CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2012-3682

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.

    Published: 25 Jul 2012
    9.3
    Critical

    CVE-2012-3686

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.

    Published: 25 Jul 2012
    9.3
    Critical

    CVE-2012-0682

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.

    Published: 25 Jul 2012
    9.3
    Critical

    CVE-2012-3610

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.

    Published: 25 Jul 2012
    9.3
    Critical

    CVE-2012-3640

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.

    Published: 25 Jul 2012
    9.3
    Critical

    CVE-2012-3641

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.

    Published: 25 Jul 2012
    9.3
    Critical

    CVE-2012-3669

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.

    Published: 25 Jul 2012
    9.3
    Critical

    CVE-2012-3594

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.

    Published: 25 Jul 2012
    9.3
    Critical

    CVE-2012-3609

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.

    Published: 25 Jul 2012
    9.3
    Critical

    CVE-2012-3629

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.

    Published: 25 Jul 2012
    9.3
    Critical

    CVE-2012-3633

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.

    Published: 25 Jul 2012
    9.3
    Critical

    CVE-2012-3668

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.

    Published: 25 Jul 2012
    9.3
    Critical

    CVE-2012-3683

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.

    Published: 25 Jul 2012
    5
    Medium

    CVE-2005-4895

    Last Modified: 11 Apr 2025

    Multiple integer overflows in TCMalloc (tcmalloc.cc) in gperftools before 0.4 make it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, which causes less memory to be allocated than expected.

    Published: 25 Jul 2012
    5
    Medium

    CVE-2006-7252

    Last Modified: 11 Apr 2025

    Integer overflow in the calloc function in libc/stdlib/malloc.c in jemalloc in libc for FreeBSD 6.4 and NetBSD makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, which triggers a memory allocation of one byte.

    Published: 25 Jul 2012
    4.3
    Medium

    CVE-2012-0678

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Apple Safari before 6.0 allows remote attackers to inject arbitrary web script or HTML via a feed:// URL.

    Published: 25 Jul 2012
    5
    Medium

    CVE-2012-0680

    Last Modified: 11 Apr 2025

    Apple Safari before 6.0 does not properly handle the autocomplete attribute of a password input element, which allows remote attackers to bypass authentication by leveraging an unattended workstation.

    Published: 25 Jul 2012
    4.3
    Medium

    CVE-2012-2675

    Last Modified: 11 Apr 2025

    Multiple integer overflows in the (1) CallMalloc (malloc) and (2) nedpcalloc (calloc) functions in nedmalloc (nedmalloc.c) before 1.10 beta2 make it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, which causes less memory to be allocated than expected.

    Published: 25 Jul 2012
    4.3
    Medium

    CVE-2012-2676

    Last Modified: 11 Apr 2025

    Multiple integer overflows in the (1) malloc and (2) calloc functions in Hoard before 3.9 make it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows on implementing code via a large size value, which causes less memory to be allocated than expected.

    Published: 25 Jul 2012
    2.1
    Low

    CVE-2012-2760

    Last Modified: 11 Apr 2025

    mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local users to obtain session ids.

    Published: 25 Jul 2012
    5.8
    Medium

    CVE-2012-3689

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to bypass the Same Origin Policy via a crafted web site.

    Published: 25 Jul 2012
    4.3
    Medium

    CVE-2012-3690

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to read arbitrary files via a crafted web site.

    Published: 25 Jul 2012
    5
    Medium

    CVE-2012-3693

    Last Modified: 11 Apr 2025

    Incomplete blacklist vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to spoof domain names in URLs, and possibly conduct phishing attacks, by leveraging the availability of IDN support and Unicode fonts to construct unspecified homoglyphs.

    Published: 25 Jul 2012
    4.3
    Medium

    CVE-2012-3694

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to obtain sensitive information about full pathnames via a crafted web site.

    Published: 25 Jul 2012
    4.3
    Medium

    CVE-2012-3696

    Last Modified: 11 Apr 2025

    CRLF injection vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP request splitting attacks via a crafted web site that leverages improper WebSockets URI handling.

    Published: 25 Jul 2012
    7.1
    High

    CVE-2012-3697

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 6.0 does not properly handle file: URLs, which allows remote attackers to bypass intended sandbox restrictions and read arbitrary files by leveraging a WebProcess compromise.

    Published: 25 Jul 2012
    6.8
    Medium

    CVE-2012-4053

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in eZOE flash player in eZ Publish 4.1 through 4.6 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 25 Jul 2012
    5
    Medium

    CVE-2007-6754

    Last Modified: 11 Apr 2025

    The ipalloc function in libc/stdlib/malloc.c in jemalloc in libc for FreeBSD 6.4 and NetBSD does not properly allocate memory, which makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, related to "integer rounding and overflow" errors.

    Published: 25 Jul 2012
    4.3
    Medium

    CVE-2012-3695

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to inject arbitrary web script or HTML by leveraging improper URL canonicalization during the handling of the location.href property.

    Published: 25 Jul 2012
    4.3
    Medium

    CVE-2012-0679

    Last Modified: 11 Apr 2025

    Apple Safari before 6.0 allows remote attackers to read arbitrary files via a feed:// URL.

    Published: 25 Jul 2012
    4.3
    Medium

    CVE-2012-2674

    Last Modified: 11 Apr 2025

    Multiple integer overflows in the (1) chk_malloc, (2) leak_malloc, and (3) leak_memalign functions in libc/bionic/malloc_debug_leak.c in Bionic (libc) for Android, when libc.debug.malloc is set, make it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, which causes less memory to be allocated than expected.

    Published: 25 Jul 2012
    5.8
    Medium

    CVE-2012-3691

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 6.0 does not properly handle Cascading Style Sheets (CSS) property values, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

    Published: 25 Jul 2012
    4.3
    Medium

    CVE-2012-3650

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 6.0 accesses uninitialized memory locations during the rendering of SVG images, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.

    Published: 25 Jul 2012
    5
    Medium

    CVE-2012-2194

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the SQLJ.DB2_INSTALL_JAR stored procedure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote attackers to replace JAR files via unspecified vectors.

    Published: 25 Jul 2012
    5
    Medium

    CVE-2012-2196

    Last Modified: 11 Apr 2025

    IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote attackers to read arbitrary XML files via the (1) GET_WRAP_CFG_C or (2) GET_WRAP_CFG_C2 stored procedure.

    Published: 25 Jul 2012
    7.1
    High

    CVE-2012-2197

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the Java Stored Procedure infrastructure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote authenticated users to execute arbitrary code by leveraging certain CONNECT and EXECUTE privileges.

    Published: 25 Jul 2012
    5
    Medium

    CVE-2012-2646

    Last Modified: 11 Apr 2025

    The Sleipnir Mobile application before 2.1.0 and Sleipnir Mobile Black Edition application before 2.1.0 for Android do not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application.

    Published: 25 Jul 2012
    6.4
    Medium

    CVE-2015-0250

    Last Modified: 12 Apr 2025

    XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.

    Published: 25 Jul 2012
    10
    Critical

    CVE-2012-4050

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome OS before 21.0.1180.50 on the Cr-48 and Samsung Series 5 and 5 550 Chromebook platforms, and the Samsung Chromebox Series 3, have unknown impact and attack vectors.

    Published: 24 Jul 2012
    5.7
    Medium

    CVE-2012-3570

    Last Modified: 11 Apr 2025

    Buffer overflow in ISC DHCP 4.2.x before 4.2.4-P1, when DHCPv6 mode is enabled, allows remote attackers to cause a denial of service (segmentation fault and daemon exit) via a crafted client identifier parameter.

    Published: 24 Jul 2012
    3.6
    Low

    CVE-2012-1699

    Last Modified: 11 Apr 2025

    The ProcSetEventMask function in difs/events.c in the xfs font server for X.Org X11R6 through X11R6.6 and XFree86 before 3.3.3 calls the SendErrToClient function with a mask value instead of a pointer, which allows local users to cause a denial of service (memory corruption and crash) or obtain potentially sensitive information from memory via a SetEventMask request that triggers an invalid pointer dereference.

    Published: 24 Jul 2012
    6.1
    Medium

    CVE-2012-3571

    Last Modified: 11 Apr 2025

    ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed client identifier.

    Published: 24 Jul 2012
    7.8
    High

    CVE-2012-3817

    Last Modified: 11 Apr 2025

    ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.

    Published: 24 Jul 2012
    4.3
    Medium

    CVE-2012-3868

    Last Modified: 11 Apr 2025

    Race condition in the ns_client structure management in ISC BIND 9.9.x before 9.9.1-P2 allows remote attackers to cause a denial of service (memory consumption or process exit) via a large volume of TCP queries.

    Published: 24 Jul 2012
    3.3
    Low

    CVE-2012-3954

    Last Modified: 11 Apr 2025

    Multiple memory leaks in ISC DHCP 4.1.x and 4.2.x before 4.2.4-P1 and 4.1-ESV before 4.1-ESV-R6 allow remote attackers to cause a denial of service (memory consumption) by sending many requests.

    Published: 24 Jul 2012
    5
    Medium

    CVE-2012-4423

    Last Modified: 11 Apr 2025

    The virNetServerProgramDispatchCall function in libvirt before 0.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and segmentation fault) via an RPC call with (1) an event as the RPC number or (2) an RPC number whose value is in a "gap" in the RPC dispatch table.

    Published: 24 Jul 2012
    4
    Medium

    CVE-2012-3387

    Last Modified: 11 Apr 2025

    Moodle 2.3.x before 2.3.1 uses only a client-side check for whether references are permitted in a file upload, which allows remote authenticated users to bypass intended alias (aka shortcut) restrictions via a client that omits this check.

    Published: 23 Jul 2012
    4
    Medium

    CVE-2012-3388

    Last Modified: 11 Apr 2025

    The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified vectors that trigger caching of a user record.

    Published: 23 Jul 2012
    4.3
    Medium

    CVE-2012-3389

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typessettings.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) lti_typename or (2) lti_toolurl parameter.

    Published: 23 Jul 2012
    3.5
    Low

    CVE-2012-3390

    Last Modified: 11 Apr 2025

    lib/filelib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly restrict file access after a block has been hidden, which allows remote authenticated users to obtain sensitive information by reading a file that is embedded in a block.

    Published: 23 Jul 2012