CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2012-0666

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the plugin in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted QTMovie object.

    Published: 16 May 2012
    9.3
    Critical

    CVE-2012-0669

    Last Modified: 11 Apr 2025

    Buffer overflow in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with Sorenson encoding.

    Published: 16 May 2012
    9.3
    Critical

    CVE-2012-0671

    Last Modified: 11 Apr 2025

    Apple QuickTime before 7.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .pict file.

    Published: 16 May 2012
    10
    Critical

    CVE-2011-3092

    Last Modified: 11 Apr 2025

    The regex implementation in Google V8, as used in Google Chrome before 19.0.1084.46, allows remote attackers to cause a denial of service (invalid write operation) or possibly have unspecified other impact via unknown vectors.

    Published: 16 May 2012
    5
    Medium

    CVE-2011-3083

    Last Modified: 11 Apr 2025

    browser/profiles/profile_impl_io_data.cc in Google Chrome before 19.0.1084.46 does not properly handle a malformed ftp URL in the SRC attribute of a VIDEO element, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted web page.

    Published: 16 May 2012
    7.5
    High

    CVE-2011-3084

    Last Modified: 11 Apr 2025

    Google Chrome before 19.0.1084.46 does not use a dedicated process for the loading of links found on an internal page, which might allow attackers to bypass intended sandbox restrictions via a crafted page.

    Published: 16 May 2012
    10
    Critical

    CVE-2011-3087

    Last Modified: 11 Apr 2025

    Google Chrome before 19.0.1084.46 does not properly perform window navigation, which has unspecified impact and remote attack vectors.

    Published: 16 May 2012
    5
    Medium

    CVE-2011-3088

    Last Modified: 11 Apr 2025

    Google Chrome before 19.0.1084.46 does not properly draw hairlines, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 16 May 2012
    5
    Medium

    CVE-2011-3094

    Last Modified: 11 Apr 2025

    Google Chrome before 19.0.1084.46 does not properly handle Tibetan text, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 16 May 2012
    10
    Critical

    CVE-2011-3095

    Last Modified: 11 Apr 2025

    The OGG container in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an out-of-bounds write.

    Published: 16 May 2012
    7.5
    High

    CVE-2011-3096

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 19.0.1084.46 on Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging an error in the GTK implementation of the omnibox.

    Published: 16 May 2012
    10
    Critical

    CVE-2011-3097

    Last Modified: 11 Apr 2025

    The PDF functionality in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging an out-of-bounds write error in the implementation of sampled functions.

    Published: 16 May 2012
    5
    Medium

    CVE-2011-3100

    Last Modified: 11 Apr 2025

    Google Chrome before 19.0.1084.46 does not properly draw dash paths, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 16 May 2012
    7.2
    High

    CVE-2012-2337

    Last Modified: 11 Apr 2025

    sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address.

    Published: 16 May 2012
    10
    Critical

    CVE-2011-3091

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the IndexedDB implementation in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 16 May 2012
    10
    Critical

    CVE-2011-3099

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the PDF functionality in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a malformed name for the font encoding.

    Published: 16 May 2012
    10
    Critical

    CVE-2011-3101

    Last Modified: 11 Apr 2025

    Google Chrome before 19.0.1084.46 on Linux does not properly mitigate an unspecified flaw in an NVIDIA driver, which has unknown impact and attack vectors. NOTE: see CVE-2012-3105 for the related MFSA 2012-34 issue in Mozilla products.

    Published: 16 May 2012
    7.5
    High

    CVE-2012-1149

    Last Modified: 11 Apr 2025

    Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC file, which triggers a heap-based buffer overflow.

    Published: 16 May 2012
    7.5
    High

    CVE-2012-2149

    Last Modified: 11 Apr 2025

    The WPXContentListener::_closeTableRow function in WPXContentListener.cpp in libwpd 0.8.8, as used by OpenOffice.org (OOo) before 3.4, allows remote attackers to execute arbitrary code via a crafted Wordperfect .WPD document that causes a negative array index to be used. NOTE: some sources report this issue as an integer overflow.

    Published: 16 May 2012
    6.8
    Medium

    CVE-2012-2334

    Last Modified: 11 Apr 2025

    Integer overflow in filter/source/msfilter/msdffimp.cxx in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the length of an Escher graphics record in a PowerPoint (.ppt) document, which triggers a buffer overflow.

    Published: 16 May 2012
    5
    Medium

    CVE-2011-3085

    Last Modified: 11 Apr 2025

    The Autofill feature in Google Chrome before 19.0.1084.46 does not properly restrict field values, which allows remote attackers to cause a denial of service (UI corruption) and possibly conduct spoofing attacks via vectors involving long values.

    Published: 16 May 2012
    7.2
    High

    CVE-2011-3098

    Last Modified: 11 Apr 2025

    Google Chrome before 19.0.1084.46 on Windows uses an incorrect search path for the Windows Media Player plug-in, which might allow local users to gain privileges via a Trojan horse plug-in in an unspecified directory.

    Published: 16 May 2012
    4.3
    Medium

    CVE-2012-1246

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in KENT-WEB WEB MART 1.7 and earlier might allow remote attackers to inject arbitrary web script or HTML via a crafted cookie.

    Published: 15 May 2012
    5.1
    Medium

    CVE-2012-1248

    Last Modified: 11 Apr 2025

    app/config/core.php in baserCMS 1.6.15 and earlier does not properly handle installations in shared-hosting environments, which allows remote attackers to hijack sessions by leveraging administrative access to a different domain.

    Published: 15 May 2012
    2.6
    Low

    CVE-2012-1247

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in KENT-WEB WEB MART 1.7 and earlier, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML by leveraging support for Cascading Style Sheets (CSS) expressions.

    Published: 15 May 2012
    5
    Medium

    CVE-2012-2511

    Last Modified: 11 Apr 2025

    The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

    Published: 15 May 2012
    5
    Medium

    CVE-2012-2513

    Last Modified: 11 Apr 2025

    The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

    Published: 15 May 2012
    5
    Medium

    CVE-2012-2612

    Last Modified: 11 Apr 2025

    The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

    Published: 15 May 2012
    5
    Medium

    CVE-2012-2512

    Last Modified: 11 Apr 2025

    The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

    Published: 15 May 2012
    5
    Medium

    CVE-2012-2514

    Last Modified: 11 Apr 2025

    The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

    Published: 15 May 2012
    9.3
    Critical

    CVE-2012-2611

    Last Modified: 11 Apr 2025

    The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2, when a certain Developer Trace configuration is enabled, allows remote attackers to execute arbitrary code via a crafted SAP Diag packet.

    Published: 15 May 2012
    5
    Medium

    CVE-2011-3093

    Last Modified: 11 Apr 2025

    Google Chrome before 19.0.1084.46 does not properly handle glyphs, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 15 May 2012
    10
    Critical

    CVE-2011-3086

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a STYLE element.

    Published: 15 May 2012
    10
    Critical

    CVE-2011-3089

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving tables.

    Published: 15 May 2012
    6.8
    Medium

    CVE-2011-3102

    Last Modified: 11 Apr 2025

    Off-by-one error in libxml2, as used in Google Chrome before 19.0.1084.46 and other products, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors.

    Published: 15 May 2012
    4
    Medium

    CVE-2012-2738

    Last Modified: 11 Apr 2025

    The VteTerminal in gnome-terminal (vte) before 0.32.2 allows remote authenticated users to cause a denial of service (long loop and CPU consumption) via an escape sequence with a large repeat count value.

    Published: 15 May 2012
    7.6
    High

    CVE-2011-3090

    Last Modified: 11 Apr 2025

    Race condition in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to worker processes.

    Published: 15 May 2012
    7.8
    High

    CVE-2012-2276

    Last Modified: 11 Apr 2025

    The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via input data that (1) lacks FIPS fields or (2) has an invalid version number.

    Published: 14 May 2012
    7.5
    High

    CVE-2011-1390

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Maintenance tool in IBM Rational ClearQuest 7.1.1.x before 7.1.1.9, 7.1.2.x before 7.1.2.6, and 8.x before 8.0.0.2 allows remote attackers to execute arbitrary SQL commands by leveraging an error in the user-database upgrade feature.

    Published: 14 May 2012
    7.8
    High

    CVE-2012-2277

    Last Modified: 11 Apr 2025

    The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (pvcontrol.exe process hang) via \n (line feed) characters in the Id fields of many "batch begin untethered" commands.

    Published: 14 May 2012
    7.8
    High

    CVE-2012-1804

    Last Modified: 11 Apr 2025

    The OPC server in Progea Movicon before 11.3 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted HTTP request.

    Published: 14 May 2012
    6.9
    Medium

    CVE-2012-0649

    Last Modified: 11 Apr 2025

    Race condition in the initialization routine in blued in Bluetooth in Apple Mac OS X before 10.7.4 allows local users to gain privileges via vectors involving a temporary file.

    Published: 11 May 2012
    5
    Medium

    CVE-2012-0651

    Last Modified: 11 Apr 2025

    The directory server in Directory Service in Apple Mac OS X 10.6.8 allows remote attackers to obtain sensitive information from process memory via a crafted message.

    Published: 11 May 2012
    4.9
    Medium

    CVE-2012-0652

    Last Modified: 11 Apr 2025

    Login Window in Apple Mac OS X 10.7.3, when Legacy File Vault or networked home directories are enabled, does not properly restrict what is written to the system log for network logins, which allows local users to obtain sensitive information by reading the log.

    Published: 11 May 2012
    6.8
    Medium

    CVE-2012-0654

    Last Modified: 11 Apr 2025

    libsecurity in Apple Mac OS X before 10.7.4 accesses uninitialized memory locations during the processing of X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted certificate.

    Published: 11 May 2012
    6.9
    Medium

    CVE-2012-0656

    Last Modified: 11 Apr 2025

    Race condition in LoginUIFramework in Apple Mac OS X 10.7.x before 10.7.4, when the Guest account is enabled, allows physically proximate attackers to login to arbitrary accounts by entering the account name and no password.

    Published: 11 May 2012
    2.1
    Low

    CVE-2012-0657

    Last Modified: 11 Apr 2025

    Quartz Composer in Apple Mac OS X before 10.7.4, when the RSS Visualizer screensaver is enabled, allows physically proximate attackers to bypass screen locking and launch a Safari process via unspecified vectors.

    Published: 11 May 2012
    6.8
    Medium

    CVE-2012-0659

    Last Modified: 11 Apr 2025

    Integer overflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG file.

    Published: 11 May 2012
    6.8
    Medium

    CVE-2012-0660

    Last Modified: 11 Apr 2025

    Buffer underflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG file.

    Published: 11 May 2012
    6.8
    Medium

    CVE-2012-0661

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in QuickTime in Apple Mac OS X 10.7.x before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with JPEG2000 encoding.

    Published: 11 May 2012