CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2012-2660

    Last Modified: 11 Apr 2025

    actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly consider differences in parameter handling between the Active Record component and the Rack interface, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks via a crafted request, as demonstrated by certain "[nil]" values, a related issue to CVE-2012-2694.

    Published: 31 May 2012
    5
    Medium

    CVE-2012-2661

    Last Modified: 11 Apr 2025

    The Active Record component in Ruby on Rails 3.0.x before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly implement the passing of request data to a where method in an ActiveRecord class, which allows remote attackers to conduct certain SQL injection attacks via nested query parameters that leverage unintended recursion, a related issue to CVE-2012-2695.

    Published: 31 May 2012
    7.5
    High

    CVE-2012-4456

    Last Modified: 11 Apr 2025

    The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create, or delete arbitrary services.

    Published: 31 May 2012
    6.8
    Medium

    CVE-2010-5099

    Last Modified: 11 Apr 2025

    The fileDenyPattern functionality in the PHP file inclusion protection API in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 does not properly filter file types, which allows remote attackers to bypass intended access restrictions and access arbitrary PHP files, as demonstrated using path traversal sequences with %00 null bytes and CVE-2010-3714 to read the TYPO3 encryption key from localconf.php.

    Published: 30 May 2012
    4.3
    Medium

    CVE-2012-2143

    Last Modified: 11 Apr 2025

    The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.

    Published: 30 May 2012
    9.8
    Critical

    CVE-2012-4406

    Last Modified: 11 Apr 2025

    OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.

    Published: 30 May 2012
    4
    Medium

    CVE-2012-2655

    Last Modified: 11 Apr 2025

    PostgreSQL 8.3.x before 8.3.19, 8.4.x before 8.4.12, 9.0.x before 9.0.8, and 9.1.x before 9.1.4 allows remote authenticated users to cause a denial of service (server crash) by adding the (1) SECURITY DEFINER or (2) SET attributes to a procedural language's call handler.

    Published: 30 May 2012
    7.5
    High

    CVE-2012-2763

    Last Modified: 11 Apr 2025

    Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.

    Published: 30 May 2012
    4.3
    Medium

    CVE-2012-0220

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the meta plugin (Plugin/meta.pm) in ikiwiki before 3.20120516 allow remote attackers to inject arbitrary web script or HTML via the (1) author or (2) authorurl meta tags.

    Published: 29 May 2012
    7.5
    High

    CVE-2012-2952

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in add_ons.php in Jaow 2.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the add_ons parameter.

    Published: 29 May 2012
    Unknown

    CVE-2012-2951

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-6587. Reason: This candidate is a duplicate of CVE-2007-6587. Notes: All CVE users should reference CVE-2007-6587 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 29 May 2012
    10
    Critical

    CVE-2012-2949

    Last Modified: 11 Apr 2025

    The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, which allows remote attackers to gain privileges via a crafted application.

    Published: 29 May 2012
    7.2
    High

    CVE-2012-2136

    Last Modified: 11 Apr 2025

    The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before 3.4.5 does not properly validate a certain length value, which allows local users to cause a denial of service (heap-based buffer overflow and system crash) or possibly gain privileges by leveraging access to a TUN/TAP device.

    Published: 29 May 2012
    2.1
    Low

    CVE-2012-2657

    Last Modified: 11 Apr 2025

    Buffer overflow in the SQLDriverConnect function in unixODBC 2.0.10, 2.3.1, and earlier allows local users to cause a denial of service (crash) via a long string in the FILEDSN option. NOTE: this issue might not be a vulnerability, since the ability to set this option typically implies that the attacker already has legitimate access to cause a DoS or execute code, and therefore the issue would not cross privilege boundaries. There may be limited attack scenarios if isql command-line options are exposed to an attacker, although it seems likely that other, more serious issues would also be exposed, and this issue might not cross privilege boundaries in that context.

    Published: 29 May 2012
    2.1
    Low

    CVE-2012-2658

    Last Modified: 11 Apr 2025

    Buffer overflow in the SQLDriverConnect function in unixODBC 2.3.1 allows local users to cause a denial of service (crash) via a long string in the DRIVER option. NOTE: this issue might not be a vulnerability, since the ability to set this option typically implies that the attacker already has legitimate access to cause a DoS or execute code, and therefore the issue would not cross privilege boundaries. There may be limited attack scenarios if isql command-line options are exposed to an attacker, although it seems likely that other, more serious issues would also be exposed, and this issue might not cross privilege boundaries in that context.

    Published: 29 May 2012
    3.3
    Low

    CVE-2012-1906

    Last Modified: 11 Apr 2025

    Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 uses predictable file names when installing Mac OS X packages from a remote source, which allows local users to overwrite arbitrary files or install arbitrary packages via a symlink attack on a temporary file in /tmp.

    Published: 29 May 2012
    7.5
    High

    CVE-2012-2656

    Last Modified: 21 Nov 2024

    An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote attacker obtain sensitive information.

    Published: 29 May 2012
    4.4
    Medium

    CVE-2012-2652

    Last Modified: 11 Apr 2025

    The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, which allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.

    Published: 28 May 2012
    6.5
    Medium

    CVE-2012-2435

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the captcha module in Pligg CMS before 1.2.2 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the captcha parameter to module.php, as demonstrated by cross-site request forgery (CSRF) attacks.

    Published: 27 May 2012
    4.3
    Medium

    CVE-2012-2436

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to inject arbitrary web script or HTML via (1) an arbitrary parameter in a move or (2) minimize action to admin/admin_index.php; (3) the karma_username parameter to module.php in the karma module; (4) q_1_low, (5) q_1_high, (6) q_2_low, or (7) q_2_high parameter in a configure action to module.php in the captcha module; or (8) the edit parameter to module.php in the admin_language module.

    Published: 27 May 2012
    4.3
    Medium

    CVE-2012-2936

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) page parameter to (a) admin/admin_comments.php or (b) admin/admin_links.php; or list parameter in a (3) move or (4) minimize action to (c) admin/admin_index.php.

    Published: 27 May 2012
    4.3
    Medium

    CVE-2012-2938

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Travelon Express 6.2.2 allow remote attackers to inject arbitrary web script or HTML via the holiday name field to (1) holiday_add.php or (2) holiday_view.php.

    Published: 27 May 2012
    6.5
    Medium

    CVE-2012-2939

    Last Modified: 11 Apr 2025

    Multiple unrestricted file upload vulnerabilities in Travelon Express 6.2.2 allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension using (1) airline-edit.php, (2) hotel-image-add.php, or (3) hotel-add.php.

    Published: 27 May 2012
    4.3
    Medium

    CVE-2012-2940

    Last Modified: 11 Apr 2025

    MediaChance Real-DRAW PRO 5.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted (1) PNG, (2) WMF, (3) PSD, (4) TGA, (5) TTF, (6) BMP, (7) TIFF, or (8) PCX file.

    Published: 27 May 2012
    4.3
    Medium

    CVE-2012-2941

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in search/ in Yandex.Server 2010 9.0 Enterprise allows remote attackers to inject arbitrary web script or HTML via the text parameter.

    Published: 27 May 2012
    5.1
    Medium

    CVE-2012-2942

    Last Modified: 11 Apr 2025

    Buffer overflow in the trash buffer in the header capture functionality in HAProxy before 1.4.21, when global.tune.bufsize is set to a value greater than the default and header rewriting is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors.

    Published: 27 May 2012
    5
    Medium

    CVE-2012-2943

    Last Modified: 11 Apr 2025

    CRLF injection vulnerability in cryptographp.inc.php in Cryptographp allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the cfg parameter.

    Published: 27 May 2012
    7.5
    High

    CVE-2012-2937

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) list parameter in a move action to admin/admin_index.php, (2) display parameter in a minimize action to admin/admin_index.php, (3) enabled[] parameter to admin/admin_users.php, or (4) msg_id to the module.php in the simple_messaging module.

    Published: 27 May 2012
    4.3
    Medium

    CVE-2012-2235

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Support Incident Tracker (SiT!) 3.65 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter to index.php, which is not properly handled in an error message.

    Published: 27 May 2012
    4.3
    Medium

    CVE-2012-2935

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Checkout/pages/main.php in OSCommerce Online Merchant 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the value_title parameter, a different vulnerability than CVE-2012-1059.

    Published: 27 May 2012
    2.6
    Low

    CVE-2012-1413

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in zc_install/includes/modules/pages/database_setup/header_php.php in Zen Cart 1.5.0 and earlier, when the software is being installed, allows remote attackers to inject arbitrary web script or HTML via the db_username parameter to zc_install/index.php.

    Published: 27 May 2012
    2.6
    Low

    CVE-2012-1792

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Setup/Application/Install/RPC/DBCheck.php in OSCommerce Online Merchant 3.0.2, when the software is being installed, allows remote attackers to inject arbitrary web script or HTML via the name parameter to oscommerce/index.php, which is not properly handled in an error message. NOTE: this might not be a vulnerability, since the ability to access oscommerce/index.php during installation may already imply administrator privileges.

    Published: 27 May 2012
    4
    Medium

    CVE-2012-4457

    Last Modified: 11 Apr 2025

    OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant.

    Published: 26 May 2012
    2.1
    Low

    CVE-2012-4571

    Last Modified: 11 Apr 2025

    Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.

    Published: 26 May 2012
    9.3
    Critical

    CVE-2012-2176

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in a certain ActiveX control in qp2.cab in IBM Lotus Quickr 8.2 before 8.2.0.27-002a for Domino allow remote attackers to execute arbitrary code via a long argument to the (1) Attachment_Times or (2) Import_Times method.

    Published: 25 May 2012
    10
    Critical

    CVE-2012-2568

    Last Modified: 11 Apr 2025

    d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the administrator password via unspecified vectors.

    Published: 25 May 2012
    7.2
    High

    CVE-2012-1824

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Measuresoft ScadaPro Client before 4.0.0 and ScadaPro Server before 4.0.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory.

    Published: 25 May 2012
    7.8
    High

    CVE-2012-2426

    Last Modified: 11 Apr 2025

    The server in xArrow before 3.4.1 does not properly allocate memory, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via unspecified vectors.

    Published: 25 May 2012
    10
    Critical

    CVE-2012-2427

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via packets that trigger an invalid free operation.

    Published: 25 May 2012
    10
    Critical

    CVE-2012-2429

    Last Modified: 11 Apr 2025

    The server in xArrow before 3.4.1 performs an invalid read operation, which allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 25 May 2012
    10
    Critical

    CVE-2012-2428

    Last Modified: 11 Apr 2025

    Integer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via a crafted packet that triggers an out-of-bounds read operation.

    Published: 25 May 2012
    4.9
    Medium

    CVE-2011-2518

    Last Modified: 11 Apr 2025

    The tomoyo_mount_acl function in security/tomoyo/mount.c in the Linux kernel before 2.6.39.2 calls the kern_path function with arguments taken directly from a mount system call, which allows local users to cause a denial of service (OOPS) or possibly have unspecified other impact via a NULL value for the device name.

    Published: 24 May 2012
    7.5
    High

    CVE-2011-3103

    Last Modified: 11 Apr 2025

    Google V8, as used in Google Chrome before 19.0.1084.52, does not properly perform garbage collection, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code.

    Published: 24 May 2012
    5
    Medium

    CVE-2011-3104

    Last Modified: 11 Apr 2025

    Skia, as used in Google Chrome before 19.0.1084.52, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 24 May 2012
    10
    Critical

    CVE-2011-3108

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 19.0.1084.52 allows remote attackers to execute arbitrary code via vectors related to the browser cache.

    Published: 24 May 2012
    7.5
    High

    CVE-2011-3110

    Last Modified: 11 Apr 2025

    The PDF functionality in Google Chrome before 19.0.1084.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger out-of-bounds write operations.

    Published: 24 May 2012
    5
    Medium

    CVE-2011-3111

    Last Modified: 11 Apr 2025

    Google V8, as used in Google Chrome before 19.0.1084.52, allows remote attackers to cause a denial of service (invalid read operation) via unspecified vectors.

    Published: 24 May 2012
    5
    Medium

    CVE-2011-3112

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the PDF functionality in Google Chrome before 19.0.1084.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via an invalid encrypted document.

    Published: 24 May 2012
    7.5
    High

    CVE-2011-3113

    Last Modified: 11 Apr 2025

    The PDF functionality in Google Chrome before 19.0.1084.52 does not properly perform a cast of an unspecified variable during handling of color spaces, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.

    Published: 24 May 2012
    7.5
    High

    CVE-2011-3115

    Last Modified: 11 Apr 2025

    Google V8, as used in Google Chrome before 19.0.1084.52, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger "type corruption."

    Published: 24 May 2012