CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2012-1827

    Last Modified: 11 Apr 2025

    The web service in AutoFORM PDM Archive before 7.1 does not have authorization requirements, which allows remote authenticated users to perform database operations via a SOAP request, as demonstrated by the initializeQueryDatabase2 request.

    Published: 13 Jun 2012
    3.5
    Low

    CVE-2012-2604

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in GuestAccess.jsp in the Guest/Contractor access component in the administrative interface in Bradford Network Sentry before 5.3.3 allow remote authenticated users to inject arbitrary web script or HTML via unspecified fields.

    Published: 13 Jun 2012
    6.8
    Medium

    CVE-2012-2605

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Bradford Network Sentry before 5.3.3 allow remote attackers to hijack the authentication of administrators for requests that (1) insert XSS sequences or (2) send messages to clients.

    Published: 13 Jun 2012
    5
    Medium

    CVE-2012-2606

    Last Modified: 11 Apr 2025

    The agent in Bradford Network Sentry before 5.3.3 does not require authentication for messages, which allows remote attackers to trigger the display of arbitrary text on a workstation via a crafted packet to UDP port 4567, as demonstrated by a replay attack.

    Published: 13 Jun 2012
    2.1
    Low

    CVE-2011-2208

    Last Modified: 11 Apr 2025

    Integer signedness error in the osf_getdomainname function in arch/alpha/kernel/osf_sys.c in the Linux kernel before 2.6.39.4 on the Alpha platform allows local users to obtain sensitive information from kernel memory via a crafted call.

    Published: 13 Jun 2012
    6.2
    Medium

    CVE-2011-1759

    Last Modified: 11 Apr 2025

    Integer overflow in the sys_oabi_semtimedop function in arch/arm/kernel/sys_oabi-compat.c in the Linux kernel before 2.6.39 on the ARM platform, when CONFIG_OABI_COMPAT is enabled, allows local users to gain privileges or cause a denial of service (heap memory corruption) by providing a crafted argument and leveraging a race condition.

    Published: 13 Jun 2012
    5
    Medium

    CVE-2011-1927

    Last Modified: 11 Apr 2025

    The ip_expire function in net/ipv4/ip_fragment.c in the Linux kernel before 2.6.39 does not properly construct ICMP_TIME_EXCEEDED packets after a timeout, which allows remote attackers to cause a denial of service (invalid pointer dereference) via crafted fragmented packets.

    Published: 13 Jun 2012
    2.1
    Low

    CVE-2011-2209

    Last Modified: 11 Apr 2025

    Integer signedness error in the osf_sysinfo function in arch/alpha/kernel/osf_sys.c in the Linux kernel before 2.6.39.4 on the Alpha platform allows local users to obtain sensitive information from kernel memory via a crafted call.

    Published: 13 Jun 2012
    2.1
    Low

    CVE-2011-2210

    Last Modified: 11 Apr 2025

    The osf_getsysinfo function in arch/alpha/kernel/osf_sys.c in the Linux kernel before 2.6.39.4 on the Alpha platform does not properly restrict the data size for GSI_GET_HWRPB operations, which allows local users to obtain sensitive information from kernel memory via a crafted call.

    Published: 13 Jun 2012
    7.2
    High

    CVE-2011-2182

    Last Modified: 11 Apr 2025

    The ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel before 2.6.39.1 does not properly handle memory allocation for non-initial fragments, which might allow local users to conduct buffer overflow attacks, and gain privileges or obtain sensitive information, via a crafted LDM partition table. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1017.

    Published: 13 Jun 2012
    2.1
    Low

    CVE-2011-2493

    Last Modified: 11 Apr 2025

    The ext4_fill_super function in fs/ext4/super.c in the Linux kernel before 2.6.39 does not properly initialize a certain error-report data structure, which allows local users to cause a denial of service (OOPS) by attempting to mount a crafted ext4 filesystem.

    Published: 13 Jun 2012
    7.2
    High

    CVE-2011-2211

    Last Modified: 11 Apr 2025

    The osf_wait4 function in arch/alpha/kernel/osf_sys.c in the Linux kernel before 2.6.39.4 on the Alpha platform uses an incorrect pointer, which allows local users to gain privileges by writing a certain integer value to kernel memory.

    Published: 13 Jun 2012
    8.8
    High

    CVE-2012-1889

    Last Modified: 22 Apr 2026

    Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

    Published: 13 Jun 2012
    4.3
    Medium

    CVE-2012-2041

    Last Modified: 11 Apr 2025

    CRLF injection vulnerability in the Component Browser in Adobe ColdFusion 8.0 through 9.0.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

    Published: 13 Jun 2012
    2.6
    Low

    CVE-2012-2687

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.

    Published: 13 Jun 2012
    9.3
    Critical

    CVE-2012-1523

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Center Element Remote Code Execution Vulnerability."

    Published: 12 Jun 2012
    7.2
    High

    CVE-2012-1864

    Last Modified: 11 Apr 2025

    win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver objects, which allows local users to gain privileges via a crafted application, aka "String Atom Class Name Handling Vulnerability," a different vulnerability than CVE-2012-1865.

    Published: 12 Jun 2012
    7.2
    High

    CVE-2012-1865

    Last Modified: 11 Apr 2025

    win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver objects, which allows local users to gain privileges via a crafted application, aka "String Atom Class Name Handling Vulnerability," a different vulnerability than CVE-2012-1864.

    Published: 12 Jun 2012
    7.2
    High

    CVE-2012-1866

    Last Modified: 11 Apr 2025

    win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver objects, which allows local users to gain privileges via a crafted application, aka "Clipboard Format Atom Name Handling Vulnerability."

    Published: 12 Jun 2012
    6.1
    Medium

    CVE-2012-1872

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to inject arbitrary web script or HTML via crafted character sequences with EUC-JP encoding, aka "EUC-JP Character Encoding Vulnerability."

    Published: 12 Jun 2012
    9.3
    Critical

    CVE-2012-1877

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Title Element Change Remote Code Execution Vulnerability."

    Published: 12 Jun 2012
    9.3
    Critical

    CVE-2012-1878

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "OnBeforeDeactivate Event Remote Code Execution Vulnerability."

    Published: 12 Jun 2012
    8.1
    High

    CVE-2012-1879

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access an undefined memory location, aka "insertAdjacentText Remote Code Execution Vulnerability."

    Published: 12 Jun 2012
    4.3
    Medium

    CVE-2012-1882

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 9 does not block cross-domain scrolling events, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Scrolling Events Information Disclosure Vulnerability."

    Published: 12 Jun 2012
    9.3
    Critical

    CVE-2012-0173

    Last Modified: 11 Apr 2025

    The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remote attackers to execute arbitrary code by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, aka "Remote Desktop Protocol Vulnerability," a different vulnerability than CVE-2012-0002.

    Published: 12 Jun 2012
    9.3
    Critical

    CVE-2012-1849

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Microsoft Lync 2010, 2010 Attendee, and 2010 Attendant allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .ocsmeet file, aka "Lync Insecure Library Loading Vulnerability."

    Published: 12 Jun 2012
    9.3
    Critical

    CVE-2012-1855

    Last Modified: 11 Apr 2025

    Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly handle function pointers, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Memory Access Vulnerability."

    Published: 12 Jun 2012
    4.3
    Medium

    CVE-2012-1857

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Enterprise Portal component in Microsoft Dynamics AX 2012 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Dynamics AX Enterprise Portal XSS Vulnerability."

    Published: 12 Jun 2012
    4.3
    Medium

    CVE-2012-1858

    Last Modified: 11 Apr 2025

    The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document, aka "HTML Sanitization Vulnerability."

    Published: 12 Jun 2012
    8.4
    High

    CVE-2012-1867

    Last Modified: 11 Apr 2025

    Integer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted TrueType font file that triggers incorrect memory allocation, aka "Font Resource Refcount Integer Overflow Vulnerability."

    Published: 12 Jun 2012
    4.3
    Medium

    CVE-2012-1873

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 7 through 9 does not properly create and initialize string data, which allows remote attackers to obtain sensitive information from process memory via a crafted HTML document, aka "Null Byte Information Disclosure Vulnerability."

    Published: 12 Jun 2012
    9.3
    Critical

    CVE-2012-1874

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows user-assisted remote attackers to execute arbitrary code by accessing a deleted object, aka "Developer Toolbar Remote Code Execution Vulnerability."

    Published: 12 Jun 2012
    9.3
    Critical

    CVE-2012-1875

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Same ID Property Remote Code Execution Vulnerability."

    Published: 12 Jun 2012
    9.3
    Critical

    CVE-2012-1881

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "OnRowsInserted Event Remote Code Execution Vulnerability."

    Published: 12 Jun 2012
    6.9
    Medium

    CVE-2012-1868

    Last Modified: 11 Apr 2025

    Race condition in the thread-creation implementation in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3 allows local users to gain privileges via a crafted application, aka "Win32k.sys Race Condition Vulnerability."

    Published: 12 Jun 2012
    9.3
    Critical

    CVE-2012-1876

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access a nonexistent object, leading to a heap-based buffer overflow, aka "Col Element Remote Code Execution Vulnerability," as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.

    Published: 12 Jun 2012
    9.3
    Critical

    CVE-2012-1880

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "insertRow Remote Code Execution Vulnerability."

    Published: 12 Jun 2012
    9.3
    Critical

    CVE-2012-0677

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Apple iTunes before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted .m3u playlist.

    Published: 12 Jun 2012
    9.8
    Critical

    CVE-2012-1723

    Last Modified: 21 Apr 2026

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

    Published: 12 Jun 2012
    10
    Critical

    CVE-2012-1716

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, and 5 update 35 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Swing.

    Published: 12 Jun 2012
    10
    Critical

    CVE-2012-1721

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, and 6 update 32 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2012-1722.

    Published: 12 Jun 2012
    5
    Medium

    CVE-2012-1724

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, and 6 update 32 and earlier, allows remote attackers to affect availability, related to JAXP.

    Published: 12 Jun 2012
    3.3
    Low

    CVE-2012-2148

    Last Modified: 21 Nov 2024

    An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies

    Published: 12 Jun 2012
    7.2
    High

    CVE-2012-0217

    Last Modified: 11 Apr 2025

    The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1; and possibly other operating systems, when running on an Intel processor, incorrectly uses the sysret path in cases where a certain address is not a canonical address, which allows local users to gain privileges via a crafted application. NOTE: because this issue is due to incorrect use of the Intel specification, it should have been split into separate identifiers; however, there was some value in preserving the original mapping of the multi-codebase coordinated-disclosure effort to a single identifier.

    Published: 12 Jun 2012
    1.9
    Low

    CVE-2012-0218

    Last Modified: 11 Apr 2025

    Xen 3.4, 4.0, and 4.1, when the guest OS has not registered a handler for a syscall or sysenter instruction, does not properly clear a flag for exception injection when injecting a General Protection Fault, which allows local PV guest OS users to cause a denial of service (guest crash) by later triggering an exception that would normally be handled within Xen.

    Published: 12 Jun 2012
    4.6
    Medium

    CVE-2012-1167

    Last Modified: 11 Apr 2025

    The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the JBossWebRealm, does not properly check the permissions created by the WebPermissionMapping class, which allows remote authenticated users to access arbitrary applications.

    Published: 12 Jun 2012
    7.5
    High

    CVE-2012-1711

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to CORBA.

    Published: 12 Jun 2012
    2.1
    Low

    CVE-2012-1717

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows local users to affect confidentiality via unknown vectors related to printing on Solaris or Linux.

    Published: 12 Jun 2012
    5
    Medium

    CVE-2012-1718

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect availability via unknown vectors related to Security.

    Published: 12 Jun 2012
    10
    Critical

    CVE-2012-1725

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, and 5 update 35 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

    Published: 12 Jun 2012