CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2012-2347

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-5102. Reason: This candidate is a duplicate of CVE-2010-5102. Notes: All CVE users should reference CVE-2010-5102 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 May 2012
    3.5
    Low

    CVE-2012-2340

    Last Modified: 11 Apr 2025

    The Contact Forms module 7.x-1.x before 7.x-1.2 for Drupal does not specify sufficiently restrictive permissions, which allows remote authenticated users with the "access the site-wide contact form" permission to modify the module settings via unspecified vectors.

    Published: 21 May 2012
    3.5
    Low

    CVE-2010-5098

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the FORM content object in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 21 May 2012
    4.3
    Medium

    CVE-2012-0296

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 21 May 2012
    4.3
    Medium

    CVE-2012-2339

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Glossary module 6.x-1.x before 6.x-1.8 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "taxonomy information."

    Published: 21 May 2012
    Unknown

    CVE-2012-2348

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-5103. Reason: This candidate is a duplicate of CVE-2010-5103. Notes: All CVE users should reference CVE-2010-5103 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 May 2012
    10
    Critical

    CVE-2012-2561

    Last Modified: 11 Apr 2025

    HP Business Service Management (BSM) 9.12 does not properly restrict the uploading of .war files, which allows remote attackers to execute arbitrary JSP code within the JBOSS Application Server component via a crafted request to TCP port 1098, 1099, or 4444.

    Published: 21 May 2012
    Unknown

    CVE-2012-2349

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-5104. Reason: This candidate is a reservation duplicate of CVE-2010-5104. Notes: All CVE users should reference CVE-2010-5104 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 May 2012
    4.3
    Medium

    CVE-2012-2901

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Profile List in the Joomla Content Editor (JCE) component before 2.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the search parameter to administrator/index.php.

    Published: 21 May 2012
    6
    Medium

    CVE-2012-2902

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in editor/extensions/browser/file.php in the Joomla Content Editor (JCE) component before 2.1 for Joomla!, when chunking is set to greater than zero, allows remote authors to execute arbitrary PHP code by uploading a PHP file with a double extension as demonstrated by .jpg.pht.

    Published: 21 May 2012
    4.3
    Medium

    CVE-2012-2903

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 7.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to group.php, or the (2) target_language or (3) target_flag parameter to translate.php.

    Published: 21 May 2012
    5
    Medium

    CVE-2012-2905

    Last Modified: 11 Apr 2025

    Artiphp CMS 5.5.0 Neo (r422) stores database backups with predictable names under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request.

    Published: 21 May 2012
    4.3
    Medium

    CVE-2012-2906

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in artpublic/recommandation/index.php in Artiphp CMS 5.5.0 Neo (r422) allow remote attackers to inject arbitrary web script or HTML via the (1) add_img_name_post, (2) asciiart_post, (3) expediteur, (4) titre_sav, or (5) z39d27af885b32758ac0e7d4014a61561 parameter.

    Published: 21 May 2012
    2.6
    Low

    CVE-2012-2907

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the aberdeen_breadcrumb function in template.php in the Aberdeen theme 6.x-1.x before 6.x-1.11 for Drupal, when set to append the content title to the breadcrumb, allows remote attackers to inject arbitrary web script or HTML via the content title in a breadcrumb.

    Published: 21 May 2012
    4.3
    Medium

    CVE-2012-2910

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in SiliSoftware phpThumb() 1.7.11 allow remote attackers to inject arbitrary web script or HTML via the (1) dir parameter to demo/phpThumb.demo.random.php or (2) title parameter to demo/phpThumb.demo.showpic.php.

    Published: 21 May 2012
    4.3
    Medium

    CVE-2012-2911

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in backupDB.php in SiliSoftware backupDB() 1.2.7a allows remote attackers to inject arbitrary web script or HTML via the onlyDB parameter.

    Published: 21 May 2012
    4.3
    Medium

    CVE-2012-2912

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the LeagueManager plugin 3.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter in the show-league page or (2) season parameter in the team page to wp-admin/admin.php.

    Published: 21 May 2012
    4.3
    Medium

    CVE-2012-2913

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Leaflet plugin 0.0.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) leaflet_layer.php or (2) leaflet_marker.php, as reachable through wp-admin/admin.php.

    Published: 21 May 2012
    4.3
    Medium

    CVE-2012-2914

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in captchademo.php in Unijimpe Captcha allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Published: 21 May 2012
    7.5
    High

    CVE-2012-2908

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in admin/bbcodes.php in Viscacha 0.8.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) bbcodeexample, (2) buttonimage, or (3) bbcodetag parameter.

    Published: 21 May 2012
    4.3
    Medium

    CVE-2012-2909

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Viscacha 0.8.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) text field in the Private Messages System, (2) Bad Word field in Zensur, or (3) Portal or (4) Topic field in Kommentar.

    Published: 21 May 2012
    9.3
    Critical

    CVE-2012-2915

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Lattice Semiconductor PAC-Designer 6.2.1344 allows remote attackers to execute arbitrary code via a long string in a Value tag in a SymbolicSchematicData definition tag in PAC Design (.pac) file.

    Published: 21 May 2012
    4.3
    Medium

    CVE-2012-2917

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Share and Follow plugin 1.80.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the CDN API Key (cnd-key) in a share-and-follow-menu page to wp-admin/admin.php.

    Published: 21 May 2012
    4.3
    Medium

    CVE-2012-2904

    Last Modified: 11 Apr 2025

    player.swf in LongTail JW Player 5.9 allows remote attackers to conduct cross-site scripting (XSS) attacks to inject arbitrary web script or HTML via multiple "javascript:" sequences in the debug parameter.

    Published: 21 May 2012
    4.3
    Medium

    CVE-2012-2916

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in sabre_class_admin.php in the SABRE plugin before 2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the active_option parameter to wp-admin/tools.php.

    Published: 21 May 2012
    7.5
    High

    CVE-2012-2386

    Last Modified: 11 Apr 2025

    Integer overflow in the phar_parse_tarfile function in tar.c in the phar extension in PHP before 5.3.14 and 5.4.x before 5.4.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted tar file that triggers a heap-based buffer overflow.

    Published: 21 May 2012
    3.3
    Low

    CVE-2012-2392

    Last Modified: 11 Apr 2025

    Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allows remote attackers to cause a denial of service (infinite loop) via vectors related to the (1) ANSI MAP, (2) ASF, (3) IEEE 802.11, (4) IEEE 802.3, and (5) LTP dissectors.

    Published: 21 May 2012
    3.3
    Low

    CVE-2012-2393

    Last Modified: 11 Apr 2025

    epan/dissectors/packet-diameter.c in the DIAMETER dissector in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 does not properly construct certain array data structures, which allows remote attackers to cause a denial of service (application crash) via a crafted packet that triggers incorrect memory allocation.

    Published: 21 May 2012
    3.3
    Low

    CVE-2012-2394

    Last Modified: 11 Apr 2025

    Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 on the SPARC and Itanium platforms does not properly perform data alignment for a certain structure member, which allows remote attackers to cause a denial of service (application crash) via a (1) ICMP or (2) ICMPv6 Echo Request packet.

    Published: 21 May 2012
    7.8
    High

    CVE-2012-6701

    Last Modified: 12 Apr 2025

    Integer overflow in fs/aio.c in the Linux kernel before 3.4.1 allows local users to cause a denial of service or possibly have unspecified other impact via a large AIO iovec.

    Published: 21 May 2012
    10
    Critical

    CVE-2012-2376

    Last Modified: 11 Apr 2025

    Buffer overflow in the com_print_typeinfo function in PHP 5.4.3 and earlier on Windows allows remote attackers to execute arbitrary code via crafted arguments that trigger incorrect handling of COM object VARIANT types, as exploited in the wild in May 2012.

    Published: 19 May 2012
    3.3
    Low

    CVE-2012-2093

    Last Modified: 11 Apr 2025

    src/common/latex.py in Gajim 0.15 allows local users to overwrite arbitrary files via a symlink attack on a temporary latex file, related to the get_tmpfile_name function.

    Published: 18 May 2012
    7.8
    High

    CVE-2012-2320

    Last Modified: 11 Apr 2025

    ConnMan before 0.85 does not ensure that netlink messages originate from the kernel, which allows remote attackers to bypass intended access restrictions and cause a denial of service via a crafted netlink message.

    Published: 18 May 2012
    10
    Critical

    CVE-2012-2321

    Last Modified: 11 Apr 2025

    The loopback plug-in in ConnMan before 0.85 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) host name or (2) domain name in a DHCP reply.

    Published: 18 May 2012
    6.8
    Medium

    CVE-2012-2341

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Take Control module 6.x-2.x before 6.x-2.2 for Drupal allows remote attackers to hijack the authentication of unspecified users for Ajax requests that manipulate files.

    Published: 18 May 2012
    3.3
    Low

    CVE-2012-2120

    Last Modified: 11 Apr 2025

    latex2man in texlive-extra-utils 2011.20120322, and possibly other versions or packages, when used with the H or T option, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

    Published: 18 May 2012
    5
    Medium

    CVE-2012-2322

    Last Modified: 11 Apr 2025

    Integer overflow in the dhcpv6_get_option function in gdhcp/client.c in ConnMan before 0.85 allows remote attackers to cause a denial of service (infinite loop and crash) via an invalid length value in a DHCP packet.

    Published: 18 May 2012
    6.9
    Medium

    CVE-2012-2010

    Last Modified: 11 Apr 2025

    The ACMELOGIN implementation in HP OpenVMS 8.3 and 8.4 on the Alpha platform, and 8.3, 8.3-1H1, and 8.4 on the Itanium platform, when the SYS$ACM system service is enabled, allows local users to gain privileges via unspecified vectors.

    Published: 18 May 2012
    5.8
    Medium

    CVE-2012-1589

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in the Form API in Drupal 7.x before 7.13 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted parameters in a destination URL.

    Published: 18 May 2012
    9.3
    Critical

    CVE-2012-2406

    Last Modified: 11 Apr 2025

    RealNetworks RealPlayer before 15.0.4.53, and RealPlayer SP 1.0 through 1.1.5, does not properly parse ASMRuleBook data in RealMedia files, which allows remote attackers to execute arbitrary code via a crafted file.

    Published: 18 May 2012
    9.3
    Critical

    CVE-2012-2411

    Last Modified: 11 Apr 2025

    Buffer overflow in RealNetworks RealPlayer before 15.0.4.53, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted RealJukebox Media file.

    Published: 18 May 2012
    4
    Medium

    CVE-2012-2373

    Last Modified: 11 Apr 2025

    The Linux kernel before 3.4.5 on the x86 platform, when Physical Address Extension (PAE) is enabled, does not properly use the Page Middle Directory (PMD), which allows local users to cause a denial of service (panic) via a crafted application that triggers a race condition.

    Published: 17 May 2012
    4.9
    Medium

    CVE-2012-2390

    Last Modified: 11 Apr 2025

    Memory leak in mm/hugetlb.c in the Linux kernel before 3.4.2 allows local users to cause a denial of service (memory consumption or system crash) via invalid MAP_HUGETLB mmap operations.

    Published: 17 May 2012
    9.3
    Critical

    CVE-2012-0667

    Last Modified: 11 Apr 2025

    Integer signedness error in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted QTVR movie file.

    Published: 16 May 2012
    9.3
    Critical

    CVE-2012-0668

    Last Modified: 11 Apr 2025

    Buffer overflow in Apple QuickTime before 7.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with RLE encoding.

    Published: 16 May 2012
    9.3
    Critical

    CVE-2012-0265

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted pathname for a file.

    Published: 16 May 2012
    9.3
    Critical

    CVE-2012-0663

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in Apple QuickTime before 7.7.2 on Windows allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TeXML file.

    Published: 16 May 2012
    9.3
    Critical

    CVE-2012-0664

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted text track in a movie file.

    Published: 16 May 2012
    9.3
    Critical

    CVE-2012-0665

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Apple QuickTime before 7.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.264 encoding.

    Published: 16 May 2012
    9.3
    Critical

    CVE-2012-0670

    Last Modified: 11 Apr 2025

    Integer overflow in Apple QuickTime before 7.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted sean atom in a movie file.

    Published: 16 May 2012