CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2012-2138

    Last Modified: 11 Apr 2025

    The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to copy an ancestor node to a descendant node, which allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP request.

    Published: 9 Jul 2012
    7.8
    High

    CVE-2012-2970

    Last Modified: 11 Apr 2025

    The Synel SY-780/A Time & Attendance terminal allows remote attackers to cause a denial of service (device hang) via network traffic to port (1) 1641, (2) 3734, or (3) 3735.

    Published: 9 Jul 2012
    4.3
    Medium

    CVE-2012-3238

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Backup/Restore component in WebAdmin in Astaro Security Gateway before 8.305 allows remote attackers to inject arbitrary web script or HTML via the "Comment (optional)" field.

    Published: 9 Jul 2012
    7.8
    High

    CVE-2012-1493

    Last Modified: 11 Apr 2025

    F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before 2.3.0-HF3, use a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins via the PubkeyAuthentication option.

    Published: 9 Jul 2012
    4
    Medium

    CVE-2012-3812

    Last Modified: 11 Apr 2025

    Double free vulnerability in apps/app_voicemail.c in Asterisk Open Source 1.8.x before 1.8.13.1 and 10.x before 10.5.2, Certified Asterisk 1.8.11-certx before 1.8.11-cert4, and Asterisk Digiumphones 10.x.x-digiumphones before 10.5.2-digiumphones allows remote authenticated users to cause a denial of service (daemon crash) by establishing multiple voicemail sessions and accessing both the Urgent mailbox and the INBOX mailbox.

    Published: 9 Jul 2012
    6.8
    Medium

    CVE-2012-2447

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in accountmgr/adminupdate.php in the WebAdmin Portal in Netsweeper allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts via an add action.

    Published: 9 Jul 2012
    10
    Critical

    CVE-2012-3859

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the WebAdmin Portal in Netsweeper has unknown impact and attack vectors, a different vulnerability than CVE-2012-2446 and CVE-2012-2447.

    Published: 9 Jul 2012
    4.3
    Medium

    CVE-2012-2446

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in tools/local_lookup.php in the WebAdmin Portal in Netsweeper allows remote attackers to inject arbitrary web script or HTML via the group parameter in a lookup action.

    Published: 9 Jul 2012
    7.4
    High

    CVE-2012-3372

    Last Modified: 11 Apr 2025

    The default configuration of Cyberoam UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the Cyberoam_SSL_CA certificate in a list of trusted root certification authorities. NOTE: the vendor disputes the significance of this issue because the appliance "does not allow import or export of the foresaid private key.

    Published: 9 Jul 2012
    4
    Medium

    CVE-2012-3863

    Last Modified: 11 Apr 2025

    channels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.13.1 and 10.x before 10.5.2, Asterisk Business Edition C.3.x before C.3.7.5, Certified Asterisk 1.8.11-certx before 1.8.11-cert4, and Asterisk Digiumphones 10.x.x-digiumphones before 10.5.2-digiumphones does not properly handle a provisional response to a SIP reINVITE request, which allows remote authenticated users to cause a denial of service (RTP port exhaustion) via sessions that lack final responses.

    Published: 9 Jul 2012
    4.4
    Medium

    CVE-2012-3386

    Last Modified: 11 Apr 2025

    The "make distcheck" rule in GNU Automake before 1.11.6 and 1.12.x before 1.12.2 grants world-writable permissions to the extraction directory, which introduces a race condition that allows local users to execute arbitrary code via unspecified vectors.

    Published: 9 Jul 2012
    5
    Medium

    CVE-2012-3411

    Last Modified: 11 Apr 2025

    Dnsmasq before 2.63test1, when used with certain libvirt configurations, replies to requests from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed DNS query.

    Published: 9 Jul 2012
    4.3
    Medium

    CVE-2012-2642

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the MT4i plugin 3.1 beta 4 and earlier for Movable Type allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-2644.

    Published: 7 Jul 2012
    4.3
    Medium

    CVE-2012-2643

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in KENT-WEB YY-BOARD before 6.4 allows remote attackers to inject arbitrary web script or HTML via a crafted form entry.

    Published: 7 Jul 2012
    4.3
    Medium

    CVE-2012-2644

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the MT4i plugin 3.1 beta 4 and earlier for Movable Type allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-2642.

    Published: 7 Jul 2012
    4.4
    Medium

    CVE-2012-3381

    Last Modified: 11 Apr 2025

    sfcb in sblim-sfcb places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 6 Jul 2012
    6.2
    Medium

    CVE-2012-3511

    Last Modified: 11 Apr 2025

    Multiple race conditions in the madvise_remove function in mm/madvise.c in the Linux kernel before 3.4.5 allow local users to cause a denial of service (use-after-free and system crash) via vectors involving a (1) munmap or (2) close system call.

    Published: 6 Jul 2012
    4.3
    Medium

    CVE-2012-2018

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Network Node Manager i (NNMi) 8.x, 9.0x, and 9.1x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Jul 2012
    9.3
    Critical

    CVE-2012-3585

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in jpeg_ls.dll in the Jpeg_LS (aka JLS) plugin in the formats plugins in IrfanView PlugIns before 4.34 allows remote attackers to execute arbitrary code via a crafted JLS file.

    Published: 5 Jul 2012
    3.3
    Low

    CVE-2012-0300

    Last Modified: 11 Apr 2025

    Brightmail Control Center in Symantec Message Filter 6.3 does not properly restrict establishment of sessions to the listening port, which allows remote attackers to obtain potentially sensitive version information via unspecified vectors.

    Published: 5 Jul 2012
    5.4
    Medium

    CVE-2012-0301

    Last Modified: 11 Apr 2025

    Session fixation vulnerability in Brightmail Control Center in Symantec Message Filter 6.3 allows remote attackers to hijack web sessions via unspecified vectors.

    Published: 5 Jul 2012
    4.3
    Medium

    CVE-2012-0302

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Brightmail Control Center in Symantec Message Filter 6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Jul 2012
    6.8
    Medium

    CVE-2012-0303

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Brightmail Control Center in Symantec Message Filter 6.3 allow remote attackers to hijack the authentication of arbitrary users for requests that (1) execute application commands or (2) create admin accounts.

    Published: 5 Jul 2012
    5
    Medium

    CVE-2012-2640

    Last Modified: 11 Apr 2025

    The NEC BIGLOBE Yome Collection application 1.8.3 and earlier for Android allows remote attackers to read the IMEI value from an SD card via a crafted application that lacks the READ_PHONE_STATE permission.

    Published: 5 Jul 2012
    4.3
    Medium

    CVE-2012-2641

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Zenphoto before 1.4.3 allows remote attackers to inject arbitrary web script or HTML by triggering improper interaction with an unspecified library.

    Published: 5 Jul 2012
    5
    Medium

    CVE-2012-0410

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in WebAccess in Novell GroupWise before 8.03 allows remote attackers to read arbitrary files via the User.interface parameter.

    Published: 5 Jul 2012
    6.8
    Medium

    CVE-2012-2281

    Last Modified: 11 Apr 2025

    EMC RSA Access Manager Server 6.x before 6.1 SP4 and RSA Access Manager Agent do not properly validate session tokens after a logout, which might allow remote attackers to conduct replay attacks via unspecified vectors.

    Published: 5 Jul 2012
    10
    Critical

    CVE-2012-1831

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 555.

    Published: 5 Jul 2012
    10
    Critical

    CVE-2012-1832

    Last Modified: 11 Apr 2025

    WellinTech KingView 6.53 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a crafted packet to (1) TCP or (2) UDP port 2001.

    Published: 5 Jul 2012
    10
    Critical

    CVE-2012-2559

    Last Modified: 11 Apr 2025

    WellinTech KingHistorian 3.0 allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer write) via a crafted packet to TCP port 5678.

    Published: 5 Jul 2012
    5
    Medium

    CVE-2012-2560

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in WellinTech KingView 6.53 allows remote attackers to read arbitrary files via a crafted HTTP request to port 8001.

    Published: 5 Jul 2012
    5
    Medium

    CVE-2012-3007

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in slssvc.exe before 58.x in Invensys Wonderware SuiteLink in the Invensys System Platform software suite, as used in InTouch/Wonderware Application Server IT before 10.5 and WAS before 3.5, DASABCIP before 4.1 SP2, DASSiDirect before 3.0, DAServer Runtime Components before 3.0 SP2, and other products, allows remote attackers to cause a denial of service (daemon crash or hang) via a long Unicode string.

    Published: 5 Jul 2012
    9.3
    Critical

    CVE-2012-2515

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HTML Help component), as used in EMC Documentum ApplicationXtender Desktop 5.4; EMC Captiva Quickscan Pro 4.6 SP1; GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; GE Intelligent Platforms Proficy HMI/SCADA iFIX 5.0 and 5.1; GE Intelligent Platforms Proficy Pulse 1.0; GE Intelligent Platforms Proficy Batch Execution 5.6; GE Intelligent Platforms SI7 I/O Driver 7.20 through 7.42; and other products, allow remote attackers to execute arbitrary code via a long string in the second argument to the (1) JumpMappedID or (2) JumpURL method.

    Published: 5 Jul 2012
    9.3
    Critical

    CVE-2012-2516

    Last Modified: 11 Apr 2025

    An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; Proficy HMI/SCADA iFIX 5.0 and 5.1; Proficy Pulse 1.0; Proficy Batch Execution 5.6; SI7 I/O Driver 7.20 through 7.42; and other products, allows remote attackers to execute arbitrary commands via crafted input, related to a "command injection vulnerability."

    Published: 5 Jul 2012
    10
    Critical

    CVE-2012-1830

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 555.

    Published: 5 Jul 2012
    5
    Medium

    CVE-2012-3847

    Last Modified: 11 Apr 2025

    slssvc.exe in Invensys Wonderware SuiteLink in Invensys InTouch 2012 and Wonderware Application Server 2012 allows remote attackers to cause a denial of service (resource consumption) via a long Unicode string, a different vulnerability than CVE-2012-3007.

    Published: 5 Jul 2012
    7.5
    High

    CVE-2012-3374

    Last Modified: 11 Apr 2025

    Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.5 allows remote attackers to execute arbitrary code via a crafted inline image in a message.

    Published: 5 Jul 2012
    4.3
    Medium

    CVE-2012-3840

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in index.php/users/form/user_id in MyClientBase 0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) first_name or (2) last_name parameters.

    Published: 3 Jul 2012
    4.3
    Medium

    CVE-2012-3828

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Joomla! 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the Host HTTP Header.

    Published: 3 Jul 2012
    5
    Medium

    CVE-2012-3829

    Last Modified: 11 Apr 2025

    Joomla! 2.5.3 allows remote attackers to obtain the installation path via the Host HTTP Header.

    Published: 3 Jul 2012
    4.3
    Medium

    CVE-2012-3830

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in decoda/templates/video.php in Decoda before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via the video directive.

    Published: 3 Jul 2012
    4.3
    Medium

    CVE-2012-3833

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the default index page in admin/ in Quick.CMS 4.0 allows remote attackers to inject arbitrary web script or HTML via the p parameter.

    Published: 3 Jul 2012
    4.3
    Medium

    CVE-2012-3837

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in apps/users/registration.template.php in Baby Gekko 1.2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) email_address, (3) password, (4) password_verify, (5) firstname, (6) lastname, or (7) verification_code parameter to users/action/register. NOTE: some of these details are obtained from third party information.

    Published: 3 Jul 2012
    5
    Medium

    CVE-2012-3838

    Last Modified: 11 Apr 2025

    Gekko before 1.2.0 allows remote attackers to obtain the installation path via a direct request to (1) admin/templates/babygekko/index.php or (2) templates/html5demo/index.php.

    Published: 3 Jul 2012
    7.5
    High

    CVE-2012-3839

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in application/core/MY_Model.php in MyClientBase 0.12 allow remote attackers to execute arbitrary SQL commands via the (1) invoice_number or (2) tags parameter to index.php/invoice_search.

    Published: 3 Jul 2012
    9.3
    Critical

    CVE-2012-3841

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in KMPlayer 3.2.0.19 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ehtrace.dll that is located in the current working directory.

    Published: 3 Jul 2012
    4.3
    Medium

    CVE-2012-3843

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the registration page in e107, probably 1.0.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 Jul 2012
    4.3
    Medium

    CVE-2012-3844

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in vBulletin 4.1.12 allows remote attackers to inject arbitrary web script or HTML via a long string in the subject parameter when creating a post.

    Published: 3 Jul 2012
    5
    Medium

    CVE-2012-3845

    Last Modified: 11 Apr 2025

    Buffer overflow in LAN Messenger 1.2.28 and earlier allows remote attackers to cause a denial of service (crash) via a long string in an initiation request.

    Published: 3 Jul 2012
    4.3
    Medium

    CVE-2012-3846

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in PHP-pastebin 2.1 allows remote attackers to inject arbitrary web script or HTML via the title parameter.

    Published: 3 Jul 2012