CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2012-0213

    Last Modified: 11 Apr 2025

    The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial of service (OutOfMemoryError exception and possibly JVM destabilization) via a crafted length value in a Channel Definition Format (CDF) or Compound File Binary Format (CFBF) document.

    Published: 9 May 2012
    7.5
    High

    CVE-2012-1675

    Last Modified: 11 Apr 2025

    The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.0.5, as used in Oracle Fusion Middleware, Enterprise Manager, E-Business Suite, and possibly other products, allows remote attackers to execute arbitrary database commands by performing a remote registration of a database (1) instance or (2) service name that already exists, then conducting a man-in-the-middle (MITM) attack to hijack database connections, aka "TNS Poison."

    Published: 8 May 2012
    6.8
    Medium

    CVE-2012-0672

    Last Modified: 11 Apr 2025

    WebKit in Apple iOS before 5.1.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 8 May 2012
    4.3
    Medium

    CVE-2012-0674

    Last Modified: 11 Apr 2025

    Safari in Apple iOS before 5.1.1 allows remote attackers to spoof the location bar's URL via a crafted web site.

    Published: 8 May 2012
    5
    Medium

    CVE-2012-2329

    Last Modified: 11 Apr 2025

    Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote attackers to cause a denial of service (application crash) via a long string in the header of an HTTP request.

    Published: 8 May 2012
    2.1
    Low

    CVE-2012-2669

    Last Modified: 11 Apr 2025

    The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.4.5, does not validate the origin of Netlink messages, which allows local users to spoof Netlink communication via a crafted connector message.

    Published: 8 May 2012
    3.5
    Low

    CVE-2012-2214

    Last Modified: 11 Apr 2025

    proxy.c in libpurple in Pidgin before 2.10.4 does not properly handle canceled SOCKS5 connection attempts, which allows user-assisted remote authenticated users to cause a denial of service (application crash) via a sequence of XMPP file-transfer requests.

    Published: 6 May 2012
    5
    Medium

    CVE-2012-2318

    Last Modified: 11 Apr 2025

    msg.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.4 does not properly handle crafted characters, which allows remote servers to cause a denial of service (application crash) by placing these characters in a text/plain message.

    Published: 6 May 2012
    10
    Critical

    CVE-2012-0202

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in tm1admsd.exe in the Admin Server in IBM Cognos TM1 9.4.x and 9.5.x before 9.5.2 FP2 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted data.

    Published: 4 May 2012
    7.5
    High

    CVE-2012-2448

    Last Modified: 11 Apr 2025

    VMware ESXi 3.5 through 5.0 and ESX 3.5 through 4.1 allow remote attackers to execute arbitrary code or cause a denial of service (memory overwrite) via NFS traffic.

    Published: 4 May 2012
    9
    Critical

    CVE-2012-2450

    Last Modified: 11 Apr 2025

    VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 do not properly register SCSI devices, which allows guest OS users to cause a denial of service (invalid write operation and VMX process crash) or possibly execute arbitrary code on the host OS by leveraging administrative privileges on the guest OS.

    Published: 4 May 2012
    9
    Critical

    CVE-2012-1517

    Last Modified: 11 Apr 2025

    The VMX process in VMware ESXi 4.1 and ESX 4.1 does not properly handle RPC commands, which allows guest OS users to cause a denial of service (memory overwrite and process crash) or possibly execute arbitrary code on the host OS via vectors involving function pointers.

    Published: 4 May 2012
    9
    Critical

    CVE-2012-2449

    Last Modified: 11 Apr 2025

    VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x through 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 do not properly configure the virtual floppy device, which allows guest OS users to cause a denial of service (out-of-bounds write operation and VMX process crash) or possibly execute arbitrary code on the host OS by leveraging administrative privileges on the guest OS.

    Published: 4 May 2012
    7.2
    High

    CVE-2012-0745

    Last Modified: 11 Apr 2025

    The getpwnam function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.1.0.10 through 2.2.1.3 does not properly interact with customer-extended LDAP user filtering, which allows local users to gain privileges via unspecified vectors.

    Published: 4 May 2012
    9.9
    Critical

    CVE-2012-1516

    Last Modified: 11 Apr 2025

    The VMX process in VMware ESXi 3.5 through 4.1 and ESX 3.5 through 4.1 does not properly handle RPC commands, which allows guest OS users to cause a denial of service (memory overwrite and process crash) or possibly execute arbitrary code on the host OS via vectors involving data pointers.

    Published: 4 May 2012
    2.1
    Low

    CVE-2012-2314

    Last Modified: 11 Apr 2025

    The bootloader configuration module (pyanaconda/bootloader.py) in Anaconda uses 755 permissions for /etc/grub.d, which allows local users to obtain password hashes and conduct brute force password guessing attacks.

    Published: 4 May 2012
    7.2
    High

    CVE-2012-2319

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in the hfsplus filesystem implementation in the Linux kernel before 3.3.5 allow local users to gain privileges via a crafted HFS plus filesystem, a related issue to CVE-2009-4020.

    Published: 4 May 2012
    4.3
    Medium

    CVE-2013-0184

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Rack::Auth::AbstractRequest in Rack 1.1.x before 1.1.5, 1.2.x before 1.2.7, 1.3.x before 1.3.9, and 1.4.x before 1.4.4 allows remote attackers to cause a denial of service via unknown vectors related to "symbolized arbitrary strings."

    Published: 4 May 2012
    9.3
    Critical

    CVE-2012-0779

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.183.19 and 11.x before 11.2.202.235 on Windows, Mac OS X, and Linux; before 11.1.111.9 on Android 2.x and 3.x; and before 11.1.115.8 on Android 4.x allows remote attackers to execute arbitrary code via a crafted file, related to an "object confusion vulnerability," as exploited in the wild in May 2012.

    Published: 4 May 2012
    4.3
    Medium

    CVE-2012-6109

    Last Modified: 11 Apr 2025

    lib/rack/multipart.rb in Rack before 1.1.4, 1.2.x before 1.2.6, 1.3.x before 1.3.7, and 1.4.x before 1.4.2 uses an incorrect regular expression, which allows remote attackers to cause a denial of service (infinite loop) via a crafted Content-Disposion header.

    Published: 4 May 2012
    2.7
    Low

    CVE-2012-2625

    Last Modified: 11 Apr 2025

    The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4.2.x, and 4.1.x allows local para-virtualized guest users to cause a denial of service (memory consumption) via a large (1) bzip2 or (2) lzma compressed kernel image.

    Published: 4 May 2012
    4.6
    Medium

    CVE-2012-1328

    Last Modified: 11 Apr 2025

    Cisco Unified IP Phones 9900 series devices with firmware 9.1 and 9.2 do not properly handle downloads of configuration information to an RT phone, which allows local users to gain privileges via unspecified injected data, aka Bug ID CSCts32237.

    Published: 3 May 2012
    6.8
    Medium

    CVE-2012-1695

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware 28.2.2 and earlier, and JDK/JRE 5 and 6 27.7.1 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 3 May 2012
    6.4
    Medium

    CVE-2012-1694

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality and integrity, related to libsasl.

    Published: 3 May 2012
    6.8
    Medium

    CVE-2012-0575

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through 11.2.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Core.

    Published: 3 May 2012
    6.5
    Medium

    CVE-2012-0564

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50 and 8.51 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Query.

    Published: 3 May 2012
    5.5
    Medium

    CVE-2012-0565

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Agile component in Oracle Supply Chain Products Suite 5.2.2, 6.0.0, and 6.1.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Install.

    Published: 3 May 2012
    4.3
    Medium

    CVE-2012-0566

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Agile component in Oracle Supply Chain Products Suite 5.2.2, 6.0.0, and 6.1.1 allows remote attackers to affect integrity via unknown vectors related to Supplier Portal.

    Published: 3 May 2012
    4.9
    Medium

    CVE-2012-0573

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through 11.4.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Core.

    Published: 3 May 2012
    3.5
    Low

    CVE-2012-0577

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through 11.4.0 allows remote authenticated users to affect availability via unknown vectors related to Core.

    Published: 3 May 2012
    3.5
    Low

    CVE-2012-0579

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through 11.4.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Core.

    Published: 3 May 2012
    5
    Medium

    CVE-2012-0580

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Agile PLM for Process component in Oracle Supply Chain Products Suite 5.2.2, 6.0.0, and 6.1.1 allows remote attackers to affect integrity via unknown vectors related to Supplier Portal.

    Published: 3 May 2012
    4.3
    Medium

    CVE-2012-0581

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Agile component in Oracle Supply Chain Products Suite 5.2.2, 6.0.0, and 6.1.1 allows remote attackers to affect integrity, related to SCRM - Company Profiles.

    Published: 3 May 2012
    4
    Medium

    CVE-2012-0582

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Siebel Clinical component in Oracle Industry Applications 7.7, 7.8, 8.0.0.x, 8.1.1.x, and 8.2.2.x allows remote authenticated users to affect integrity via unknown vectors related to Web UI, a different vulnerability than CVE-2012-1674.

    Published: 3 May 2012
    3.5
    Low

    CVE-2012-1676

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Virtual Banking.

    Published: 3 May 2012
    4.9
    Medium

    CVE-2012-1681

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect availability via unknown vectors related to Kernel/sockfs.

    Published: 3 May 2012
    5.9
    Medium

    CVE-2012-1683

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to gssd.

    Published: 3 May 2012
    4.3
    Medium

    CVE-2012-1684

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Password Policy.

    Published: 3 May 2012
    6.6
    Medium

    CVE-2012-1691

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel/Privileges.

    Published: 3 May 2012
    4.9
    Medium

    CVE-2012-1692

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect availability, related to SCTP.

    Published: 3 May 2012
    2.6
    Low

    CVE-2012-1693

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle SPARC Enterprise M Series Servers XCP 1110 allows remote attackers to affect availability, related to XSCF Control Package (XCP).

    Published: 3 May 2012
    2.1
    Low

    CVE-2012-1698

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11 allows remote authenticated users to affect confidentiality, related to Kernel/GLD.

    Published: 3 May 2012
    4.7
    Medium

    CVE-2012-1706

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Logging.

    Published: 3 May 2012
    4
    Medium

    CVE-2012-1707

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Core-Base, a different vulnerability than CVE-2012-1704.

    Published: 3 May 2012
    4.3
    Medium

    CVE-2012-1708

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Application Express component in Oracle Database Server 4.0 and 4.1 allows remote attackers to affect integrity via unknown vectors.

    Published: 3 May 2012
    7.5
    High

    CVE-2012-1709

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Designer, a different vulnerability than CVE-2012-1710.

    Published: 3 May 2012
    5.5
    Medium

    CVE-2012-0567

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through 11.2.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Core, a different vulnerability than CVE-2012-0545 and CVE-2012-0546.

    Published: 3 May 2012
    4
    Medium

    CVE-2012-0576

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 6.0.1 and 6.2.0 allows remote authenticated users to affect integrity via unknown vectors related to Core-Help.

    Published: 3 May 2012
    4
    Medium

    CVE-2012-1674

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Siebel Clinical component in Oracle Industry Applications 7.7, 7.8, 8.0.0.x, 8.1.1.x, and 8.2.2.x allows remote authenticated users to affect integrity via unknown vectors related to Web UI, a different vulnerability than CVE-2012-0582.

    Published: 3 May 2012
    3.5
    Low

    CVE-2012-1679

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect integrity via unknown vectors related to Core-Base.

    Published: 3 May 2012