CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2011-4605

    Last Modified: 11 Apr 2025

    The (1) JNDI service, (2) HA-JNDI service, and (3) HAJNDIFactory invoker servlet in JBoss Enterprise Application Platform 4.3.0 CP10 and 5.1.2, Web Platform 5.1.2, SOA Platform 4.2.0.CP05 and 4.3.0.CP05, Portal Platform 4.3 CP07 and 5.2.x before 5.2.2, and BRMS Platform before 5.3.0 do not properly restrict write access, which allows remote attackers to add, delete, or modify items in a JNDI tree via unspecified vectors.

    Published: 20 Jun 2012
    1.2
    Low

    CVE-2012-2678

    Last Modified: 11 Apr 2025

    389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server has been reset, allows remote attackers to read the plaintext password via the unhashed#user#password attribute.

    Published: 20 Jun 2012
    7.5
    High

    CVE-2009-0693

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in Wyse Device Manager (WDM) 4.7.x allow remote attackers to execute arbitrary code via (1) the User-Agent HTTP header to hserver.dll or (2) unspecified input to hagent.exe.

    Published: 19 Jun 2012
    7.5
    High

    CVE-2009-0695

    Last Modified: 11 Apr 2025

    hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain management access via a crafted query, as demonstrated by a V52 query that triggers a power-off action.

    Published: 19 Jun 2012
    7.5
    High

    CVE-2012-0802

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in Spamdyke before 4.3.0 might allow remote attackers to execute arbitrary code via vectors related to "serious errors in the usage of snprintf()/vsnprintf()" in which the return values may be larger than the size of the buffer.

    Published: 19 Jun 2012
    5
    Medium

    CVE-2012-0950

    Last Modified: 11 Apr 2025

    The Apport hook (DistUpgradeApport.py) in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uploads the /var/log/dist-upgrade directory when reporting bugs to Launchpad, which allows remote attackers to read repository credentials by viewing a public bug report. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0949.

    Published: 19 Jun 2012
    6.9
    Medium

    CVE-2012-2753

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in TrGUI.exe in the Endpoint Connect (aka EPC) GUI in Check Point Endpoint Security R73.x and E80.x on the VPN blade platform, Endpoint Security VPN R75, Endpoint Connect R73.x, and Remote Access Clients E75.x allows local users to gain privileges via a Trojan horse DLL in the current working directory.

    Published: 19 Jun 2012
    4
    Medium

    CVE-2012-3553

    Last Modified: 11 Apr 2025

    chan_skinny.c in the Skinny (aka SCCP) channel driver in Asterisk Open Source 10.x before 10.5.1 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by sending a Station Key Pad Button message and closing a connection in off-hook mode, a related issue to CVE-2012-2948.

    Published: 19 Jun 2012
    5
    Medium

    CVE-2012-3588

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in preview.php in the Plugin Newsletter plugin 1.5 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the data parameter.

    Published: 19 Jun 2012
    2.6
    Low

    CVE-2012-0954

    Last Modified: 11 Apr 2025

    APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attackers to install altered packages via a man-in-the-middle (MITM) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3587.

    Published: 19 Jun 2012
    2.6
    Low

    CVE-2012-3587

    Last Modified: 11 Apr 2025

    APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attackers to install Trojan horse packages via a man-in-the-middle (MITM) attack.

    Published: 19 Jun 2012
    7.1
    High

    CVE-2012-3006

    Last Modified: 11 Apr 2025

    The Innominate mGuard Smart HW before HW-101130 and BD before BD-101030, mGuard industrial RS, mGuard delta HW before HW-103060 and BD before BD-211010, mGuard PCI, mGuard blade, and EAGLE mGuard appliances with software before 7.5.0 do not use a sufficient source of entropy for private keys, which makes it easier for man-in-the-middle attackers to spoof (1) HTTPS or (2) SSH servers by predicting a key value.

    Published: 19 Jun 2012
    4.3
    Medium

    CVE-2012-2638

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in SmallPICT.cgi in SmallPICT before 2.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 19 Jun 2012
    4.3
    Medium

    CVE-2012-2637

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in KENT-WEB WEB PATIO 4.04 and earlier might allow remote attackers to inject arbitrary web script or HTML via a crafted cookie.

    Published: 19 Jun 2012
    4.3
    Medium

    CVE-2012-2636

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in KENT-WEB WEB PATIO 4.04 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3768

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3771

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3619

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3662

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3717

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3760

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3761

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3762

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3763

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3764

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3765

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3767

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3772

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3774

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3777

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3778

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3781

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3783

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3784

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3785

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3787

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3766

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3788

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3759

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3769

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3770

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3773

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3775

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3776

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3779

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3780

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3782

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    Unknown

    CVE-2012-3786

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Jun 2012
    7.5
    High

    CVE-2011-3671

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the nsHTMLSelectElement function in nsHTMLSelectElement.cpp in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allows remote attackers to execute arbitrary code via vectors involving removal of the parent node of an element.

    Published: 18 Jun 2012
    6.5
    Medium

    CVE-2012-2670

    Last Modified: 11 Apr 2025

    manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar.

    Published: 17 Jun 2012