CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2012-0470

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the nsSVGFEDiffuseLightingElement::LightPixel function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to cause a denial of service (invalid gfxImageSurface free operation) or possibly execute arbitrary code by leveraging the use of "different number systems."

    Published: 24 Apr 2012
    4.3
    Medium

    CVE-2012-0471

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to inject arbitrary web script or HTML via a multibyte character set.

    Published: 24 Apr 2012
    2.6
    Low

    CVE-2012-0475

    Last Modified: 11 Apr 2025

    Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey before 2.9 do not properly construct the Origin and Sec-WebSocket-Origin HTTP headers, which might allow remote attackers to bypass an IPv6 literal ACL via a cross-site (1) XMLHttpRequest or (2) WebSocket operation involving a nonstandard port number and an IPv6 address that contains certain zero fields.

    Published: 24 Apr 2012
    9.3
    Critical

    CVE-2012-0478

    Last Modified: 11 Apr 2025

    The texImage2D implementation in the WebGL subsystem in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 does not properly restrict JSVAL_TO_OBJECT casts, which might allow remote attackers to execute arbitrary code via a crafted web page.

    Published: 24 Apr 2012
    4.3
    Medium

    CVE-2012-0479

    Last Modified: 11 Apr 2025

    Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to spoof the address bar via an https URL for invalid (1) RSS or (2) Atom XML content.

    Published: 24 Apr 2012
    10
    Critical

    CVE-2012-0467

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 24 Apr 2012
    10
    Critical

    CVE-2012-0468

    Last Modified: 11 Apr 2025

    The browser engine in Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey before 2.9 allows remote attackers to cause a denial of service (assertion failure and memory corruption) or possibly execute arbitrary code via vectors related to jsval.h and the js::array_shift function.

    Published: 24 Apr 2012
    9.3
    Critical

    CVE-2012-0472

    Last Modified: 11 Apr 2025

    The cairo-dwrite implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9, when certain Windows Vista and Windows 7 configurations are used, does not properly restrict font-rendering attempts, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.

    Published: 24 Apr 2012
    4.3
    Medium

    CVE-2012-0474

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the docshell implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to inject arbitrary web script or HTML via vectors related to short-circuited page loads, aka "Universal XSS (UXSS)."

    Published: 24 Apr 2012
    4.3
    Medium

    CVE-2012-0477

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to inject arbitrary web script or HTML via the (1) ISO-2022-KR or (2) ISO-2022-CN character set.

    Published: 24 Apr 2012
    4.3
    Medium

    CVE-2012-2134

    Last Modified: 12 Apr 2025

    The handle_connection_error function in ldap_helper.c in bind-dyndb-ldap before 1.1.0rc1 does not properly handle LDAP query errors, which allows remote attackers to cause a denial of service (infinite loop and named server hang) via a non-alphabet character in the base DN in an LDAP search DNS query.

    Published: 24 Apr 2012
    5
    Medium

    CVE-2012-0473

    Last Modified: 11 Apr 2025

    The WebGLBuffer::FindMaxUshortElement function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 calls the FindMaxElementInSubArray function with incorrect template arguments, which allows remote attackers to obtain sensitive information from video memory via a crafted WebGL.drawElements call.

    Published: 24 Apr 2012
    3.5
    Low

    CVE-2012-2141

    Last Modified: 11 Apr 2025

    Array index error in the handle_nsExtendOutput2Table function in agent/mibgroup/agent/extend.c in Net-SNMP 5.7.1 allows remote authenticated users to cause a denial of service (out-of-bounds read and snmpd crash) via an SNMP GET request for an entry not in the extension table.

    Published: 24 Apr 2012
    5
    Medium

    CVE-2012-2145

    Last Modified: 11 Apr 2025

    Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of incomplete connections.

    Published: 24 Apr 2012
    9.3
    Critical

    CVE-2012-1616

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in icclib before 2.13, as used by Argyll CMS before 1.4 and possibly other programs, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted ICC profile file.

    Published: 23 Apr 2012
    7.5
    High

    CVE-2012-2131

    Last Modified: 11 Apr 2025

    Multiple integer signedness errors in crypto/buffer/buffer.c in OpenSSL 0.9.8v allow remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-2110.

    Published: 23 Apr 2012
    5
    Medium

    CVE-2012-2132

    Last Modified: 11 Apr 2025

    libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by connecting with a SSL connection.

    Published: 23 Apr 2012
    4.9
    Medium

    CVE-2012-2383

    Last Modified: 11 Apr 2025

    Integer overflow in the i915_gem_execbuffer2 function in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 3.3.5 on 32-bit platforms allows local users to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted ioctl call.

    Published: 23 Apr 2012
    4.9
    Medium

    CVE-2012-2384

    Last Modified: 11 Apr 2025

    Integer overflow in the i915_gem_do_execbuffer function in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 3.3.5 on 32-bit platforms allows local users to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted ioctl call.

    Published: 23 Apr 2012
    7.5
    High

    CVE-2012-2395

    Last Modified: 11 Apr 2025

    Incomplete blacklist vulnerability in action_power.py in Cobbler 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) username or (2) password fields to the power_system method in the xmlrpc API.

    Published: 23 Apr 2012
    9.3
    Critical

    CVE-2012-0708

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the Ole API in the CQOle ActiveX control in cqole.dll in IBM Rational ClearQuest 7.1.1 before 7.1.1.9, 7.1.2 before 7.1.2.6, and 8.0.0 before 8.0.0.2 allows remote attackers to execute arbitrary code via a crafted web page that leverages a RegisterSchemaRepoFromFileByDbSet function-prototype mismatch.

    Published: 22 Apr 2012
    6.4
    Medium

    CVE-2012-0726

    Last Modified: 11 Apr 2025

    The default configuration of TLS in IBM Tivoli Directory Server (TDS) 6.3 and earlier supports the (1) NULL-MD5 and (2) NULL-SHA ciphers, which allows remote attackers to trigger unencrypted communication via the TLS Handshake Protocol.

    Published: 22 Apr 2012
    4.3
    Medium

    CVE-2012-0740

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web Admin Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.22 and 6.3 before 6.3.0.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 Apr 2012
    5
    Medium

    CVE-2012-0743

    Last Modified: 11 Apr 2025

    IBM Tivoli Directory Server (TDS) 6.3 and earlier allows remote attackers to cause a denial of service (daemon crash) via a malformed LDAP paged search request.

    Published: 22 Apr 2012
    4.6
    Medium

    CVE-2012-0946

    Last Modified: 11 Apr 2025

    The NVIDIA UNIX driver before 295.40 allows local users to access arbitrary memory locations by leveraging GPU device-node read/write privileges.

    Published: 22 Apr 2012
    4.3
    Medium

    CVE-2012-1113

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the administration subsystem in Gallery 2 before 2.3.2 and 3 before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 Apr 2012
    10
    Critical

    CVE-2012-2405

    Last Modified: 11 Apr 2025

    Gallery 2 before 2.3.2 and 3 before 3.0.3 does not properly implement encryption, which has unspecified impact and attack vectors, a different vulnerability than CVE-2012-1113.

    Published: 22 Apr 2012
    4.4
    Medium

    CVE-2012-0216

    Last Modified: 27 Aug 2025

    The default configuration of the apache2 package in Debian GNU/Linux squeeze before 2.2.16-6+squeeze7, wheezy before 2.2.22-4, and sid before 2.2.22-4, when mod_php or mod_rivet is used, provides example scripts under the doc/ URI, which might allow local users to conduct cross-site scripting (XSS) attacks, gain privileges, or obtain sensitive information via vectors involving localhost HTTP requests to the Apache HTTP Server.

    Published: 22 Apr 2012
    5
    Medium

    CVE-2012-1243

    Last Modified: 11 Apr 2025

    The TwitRocker2 application before 1.0.23 for Android does not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application.

    Published: 22 Apr 2012
    4.3
    Medium

    CVE-2012-2234

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in sources/users.queries.php in TeamPass before 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the login parameter in an add_new_user action.

    Published: 22 Apr 2012
    10
    Critical

    CVE-2012-2399

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote attackers to inject arbitrary web script or HTML via the buttonText parameter, a different vulnerability than CVE-2012-3414.

    Published: 21 Apr 2012
    10
    Critical

    CVE-2012-2400

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors.

    Published: 21 Apr 2012
    5.5
    Medium

    CVE-2012-2402

    Last Modified: 11 Apr 2025

    wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and deactivate network-wide plugins via unspecified vectors.

    Published: 21 Apr 2012
    5
    Medium

    CVE-2012-2401

    Last Modified: 11 Apr 2025

    Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was loaded, which allows remote attackers to bypass the Same Origin Policy via crafted content.

    Published: 21 Apr 2012
    4.3
    Medium

    CVE-2012-2403

    Last Modified: 11 Apr 2025

    wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickable links inside attributes, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

    Published: 21 Apr 2012
    4.3
    Medium

    CVE-2012-2404

    Last Modified: 11 Apr 2025

    wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

    Published: 21 Apr 2012
    6.5
    Medium

    CVE-2012-2236

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in users.php in PHP Gift Registry 1.5.5 allows remote authenticated users to execute arbitrary SQL commands via the userid parameter in an edit action.

    Published: 20 Apr 2012
    4.3
    Medium

    CVE-2012-2398

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in files/ajax/download.php in ownCloud before 3.0.3 allows remote attackers to inject arbitrary web script or HTML via the files parameter, a different vulnerability than CVE-2012-2269.4.

    Published: 20 Apr 2012
    5.8
    Medium

    CVE-2012-2270

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in index.php (aka the Login Page) in ownCloud before 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter.

    Published: 20 Apr 2012
    6.8
    Medium

    CVE-2012-2397

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in ownCloud before 3.0.3 allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) sequences via vectors involving contacts.

    Published: 20 Apr 2012
    4.3
    Medium

    CVE-2012-2269

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) an arbitrary field to apps/contacts/ajax/addcard.php, (2) the parameter parameter to apps/contacts/ajax/addproperty.php, (3) the name parameter to apps/contacts/ajax/createaddressbook, (4) the file parameter to files/download.php, or the (5) name, (6) user, or (7) redirect_url parameter to files/index.php.

    Published: 20 Apr 2012
    7.8
    High

    CVE-2012-0406

    Last Modified: 11 Apr 2025

    The DPA_Utilities.cProcessAuthenticationData function in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an AUTHENTICATECONNECTION command that (1) lacks a password field or (2) has an empty password.

    Published: 20 Apr 2012
    5
    Medium

    CVE-2012-0407

    Last Modified: 11 Apr 2025

    Integer overflow in the DPA_Utilities library in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a denial of service (infinite loop) via a negative 64-bit value in a certain size field.

    Published: 20 Apr 2012
    4.9
    Medium

    CVE-2012-2273

    Last Modified: 11 Apr 2025

    Comodo Internet Security before 5.10.228257.2253 on Windows 7 x64 allows local users to cause a denial of service (system crash) via a crafted 32-bit Portable Executable (PE) file with a kernel ImageBase value.

    Published: 20 Apr 2012
    5
    Medium

    CVE-2012-2124

    Last Modified: 11 Apr 2025

    functions/imap_general.php in SquirrelMail, as used in Red Hat Enterprise Linux (RHEL) 4 and 5, does not properly handle 8-bit characters in passwords, which allows remote attackers to cause a denial of service (disk consumption) by making many IMAP login attempts with different usernames, leading to the creation of many preference files. NOTE: this issue exists because of an incorrect fix for CVE-2010-2813.

    Published: 20 Apr 2012
    5
    Medium

    CVE-2012-2127

    Last Modified: 11 Apr 2025

    fs/proc/root.c in the procfs implementation in the Linux kernel before 3.2 does not properly interact with CLONE_NEWPID clone system calls, which allows remote attackers to cause a denial of service (reference leak and memory consumption) by making many connections to a daemon that uses PID namespaces to isolate clients, as demonstrated by vsftpd.

    Published: 20 Apr 2012
    4.9
    Medium

    CVE-2012-0134

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP OpenVMS 7.3-2 on the Alpha platform, 8.3 and 8.4 on the Alpha and IA64 platforms, and 8.3-1h1 on the IA64 platform allows local users to cause a denial of service via unknown vectors.

    Published: 19 Apr 2012
    4.3
    Medium

    CVE-2012-2396

    Last Modified: 11 Apr 2025

    VideoLAN VLC media player 2.0.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted MP4 file.

    Published: 19 Apr 2012
    5.3
    Medium

    CVE-2012-4550

    Last Modified: 14 May 2026

    A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system does not correctly call the necessary authorization modules. This prevents Java Authorization Contract for Containers (JACC) permissions from being applied, allowing remote attackers to gain unauthorized access to EJBs.

    Published: 19 Apr 2012
    5.8
    Medium

    CVE-2012-2125

    Last Modified: 11 Apr 2025

    RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack.

    Published: 19 Apr 2012