CVE Feed

    Dashboard / CVE

    4.4
    Medium

    CVE-2012-1750

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to mailx.

    Published: 17 Jul 2012
    7.5
    High

    CVE-2012-3241

    Last Modified: 11 Apr 2025

    The VMware Broker in Eucalyptus 2.0.3 and 3.0.x before 3.0.2 does not properly authenticate SOAP requests, which allows remote attackers to execute arbitrary VMware Broker API commands.

    Published: 17 Jul 2012
    6.8
    Medium

    CVE-2012-0276

    Last Modified: 11 Apr 2025

    Multiple heap-based buffer overflows in XnView before 1.99 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a (1) SGI32LogLum compressed TIFF image or (2) SGI32LogLum compressed TIFF image with the PhotometricInterpretation encoding set to LogL.

    Published: 17 Jul 2012
    6.8
    Medium

    CVE-2012-0282

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ImageLeftPosition value in an ImageDescriptor structure in a GIF image.

    Published: 17 Jul 2012
    7.5
    High

    CVE-2012-3240

    Last Modified: 11 Apr 2025

    The Walrus service in Eucalyptus 2.0.3 and 3.0.x before 3.0.2 allows remote attackers to gain administrator privileges via a crafted REST request.

    Published: 17 Jul 2012
    5
    Medium

    CVE-2012-4031

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in src/acloglogin.php in Wangkongbao CNS-1000 and 1100 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) lang or (2) langid cookie to port 85.

    Published: 17 Jul 2012
    5.8
    Medium

    CVE-2012-4032

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in the login page in WebsitePanel before 1.2.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in ReturnUrl to Default.aspx.

    Published: 17 Jul 2012
    6.8
    Medium

    CVE-2012-0277

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PCT image.

    Published: 17 Jul 2012
    3.5
    Low

    CVE-2012-3371

    Last Modified: 11 Apr 2025

    The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when DifferentHostFilter or SameHostFilter is enabled, allows remote authenticated users to cause a denial of service (excessive database lookup calls and server hang) via a request with many repeated IDs in the os:scheduler_hints section.

    Published: 17 Jul 2012
    4
    Medium

    CVE-2012-0792

    Last Modified: 11 Apr 2025

    mod/forum/user.php in Moodle 1.9.x before 1.9.16 allows remote authenticated users to obtain the names and other details of arbitrary user accounts by searching for posts.

    Published: 17 Jul 2012
    5
    Medium

    CVE-2012-0793

    Last Modified: 11 Apr 2025

    Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote attackers to view the profile images of arbitrary user accounts via unspecified vectors.

    Published: 17 Jul 2012
    5
    Medium

    CVE-2012-0794

    Last Modified: 11 Apr 2025

    The rc4encrypt function in lib/moodlelib.php in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 uses a hardcoded password of nfgjeingjk, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by reading this script's source code within the open-source software distribution.

    Published: 17 Jul 2012
    6.5
    Medium

    CVE-2012-0795

    Last Modified: 11 Apr 2025

    Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 does not validate e-mail address settings, which allows remote authenticated users to have an unspecified impact via a crafted address.

    Published: 17 Jul 2012
    5.5
    Medium

    CVE-2012-0797

    Last Modified: 11 Apr 2025

    The webservices functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote authenticated users to bypass the deleted status and continue using a server via a token.

    Published: 17 Jul 2012
    5.5
    Medium

    CVE-2012-0798

    Last Modified: 11 Apr 2025

    The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by leveraging the teacher role.

    Published: 17 Jul 2012
    4.3
    Medium

    CVE-2012-0799

    Last Modified: 11 Apr 2025

    Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous front-page forum is enabled, allows remote attackers to obtain session keys for their sessions by visiting the front page.

    Published: 17 Jul 2012
    2.1
    Low

    CVE-2012-0800

    Last Modified: 11 Apr 2025

    The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 makes it easier for physically proximate attackers to discover passwords by reading the contents of a non-password field, as demonstrated by accessing a create-groups page with Safari on an iPad device.

    Published: 17 Jul 2012
    7.5
    High

    CVE-2012-0801

    Last Modified: 11 Apr 2025

    lib/formslib.php in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 does not properly handle multiple instances of a form element, which has unspecified impact and remote attack vectors.

    Published: 17 Jul 2012
    4
    Medium

    CVE-2012-0796

    Last Modified: 11 Apr 2025

    class.phpmailer.php in the PHPMailer library, as used in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 and other products, allows remote authenticated users to inject arbitrary e-mail headers via vectors involving a crafted (1) From: or (2) Sender: header.

    Published: 17 Jul 2012
    9.3
    Critical

    CVE-2012-1948

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 17 Jul 2012
    6.4
    Medium

    CVE-2012-1950

    Last Modified: 11 Apr 2025

    The drag-and-drop implementation in Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 allows remote attackers to spoof the address bar by canceling a page load.

    Published: 17 Jul 2012
    10
    Critical

    CVE-2012-1954

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the nsDocument::AdoptNode function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code via vectors involving multiple adoptions and empty documents.

    Published: 17 Jul 2012
    9.3
    Critical

    CVE-2012-1958

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the nsGlobalWindow::PageHidden function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 might allow remote attackers to execute arbitrary code via vectors related to focused content.

    Published: 17 Jul 2012
    5
    Medium

    CVE-2012-1959

    Last Modified: 11 Apr 2025

    Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 do not consider the presence of same-compartment security wrappers (SCSW) during the cross-compartment wrapping of objects, which allows remote attackers to bypass intended XBL access restrictions via crafted content.

    Published: 17 Jul 2012
    5
    Medium

    CVE-2012-1960

    Last Modified: 11 Apr 2025

    The qcms_transform_data_rgb_out_lut_sse2 function in the QCMS implementation in Mozilla Firefox 4.x through 13.0, Thunderbird 5.0 through 13.0, and SeaMonkey before 2.11 might allow remote attackers to obtain sensitive information from process memory via a crafted color profile that triggers an out-of-bounds read operation.

    Published: 17 Jul 2012
    4
    Medium

    CVE-2012-1964

    Last Modified: 11 Apr 2025

    The certificate-warning functionality in browser/components/certerror/content/aboutCertError.xhtml in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.10 does not properly handle attempted clickjacking of the about:certerror page, which allows man-in-the-middle attackers to trick users into adding an unintended exception via an IFRAME element.

    Published: 17 Jul 2012
    9.3
    Critical

    CVE-2012-1952

    Last Modified: 11 Apr 2025

    The nsTableFrame::InsertFrames function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 does not properly perform a cast of a frame variable during processing of mixed row-group and column-group frames, which might allow remote attackers to execute arbitrary code via a crafted web site.

    Published: 17 Jul 2012
    9.3
    Critical

    CVE-2012-1953

    Last Modified: 11 Apr 2025

    The ElementAnimations::EnsureStyleRuleFor function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allows remote attackers to cause a denial of service (buffer over-read, incorrect pointer dereference, and heap-based buffer overflow) or possibly execute arbitrary code via a crafted web site.

    Published: 17 Jul 2012
    10
    Critical

    CVE-2012-1962

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the JSDependentString::undepend function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via vectors involving strings with multiple dependencies.

    Published: 17 Jul 2012
    4.3
    Medium

    CVE-2012-1963

    Last Modified: 11 Apr 2025

    The Content Security Policy (CSP) functionality in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 does not properly restrict the strings placed into the blocked-uri parameter of a violation report, which allows remote web servers to capture OpenID credentials and OAuth 2.0 access tokens by triggering a violation.

    Published: 17 Jul 2012
    4.3
    Medium

    CVE-2012-1966

    Last Modified: 11 Apr 2025

    Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do not have the same context-menu restrictions for data: URLs as for javascript: URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.

    Published: 17 Jul 2012
    9.3
    Critical

    CVE-2012-1949

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 13.0, Thunderbird 5.0 through 13.0, and SeaMonkey before 2.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 17 Jul 2012
    10
    Critical

    CVE-2012-1951

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the nsSMILTimeValueSpec::IsEventBased function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code by interacting with objects used for SMIL Timing.

    Published: 17 Jul 2012
    6.8
    Medium

    CVE-2012-1955

    Last Modified: 11 Apr 2025

    Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allow remote attackers to spoof the address bar via vectors involving history.forward and history.back calls.

    Published: 17 Jul 2012
    4.3
    Medium

    CVE-2012-1957

    Last Modified: 11 Apr 2025

    An unspecified parser-utility class in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 does not properly handle EMBED elements within description elements in RSS feeds, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a feed.

    Published: 17 Jul 2012
    4.3
    Medium

    CVE-2012-1961

    Last Modified: 11 Apr 2025

    Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 do not properly handle duplicate values in X-Frame-Options headers, which makes it easier for remote attackers to conduct clickjacking attacks via a FRAME element referencing a web site that produces these duplicate values.

    Published: 17 Jul 2012
    4.3
    Medium

    CVE-2012-1965

    Last Modified: 11 Apr 2025

    Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do not properly establish the security context of a feed: URL, which allows remote attackers to bypass unspecified cross-site scripting (XSS) protection mechanisms via a feed:javascript: URL.

    Published: 17 Jul 2012
    10
    Critical

    CVE-2012-1967

    Last Modified: 11 Apr 2025

    Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 do not properly implement the JavaScript sandbox utility, which allows remote attackers to execute arbitrary JavaScript code with improper privileges via a javascript: URL.

    Published: 17 Jul 2012
    6.5
    Medium

    CVE-2012-2282

    Last Modified: 11 Apr 2025

    EMC Celerra Network Server 6.x before 6.0.61.0, VNX 7.x before 7.0.53.2, and VNXe 2.0 and 2.1 before 2.1.3.19077 (aka MR1 SP3.2) and 2.2 before 2.2.0.19078 (aka MR2 SP0.2) do not properly implement NFS access control, which allows remote authenticated users to read or modify files via a (1) NFSv2, (2) NFSv3, or (3) NFSv4 request.

    Published: 16 Jul 2012
    5
    Medium

    CVE-2012-4027

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Tridium Niagara AX Framework allows remote attackers to read files outside of the intended images, nav, and px folders by leveraging incorrect permissions, as demonstrated by reading the config.bog file.

    Published: 16 Jul 2012
    7.8
    High

    CVE-2012-4028

    Last Modified: 11 Apr 2025

    Tridium Niagara AX Framework does not properly store credential data, which allows context-dependent attackers to bypass intended access restrictions by using the stored information for authentication.

    Published: 16 Jul 2012
    4.3
    Medium

    CVE-2012-2021

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in HP AssetManager 5.20, 5.21, 5.22, and 9.30 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Jul 2012
    7.5
    High

    CVE-2012-2607

    Last Modified: 11 Apr 2025

    The Johnson Controls CK721-A controller with firmware before SSM4388_03.1.0.14_BB allows remote attackers to perform arbitrary actions via crafted packets to TCP port 41014 (aka the download port).

    Published: 16 Jul 2012
    4.3
    Medium

    CVE-2012-2645

    Last Modified: 11 Apr 2025

    The Yahoo! Japan Yahoo! Browser application 1.2.0 and earlier for Android does not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application.

    Published: 16 Jul 2012
    5
    Medium

    CVE-2012-4026

    Last Modified: 11 Apr 2025

    The Johnson Controls Pegasys P2000 server with software before 3.11 allows remote attackers to trigger false alerts via crafted packets to TCP port 41013 (aka the upload port), a different vulnerability than CVE-2012-2607.

    Published: 16 Jul 2012
    6.8
    Medium

    CVE-2011-4133

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Moodle 1.9.x before 1.9.11 allows remote attackers to hijack the authentication of unspecified victims for requests that modify an RSS feed in an RSS block.

    Published: 16 Jul 2012
    4.3
    Medium

    CVE-2011-4278

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the tag autocomplete functionality in Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Jul 2012
    5
    Medium

    CVE-2011-4279

    Last Modified: 11 Apr 2025

    Moodle 2.0.x before 2.0.2 does not use the forceloginforprofiles setting for course-profiles access control, which makes it easier for remote attackers to obtain potentially sensitive information via vectors involving use of a search engine, as demonstrated by the search functionality of Google, Yahoo!, Wrensoft Zoom, MSN, Yandex, and AltaVista.

    Published: 16 Jul 2012
    4.3
    Medium

    CVE-2011-4280

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Spike PHPCoverage (aka spikephpcoverage) library, as used in Moodle 2.0.x before 2.0.2 and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Jul 2012
    6.8
    Medium

    CVE-2011-4281

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 2.0.x before 2.0.2 allow remote attackers to hijack the authentication of arbitrary users for requests that mark the completion of (1) an activity or (2) a course.

    Published: 16 Jul 2012