CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2012-2110

    Last Modified: 11 Apr 2025

    The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key.

    Published: 19 Apr 2012
    4.3
    Medium

    CVE-2012-2126

    Last Modified: 11 Apr 2025

    RubyGems before 1.8.23 does not verify an SSL certificate, which allows remote attackers to modify a gem during installation via a man-in-the-middle attack.

    Published: 19 Apr 2012
    9.3
    Critical

    CVE-2011-5088

    Last Modified: 11 Apr 2025

    The GENESIS32 IcoSetServer ActiveX control in ICONICS GENESIS32 9.21 and BizViz 9.21 configures the trusted zone on the basis of user input, which allows remote attackers to execute arbitrary code via a crafted web site, related to a "Workbench32/WebHMI component SetTrustedZone Policy vulnerability."

    Published: 18 Apr 2012
    10
    Critical

    CVE-2011-5089

    Last Modified: 11 Apr 2025

    Buffer overflow in the Security Login ActiveX controls in ICONICS GENESIS32 8.05, 9.0, 9.1, and 9.2 and BizViz 8.05, 9.0, 9.1, and 9.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long password.

    Published: 18 Apr 2012
    4.3
    Medium

    CVE-2012-0253

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Demand Media Pluck SiteLife before 5.0.13 allow remote attackers to inject arbitrary web script or HTML via (1) the jsonRequest parameter to Direct/Process, the (2) r or (3) cb parameter to Direct/jsonp.htm, or (4) the cb parameter to sys/jsonp.app/.htm.

    Published: 18 Apr 2012
    5
    Medium

    CVE-2011-5087

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in AdAstrA TRACE MODE Data Center allows remote attackers to read arbitrary files via unknown vectors, as demonstrated by the GLEG Agora SCADA+ Exploit Pack for Immunity CANVAS.

    Published: 18 Apr 2012
    3.5
    Low

    CVE-2012-0135

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP System Management Homepage (SMH) before 7.0 allows remote authenticated users to cause a denial of service via unknown vectors.

    Published: 18 Apr 2012
    3.2
    Low

    CVE-2012-1993

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP System Management Homepage (SMH) before 7.0 allows local users to modify data or obtain sensitive information via unknown vectors.

    Published: 18 Apr 2012
    5
    Medium

    CVE-2011-4871

    Last Modified: 11 Apr 2025

    Open Automation Software OPC Systems.NET before 5.0 allows remote attackers to cause a denial of service via a malformed .NET RPC packet on TCP port 58723.

    Published: 18 Apr 2012
    6.8
    Medium

    CVE-2011-5086

    Last Modified: 11 Apr 2025

    https50.ocx in IP*Works! SSL in the server in Unitronics UniOPC before 2.0.0 does not properly implement an unspecified function, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site.

    Published: 18 Apr 2012
    9.3
    Critical

    CVE-2012-0278

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the FlashPix PlugIn before 4.3.4.0 for IrfanView might allow remote attackers to execute arbitrary code via a .fpx file containing a crafted FlashPix image that is not properly handled during decompression.

    Published: 18 Apr 2012
    10
    Critical

    CVE-2012-1799

    Last Modified: 11 Apr 2025

    The web server on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with firmware before 2.3.0.3 does not limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack on the administrative password.

    Published: 18 Apr 2012
    7.7
    High

    CVE-2012-1801

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in (1) COM and (2) ActiveX controls in ABB WebWare Server, WebWare SDK, Interlink Module, S4 OPC Server, QuickTeach, RobotStudio S4, and RobotStudio Lite allow remote attackers to execute arbitrary code via crafted input data.

    Published: 18 Apr 2012
    6.1
    Medium

    CVE-2012-1800

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the Profinet DCP protocol implementation on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with firmware before 2.3.0.3 allows remote attackers to cause a denial of service (device outage) or possibly execute arbitrary code via a crafted DCP frame.

    Published: 18 Apr 2012
    7.8
    High

    CVE-2012-1802

    Last Modified: 11 Apr 2025

    Buffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414-3E before 3.7.1, X308-2M before 3.7.2, X-300EEC before 3.7.2, XR-300 before 3.7.2, and X-300 before 3.7.2 allows remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary code via a malformed URL.

    Published: 18 Apr 2012
    10
    Critical

    CVE-2012-2118

    Last Modified: 11 Apr 2025

    Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service or possibly execute arbitrary code via format string specifiers in an input device name.

    Published: 18 Apr 2012
    4.3
    Medium

    CVE-2012-2417

    Last Modified: 11 Apr 2025

    PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.

    Published: 18 Apr 2012
    4.3
    Medium

    CVE-2012-2146

    Last Modified: 11 Apr 2025

    Elixir 0.8.0 uses Blowfish in CFB mode without constructing a unique initialization vector (IV), which makes it easier for context-dependent users to obtain sensitive information and decrypt the database.

    Published: 18 Apr 2012
    5
    Medium

    CVE-2012-1180

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.

    Published: 17 Apr 2012
    8.3
    High

    CVE-2012-1518

    Last Modified: 11 Apr 2025

    VMware Workstation 8.x before 8.0.2, VMware Player 4.x before 4.0.2, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 use an incorrect ACL for the VMware Tools folder, which allows guest OS users to gain guest OS privileges via unspecified vectors.

    Published: 17 Apr 2012
    6.8
    Medium

    CVE-2012-2089

    Last Modified: 11 Apr 2025

    Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (memory overwrite) or possibly execute arbitrary code via a crafted MP4 file.

    Published: 17 Apr 2012
    3.5
    Low

    CVE-2012-1979

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in starnet/index.php in SyndeoCMS 3.0.01 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the email parameter (aka Email address field) in an edit_user configuration action.

    Published: 17 Apr 2012
    9.3
    Critical

    CVE-2011-2478

    Last Modified: 11 Apr 2025

    Google SketchUp before 8 does not properly handle edge geometry in SketchUp (aka .SKP) files, which allows remote attackers to execute arbitrary code via a crafted file.

    Published: 17 Apr 2012
    7.5
    High

    CVE-2012-0942

    Last Modified: 11 Apr 2025

    Buffer overflow in rn5auth.dll in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to execute arbitrary code via crafted authentication credentials.

    Published: 17 Apr 2012
    4.3
    Medium

    CVE-2012-1984

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Apr 2012
    6.8
    Medium

    CVE-2012-1985

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to hijack the authentication of administrators for requests that cause a denial of service (stack consumption and daemon crash) via a malformed URL.

    Published: 17 Apr 2012
    2.1
    Low

    CVE-2012-1923

    Last Modified: 11 Apr 2025

    RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x store passwords in cleartext under adm_b_db\users\, which allows local users to obtain sensitive information by reading a database.

    Published: 17 Apr 2012
    5
    Medium

    CVE-2012-2267

    Last Modified: 11 Apr 2025

    master.exe in the SNMP Master Agent in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to cause a denial of service (daemon crash) by establishing and closing a port-705 TCP connection, a different vulnerability than CVE-2012-1923.

    Published: 17 Apr 2012
    5
    Medium

    CVE-2012-2268

    Last Modified: 11 Apr 2025

    master.exe in the SNMP Master Agent in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to cause a denial of service (unhandled exception and daemon crash) via a crafted Open-PDU request that triggers incorrect DisplayString processing, a different vulnerability than CVE-2012-1923.

    Published: 17 Apr 2012
    4
    Medium

    CVE-2012-0583

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.60 and earlier, and 5.5.19 and earlier, allows remote authenticated users to affect availability, related to MyISAM.

    Published: 17 Apr 2012
    5
    Medium

    CVE-2012-1583

    Last Modified: 11 Apr 2025

    Double free vulnerability in the xfrm6_tunnel_rcv function in net/ipv6/xfrm6_tunnel.c in the Linux kernel before 2.6.22, when the xfrm6_tunnel module is enabled, allows remote attackers to cause a denial of service (panic) via crafted IPv6 packets.

    Published: 17 Apr 2012
    4
    Medium

    CVE-2012-1688

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability, related to Server DML.

    Published: 17 Apr 2012
    4
    Medium

    CVE-2012-1690

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer, a different vulnerability than CVE-2012-1703.

    Published: 17 Apr 2012
    4
    Medium

    CVE-2012-1697

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.21 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition.

    Published: 17 Apr 2012
    7.2
    High

    CVE-2012-2123

    Last Modified: 11 Apr 2025

    The cap_bprm_set_creds function in security/commoncap.c in the Linux kernel before 3.3.3 does not properly handle the use of file system capabilities (aka fcaps) for implementing a privileged executable file, which allows local users to bypass intended personality restrictions via a crafted application, as demonstrated by an attack that uses a parent process to disable ASLR.

    Published: 17 Apr 2012
    4
    Medium

    CVE-2012-1696

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.

    Published: 17 Apr 2012
    6.8
    Medium

    CVE-2012-1703

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer, a different vulnerability than CVE-2012-1690.

    Published: 17 Apr 2012
    4.3
    Medium

    CVE-2012-2094

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the refresh mechanism in the log viewer in horizon/static/horizon/js/horizon.js in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the guest console.

    Published: 17 Apr 2012
    4.3
    Medium

    CVE-2012-1240

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the RECRUIT Dokodemo Rikunabi 2013 extension before 1.0.1 for Google Chrome allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Apr 2012
    7.5
    High

    CVE-2012-1241

    Last Modified: 11 Apr 2025

    GRScript18.dll before 1.2.2.0 in ActiveScriptRuby (ASR) before 1.8.7 does not properly restrict interaction with an Internet Explorer ActiveX environment, which allows remote attackers to execute arbitrary Ruby code via a crafted HTML document.

    Published: 16 Apr 2012
    5
    Medium

    CVE-2012-2213

    Last Modified: 11 Apr 2025

    Squid 3.1.9 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host HTTP header. NOTE: this issue might not be reproducible, because the researcher is unable to provide a squid.conf file for a vulnerable system, and the observed behavior is consistent with a squid.conf file that was (perhaps inadvertently) designed to allow access based on a "req_header Host" acl regex that matches www.uol.com.br

    Published: 16 Apr 2012
    3.3
    Low

    CVE-2012-3826

    Last Modified: 11 Apr 2025

    Multiple integer underflows in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allow remote attackers to cause a denial of service (loop) via vectors related to the R3 dissector, a different vulnerability than CVE-2012-2392.

    Published: 16 Apr 2012
    5.2
    Medium

    CVE-2012-2119

    Last Modified: 11 Apr 2025

    Buffer overflow in the macvtap device driver in the Linux kernel before 3.4.5, when running in certain configurations, allows privileged KVM guest users to cause a denial of service (crash) via a long descriptor with a long vector length.

    Published: 16 Apr 2012
    3.3
    Low

    CVE-2012-3825

    Last Modified: 11 Apr 2025

    Multiple integer overflows in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allow remote attackers to cause a denial of service (infinite loop) via vectors related to the (1) BACapp and (2) Bluetooth HCI dissectors, a different vulnerability than CVE-2012-2392.

    Published: 16 Apr 2012
    6
    Medium

    CVE-2012-4450

    Last Modified: 11 Apr 2025

    389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users with certain permissions to bypass ACL restrictions and access the DN entry.

    Published: 16 Apr 2012
    7.5
    High

    CVE-2012-1806

    Last Modified: 11 Apr 2025

    The ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 supports a maximum password length of 8 bytes, which makes it easier for remote attackers to obtain access via a brute-force attack.

    Published: 13 Apr 2012
    4.3
    Medium

    CVE-2012-1807

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web server in the ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 13 Apr 2012
    5
    Medium

    CVE-2012-1809

    Last Modified: 11 Apr 2025

    The web server in the ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 allows remote attackers to cause a denial of service (resource consumption) via unspecified vectors.

    Published: 13 Apr 2012
    10
    Critical

    CVE-2012-1805

    Last Modified: 11 Apr 2025

    Buffer overflow in the ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 allows remote attackers to execute arbitrary code via long strings in unspecified parameters.

    Published: 13 Apr 2012
    10
    Critical

    CVE-2012-1808

    Last Modified: 11 Apr 2025

    The web server in the ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 does not require authentication, which allows remote attackers to perform unspecified functions via unknown vectors.

    Published: 13 Apr 2012