CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2012-6119

    Last Modified: 11 Apr 2025

    Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.

    Published: 27 Jun 2012
    Unknown

    CVE-2012-2732

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-2021. Reason: This candidate is a duplicate of CVE-2010-2021. Notes: All CVE users should reference CVE-2010-2021 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 26 Jun 2012
    6.8
    Medium

    CVE-2012-2380

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the admin/editor console in Apache Roller before 5.0.1 allow remote attackers to hijack the authentication of admins or editors by leveraging the HTTP POST functionality.

    Published: 26 Jun 2012
    3.5
    Low

    CVE-2012-2381

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.1 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the blogger role.

    Published: 26 Jun 2012
    6.8
    Medium

    CVE-2012-2807

    Last Modified: 11 Apr 2025

    Multiple integer overflows in libxml2, as used in Google Chrome before 20.0.1132.43 and other products, on 64-bit Linux platforms allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 26 Jun 2012
    5
    Medium

    CVE-2012-2825

    Last Modified: 11 Apr 2025

    The XSL implementation in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service (incorrect read operation) via unspecified vectors.

    Published: 26 Jun 2012
    5.8
    Medium

    CVE-2010-2021

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in the Global Redirect module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.4 for Drupal, when non-clean to clean is enabled, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter.

    Published: 25 Jun 2012
    5
    Medium

    CVE-2012-3792

    Last Modified: 11 Apr 2025

    Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (out-of-bounds read operation) via a crafted packet that triggers a certain Find Node check attempt.

    Published: 25 Jun 2012
    5
    Medium

    CVE-2012-3793

    Last Modified: 11 Apr 2025

    Integer overflow in Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (daemon crash) via a crafted packet with a certain opcode that triggers an incorrect memory allocation and a buffer overflow.

    Published: 25 Jun 2012
    5
    Medium

    CVE-2012-3794

    Last Modified: 11 Apr 2025

    Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (unhandled exception and daemon crash) via a crafted packet with a certain opcode that triggers an invalid attempt to allocate a large amount of memory.

    Published: 25 Jun 2012
    5
    Medium

    CVE-2012-3795

    Last Modified: 11 Apr 2025

    Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (daemon crash) via a crafted packet with a certain opcode and a large value in a size field.

    Published: 25 Jun 2012
    10
    Critical

    CVE-2012-3797

    Last Modified: 11 Apr 2025

    Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, does not properly check packet sizes before reusing packet memory buffers, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a short crafted packet with a certain opcode.

    Published: 25 Jun 2012
    5
    Medium

    CVE-2012-3796

    Last Modified: 11 Apr 2025

    Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to obtain sensitive information from daemon memory via a crafted packet with a certain opcode.

    Published: 25 Jun 2012
    4
    Medium

    CVE-2013-0454

    Last Modified: 11 Apr 2025

    The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated users to (1) write to a read-only share; (2) trigger data-integrity problems related to the oplock, locking, coherency, or leases attribute; or (3) have an unspecified impact by leveraging incorrect handling of the browseable or "hide unreadable" parameter.

    Published: 25 Jun 2012
    4.3
    Medium

    CVE-2012-0186

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Eclipse Help component in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack allows remote attackers to discover the locations of files via a crafted URL.

    Published: 22 Jun 2012
    9.3
    Critical

    CVE-2012-0187

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack allows local users to gain privileges via a Trojan horse DLL in the current working directory.

    Published: 22 Jun 2012
    6.9
    Medium

    CVE-2012-0304

    Last Modified: 11 Apr 2025

    Symantec LiveUpdate Administrator before 2.3.1 uses weak permissions (Everyone: Full Control) for the installation directory, which allows local users to gain privileges via a Trojan horse file.

    Published: 22 Jun 2012
    4.3
    Medium

    CVE-2012-2172

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in SoftwareRegistration.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote attackers to inject arbitrary web script or HTML via the updateRegn parameter.

    Published: 22 Jun 2012
    6.9
    Medium

    CVE-2012-2179

    Last Modified: 11 Apr 2025

    libodm.a in IBM AIX 5.3, 6.1, and 7.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

    Published: 22 Jun 2012
    5
    Medium

    CVE-2012-0191

    Last Modified: 11 Apr 2025

    The web container in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack does not properly perform access control for requests, which allows remote attackers to spoof a localhost request origin via crafted headers.

    Published: 22 Jun 2012
    6.5
    Medium

    CVE-2012-2171

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in ModuleServlet.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote authenticated users to execute arbitrary SQL commands via the selectedModuleOnly parameter in a state_viewmodulelog action to the ModuleServlet URI.

    Published: 22 Jun 2012
    5
    Medium

    CVE-2012-3467

    Last Modified: 11 Apr 2025

    Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remote attackers to bypass authentication.

    Published: 22 Jun 2012
    7.2
    High

    CVE-2011-1477

    Last Modified: 11 Apr 2025

    Multiple array index errors in sound/oss/opl3.c in the Linux kernel before 2.6.39 allow local users to cause a denial of service (heap memory corruption) or possibly gain privileges by leveraging write access to /dev/sequencer.

    Published: 21 Jun 2012
    4
    Medium

    CVE-2011-1476

    Last Modified: 11 Apr 2025

    Integer underflow in the Open Sound System (OSS) subsystem in the Linux kernel before 2.6.39 on unspecified non-x86 platforms allows local users to cause a denial of service (memory corruption) by leveraging write access to /dev/sequencer.

    Published: 21 Jun 2012
    7.5
    High

    CVE-2012-3791

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Simple Web Content Management System 1.1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) item_delete.php, (2) item_status.php, (3) item_detail.php, (4) item_modify.php, or (5) item_position.php in admin/; or (6) status parameter to admin/item_status.php.

    Published: 21 Jun 2012
    6.2
    Medium

    CVE-2012-0219

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the xioscan_readline function in xio-readline.c in socat 1.4.0.0 through 1.7.2.0 and 2.0.0-b1 through 2.0.0-b4 allows local users to execute arbitrary code via the READLINE address.

    Published: 21 Jun 2012
    4.3
    Medium

    CVE-2012-2654

    Last Modified: 11 Apr 2025

    The (1) EC2 and (2) OS APIs in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) do not properly check the protocol when security groups are created and the network protocol is not specified entirely in lowercase, which allows remote attackers to bypass intended access restrictions.

    Published: 21 Jun 2012
    7.5
    High

    CVE-2012-2718

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Counter module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to "recording visits."

    Published: 21 Jun 2012
    2.1
    Low

    CVE-2012-2389

    Last Modified: 11 Apr 2025

    hostapd 0.7.3, and possibly other versions before 1.0, uses 0644 permissions for /etc/hostapd/hostapd.conf, which might allow local users to obtain sensitive information such as credentials.

    Published: 21 Jun 2012
    6.8
    Medium

    CVE-2012-2716

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Comment Moderation module 6.x-1.x before 6.x-1.1 for Drupal allows remote attackers to hijack the authentication of administrators for requests that publish comments.

    Published: 21 Jun 2012
    4.3
    Medium

    CVE-2012-2494

    Last Modified: 11 Apr 2025

    The VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2.x before 2.5 MR6 and 3.x before 3.0 MR8 does not compare the timestamp of offered software to the timestamp of installed software, which allows remote attackers to force a version downgrade by using (1) ActiveX or (2) Java components to offer signed code that corresponds to an older software release, aka Bug ID CSCtw48681.

    Published: 20 Jun 2012
    9.3
    Critical

    CVE-2012-2493

    Last Modified: 11 Apr 2025

    The VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2.x before 2.5 MR6 on Windows, and 2.x before 2.5 MR6 and 3.x before 3.0 MR8 on Mac OS X and Linux, does not properly validate binaries that are received by the downloader process, which allows remote attackers to execute arbitrary code via vectors involving (1) ActiveX or (2) Java components, aka Bug ID CSCtw47523.

    Published: 20 Jun 2012
    4.3
    Medium

    CVE-2012-2495

    Last Modified: 11 Apr 2025

    The HostScan downloader implementation in Cisco AnyConnect Secure Mobility Client 3.x before 3.0 MR8 and Cisco Secure Desktop before 3.6.6020 does not compare the timestamp of offered software to the timestamp of installed software, which allows remote attackers to force a version downgrade by using (1) ActiveX or (2) Java components to offer signed code that corresponds to an older software release, aka Bug ID CSCtx74235.

    Published: 20 Jun 2012
    7.8
    High

    CVE-2012-3058

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.4 before 8.4(4.1), 8.5 before 8.5(1.11), and 8.6 before 8.6(1.3) allow remote attackers to cause a denial of service (device reload) via IPv6 transit traffic that triggers syslog message 110003, aka Bug ID CSCua27134.

    Published: 20 Jun 2012
    7.1
    High

    CVE-2012-3063

    Last Modified: 11 Apr 2025

    Cisco Application Control Engine (ACE) before A4(2.3) and A5 before A5(1.1), when multicontext mode is enabled, does not properly share a management IP address among multiple contexts, which allows remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances, and read or modify configuration settings, via a login attempt to a context, aka Bug ID CSCts30631, a different vulnerability than CVE-2012-3058.

    Published: 20 Jun 2012
    6.8
    Medium

    CVE-2012-2496

    Last Modified: 11 Apr 2025

    A certain Java applet in the VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 3.x before 3.0 MR7 on 64-bit Linux platforms does not properly restrict use of Java components, which allows remote attackers to execute arbitrary code via a crafted web site, aka Bug ID CSCty45925.

    Published: 20 Jun 2012
    4
    Medium

    CVE-2011-1923

    Last Modified: 11 Apr 2025

    The Diffie-Hellman key-exchange implementation in dhm.c in PolarSSL before 0.14.2 does not properly validate a public parameter, which makes it easier for man-in-the-middle attackers to obtain the shared secret key by modifying network traffic, a related issue to CVE-2011-5095.

    Published: 20 Jun 2012
    4.3
    Medium

    CVE-2012-3790

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in Adiscon LogAnalyzer before 3.4.4 and 3.5.x before 3.5.5 allows remote attackers to inject arbitrary web script or HTML via the highlight parameter in a Search action.

    Published: 20 Jun 2012
    4.3
    Medium

    CVE-2012-0716

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server 7.0 before 7.0.0.23 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 20 Jun 2012
    2.6
    Low

    CVE-2012-0717

    Last Modified: 11 Apr 2025

    IBM WebSphere Application Server 7.0 before 7.0.0.23, when a certain SSLv2 configuration with client authentication is used, allows remote attackers to bypass X.509 client-certificate authentication via unspecified vectors.

    Published: 20 Jun 2012
    5.8
    Medium

    CVE-2012-2159

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0 and 6.0.1, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 20 Jun 2012
    4.3
    Medium

    CVE-2012-2170

    Last Modified: 11 Apr 2025

    The Application Snoop Servlet in IBM WebSphere Application Server 7.0 before 7.0.0.23 does not properly restrict access, which allows remote attackers to obtain sensitive client and request information via a direct request.

    Published: 20 Jun 2012
    9.3
    Critical

    CVE-2012-2175

    Last Modified: 11 Apr 2025

    Buffer overflow in the Attachment_Times method in a certain ActiveX control in dwa85W.dll in IBM Lotus iNotes 8.5.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a long argument.

    Published: 20 Jun 2012
    4.3
    Medium

    CVE-2012-2180

    Last Modified: 11 Apr 2025

    The chaining functionality in the Distributed Relational Database Architecture (DRDA) module in IBM DB2 9.7 before FP6 and 9.8 before FP5 allows remote attackers to cause a denial of service (NULL pointer dereference, and resource consumption or daemon crash) via a crafted request.

    Published: 20 Jun 2012
    4.3
    Medium

    CVE-2012-0720

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Integration Solution Console in the Administration Console in IBM WebSphere Application Server 7.0 before 7.0.0.23 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 20 Jun 2012
    4.3
    Medium

    CVE-2012-2161

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in deferredView.jsp in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0 and 6.0.1, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 20 Jun 2012
    9.3
    Critical

    CVE-2012-2174

    Last Modified: 11 Apr 2025

    The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a crafted notes:// URL.

    Published: 20 Jun 2012
    4.9
    Medium

    CVE-2012-2192

    Last Modified: 11 Apr 2025

    The socketpair function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.1.4-FP-25 SP-02 allows local users to cause a denial of service (system crash) via a crafted application that leverages the presence of a socket on the free list.

    Published: 20 Jun 2012
    5
    Medium

    CVE-2012-2173

    Last Modified: 11 Apr 2025

    The ODBC driver in IBM Security AppScan Source 7.x and 8.x before 8.6 sends an SHA-1 hash of the connection password during connections to a solidDB database, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 20 Jun 2012
    5
    Medium

    CVE-2012-4429

    Last Modified: 11 Apr 2025

    Vino 2.28, 2.32, 3.4.2, and earlier allows remote attackers to read clipboard activity by listening on TCP port 5900.

    Published: 20 Jun 2012