CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2012-3832

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in decoda/Decoda.php in Decoda before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to (1) b or (2) div tags.

    Published: 3 Jul 2012
    6.5
    Medium

    CVE-2012-3834

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in forensics/base_qry_main.php in AlienVault Open Source Security Information Management (OSSIM) 3.1 allows remote authenticated users to execute arbitrary SQL commands via the time[0][0] parameter.

    Published: 3 Jul 2012
    4.3
    Medium

    CVE-2012-3835

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to top.php or (2) time[0][0] parameter to forensics/base_qry_main.php, which is not properly handled in an error page.

    Published: 3 Jul 2012
    4.3
    Medium

    CVE-2012-3842

    Last Modified: 5 Dec 2025

    Multiple cross-site scripting (XSS) vulnerabilities in CMD_DOMAIN in JBMC Software DirectAdmin 1.403 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via the (1) select0 or (2) select8 parameters.

    Published: 3 Jul 2012
    4.3
    Medium

    CVE-2012-3831

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in decoda/templates/video.php in Decoda before 3.3.1 allows remote attackers to inject arbitrary web script or HTML via multiple URLs in an img tag.

    Published: 3 Jul 2012
    4.3
    Medium

    CVE-2012-3836

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko before 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) groupname parameter in a savecategory in the users module; (2) virtual_filename, (3) branch, (4) contact_person, (5) street, (6) city, (7) province, (8) postal, (9) country, (10) tollfree, (11) phone, (12) fax, or (13) mobile parameter in a saveitem action in the contacts module; (14) title parameter in a savecategory action in the menus module; (15) firstname or (16) lastname in a saveitem action in the users module; (17) meta_key or (18) meta_description in a saveitem action in the blog module; or (19) the PATH_INFO to admin/index.php.

    Published: 3 Jul 2012
    10
    Critical

    CVE-2011-5096

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in cstore.exe in the Media Application Server (MAS) in Avaya Aura Application Server 5300 (formerly Nortel Media Application Server) 1.x before 1.0.2 and 2.0 before Patch Bundle 10 allows remote attackers to execute arbitrary code via a crafted cs_anams parameter in a CONTENT_STORE_ADMIN_REQ packet.

    Published: 3 Jul 2012
    5
    Medium

    CVE-2012-2181

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Dojo module in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF14, and 8.0, allows remote attackers to read arbitrary files via a crafted URL.

    Published: 3 Jul 2012
    7.5
    High

    CVE-2012-2747

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allows remote attackers to gain privileges via unknown attack vectors related to "Inadequate checking."

    Published: 3 Jul 2012
    5
    Medium

    CVE-2012-2748

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allows remote attackers to obtain sensitive information via vectors related to "Inadequate filtering" and a "SQL error."

    Published: 3 Jul 2012
    10
    Critical

    CVE-2012-3811

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in ImageUpload.ashx in the Wallboard application in Avaya IP Office Customer Call Reporter 7.0 before 7.0.5.8 Q1 2012 Maintenance Release and 8.0 before 8.0.9.13 Q1 2012 Maintenance Release allows remote attackers to execute arbitrary code by uploading an executable file and then accessing it via a direct request.

    Published: 3 Jul 2012
    9
    Critical

    CVE-2012-3366

    Last Modified: 11 Apr 2025

    The Trigger plugin in bcfg2 1.2.x before 1.2.3 allows remote attackers with root access to the client to execute arbitrary commands via shell metacharacters in the UUID field to the server process (bcfg2-server).

    Published: 3 Jul 2012
    4.3
    Medium

    CVE-2012-3413

    Last Modified: 11 Apr 2025

    The HTMLQuoteColorer::process function in messageviewer/htmlquotecolorer.cpp in KDE PIM 4.6 through 4.8 does not disable JavaScript, Java, and Plugins, which allows remote attackers to inject arbitrary web script or HTML via a crafted email.

    Published: 2 Jul 2012
    7.8
    High

    CVE-2012-2017

    Last Modified: 11 Apr 2025

    Unspecified vulnerability on HP Photosmart Wireless e-All-in-One B110, e-All-in-One D110, Plus e-All-in-One B210, eStation All-in-One C510, Ink Advantage e-All-in-One K510, and Premium Fax e-All-in-One C410 printers allows remote attackers to cause a denial of service via unknown vectors.

    Published: 30 Jun 2012
    7.5
    High

    CVE-2012-2013

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP System Management Homepage (SMH) before 7.1.1 allows remote attackers to cause a denial of service, or possibly obtain sensitive information or modify data, via unknown vectors.

    Published: 29 Jun 2012
    9
    Critical

    CVE-2012-2014

    Last Modified: 11 Apr 2025

    HP System Management Homepage (SMH) before 7.1.1 does not properly validate input, which allows remote authenticated users to have an unspecified impact via unknown vectors.

    Published: 29 Jun 2012
    9
    Critical

    CVE-2012-2015

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP System Management Homepage (SMH) before 7.1.1 allows remote authenticated users to gain privileges and obtain sensitive information via unknown vectors.

    Published: 29 Jun 2012
    4.9
    Medium

    CVE-2012-2016

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP System Management Homepage (SMH) before 7.1.1 allows local users to obtain sensitive information via unknown vectors.

    Published: 29 Jun 2012
    10
    Critical

    CVE-2012-2012

    Last Modified: 11 Apr 2025

    HP System Management Homepage (SMH) before 7.1.1 does not have an off autocomplete attribute for unspecified form fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

    Published: 29 Jun 2012
    2.1
    Low

    CVE-2012-0813

    Last Modified: 11 Apr 2025

    Wicd before 1.7.1 saves sensitive information in log files in /var/log/wicd, which allows context-dependent attackers to obtain passwords and other sensitive information.

    Published: 29 Jun 2012
    6.4
    Medium

    CVE-2012-1119

    Last Modified: 11 Apr 2025

    MantisBT before 1.2.9 does not audit when users copy or clone a bug report, which makes it easier for remote attackers to copy bug reports without detection.

    Published: 29 Jun 2012
    3.6
    Low

    CVE-2012-1120

    Last Modified: 11 Apr 2025

    The SOAP API in MantisBT before 1.2.9 does not properly enforce the bugnote_allow_user_edit_delete and delete_bug_threshold permissions, which allows remote authenticated users with read and write SOAP API privileges to delete arbitrary bug reports and bug notes.

    Published: 29 Jun 2012
    4.9
    Medium

    CVE-2012-1121

    Last Modified: 11 Apr 2025

    MantisBT before 1.2.9 does not properly check permissions, which allows remote authenticated users with manager privileges to (1) modify or (2) delete global categories.

    Published: 29 Jun 2012
    7.5
    High

    CVE-2012-1123

    Last Modified: 11 Apr 2025

    The mci_check_login function in api/soap/mc_api.php in the SOAP API in MantisBT before 1.2.9 allows remote attackers to bypass authentication via a null password.

    Published: 29 Jun 2012
    4
    Medium

    CVE-2012-2385

    Last Modified: 11 Apr 2025

    The terminal dispatcher in mosh before 1.2.1 allows remote authenticated users to cause a denial of service (long loop and CPU consumption) via an escape sequence with a large repeat count value.

    Published: 29 Jun 2012
    4.3
    Medium

    CVE-2012-2698

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the outputPage function in includes/SkinTemplate.php in MediaWiki before 1.17.5, 1.18.x before 1.18.4, and 1.19.x before 1.19.1 allows remote attackers to inject arbitrary web script or HTML via the uselang parameter to index.php/Main_page.

    Published: 29 Jun 2012
    Unknown

    CVE-2012-2709

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-2907. Reason: This candidate is a duplicate of CVE-2012-2907. Notes: All CVE users should reference CVE-2012-2907 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 29 Jun 2012
    4.3
    Medium

    CVE-2012-1118

    Last Modified: 11 Apr 2025

    The access_has_bug_level function in core/access_api.php in MantisBT before 1.2.9 does not properly restrict access when the private_bug_view_threshold is set to an array, which allows remote attackers to bypass intended restrictions and perform certain operations on private bug reports.

    Published: 29 Jun 2012
    3.6
    Low

    CVE-2012-1122

    Last Modified: 11 Apr 2025

    bug_actiongroup.php in MantisBT before 1.2.9 does not properly check the report_bug_threshold permission of the receiving project when moving a bug report, which allows remote authenticated users with the report_bug_threshold and move_bug_threshold privileges for a project to bypass intended access restrictions and move bug reports to a different project.

    Published: 29 Jun 2012
    4.3
    Medium

    CVE-2012-3232

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in search.php in web@all 2.0, as downloaded before May 30, 2012, allows remote attackers to inject arbitrary web script or HTML via the _text[title] parameter.

    Published: 29 Jun 2012
    2.1
    Low

    CVE-2012-3818

    Last Modified: 11 Apr 2025

    The fpm exporter in Revelation 0.4.13-2 and earlier encrypts the version number but not the password when exporting a file, which might allow local users to obtain sensitive information.

    Published: 29 Jun 2012
    9.3
    Critical

    CVE-2012-3054

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 LC before SP25 EP11, T27 LD before SP32 CP2, and T28 L10N before SP1 allows remote attackers to execute arbitrary code via a crafted WRF file, aka Bug ID CSCtz72977.

    Published: 29 Jun 2012
    9.3
    Critical

    CVE-2012-3057

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 LC before SP25 EP11, T27 LD before SP32 CP2, and T28 L10N before SP1 allows remote attackers to execute arbitrary code via a crafted size field in audio data within a WRF file, aka Bug ID CSCtz00755.

    Published: 29 Jun 2012
    9.3
    Critical

    CVE-2012-3056

    Last Modified: 11 Apr 2025

    Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 LC before SP25 EP11, T27 LD before SP32 CP2, and T28 L10N before SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted WRF file, aka Bug ID CSCtz72946.

    Published: 29 Jun 2012
    9.3
    Critical

    CVE-2012-3053

    Last Modified: 11 Apr 2025

    Buffer overflow in the Cisco WebEx Advanced Recording Format (ARF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 LC before SP25 EP11, T27 LD before SP32 CP2, and T28 L10N before SP1 allows remote attackers to execute arbitrary code via a crafted ARF file, aka Bug ID CSCtz72985.

    Published: 29 Jun 2012
    9.3
    Critical

    CVE-2012-3055

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 LC before SP25 EP11, T27 LD before SP32 CP2, and T28 L10N before SP1 allows remote attackers to execute arbitrary code via a crafted DHT chunk in a JPEG image within a WRF file, aka Bug ID CSCtz72953.

    Published: 29 Jun 2012
    4.3
    Medium

    CVE-2012-3236

    Last Modified: 11 Apr 2025

    fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed XTENSION header of a .fit file, as demonstrated using a long string.

    Published: 29 Jun 2012
    5
    Medium

    CVE-2012-2743

    Last Modified: 11 Apr 2025

    Revelation 0.4.13-2 and earlier does not iterate through SHA hashing algorithms for AES encryption, which makes it easier for context-dependent attackers to guess passwords via a brute force attack.

    Published: 27 Jun 2012
    6.8
    Medium

    CVE-2012-3231

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in web@all 2.0, as downloaded before May 30, 2012, allow remote attackers to hijack the authentication of administrators for requests that add, delete, or modify sensitive information, as demonstrated by adding a file to execute arbitrary code via a do_addfile action to inc/browser/action.php.

    Published: 27 Jun 2012
    5
    Medium

    CVE-2012-2742

    Last Modified: 11 Apr 2025

    Revelation 0.4.13-2 and earlier uses only the first 32 characters of a password followed by a sequence of zeros, which reduces the entropy and makes it easier for context-dependent attackers to crack passwords and obtain access to keys via a brute-force attack.

    Published: 27 Jun 2012
    4.3
    Medium

    CVE-2011-4956

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in WordPress before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 Jun 2012
    5
    Medium

    CVE-2011-4957

    Last Modified: 11 Apr 2025

    The make_clickable function in wp-includes/formatting.php in WordPress before 3.1.1 does not properly check URLs before passing them to the PCRE library, which allows remote attackers to cause a denial of service (crash) via a comment with a crafted URL that triggers many recursive calls.

    Published: 27 Jun 2012
    4.3
    Medium

    CVE-2012-2717

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Mobile Tools module 6.x-2.x before 6.x-2.3 for Drupal allow remote attackers to inject arbitrary web script or HTML via the (1) Mobile URL field or (2) Desktop URL field to the General configuration page, or the (3) message to the Mobile Tools block message options.

    Published: 27 Jun 2012
    7.8
    High

    CVE-2012-3816

    Last Modified: 11 Apr 2025

    WinRadius Server 2009 allows remote attackers to cause a denial of service (crash) via a long password in an Access-Request packet.

    Published: 27 Jun 2012
    9.3
    Critical

    CVE-2012-3815

    Last Modified: 11 Apr 2025

    Buffer overflow in RunTime.exe in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 46824. NOTE: some of these details are obtained from third party information.

    Published: 27 Jun 2012
    7.5
    High

    CVE-2012-2388

    Last Modified: 11 Apr 2025

    The GMP Plugin in strongSwan 4.2.0 through 4.6.3 allows remote attackers to bypass authentication via a (1) empty or (2) zeroed RSA signature, aka "RSA signature verification vulnerability."

    Published: 27 Jun 2012
    7.5
    High

    CVE-2012-3814

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in font-upload.php in the Font Uploader plugin 1.2.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file with a .php.ttf extension, then accessing it via a direct request to the file in font-uploader/fonts.

    Published: 27 Jun 2012
    4
    Medium

    CVE-2012-3802

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Post Affiliate Pro (PAP) module for Drupal allows remote authenticated users to read the commissions of other users via unknown attack vectors.

    Published: 27 Jun 2012
    7.2
    High

    CVE-2012-2200

    Last Modified: 11 Apr 2025

    The default configuration of sendmail in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, allows local users to gain privileges by entering a command in a .forward file in a home directory.

    Published: 27 Jun 2012
    7.2
    High

    CVE-2012-2764

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Google Chrome before 20.0.1132.43 on Windows might allow local users to gain privileges via a Trojan horse Metro DLL in the current working directory.

    Published: 27 Jun 2012