CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2012-1910

    Last Modified: 11 Apr 2025

    Bitcoin-Qt 0.5.0.x before 0.5.0.5; 0.5.1.x, 0.5.2.x, and 0.5.3.x before 0.5.3.1; and 0.6.x before 0.6.0rc4 on Windows does not use MinGW multithread-safe exception handling, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted Bitcoin protocol messages.

    Published: 6 Aug 2012
    7.2
    High

    CVE-2012-2188

    Last Modified: 11 Apr 2025

    IBM Power Hardware Management Console (HMC) 7R3.5.0 before SP4, 7R7.1.0 and 7R7.2.0 before 7R7.2.0 SP3, and 7R7.3.0 before SP2, and Systems Director Management Console (SDMC) 6R7.3.0 before SP2, does not properly restrict the VIOS viosrvcmd command, which allows local users to gain privileges via vectors involving a (1) $ (dollar sign) or (2) & (ampersand) character.

    Published: 6 Aug 2012
    5
    Medium

    CVE-2012-2459

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in bitcoind and Bitcoin-Qt before 0.4.6, 0.5.x before 0.5.5, 0.6.0.x before 0.6.0.7, and 0.6.x before 0.6.2 allows remote attackers to cause a denial of service (block-processing outage and incorrect block count) via unknown behavior on a Bitcoin network.

    Published: 6 Aug 2012
    2.1
    Low

    CVE-2012-3866

    Last Modified: 11 Apr 2025

    lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for last_run_report.yaml, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master server to read this file.

    Published: 6 Aug 2012
    10
    Critical

    CVE-2012-4145

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, has unknown impact and attack vectors, related to a "low severity issue."

    Published: 6 Aug 2012
    4.3
    Medium

    CVE-2012-4146

    Last Modified: 11 Apr 2025

    Opera before 12.01 allows remote attackers to cause a denial of service (application crash) via a crafted web site, as demonstrated by the Lenovo "Shop now" page.

    Published: 6 Aug 2012
    5
    Medium

    CVE-2010-5137

    Last Modified: 11 Apr 2025

    wxBitcoin and bitcoind before 0.3.5 allow remote attackers to cause a denial of service (daemon crash) via a Bitcoin transaction containing an OP_LSHIFT script opcode.

    Published: 6 Aug 2012
    7.5
    High

    CVE-2010-5139

    Last Modified: 11 Apr 2025

    Integer overflow in wxBitcoin and bitcoind before 0.3.11 allows remote attackers to bypass intended economic restrictions and create many bitcoins via a crafted Bitcoin transaction.

    Published: 6 Aug 2012
    7.5
    High

    CVE-2012-3020

    Last Modified: 11 Apr 2025

    The Siemens Synco OZW Web Server devices OZW672.*, OZW772.*, and OZW775 with firmware before 4 have an unspecified default password, which makes it easier for remote attackers to obtain administrative access via a network session.

    Published: 6 Aug 2012
    5
    Medium

    CVE-2012-3789

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in bitcoind and Bitcoin-Qt before 0.4.7rc3, 0.5.x before 0.5.6rc3, 0.6.0.x before 0.6.0.9rc1, and 0.6.x before 0.6.3rc1 allows remote attackers to cause a denial of service (process hang) via unknown behavior on a Bitcoin network.

    Published: 6 Aug 2012
    6.8
    Medium

    CVE-2012-4143

    Last Modified: 11 Apr 2025

    Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, allows user-assisted remote attackers to trick users into downloading and executing arbitrary files via a small window for the download dialog, a different vulnerability than CVE-2012-1924.

    Published: 6 Aug 2012
    5
    Medium

    CVE-2010-5138

    Last Modified: 11 Apr 2025

    wxBitcoin and bitcoind 0.3.x allow remote attackers to cause a denial of service (electricity consumption) via a Bitcoin transaction containing multiple OP_CHECKSIG script opcodes.

    Published: 6 Aug 2012
    4.3
    Medium

    CVE-2012-4142

    Last Modified: 11 Apr 2025

    Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, ignores some characters in HTML documents in unspecified circumstances, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document.

    Published: 6 Aug 2012
    4.3
    Medium

    CVE-2012-4144

    Last Modified: 11 Apr 2025

    Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, does not properly escape characters in DOM elements, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted HTML document.

    Published: 6 Aug 2012
    4
    Medium

    CVE-2012-1364

    Last Modified: 11 Apr 2025

    Cisco Unified Computing System (UCS) 1.4 and 2.0 allows remote authenticated users to cause a denial of service (device reload) via a malformed SNMP request to a Fabric Interconnect (FI) device, aka Bug ID CSCts32452.

    Published: 6 Aug 2012
    4
    Medium

    CVE-2012-1365

    Last Modified: 11 Apr 2025

    Cisco Unified Computing System (UCS) 1.4 and 2.0 allows remote authenticated users to cause a denial of service (device reload) via a malformed SNMP request to a Fabric Interconnect (FI) device, aka Bug ID CSCts32463.

    Published: 6 Aug 2012
    3.5
    Low

    CVE-2012-1370

    Last Modified: 11 Apr 2025

    Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 allows remote authenticated users to cause a denial of service (vpnagentd process crash) via a crafted packet, aka Bug ID CSCty01670.

    Published: 6 Aug 2012
    5
    Medium

    CVE-2012-2846

    Last Modified: 11 Apr 2025

    Google Chrome before 21.0.1180.57 on Linux does not properly isolate renderer processes, which allows remote attackers to cause a denial of service (cross-process interference) via unspecified vectors.

    Published: 6 Aug 2012
    6.8
    Medium

    CVE-2012-2852

    Last Modified: 11 Apr 2025

    The PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, does not properly handle object linkage, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted document.

    Published: 6 Aug 2012
    6.8
    Medium

    CVE-2012-2855

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.

    Published: 6 Aug 2012
    7.5
    High

    CVE-2012-2856

    Last Modified: 11 Apr 2025

    The PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger out-of-bounds write operations.

    Published: 6 Aug 2012
    6.8
    Medium

    CVE-2012-2857

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the Cascading Style Sheets (CSS) DOM implementation in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.

    Published: 6 Aug 2012
    6.8
    Medium

    CVE-2012-2858

    Last Modified: 11 Apr 2025

    Buffer overflow in the WebP decoder in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted WebP image.

    Published: 6 Aug 2012
    6.8
    Medium

    CVE-2012-2860

    Last Modified: 11 Apr 2025

    The date-picker implementation in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site.

    Published: 6 Aug 2012
    5
    Medium

    CVE-2012-1367

    Last Modified: 11 Apr 2025

    The MallocLite implementation in Cisco IOS 12.0, 12.2, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (Route Processor crash) via a BGP UPDATE message with a modified local-preference (aka LOCAL_PREF) attribute length, aka Bug ID CSCtq06538.

    Published: 6 Aug 2012
    4.3
    Medium

    CVE-2012-2847

    Last Modified: 11 Apr 2025

    Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, does not request user confirmation before continuing a large series of downloads, which allows user-assisted remote attackers to cause a denial of service (resource consumption) via a crafted web site.

    Published: 6 Aug 2012
    4.3
    Medium

    CVE-2012-2848

    Last Modified: 11 Apr 2025

    The drag-and-drop implementation in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows user-assisted remote attackers to bypass intended file access restrictions via a crafted web site.

    Published: 6 Aug 2012
    6.8
    Medium

    CVE-2012-2850

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allow remote attackers to have an unknown impact via a crafted document.

    Published: 6 Aug 2012
    6.8
    Medium

    CVE-2012-2851

    Last Modified: 11 Apr 2025

    Multiple integer overflows in the PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.

    Published: 6 Aug 2012
    5
    Medium

    CVE-2012-2854

    Last Modified: 11 Apr 2025

    Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to obtain potentially sensitive information about pointer values by leveraging access to a WebUI renderer process.

    Published: 6 Aug 2012
    4.3
    Medium

    CVE-2012-2849

    Last Modified: 11 Apr 2025

    Off-by-one error in the GIF decoder in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image.

    Published: 6 Aug 2012
    6.8
    Medium

    CVE-2012-2853

    Last Modified: 11 Apr 2025

    The webRequest API in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, does not properly interact with the Chrome Web Store, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site.

    Published: 6 Aug 2012
    7.5
    High

    CVE-2012-2859

    Last Modified: 11 Apr 2025

    Google Chrome before 21.0.1180.57 on Linux does not properly handle tabs, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.

    Published: 6 Aug 2012
    4.4
    Medium

    CVE-2012-3466

    Last Modified: 11 Apr 2025

    GNOME gnome-keyring 3.4.0 through 3.4.1, when gpg-cache-method is set to "idle" or "timeout," does not properly limit the amount of time a passphrase is cached, which allows attackers to have an unspecified impact via unknown attack vectors.

    Published: 2 Aug 2012
    5.5
    Medium

    CVE-2012-6136

    Last Modified: 21 Nov 2024

    tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.

    Published: 2 Aug 2012
    5
    Medium

    CVE-2012-3429

    Last Modified: 11 Apr 2025

    The dns_to_ldap_dn_escape function in src/ldap_convert.c in bind-dyndb-ldap 1.1.0rc1 and earlier does not properly escape distinguished names (DN) for LDAP queries, which allows remote DNS servers to cause a denial of service (named service hang) via a "$" character in a DN in a DNS query.

    Published: 1 Aug 2012
    7.5
    High

    CVE-2012-2665

    Last Modified: 11 Apr 2025

    Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a Base64 ChecksumAttribute whose length is not evenly divisible by four.

    Published: 1 Aug 2012
    4
    Medium

    CVE-2012-5517

    Last Modified: 11 Apr 2025

    The online_pages function in mm/memory_hotplug.c in the Linux kernel before 3.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact in opportunistic circumstances by using memory that was hot-added by an administrator.

    Published: 1 Aug 2012
    4.3
    Medium

    CVE-2012-3442

    Last Modified: 16 Apr 2026

    The (1) django.http.HttpResponseRedirect and (2) django.http.HttpResponsePermanentRedirect classes in Django before 1.3.2 and 1.4.x before 1.4.1 do not validate the scheme of a redirect target, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via a data: URL.

    Published: 31 Jul 2012
    5
    Medium

    CVE-2012-3443

    Last Modified: 11 Apr 2025

    The django.forms.ImageField class in the form system in Django before 1.3.2 and 1.4.x before 1.4.1 completely decompresses image data during image validation, which allows remote attackers to cause a denial of service (memory consumption) by uploading an image file.

    Published: 31 Jul 2012
    5
    Medium

    CVE-2012-3444

    Last Modified: 11 Apr 2025

    The get_image_dimensions function in the image-handling functionality in Django before 1.3.2 and 1.4.x before 1.4.1 uses a constant chunk size in all attempts to determine dimensions, which allows remote attackers to cause a denial of service (process or thread consumption) via a large TIFF image.

    Published: 31 Jul 2012
    9.4
    Critical

    CVE-2012-2627

    Last Modified: 11 Apr 2025

    d4d/uploader.php in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allows remote attackers to create or overwrite arbitrary files in %PROGRAMFILES%\Scrutinizer\snmp\mibs\ via a multipart/form-data POST request.

    Published: 31 Jul 2012
    5.8
    Medium

    CVE-2012-2647

    Last Modified: 11 Apr 2025

    Yahoo! Toolbar 1.0.0.5 and earlier for Chrome and Safari allows remote attackers to modify the configured search URL, and intercept search terms, via a crafted web page.

    Published: 31 Jul 2012
    7.8
    High

    CVE-2012-3017

    Last Modified: 11 Apr 2025

    Siemens SIMATIC S7-400 PN CPU devices with firmware 5.x allow remote attackers to cause a denial of service (defect-mode transition and service outage) via (1) malformed HTTP traffic or (2) malformed IP packets.

    Published: 31 Jul 2012
    7.8
    High

    CVE-2012-3016

    Last Modified: 11 Apr 2025

    Siemens SIMATIC S7-400 PN CPU devices with firmware 6 before 6.0.3 allow remote attackers to cause a denial of service (defect-mode transition and service outage) via crafted ICMP packets.

    Published: 31 Jul 2012
    4.9
    Medium

    CVE-2012-3426

    Last Modified: 11 Apr 2025

    OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1) creating new tokens through token chaining, (2) leveraging possession of a token for a disabled user account, or (3) leveraging possession of a token for an account with a changed password.

    Published: 31 Jul 2012
    4.3
    Medium

    CVE-2012-3848

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to d4d/exporters.php, (2) the HTTP Referer header to d4d/exporters.php, or (3) unspecified input to d4d/contextMenu.php.

    Published: 31 Jul 2012
    7.5
    High

    CVE-2012-3951

    Last Modified: 11 Apr 2025

    The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (1) scrutinizer and (2) scrutremote accounts, which allows remote attackers to execute arbitrary SQL commands via a TCP session.

    Published: 31 Jul 2012
    5
    Medium

    CVE-2012-2626

    Last Modified: 11 Apr 2025

    cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authentication, which allows remote attackers to add administrative accounts via a userprefs action.

    Published: 31 Jul 2012
    4.4
    Medium

    CVE-2012-3018

    Last Modified: 11 Apr 2025

    The lockout-recovery feature in the Security Configurator component in ICONICS GENESIS32 9.22 and earlier and BizViz 9.22 and earlier uses an improper encryption algorithm for generation of an authentication code, which allows local users to bypass intended access restrictions and obtain administrative access by predicting a challenge response.

    Published: 31 Jul 2012