CVE Feed

    Dashboard / CVE

    2.6
    Low

    CVE-2012-0513

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6 and 12.1.3 allows remote attackers to affect integrity, related to REST Services.

    Published: 3 May 2012
    7.1
    High

    CVE-2012-0519

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.2.0.2, when running on Windows, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 3 May 2012
    7.2
    High

    CVE-2012-0523

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Grid Engine component in Oracle Sun Products Suite 6.1 and 6.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to sgepasswd.

    Published: 3 May 2012
    3.2
    Low

    CVE-2012-0524

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows local users to affect confidentiality and integrity via unknown vectors related to File Processing.

    Published: 3 May 2012
    5.5
    Medium

    CVE-2012-0532

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Identity Manager component in Oracle Fusion Middleware 11.1.1.3 and 11.1.1.5 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to User Config Management.

    Published: 3 May 2012
    6.4
    Medium

    CVE-2012-0511

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the OCI component in Oracle Database Server 10.2.0.3, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality and integrity via unknown vectors.

    Published: 3 May 2012
    6.8
    Medium

    CVE-2012-0516

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle iPlanet Web Server component in Oracle Sun Products Suite 7.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Administration Console.

    Published: 3 May 2012
    3.5
    Low

    CVE-2012-0531

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise Portal component in Oracle PeopleSoft Products 9.1 allows remote authenticated users to affect integrity via unknown vectors related to Enterprise Portal.

    Published: 3 May 2012
    4
    Medium

    CVE-2012-0533

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise FCSM component in Oracle PeopleSoft Products 9.0 and 9.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Receivables.

    Published: 3 May 2012
    5.4
    Medium

    CVE-2011-4019

    Last Modified: 11 Apr 2025

    Memory leak in Cisco IOS 12.4 and 15.0 through 15.2, and Cisco Unified Communications Manager (CUCM) 7.x, allows remote attackers to cause a denial of service (memory consumption) via a crafted response to a SIP SUBSCRIBE message, aka Bug IDs CSCto93837 and CSCtj61883.

    Published: 3 May 2012
    5
    Medium

    CVE-2011-4022

    Last Modified: 11 Apr 2025

    The sensor in Cisco Intrusion Prevention System (IPS) 7.0 and 7.1 allows remote attackers to cause a denial of service (file-handle exhaustion and mainApp hang) by making authentication attempts that exceed the configured limit, aka Bug ID CSCto51204.

    Published: 3 May 2012
    7.8
    High

    CVE-2011-4023

    Last Modified: 11 Apr 2025

    Memory leak in libcmd in Cisco NX-OS 5.0 on Nexus switches allows remote authenticated users to cause a denial of service (memory consumption) via SNMP requests, aka Bug ID CSCtr65682.

    Published: 3 May 2012
    6.3
    Medium

    CVE-2011-4231

    Last Modified: 11 Apr 2025

    Cisco IOS 15.1 and 15.2 and IOS XE 3.x, when configured as an IPsec hub with X.509 certificates in use, allows remote authenticated users to cause a denial of service (segmentation fault and device crash) via unspecified vectors, aka Bug ID CSCtq61128.

    Published: 3 May 2012
    5
    Medium

    CVE-2011-4232

    Last Modified: 11 Apr 2025

    The web server in Cisco Unified MeetingPlace 6.1 and 8.5 produces different responses for directory queries depending on whether the directory exists, which allows remote attackers to enumerate directory names via a series of queries, aka Bug ID CSCtt94070.

    Published: 3 May 2012
    4.3
    Medium

    CVE-2011-4237

    Last Modified: 11 Apr 2025

    CRLF injection vulnerability in autologin.jsp in Cisco CiscoWorks Common Services 4.0, as used in Cisco Prime LAN Management Solution and other products, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the URL parameter, aka Bug ID CSCtu18693.

    Published: 3 May 2012
    6.8
    Medium

    CVE-2012-0731

    Last Modified: 11 Apr 2025

    IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not prevent service-account impersonation, which allows remote authenticated users to read arbitrary files via unspecified vectors.

    Published: 3 May 2012
    5.8
    Medium

    CVE-2012-0732

    Last Modified: 11 Apr 2025

    The Enterprise Console client in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 3 May 2012
    6
    Medium

    CVE-2012-0733

    Last Modified: 11 Apr 2025

    IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1, when Integrated Windows authentication is used, allows remote authenticated users to obtain administrative privileges by hijacking a session associated with the service account.

    Published: 3 May 2012
    7.6
    High

    CVE-2012-0735

    Last Modified: 11 Apr 2025

    IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly scan file: URLs, which allows man-in-the-middle attackers to obtain sensitive information or possibly have unspecified other impact via a crafted URI.

    Published: 3 May 2012
    4.3
    Medium

    CVE-2012-1190

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the replication-setup functionality in js/replication.js in phpMyAdmin 3.4.x before 3.4.10.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted database name.

    Published: 3 May 2012
    6
    Medium

    CVE-2012-0729

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 allows remote authenticated users to execute arbitrary ASP.NET code by uploading a .aspx file, and then accessing it via unspecified vectors.

    Published: 3 May 2012
    3.5
    Low

    CVE-2012-0737

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 May 2012
    6
    Medium

    CVE-2012-0730

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 allow remote attackers to hijack the authentication of administrators for requests that create administrative accounts.

    Published: 3 May 2012
    7.6
    High

    CVE-2012-0734

    Last Modified: 11 Apr 2025

    IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly import jobs, which allows man-in-the-middle attackers to obtain sensitive information or possibly have unspecified other impact via a crafted job.

    Published: 3 May 2012
    9.3
    Critical

    CVE-2012-0736

    Last Modified: 11 Apr 2025

    IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly create scan jobs, which allows remote attackers to execute arbitrary code via a crafted web site.

    Published: 3 May 2012
    9.8
    Critical

    CVE-2012-1823

    Last Modified: 21 Apr 2026

    sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.

    Published: 3 May 2012
    7.5
    High

    CVE-2012-2335

    Last Modified: 11 Apr 2025

    php-wrapper.fcgi does not properly handle command-line arguments, which allows remote attackers to bypass a protection mechanism in PHP 5.3.12 and 5.4.2 and execute arbitrary code by leveraging improper interaction between the PHP sapi/cgi/cgi_main.c component and a query string beginning with a +- sequence.

    Published: 3 May 2012
    5
    Medium

    CVE-2012-2336

    Last Modified: 11 Apr 2025

    sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to cause a denial of service (resource consumption) by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'T' case. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.

    Published: 3 May 2012
    7.5
    High

    CVE-2012-2311

    Last Modified: 11 Apr 2025

    sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that contain a %3D sequence but no = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.

    Published: 3 May 2012
    4.3
    Medium

    CVE-2012-2001

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP SNMP Agents for Linux before 9.0.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 2 May 2012
    8.3
    High

    CVE-2012-2002

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in HP SNMP Agents for Linux before 9.0.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 2 May 2012
    4.9
    Medium

    CVE-2012-2006

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to modify data or cause a denial of service via unknown vectors.

    Published: 2 May 2012
    9.3
    Critical

    CVE-2012-1819

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in WellinTech KingView 6.53 allows local users to gain privileges via a Trojan horse DLL in the current working directory.

    Published: 2 May 2012
    4.3
    Medium

    CVE-2012-2005

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 2 May 2012
    6.8
    Medium

    CVE-2012-2003

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 2 May 2012
    8.3
    High

    CVE-2012-2004

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 2 May 2012
    7.5
    High

    CVE-2012-2000

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in HP System Health Application and Command Line Utilities before 9.0.0 allow remote attackers to execute arbitrary code via unknown vectors.

    Published: 2 May 2012
    5
    Medium

    CVE-2011-2583

    Last Modified: 11 Apr 2025

    Cisco Unified Contact Center Express (aka CCX) 8.0 and 8.5 allows remote attackers to cause a denial of service via network traffic, as demonstrated by an SEC-BE-STABLE test case, aka Bug ID CSCth33834.

    Published: 2 May 2012
    5.4
    Medium

    CVE-2011-2586

    Last Modified: 11 Apr 2025

    The HTTP client in Cisco IOS 12.4 and 15.0 allows user-assisted remote attackers to cause a denial of service (device crash) via a malformed HTTP response to a request for service installation, aka Bug ID CSCts12249.

    Published: 2 May 2012
    5
    Medium

    CVE-2011-3283

    Last Modified: 11 Apr 2025

    Cisco Carrier Routing System 3.9.1 allows remote attackers to cause a denial of service (Metro subsystem crash) via a fragmented GRE packet, aka Bug ID CSCts14887.

    Published: 2 May 2012
    5
    Medium

    CVE-2011-3285

    Last Modified: 11 Apr 2025

    CRLF injection vulnerability in /+CSCOE+/logon.html on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 through 8.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors, aka Bug ID CSCth63101.

    Published: 2 May 2012
    7.8
    High

    CVE-2011-3295

    Last Modified: 11 Apr 2025

    The NETIO and IPV4_IO processes in Cisco IOS XR 3.8 through 4.1, as used in Cisco Carrier Routing System and other products, allow remote attackers to cause a denial of service (CPU consumption) via crafted network traffic, aka Bug ID CSCti59888.

    Published: 2 May 2012
    4.3
    Medium

    CVE-2011-3317

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCtr78192.

    Published: 2 May 2012
    7.8
    High

    CVE-2011-4006

    Last Modified: 11 Apr 2025

    The ESMTP inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.5 allows remote attackers to cause a denial of service (CPU consumption) via an unspecified closing sequence, aka Bug ID CSCtt32565.

    Published: 2 May 2012
    5.4
    Medium

    CVE-2011-4016

    Last Modified: 11 Apr 2025

    The PPP implementation in Cisco IOS 12.2 and 15.0 through 15.2, when Point-to-Point Termination and Aggregation (PTA) and L2TP are used, allows remote attackers to cause a denial of service (device crash) via crafted network traffic, aka Bug ID CSCtf71673.

    Published: 2 May 2012
    5
    Medium

    CVE-2012-0333

    Last Modified: 11 Apr 2025

    Cisco Small Business IP phones with SPA 500 series firmware 7.4.9 and earlier do not require authentication for Push XML requests, which allows remote attackers to make telephone calls via an XML document, aka Bug ID CSCts08768.

    Published: 2 May 2012
    5
    Medium

    CVE-2012-0335

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 through 8.4 do not properly perform proxy authentication during attempts to cut through a firewall, which allows remote attackers to obtain sensitive information via a connection attempt, aka Bug ID CSCtx42746.

    Published: 2 May 2012
    6.5
    Medium

    CVE-2012-0337

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the web component in Cisco Unified MeetingPlace 7.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCtx08939.

    Published: 2 May 2012
    5
    Medium

    CVE-2012-0338

    Last Modified: 11 Apr 2025

    Cisco IOS 12.2 through 12.4 and 15.0 does not recognize the vrf-also keyword during enforcement of access-class commands, which allows remote attackers to establish SSH connections from arbitrary source IP addresses via a standard SSH client, aka Bug ID CSCsv86113.

    Published: 2 May 2012
    5
    Medium

    CVE-2012-0361

    Last Modified: 11 Apr 2025

    The sccp-protocol component in Cisco IP Communicator (CIPC) 7.0 through 8.6 does not limit the rate of SCCP messages to Cisco Unified Communications Manager (CUCM), which allows remote attackers to cause a denial of service via vectors that trigger (1) on hook and (2) off hook messages, as demonstrated by a Plantronics headset, aka Bug ID CSCti40315.

    Published: 2 May 2012