CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2011-4587

    Last Modified: 11 Apr 2025

    lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.

    Published: 20 Jul 2012
    4
    Medium

    CVE-2011-4590

    Last Modified: 11 Apr 2025

    The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.

    Published: 20 Jul 2012
    4.3
    Medium

    CVE-2011-4591

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the print_object function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors involving object states.

    Published: 20 Jul 2012
    5
    Medium

    CVE-2011-4592

    Last Modified: 11 Apr 2025

    The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might allow remote attackers to bypass intended IP address restrictions by leveraging a configuration in which IP blocking was disabled to restore cron functionality.

    Published: 20 Jul 2012
    4
    Medium

    CVE-2011-4593

    Last Modified: 11 Apr 2025

    Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle user/action_redir group messages, which allows remote authenticated users to discover e-mail addresses by visiting the messaging interface.

    Published: 20 Jul 2012
    8.5
    High

    CVE-2012-3008

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in OSIsoft PI OPC DA Interface before 2.3.20.9 allows remote authenticated users to execute arbitrary code by sending packet data during the processing of messages associated with OPC items.

    Published: 20 Jul 2012
    5.5
    Medium

    CVE-2011-4589

    Last Modified: 11 Apr 2025

    backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID numbers via a restore action.

    Published: 20 Jul 2012
    4.3
    Medium

    CVE-2012-2955

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allow remote attackers to inject arbitrary web script or HTML via the query string.

    Published: 20 Jul 2012
    5
    Medium

    CVE-2011-4588

    Last Modified: 11 Apr 2025

    The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request.

    Published: 20 Jul 2012
    4.9
    Medium

    CVE-2012-6647

    Last Modified: 12 Apr 2025

    The futex_wait_requeue_pi function in kernel/futex.c in the Linux kernel before 3.5.1 does not ensure that calls have two different futex addresses, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted FUTEX_WAIT_REQUEUE_PI command.

    Published: 20 Jul 2012
    9.3
    Critical

    CVE-2012-0284

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the SetSource method in the Cisco Linksys PlayerPT ActiveX control 1.0.0.15 in PlayerPT.ocx on the Cisco WVC200 Wireless-G PTZ Internet video camera allows remote attackers to execute arbitrary code via a long URL in the first argument (aka the sURL argument).

    Published: 19 Jul 2012
    10
    Critical

    CVE-2012-2974

    Last Modified: 11 Apr 2025

    The web interface on the SMC SMC8024L2 switch allows remote attackers to bypass authentication and obtain administrative access via a direct request to a .html file under (1) status/, (2) system/, (3) ports/, (4) trunks/, (5) vlans/, (6) qos/, (7) rstp/, (8) dot1x/, (9) security/, (10) igmps/, or (11) snmp/.

    Published: 19 Jul 2012
    5
    Medium

    CVE-2012-3365

    Last Modified: 11 Apr 2025

    The SQLite functionality in PHP before 5.3.15 allows remote attackers to bypass the open_basedir protection mechanism via unspecified vectors.

    Published: 19 Jul 2012
    5.5
    Medium

    CVE-2012-3367

    Last Modified: 11 Apr 2025

    Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System does not properly check certificate revocation requests made through the web interface, which allows remote attackers with permissions to revoke end entity certificates to revoke the Certificate Authority (CA) certificate.

    Published: 19 Jul 2012
    4.3
    Medium

    CVE-2012-3431

    Last Modified: 11 Apr 2025

    The Teiid Java Database Connectivity (JDBC) socket, as used in JBoss Enterprise Data Services Platform before 5.3.0, does not encrypt login messages by default contrary to documentation and specification, which allows remote attackers to obtain login credentials via a man-in-the-middle (MITM) attack.

    Published: 19 Jul 2012
    4.3
    Medium

    CVE-2012-2662

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to the (1) System Agent or (2) End Entity pages.

    Published: 19 Jul 2012
    3.7
    Low

    CVE-2012-0787

    Last Modified: 11 Apr 2025

    The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and EXDEV or EBUSY is returned by the rename function, allows local users to overwrite arbitrary files and obtain sensitive information via a bind mount on the (1) .augsave or (2) destination file when using the backup save option, or (3) .augnew file when using the newfile save option.

    Published: 19 Jul 2012
    10
    Critical

    CVE-2012-2688

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

    Published: 19 Jul 2012
    7.5
    High

    CVE-2012-2303

    Last Modified: 11 Apr 2025

    The Spaces module 6.x-3.x before 6.x-3.4 for Drupal does not enforce permissions on non-object pages, which allows remote attackers to obtain sensitive information and possibly have other impacts via unspecified vectors to the (1) Spaces or (2) Spaces OG module.

    Published: 18 Jul 2012
    10
    Critical

    CVE-2012-4033

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the Zingiri Web Shop plugin before 2.4.0 for WordPress have unknown impact and attack vectors.

    Published: 18 Jul 2012
    6.8
    Medium

    CVE-2012-4025

    Last Modified: 11 Apr 2025

    Integer overflow in the queue_init function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted block_log field in the superblock of a .sqsh file, leading to a heap-based buffer overflow.

    Published: 18 Jul 2012
    6.8
    Medium

    CVE-2012-3401

    Last Modified: 11 Apr 2025

    The t2p_read_tiff_init function in tiff2pdf (tools/tiff2pdf.c) in LibTIFF 4.0.2 and earlier does not properly initialize the T2P context struct pointer in certain error conditions, which allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image that triggers a heap-based buffer overflow.

    Published: 18 Jul 2012
    6.8
    Medium

    CVE-2012-4024

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the get_component function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to execute arbitrary code via a crafted list file (aka a crafted file for the -ef option). NOTE: probably in most cases, the list file is a trusted file constructed by the program's user; however, there are some realistic situations in which a list file would be obtained from an untrusted remote source.

    Published: 18 Jul 2012
    4.3
    Medium

    CVE-2012-1760

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect availability via unknown vectors related to UI Framework, a different vulnerability than CVE-2012-1742.

    Published: 17 Jul 2012
    4.3
    Medium

    CVE-2012-1761

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect integrity via unknown vectors related to UI Framework.

    Published: 17 Jul 2012
    3.5
    Low

    CVE-2012-1762

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect integrity, related to TECH, a different vulnerability than CVE-2012-3111.

    Published: 17 Jul 2012
    3.5
    Low

    CVE-2012-1764

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect integrity, related to MCF.

    Published: 17 Jul 2012
    4.7
    Medium

    CVE-2012-1765

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect integrity via unknown vectors related to Branded Zone.

    Published: 17 Jul 2012
    2.1
    Low

    CVE-2012-1768

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-3109.

    Published: 17 Jul 2012
    2.1
    Low

    CVE-2012-1770

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-1766, CVE-2012-1767, CVE-2012-1769, CVE-2012-1771, CVE-2012-1772, CVE-2012-1773, CVE-2012-3106, CVE-2012-3107, CVE-2012-3108, and CVE-2012-3110.

    Published: 17 Jul 2012
    2.1
    Low

    CVE-2012-1771

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-1766, CVE-2012-1767, CVE-2012-1769, CVE-2012-1770, CVE-2012-1772, CVE-2012-1773, CVE-2012-3106, CVE-2012-3107, CVE-2012-3108, and CVE-2012-3110.

    Published: 17 Jul 2012
    2.1
    Low

    CVE-2012-3108

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-1766, CVE-2012-1767, CVE-2012-1769, CVE-2012-1770, CVE-2012-1771, CVE-2012-1772, CVE-2012-1773, CVE-2012-3106, CVE-2012-3107, and CVE-2012-3110.

    Published: 17 Jul 2012
    2.1
    Low

    CVE-2012-3109

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-1768.

    Published: 17 Jul 2012
    3.5
    Low

    CVE-2012-3111

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect integrity, related to TECH, a different vulnerability than CVE-2012-1762.

    Published: 17 Jul 2012
    4.3
    Medium

    CVE-2012-3112

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect integrity via unknown vectors related to Solaris Management Console.

    Published: 17 Jul 2012
    5.5
    Medium

    CVE-2012-3113

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.0.20 allows remote authenticated users to affect confidentiality and integrity, related to EPERF.

    Published: 17 Jul 2012
    4.3
    Medium

    CVE-2012-3114

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 5.5.06, 6.0, 6.1, and 6.2 allows remote attackers to affect integrity via unknown vectors.

    Published: 17 Jul 2012
    4.3
    Medium

    CVE-2012-3115

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle MapViewer component in Oracle Fusion Middleware 10.1.3.1, 11.1.1.5, and 11.1.1.6 allows remote attackers to affect integrity via unknown vectors related to Install.

    Published: 17 Jul 2012
    1.9
    Low

    CVE-2012-3116

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 5.5.06, 6.0, 6.1, and 6.2 allows local users to affect confidentiality via unknown vectors.

    Published: 17 Jul 2012
    4
    Medium

    CVE-2012-3117

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 5.5.06, 6.0, 6.1, and 6.2 allows remote authenticated users to affect confidentiality via unknown vectors related to HTTP.

    Published: 17 Jul 2012
    7.8
    High

    CVE-2012-3120

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 8 allows remote attackers to affect availability, related to TCP/IP.

    Published: 17 Jul 2012
    5
    Medium

    CVE-2012-3121

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 9 and 10 allows remote attackers to affect availability via unknown vectors related to in.tnamed and NameServer.

    Published: 17 Jul 2012
    2.6
    Low

    CVE-2012-3122

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 8 and 9 allows local users to affect confidentiality and integrity via unknown vectors related to sort.

    Published: 17 Jul 2012
    5
    Medium

    CVE-2012-3123

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality, related to Apache HTTP Server.

    Published: 17 Jul 2012
    5
    Medium

    CVE-2012-3124

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect availability, related to Kernel/KSSL.

    Published: 17 Jul 2012
    7.1
    High

    CVE-2012-3125

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 8, 9, and 10 allows remote attackers to affect availability, related to TCP/IP.

    Published: 17 Jul 2012
    6.2
    Medium

    CVE-2012-3126

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Products Suite 3.3 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Apache Tomcat Agent.

    Published: 17 Jul 2012
    5.1
    Medium

    CVE-2012-3129

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality, integrity, and availability, related to Gnome PDF viewer.

    Published: 17 Jul 2012
    4.3
    Medium

    CVE-2012-3130

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect integrity via unknown vectors related to pkg.depotd.

    Published: 17 Jul 2012
    4.3
    Medium

    CVE-2012-3131

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 9, 10, and 11 allows remote attackers to affect confidentiality, related to Network/NFS.

    Published: 17 Jul 2012