CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2012-2812

    Last Modified: 11 Apr 2025

    The exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory via crafted EXIF tags in an image.

    Published: 12 Jul 2012
    6.4
    Medium

    CVE-2012-2836

    Last Modified: 11 Apr 2025

    The exif_data_load_data function in exif-data.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory via crafted EXIF tags in an image.

    Published: 12 Jul 2012
    5
    Medium

    CVE-2012-2837

    Last Modified: 11 Apr 2025

    The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (divide-by-zero error) via an image with crafted EXIF tags that are not properly handled during the formatting of EXIF maker note tags.

    Published: 12 Jul 2012
    7.5
    High

    CVE-2012-2840

    Last Modified: 11 Apr 2025

    Off-by-one error in the exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted EXIF tags in an image.

    Published: 12 Jul 2012
    7.5
    High

    CVE-2012-2841

    Last Modified: 11 Apr 2025

    Integer underflow in the exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 might allow remote attackers to execute arbitrary code via vectors involving a crafted buffer-size parameter during the formatting of an EXIF tag, leading to a heap-based buffer overflow.

    Published: 12 Jul 2012
    7.5
    High

    CVE-2012-2814

    Last Modified: 11 Apr 2025

    Buffer overflow in the exif_entry_format_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted EXIF tags in an image.

    Published: 12 Jul 2012
    6.4
    Medium

    CVE-2012-2813

    Last Modified: 11 Apr 2025

    The exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory via crafted EXIF tags in an image.

    Published: 12 Jul 2012
    6.4
    Medium

    CVE-2012-2845

    Last Modified: 11 Apr 2025

    Integer overflow in the jpeg_data_load_data function in jpeg-data.c in libjpeg in exif 0.6.20 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain potentially sensitive information via a crafted JPEG file.

    Published: 12 Jul 2012
    4.3
    Medium

    CVE-2011-4299

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to inject arbitrary web script or HTML via a wiki comment.

    Published: 11 Jul 2012
    5
    Medium

    CVE-2011-4300

    Last Modified: 11 Apr 2025

    The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which allows remote attackers to obtain potentially sensitive information via a request for a file.

    Published: 11 Jul 2012
    5
    Medium

    CVE-2011-4301

    Last Modified: 11 Apr 2025

    The MoodleQuickForm class in the Forms Library in lib/formslib.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not recognize Forms API setConstant operations, which allows remote attackers to submit unexpected form content by modifying the values of constant fields.

    Published: 11 Jul 2012
    6.8
    Medium

    CVE-2011-4302

    Last Modified: 11 Apr 2025

    mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the openssl_verify function, which allows remote attackers to bypass validation via a crafted certificate.

    Published: 11 Jul 2012
    4.3
    Medium

    CVE-2011-4303

    Last Modified: 11 Apr 2025

    lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.

    Published: 11 Jul 2012
    4
    Medium

    CVE-2011-4304

    Last Modified: 11 Apr 2025

    The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.

    Published: 11 Jul 2012
    4
    Medium

    CVE-2011-4305

    Last Modified: 11 Apr 2025

    message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing.

    Published: 11 Jul 2012
    4.3
    Medium

    CVE-2011-4306

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in course/editsection.html in Moodle 1.9.x before 1.9.14 allows remote authenticated users to inject arbitrary web script or HTML via crafted data.

    Published: 11 Jul 2012
    5
    Medium

    CVE-2011-4309

    Last Modified: 11 Apr 2025

    Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to a URL.

    Published: 11 Jul 2012
    6.8
    Medium

    CVE-2012-3889

    Last Modified: 11 Apr 2025

    The in_mod plugin in Winamp before 5.63 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a .IT file.

    Published: 11 Jul 2012
    6.8
    Medium

    CVE-2012-3890

    Last Modified: 11 Apr 2025

    The in_mod plugin in Winamp before 5.63 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a .IT file.

    Published: 11 Jul 2012
    4
    Medium

    CVE-2011-4308

    Last Modified: 11 Apr 2025

    mod/forum/user.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 allows remote authenticated users to discover the names of other users via unspecified vectors.

    Published: 11 Jul 2012
    6.8
    Medium

    CVE-2011-4298

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote attackers to hijack the authentication of arbitrary users for requests that modify wiki data.

    Published: 11 Jul 2012
    4.3
    Medium

    CVE-2011-4307

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the section parameter.

    Published: 11 Jul 2012
    10
    Critical

    CVE-2012-2020

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Operations Agent before 11.03.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1326.

    Published: 11 Jul 2012
    10
    Critical

    CVE-2012-2019

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Operations Agent before 11.03.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1325.

    Published: 11 Jul 2012
    5
    Medium

    CVE-2012-3405

    Last Modified: 11 Apr 2025

    The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (segmentation fault and crash) via a format string with a large number of format specifiers that triggers "desynchronization within the buffer size handling," a different vulnerability than CVE-2012-3404.

    Published: 11 Jul 2012
    5
    Medium

    CVE-2012-3404

    Last Modified: 11 Apr 2025

    The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (stack corruption and crash) via a format string that uses positional parameters and many format specifiers.

    Published: 11 Jul 2012
    6.8
    Medium

    CVE-2012-3406

    Last Modified: 11 Apr 2025

    The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the use of" the alloca function when allocating the SPECS array, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (crash) or possibly execute arbitrary code via a crafted format string using positional parameters and a large number of format specifiers, a different vulnerability than CVE-2012-3404 and CVE-2012-3405.

    Published: 11 Jul 2012
    7.8
    High

    CVE-2012-1854

    Last Modified: 22 Apr 2026

    Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka "Visual Basic for Applications Insecure Library Loading Vulnerability," as exploited in the wild in July 2012.

    Published: 10 Jul 2012
    9.3
    Critical

    CVE-2012-1522

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Cached Object Remote Code Execution Vulnerability."

    Published: 10 Jul 2012
    4.3
    Medium

    CVE-2012-1859

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in scriptresx.ashx in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "XSS scriptresx.ashx Vulnerability."

    Published: 10 Jul 2012
    5.5
    Medium

    CVE-2012-1860

    Last Modified: 11 Apr 2025

    Microsoft Office SharePoint Server 2007 SP2 and SP3, SharePoint Server 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 do not properly check permissions for search scopes, which allows remote authenticated users to obtain sensitive information or cause a denial of service (data modification) by changing a parameter in a search-scope URL, aka "SharePoint Search Scope Vulnerability."

    Published: 10 Jul 2012
    4.3
    Medium

    CVE-2012-1861

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "SharePoint Script in Username Vulnerability."

    Published: 10 Jul 2012
    8.8
    High

    CVE-2012-0175

    Last Modified: 11 Apr 2025

    The Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted name for a (1) file or (2) directory, aka "Command Injection Vulnerability."

    Published: 10 Jul 2012
    4.3
    Medium

    CVE-2012-1863

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "SharePoint Reflected List Parameter Vulnerability."

    Published: 10 Jul 2012
    4.3
    Medium

    CVE-2012-1870

    Last Modified: 11 Apr 2025

    The CBC mode in the TLS protocol, as used in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and other products, allows remote web servers to obtain plaintext data by triggering multiple requests to a third-party HTTPS server and sniffing the network during the resulting HTTPS session, aka "TLS Protocol Vulnerability."

    Published: 10 Jul 2012
    7.2
    High

    CVE-2012-1890

    Last Modified: 11 Apr 2025

    win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle keyboard-layout files, which allows local users to gain privileges via a crafted application, aka "Keyboard Layout Vulnerability."

    Published: 10 Jul 2012
    9.8
    Critical

    CVE-2012-1891

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote attackers to execute arbitrary code via crafted XML data that triggers access to an uninitialized object in memory, aka "ADO Cachesize Heap Overflow RCE Vulnerability."

    Published: 10 Jul 2012
    9.3
    Critical

    CVE-2012-1524

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Attribute Remove Remote Code Execution Vulnerability."

    Published: 10 Jul 2012
    6.8
    Medium

    CVE-2012-1862

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "SharePoint URL Redirection Vulnerability."

    Published: 10 Jul 2012
    7.2
    High

    CVE-2012-1893

    Last Modified: 11 Apr 2025

    win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate callback parameters during creation of a hook procedure, which allows local users to gain privileges via a crafted application, aka "Win32k Incorrect Type Handling Vulnerability."

    Published: 10 Jul 2012
    6.9
    Medium

    CVE-2012-1894

    Last Modified: 11 Apr 2025

    Microsoft Office for Mac 2011 uses world-writable permissions for the "Applications/Microsoft Office 2011/" directory and certain other directories, which allows local users to gain privileges by placing a Trojan horse executable file in one of these directories, aka "Office for Mac Improper Folder Permissions Vulnerability."

    Published: 10 Jul 2012
    4.7
    Medium

    CVE-2012-2745

    Last Modified: 11 Apr 2025

    The copy_creds function in kernel/cred.c in the Linux kernel before 3.3.2 provides an invalid replacement session keyring to a child process, which allows local users to cause a denial of service (panic) via a crafted application that uses the fork system call.

    Published: 10 Jul 2012
    10
    Critical

    CVE-2012-3358

    Last Modified: 11 Apr 2025

    Multiple heap-based buffer overflows in the j2k_read_sot function in j2k.c in OpenJPEG 1.5 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted (1) tile number or (2) tile length in a JPEG 2000 image file.

    Published: 10 Jul 2012
    4.6
    Medium

    CVE-2012-3410

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in lib/sh/eaccess.c in GNU Bash before 4.2 patch 33 might allow local users to bypass intended restricted shell access via a long filename in /dev/fd, which is not properly handled when expanding the /dev/fd prefix.

    Published: 10 Jul 2012
    4
    Medium

    CVE-2012-3864

    Last Modified: 11 Apr 2025

    Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, allows remote authenticated users to read arbitrary files on the puppet master server by leveraging an arbitrary user's certificate and private key in a GET request.

    Published: 10 Jul 2012
    3.5
    Low

    CVE-2012-3865

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remote authenticated users to delete arbitrary files on the puppet master server via a .. (dot dot) in a node name.

    Published: 10 Jul 2012
    7.8
    High

    CVE-2012-2744

    Last Modified: 11 Apr 2025

    net/ipv6/netfilter/nf_conntrack_reasm.c in the Linux kernel before 2.6.34, when the nf_conntrack_ipv6 module is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via certain types of fragmented IPv6 packets.

    Published: 10 Jul 2012
    7.8
    High

    CVE-2012-3409

    Last Modified: 21 Nov 2024

    ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation

    Published: 10 Jul 2012
    4.3
    Medium

    CVE-2012-3867

    Last Modified: 11 Apr 2025

    lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Request (CSR), which makes it easier for user-assisted remote attackers to trick administrators into signing a crafted agent certificate via ANSI control sequences.

    Published: 10 Jul 2012
    2.6
    Low

    CVE-2012-3408

    Last Modified: 11 Apr 2025

    lib/puppet/network/authstore.rb in Puppet before 2.7.18, and Puppet Enterprise before 2.5.2, supports use of IP addresses in certnames without warning of potential risks, which might allow remote attackers to spoof an agent by acquiring a previously used IP address.

    Published: 10 Jul 2012