CVE-2011-4605
Last Modified: 11 Apr 2025The (1) JNDI service, (2) HA-JNDI service, and (3) HAJNDIFactory invoker servlet in JBoss Enterprise Application Platform 4.3.0 CP10 and 5.1.2, Web Platform 5.1.2, SOA Platform 4.2.0.CP05 and 4.3.0.CP05, Portal Platform 4.3 CP07 and 5.2.x before 5.2.2, and BRMS Platform before 5.3.0 do not properly restrict write access, which allows remote attackers to add, delete, or modify items in a JNDI tree via unspecified vectors.
CVE-2012-2678
Last Modified: 11 Apr 2025389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server has been reset, allows remote attackers to read the plaintext password via the unhashed#user#password attribute.
CVE-2009-0693
Last Modified: 11 Apr 2025Multiple buffer overflows in Wyse Device Manager (WDM) 4.7.x allow remote attackers to execute arbitrary code via (1) the User-Agent HTTP header to hserver.dll or (2) unspecified input to hagent.exe.
CVE-2009-0695
Last Modified: 11 Apr 2025hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain management access via a crafted query, as demonstrated by a V52 query that triggers a power-off action.
CVE-2012-0802
Last Modified: 11 Apr 2025Multiple buffer overflows in Spamdyke before 4.3.0 might allow remote attackers to execute arbitrary code via vectors related to "serious errors in the usage of snprintf()/vsnprintf()" in which the return values may be larger than the size of the buffer.
CVE-2012-0950
Last Modified: 11 Apr 2025The Apport hook (DistUpgradeApport.py) in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uploads the /var/log/dist-upgrade directory when reporting bugs to Launchpad, which allows remote attackers to read repository credentials by viewing a public bug report. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0949.
CVE-2012-2753
Last Modified: 11 Apr 2025Untrusted search path vulnerability in TrGUI.exe in the Endpoint Connect (aka EPC) GUI in Check Point Endpoint Security R73.x and E80.x on the VPN blade platform, Endpoint Security VPN R75, Endpoint Connect R73.x, and Remote Access Clients E75.x allows local users to gain privileges via a Trojan horse DLL in the current working directory.
CVE-2012-3553
Last Modified: 11 Apr 2025chan_skinny.c in the Skinny (aka SCCP) channel driver in Asterisk Open Source 10.x before 10.5.1 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by sending a Station Key Pad Button message and closing a connection in off-hook mode, a related issue to CVE-2012-2948.
CVE-2012-3588
Last Modified: 11 Apr 2025Directory traversal vulnerability in preview.php in the Plugin Newsletter plugin 1.5 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the data parameter.
CVE-2012-0954
Last Modified: 11 Apr 2025APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attackers to install altered packages via a man-in-the-middle (MITM) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3587.
CVE-2012-3587
Last Modified: 11 Apr 2025APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attackers to install Trojan horse packages via a man-in-the-middle (MITM) attack.
CVE-2012-3006
Last Modified: 11 Apr 2025The Innominate mGuard Smart HW before HW-101130 and BD before BD-101030, mGuard industrial RS, mGuard delta HW before HW-103060 and BD before BD-211010, mGuard PCI, mGuard blade, and EAGLE mGuard appliances with software before 7.5.0 do not use a sufficient source of entropy for private keys, which makes it easier for man-in-the-middle attackers to spoof (1) HTTPS or (2) SSH servers by predicting a key value.
CVE-2012-2638
Last Modified: 11 Apr 2025Cross-site scripting (XSS) vulnerability in SmallPICT.cgi in SmallPICT before 2.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2012-2637
Last Modified: 11 Apr 2025Cross-site scripting (XSS) vulnerability in KENT-WEB WEB PATIO 4.04 and earlier might allow remote attackers to inject arbitrary web script or HTML via a crafted cookie.
CVE-2012-2636
Last Modified: 11 Apr 2025Cross-site scripting (XSS) vulnerability in KENT-WEB WEB PATIO 4.04 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2012-3768
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3771
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3619
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3662
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3717
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3760
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3761
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3762
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3763
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3764
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3765
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3767
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3772
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3774
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3777
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3778
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3781
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3783
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3784
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3785
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3787
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3766
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3788
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3759
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3769
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3770
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3773
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3775
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3776
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3779
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3780
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3782
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2012-3786
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2011-3671
Last Modified: 11 Apr 2025Use-after-free vulnerability in the nsHTMLSelectElement function in nsHTMLSelectElement.cpp in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allows remote attackers to execute arbitrary code via vectors involving removal of the parent node of an element.
CVE-2012-2670
Last Modified: 11 Apr 2025manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar.
