449

    Last Modified: 11 Apr 2025

    Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/switchca/incoming/, which allows local users to delete and overwrite arbitrary files.

    Published: 7 Aug 2012
    3.6
    Low

    CVE-2012-3454

    Last Modified: 11 Apr 2025

    eXtplorer 2.1.0b6 uses world writable permissions for the /var/lib/extplorer/ftp_tmp directory, which allows local users to delete or overwrite arbitrary files.

    Published: 7 Aug 2012
    10
    Critical

    CVE-2012-4177

    Last Modified: 11 Apr 2025

    The web browser plugin for Ubisoft Uplay PC before 2.0.4 allows remote attackers to execute arbitrary programs via the -orbit_exe_path command line argument.

    Published: 7 Aug 2012
    3.6
    Low

    CVE-2012-3453

    Last Modified: 11 Apr 2025

    logol 1.5.0 uses world writable permissions for the /var/lib/logol/results directory, which allows local users to delete or overwrite arbitrary files.

    Published: 7 Aug 2012
    3.3
    Low

    CVE-2012-3452

    Last Modified: 11 Apr 2025

    gnome-screensaver 3.4.x before 3.4.4 and 3.5.x before 3.5.4, when multiple screens are used, only locks the screen with the active focus, which allows physically proximate attackers to bypass screen locking and access an unattended workstation.

    Published: 7 Aug 2012
    4.3
    Medium

    CVE-2012-2022

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node Manager i (NNMi) 8.x, 9.0x, 9.1x, and 9.20 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 7 Aug 2012
    4.3
    Medium

    CVE-2012-2648

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the GoodReader app 3.16 and earlier for iOS on the iPad, and 3.15.1 and earlier for iOS on the iPhone and iPod touch, allows remote attackers to inject arbitrary web script or HTML via vectors involving use of this app in conjunction with a web browser.

    Published: 7 Aug 2012
    5
    Medium

    CVE-2012-4005

    Last Modified: 11 Apr 2025

    The NHN Japan NAVER LINE application before 2.5.5 for Android does not properly handle implicit intents, which allows remote attackers to obtain sensitive message information via a crafted application.

    Published: 7 Aug 2012
    4.3
    Medium

    CVE-2012-2317

    Last Modified: 11 Apr 2025

    The Debian php_crypt_revamped.patch patch for PHP 5.3.x, as used in the php5 package before 5.3.3-7+squeeze4 in Debian GNU/Linux squeeze, the php5 package before 5.3.2-1ubuntu4.17 in Ubuntu 10.04 LTS, and the php5 package before 5.3.5-1ubuntu7.10 in Ubuntu 11.04, does not properly handle an empty salt string, which might allow remote attackers to bypass authentication by leveraging an application that relies on the PHP crypt function to choose a salt for password hashing.

    Published: 7 Aug 2012
    5.6
    Medium

    CVE-2012-3440

    Last Modified: 11 Apr 2025

    A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary files via a symlink attack on the /var/tmp/nsswitch.conf.bak temporary file.

    Published: 7 Aug 2012
    6.8
    Medium

    CVE-2012-3479

    Last Modified: 11 Apr 2025

    lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the enable-local-variables option is set to :safe, which allows user-assisted remote attackers to execute arbitrary Emacs Lisp code via a crafted file.

    Published: 7 Aug 2012
    5
    Medium

    CVE-2012-1348

    Last Modified: 11 Apr 2025

    Cisco Wide Area Application Services (WAAS) appliances with software 4.4, 5.0, and 5.1 include a one-way hash of a password within output text, which might allow remote attackers to obtain sensitive information via a brute-force attack on the hash string, aka Bug ID CSCty17279.

    Published: 6 Aug 2012
    5
    Medium

    CVE-2012-1357

    Last Modified: 11 Apr 2025

    The igmp_snoop_orib_fill_source_update function in the IGMP process in NX-OS 5.0 and 5.1 on Cisco Nexus 5000 series switches allows remote attackers to cause a denial of service (device reload) via IGMP packets, aka Bug ID CSCts46521.

    Published: 6 Aug 2012
    4.3
    Medium

    CVE-2012-1361

    Last Modified: 11 Apr 2025

    Cisco IOS 15.1 and 15.2, when the Multicast Music-on-Hold (MMoH) feature of Cisco Unified Communications Manager (CUCM) is enabled, allows remote attackers to obtain sensitive crosstalk information by listening during a PSTN call, aka Bug ID CSCtx77750.

    Published: 6 Aug 2012
    7.5
    High

    CVE-2012-3448

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Ganglia Web before 3.5.1 allows remote attackers to execute arbitrary PHP code via unknown attack vectors.

    Published: 6 Aug 2012
    3.5
    Low

    CVE-2012-1344

    Last Modified: 11 Apr 2025

    Cisco IOS 15.1 and 15.2, when a clientless SSL VPN is configured, allows remote authenticated users to cause a denial of service (device reload) by using a web browser to refresh the SSL VPN portal page, as demonstrated by the Android browser, aka Bug ID CSCtr86328.

    Published: 6 Aug 2012
    5
    Medium

    CVE-2012-1346

    Last Modified: 11 Apr 2025

    Cisco Emergency Responder 8.6 and 9.2 allows remote attackers to cause a denial of service (CPU consumption) by sending malformed UDP packets to the CERPT port, aka Bug ID CSCtx38369.

    Published: 6 Aug 2012
    7.8
    High

    CVE-2012-1350

    Last Modified: 11 Apr 2025

    Cisco IOS 12.3 and 12.4 on Aironet access points allows remote attackers to cause a denial of service (radio-interface input-queue hang) via IAPP 0x3281 packets, aka Bug ID CSCtc12426.

    Published: 6 Aug 2012
    6.3
    Medium

    CVE-2012-1338

    Last Modified: 11 Apr 2025

    Cisco IOS 15.0 and 15.1 on Catalyst 3560 and 3750 series switches allows remote authenticated users to cause a denial of service (device reload) by completing local web authentication quickly, aka Bug ID CSCts88664.

    Published: 6 Aug 2012
    5
    Medium

    CVE-2012-1339

    Last Modified: 11 Apr 2025

    The Fabric Interconnect component in Cisco Unified Computing System (UCS) 2.0 allows remote attackers to cause a denial of service (process crash) via an attempted SSH session, aka Bug ID CSCtt94543.

    Published: 6 Aug 2012
    5
    Medium

    CVE-2012-1340

    Last Modified: 11 Apr 2025

    The Fibre Channel over IP (FCIP) implementation in Cisco MDS NX-OS 4.2 and 5.2 on MDS 9000 series switches allows remote attackers to cause a denial of service (module reload) via a crafted FCIP header, aka Bug ID CSCtn93151.

    Published: 6 Aug 2012
    5.8
    Medium

    CVE-2012-1342

    Last Modified: 11 Apr 2025

    Cisco Carrier Routing System (CRS) 3.9, 4.0, and 4.1 allows remote attackers to bypass ACL entries via fragmented packets, aka Bug ID CSCtj10975.

    Published: 6 Aug 2012
    7.8
    High

    CVE-2012-2472

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 and 8.4, when SIP inspection is enabled, create many identical pre-allocated secondary pinholes, which might allow remote attackers to cause a denial of service (CPU consumption) via crafted SIP traffic, aka Bug ID CSCtz63143.

    Published: 6 Aug 2012
    5
    Medium

    CVE-2012-2490

    Last Modified: 11 Apr 2025

    Cisco IP Communicator 8.6 allows man-in-the-middle attackers to modify the Certificate Trust List via unspecified vectors, aka Bug ID CSCtz01471.

    Published: 6 Aug 2012
    4
    Medium

    CVE-2012-2500

    Last Modified: 11 Apr 2025

    Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 does not verify the certificate name in an X.509 certificate during WebLaunch of IPsec, which allows man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz29470.

    Published: 6 Aug 2012
    7.8
    High

    CVE-2012-2469

    Last Modified: 11 Apr 2025

    Cisco NX-OS 4.2, 5.0, 5.1, and 5.2 on Nexus 7000 series switches, when the High Availability (HA) policy is configured for Reset, allows remote attackers to cause a denial of service (device reset) via a malformed Cisco Discovery Protocol (CDP) packet, aka Bug IDs CSCtk34535 and CSCtk19132.

    Published: 6 Aug 2012
    5.8
    Medium

    CVE-2012-2499

    Last Modified: 11 Apr 2025

    The IPsec implementation in Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 does not verify the certificate name in an X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz26985.

    Published: 6 Aug 2012
    4
    Medium

    CVE-2012-2474

    Last Modified: 11 Apr 2025

    Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.4 allows remote authenticated users to cause a denial of service (memory consumption and blank response page) by using the clientless WebVPN feature, aka Bug ID CSCth34278.

    Published: 6 Aug 2012
    4
    Medium

    CVE-2012-2498

    Last Modified: 11 Apr 2025

    Cisco AnyConnect Secure Mobility Client 3.0 through 3.0.08066 does not ensure that authentication makes use of a legitimate certificate, which allows user-assisted man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz29197.

    Published: 6 Aug 2012
    5
    Medium

    CVE-2010-5140

    Last Modified: 11 Apr 2025

    wxBitcoin and bitcoind before 0.3.13 do not properly handle bitcoins associated with Bitcoin transactions that have zero confirmations, which allows remote attackers to cause a denial of service (invalid-transaction flood) by sending low-valued transactions without transaction fees.

    Published: 6 Aug 2012
    7.5
    High

    CVE-2010-5141

    Last Modified: 11 Apr 2025

    wxBitcoin and bitcoind before 0.3.5 do not properly handle script opcodes in Bitcoin transactions, which allows remote attackers to spend bitcoins owned by other users via unspecified vectors.

    Published: 6 Aug 2012
    4.3
    Medium

    CVE-2011-4447

    Last Modified: 11 Apr 2025

    The "encrypt wallet" feature in wxBitcoin and bitcoind 0.4.x before 0.4.1, and 0.5.0rc, does not properly interact with the deletion functionality of BSDDB, which allows context-dependent attackers to obtain unencrypted private keys from Bitcoin wallet files by bypassing the BSDDB interface and reading entries that are marked for deletion.

    Published: 6 Aug 2012
    5
    Medium

    CVE-2012-1909

    Last Modified: 11 Apr 2025

    The Bitcoin protocol, as used in bitcoind before 0.4.4, wxBitcoin, Bitcoin-Qt, and other programs, does not properly handle multiple transactions with the same identifier, which allows remote attackers to cause a denial of service (unspendable transaction) by leveraging the ability to create a duplicate coinbase transaction.

    Published: 6 Aug 2012