CVE Feed

    Dashboard / CVE

    7.9
    High

    CVE-2011-4874

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in MICROSYS PROMOTIC before 8.1.7 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (data corruption and application crash) via a crafted project (aka .pra) file.

    Published: 13 Apr 2012
    5
    Medium

    CVE-2011-4880

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 allows remote attackers to read arbitrary files via a crafted HTTP request.

    Published: 13 Apr 2012
    5
    Medium

    CVE-2011-4881

    Last Modified: 11 Apr 2025

    The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 does not properly check return values from functions, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted HTTP request.

    Published: 13 Apr 2012
    5
    Medium

    CVE-2011-4882

    Last Modified: 11 Apr 2025

    The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 allows remote attackers to cause a denial of service (application exit) via an unspecified command in an HTTP request.

    Published: 13 Apr 2012
    5
    Medium

    CVE-2011-4883

    Last Modified: 11 Apr 2025

    The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 does not properly validate values in HTTP requests, which allows remote attackers to cause a denial of service (resource consumption) via a crafted request.

    Published: 13 Apr 2012
    6.8
    Medium

    CVE-2011-3846

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) 6.2.2.7 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts.

    Published: 12 Apr 2012
    3.7
    Low

    CVE-2012-0133

    Last Modified: 11 Apr 2025

    HP ProCurve 5400 zl switches with certain serial numbers include a compact flash card that contains an unspecified virus, which might allow user-assisted remote attackers to execute arbitrary code on a PC by leveraging manual transfer of this card.

    Published: 12 Apr 2012
    6.5
    Medium

    CVE-2012-1574

    Last Modified: 11 Apr 2025

    The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through CDH3u2, Cloudera hadoop-0.20-sbin before 0.20.2+923.197, and other products, allows remote authenticated users to impersonate arbitrary cluster user accounts via unspecified vectors.

    Published: 12 Apr 2012
    6.5
    Medium

    CVE-2012-2230

    Last Modified: 11 Apr 2025

    Cloudera Manager 3.7.x before 3.7.5 and Service and Configuration Manager 3.5, when Kerberos is not enabled, does not properly install taskcontroller.cfg, which allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors, a different vulnerability than CVE-2012-1574.

    Published: 12 Apr 2012
    10
    Critical

    CVE-2012-2750

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in MySQL 5.5.x before 5.5.23 has unknown impact and attack vectors related to a "Security Fix", aka Bug #59533. NOTE: this might be a duplicate of CVE-2012-1689, but as of 20120816, Oracle has not commented on this possibility.

    Published: 12 Apr 2012
    4.3
    Medium

    CVE-2012-2223

    Last Modified: 11 Apr 2025

    The xplat agent in Novell ZENworks Configuration Management (ZCM) 10.3.x before 10.3.4 and 11.x before 11.2 enables the HTTP TRACE method, which might make it easier for remote attackers to conduct cross-site tracing (XST) attacks via unspecified vectors.

    Published: 11 Apr 2012
    7.5
    High

    CVE-2012-2225

    Last Modified: 11 Apr 2025

    360zip 1.93beta allows remote attackers to execute arbitrary code via vectors related to file browsing and file extraction.

    Published: 11 Apr 2012
    7.5
    High

    CVE-2012-2224

    Last Modified: 11 Apr 2025

    Xunlei Thunder before 7.2.6 allows remote attackers to execute arbitrary code via a crafted file, related to a "DLL injection vulnerability."

    Published: 11 Apr 2012
    4.3
    Medium

    CVE-2012-1030

    Last Modified: 24 Apr 2026

    Cross-site scripting (XSS) vulnerability in DotNetNuke 6.x through 6.0.2 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted URL containing text that is used within a modal popup.

    Published: 11 Apr 2012
    4.3
    Medium

    CVE-2012-1036

    Last Modified: 24 Apr 2026

    Cross-site scripting (XSS) vulnerability in the telerik HTML editor in DotNetNuke before 5.6.4 and 6.x before 6.1.0 allows remote attackers to inject arbitrary web script or HTML via a message.

    Published: 11 Apr 2012
    7.5
    High

    CVE-2012-1672

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in getcity.php in Hotel Booking Portal 0.1 allows remote attackers to execute arbitrary SQL commands via the country parameter.

    Published: 11 Apr 2012
    7.5
    High

    CVE-2012-1673

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in loginscript.php in e-ticketing allows remote attackers to execute arbitrary SQL commands via the password parameter.

    Published: 11 Apr 2012
    4.3
    Medium

    CVE-2012-1992

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/edituser.php in CMS Made Simple 1.10.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the email parameter (aka the Email Address field in the Edit User template).

    Published: 11 Apr 2012
    4.3
    Medium

    CVE-2012-2156

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Plume CMS 1.2.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the u_email parameter (aka Authors Email field) to manager/users.php, (2) the u_realname parameter (aka Authors Name field) to manager/users.php, or (3) the c_author parameter (aka Author field) in an ADD A COMMENT section.

    Published: 11 Apr 2012
    7.8
    High

    CVE-2012-2210

    Last Modified: 11 Apr 2025

    The Sony Bravia TV KDL-32CX525 allows remote attackers to cause a denial of service (configuration outage or device crash) via a flood of TCP SYN packets, as demonstrated by hping, a related issue to CVE-1999-0116.

    Published: 11 Apr 2012
    3.6
    Low

    CVE-2012-1989

    Last Modified: 11 Apr 2025

    telnet.rb in Puppet 2.7.x before 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows local users to overwrite arbitrary files via a symlink attack on the NET::Telnet connection log (/tmp/out.log).

    Published: 11 Apr 2012
    10
    Critical

    CVE-2012-0776

    Last Modified: 11 Apr 2025

    The installer in Adobe Reader 9.x before 9.5.1 and 10.x before 10.1.3 allows attackers to bypass intended access restrictions and execute arbitrary code via unspecified vectors.

    Published: 10 Apr 2012
    9.3
    Critical

    CVE-2012-0169

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "JScript9 Remote Code Execution Vulnerability."

    Published: 10 Apr 2012
    8.8
    High

    CVE-2012-0158

    Last Modified: 22 Apr 2026

    The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2, and 2009 Gold and R2; Visual FoxPro 8.0 SP1 and 9.0 SP2; and Visual Basic 6.0 Runtime allow remote attackers to execute arbitrary code via a crafted (a) web site, (b) Office document, or (c) .rtf file that triggers "system state" corruption, as exploited in the wild in April 2012, aka "MSCOMCTL.OCX RCE Vulnerability."

    Published: 10 Apr 2012
    7.8
    High

    CVE-2012-0151

    Last Modified: 22 Apr 2026

    The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute arbitrary code via a modified file with additional content, aka "WinVerifyTrust Signature Validation Vulnerability."

    Published: 10 Apr 2012
    5.8
    Medium

    CVE-2012-0146

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "UAG Blind HTTP Redirect Vulnerability."

    Published: 10 Apr 2012
    5
    Medium

    CVE-2012-0147

    Last Modified: 11 Apr 2025

    Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 does not properly configure the default web site, which allows remote attackers to obtain sensitive information via a crafted HTTPS request, aka "Unfiltered Access to UAG Default Website Vulnerability."

    Published: 10 Apr 2012
    7.6
    High

    CVE-2012-0168

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 9 allows user-assisted remote attackers to execute arbitrary code via a crafted HTML document that is not properly handled during a "Print table of links" print operation, aka "Print Feature Remote Code Execution Vulnerability."

    Published: 10 Apr 2012
    9.3
    Critical

    CVE-2012-0172

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "VML Style Remote Code Execution Vulnerability."

    Published: 10 Apr 2012
    9.3
    Critical

    CVE-2012-0163

    Last Modified: 11 Apr 2025

    Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate function parameters, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Parameter Validation Vulnerability."

    Published: 10 Apr 2012
    9.3
    Critical

    CVE-2012-0170

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "OnReadyStateChange Remote Code Execution Vulnerability."

    Published: 10 Apr 2012
    9.3
    Critical

    CVE-2012-0171

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "SelectAll Remote Code Execution Vulnerability."

    Published: 10 Apr 2012
    9.3
    Critical

    CVE-2012-0177

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the Office Works File Converter in Microsoft Office 2007 SP2, Works 9, and Works 6-9 File Converter allows remote attackers to execute arbitrary code via a crafted Works (aka .wps) file, aka "Office WPS Converter Heap Overflow Vulnerability."

    Published: 10 Apr 2012
    3.5
    Low

    CVE-2012-1987

    Last Modified: 20 Nov 2025

    Unspecified vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys to (1) cause a denial of service (memory consumption) via a REST request to a stream that triggers a thread block, as demonstrated using CVE-2012-1986 and /dev/random; or (2) cause a denial of service (filesystem consumption) via crafted REST requests that use "a marshaled form of a Puppet::FileBucket::File object" to write to arbitrary file locations.

    Published: 10 Apr 2012
    2.1
    Low

    CVE-2012-1986

    Last Modified: 11 Apr 2025

    Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbitrary files via a symlink attack in conjunction with a crafted REST request for a file in a filebucket.

    Published: 10 Apr 2012
    6
    Medium

    CVE-2012-1988

    Last Modified: 11 Apr 2025

    Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute arbitrary commands by creating a file whose full pathname contains shell metacharacters, then performing a filebucket request.

    Published: 10 Apr 2012
    10
    Critical

    CVE-2012-1182

    Last Modified: 11 Apr 2025

    The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.

    Published: 10 Apr 2012
    5
    Medium

    CVE-2012-2215

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to read arbitrary files via an opcode 0x21 request.

    Published: 9 Apr 2012
    10
    Critical

    CVE-2011-3175

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to execute arbitrary code via an opcode 0x6c request.

    Published: 9 Apr 2012
    10
    Critical

    CVE-2011-3176

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to execute arbitrary code via an opcode 0x4c request.

    Published: 9 Apr 2012
    1.9
    Low

    CVE-2012-0742

    Last Modified: 11 Apr 2025

    IBM Tivoli Event Pump 4.2.2, when the LOG_REQUESTS and VALIDATE_SOAP_USERS options are enabled, places credentials into the AOPSCLOG (aka AOPLOG) data set, which allows local users to obtain sensitive information by reading the data.

    Published: 9 Apr 2012
    4
    Medium

    CVE-2011-4188

    Last Modified: 11 Apr 2025

    Buffer overflow in the Create Attribute function in jclient in Novell iManager 2.7.4 before patch 4 allows remote authenticated users to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted EnteredAttrName parameter, a related issue to CVE-2010-1929.

    Published: 9 Apr 2012
    4.3
    Medium

    CVE-2012-3425

    Last Modified: 11 Apr 2025

    The png_push_read_zTXt function in pngpread.c in libpng 1.0.x before 1.0.58, 1.2.x before 1.2.48, 1.4.x before 1.4.10, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (out-of-bounds read) via a large avail_in field value in a PNG image.

    Published: 8 Apr 2012
    9.3
    Critical

    CVE-2012-0724

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 11.2.202.229 in Google Chrome before 18.0.1025.151 allow attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2012-0725.

    Published: 6 Apr 2012
    9.3
    Critical

    CVE-2012-0725

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 11.2.202.229 in Google Chrome before 18.0.1025.151 allow attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2012-0724.

    Published: 6 Apr 2012
    4.3
    Medium

    CVE-2012-1902

    Last Modified: 11 Apr 2025

    show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a configuration file does not exist, allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message about this missing file.

    Published: 6 Apr 2012
    10
    Critical

    CVE-2012-1239

    Last Modified: 11 Apr 2025

    The TopAccess web-based management interface on TOSHIBA TEC e-Studio multi-function peripheral (MFP) devices with firmware 30x through 302, 35x through 354, and 4xx through 421 allows remote attackers to bypass authentication and obtain administrative privileges via unspecified vectors.

    Published: 6 Apr 2012
    6.8
    Medium

    CVE-2012-1237

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in SENCHA SNS before 1.0.2 allows remote attackers to hijack the authentication of arbitrary users.

    Published: 6 Apr 2012
    4.3
    Medium

    CVE-2012-1238

    Last Modified: 11 Apr 2025

    Session fixation vulnerability in SENCHA SNS before 1.0.2 allows remote attackers to hijack web sessions via unspecified vectors.

    Published: 6 Apr 2012
    6.8
    Medium

    CVE-2011-3066

    Last Modified: 11 Apr 2025

    Skia, as used in Google Chrome before 18.0.1025.151, does not properly perform clipping, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 5 Apr 2012