CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2011-3067

    Last Modified: 11 Apr 2025

    Google Chrome before 18.0.1025.151 allows remote attackers to bypass the Same Origin Policy via vectors related to replacement of IFRAME elements.

    Published: 5 Apr 2012
    6.8
    Medium

    CVE-2011-3068

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to run-in boxes.

    Published: 5 Apr 2012
    6.8
    Medium

    CVE-2011-3072

    Last Modified: 11 Apr 2025

    Google Chrome before 18.0.1025.151 allows remote attackers to bypass the Same Origin Policy via vectors related to pop-up windows.

    Published: 5 Apr 2012
    6.8
    Medium

    CVE-2011-3073

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of SVG resources.

    Published: 5 Apr 2012
    6.8
    Medium

    CVE-2011-3075

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to style-application commands.

    Published: 5 Apr 2012
    6.8
    Medium

    CVE-2011-3069

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to line boxes.

    Published: 5 Apr 2012
    6.8
    Medium

    CVE-2011-3070

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the Google V8 bindings.

    Published: 5 Apr 2012
    6.8
    Medium

    CVE-2011-3071

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the HTMLMediaElement implementation in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 5 Apr 2012
    6.8
    Medium

    CVE-2011-3074

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of media.

    Published: 5 Apr 2012
    6.8
    Medium

    CVE-2011-3077

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving the script bindings, related to a "read-after-free" issue.

    Published: 5 Apr 2012
    6.8
    Medium

    CVE-2011-3076

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to focus handling.

    Published: 5 Apr 2012
    10
    Critical

    CVE-2012-0774

    Last Modified: 11 Apr 2025

    Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 allows attackers to execute arbitrary code via a crafted TrueType font.

    Published: 5 Apr 2012
    6.8
    Medium

    CVE-2012-0777

    Last Modified: 11 Apr 2025

    The JavaScript API in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 on Mac OS X and Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 5 Apr 2012
    10
    Critical

    CVE-2012-0775

    Last Modified: 11 Apr 2025

    The JavaScript implementation in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 5 Apr 2012
    5.8
    Medium

    CVE-2012-0128

    Last Modified: 11 Apr 2025

    HP Onboard Administrator (OA) before 3.50 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 4 Apr 2012
    7.6
    High

    CVE-2012-0129

    Last Modified: 11 Apr 2025

    HP Onboard Administrator (OA) before 3.50 allows remote attackers to bypass intended access restrictions and execute arbitrary code via unspecified vectors.

    Published: 4 Apr 2012
    5
    Medium

    CVE-2012-0130

    Last Modified: 11 Apr 2025

    HP Onboard Administrator (OA) before 3.50 allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 4 Apr 2012
    5
    Medium

    CVE-2008-7311

    Last Modified: 11 Apr 2025

    The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging an application that contains this value within the config/environment.rb file.

    Published: 4 Apr 2012
    5
    Medium

    CVE-2008-7310

    Last Modified: 11 Apr 2025

    Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the Order state value and bypass the intended payment step via a modified URL, related to a "mass assignment" vulnerability.

    Published: 4 Apr 2012
    5
    Medium

    CVE-2008-7309

    Last Modified: 11 Apr 2025

    Insoshi before 20080920 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the ForumPost user_id value via a modified URL, related to a "mass assignment" vulnerability.

    Published: 4 Apr 2012
    4.3
    Medium

    CVE-2012-0132

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 9.01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 4 Apr 2012
    9.3
    Critical

    CVE-2012-1336

    Last Modified: 11 Apr 2025

    Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 LC before SP25 EP10, and T27 LD before SP32 CP1 allows remote attackers to execute arbitrary code via a crafted WRF file, a different vulnerability than CVE-2012-1335 and CVE-2012-1337.

    Published: 4 Apr 2012
    9.3
    Critical

    CVE-2012-1337

    Last Modified: 11 Apr 2025

    Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 LC before SP25 EP10, and T27 LD before SP32 CP1 allows remote attackers to execute arbitrary code via a crafted WRF file, a different vulnerability than CVE-2012-1335 and CVE-2012-1336.

    Published: 4 Apr 2012
    9.3
    Critical

    CVE-2012-1335

    Last Modified: 11 Apr 2025

    Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 LC before SP25 EP10, and T27 LD before SP32 CP1 allows remote attackers to execute arbitrary code via a crafted WRF file, a different vulnerability than CVE-2012-1336 and CVE-2012-1337.

    Published: 4 Apr 2012
    4.3
    Medium

    CVE-2012-0327

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Redmine before 1.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 4 Apr 2012
    7.5
    High

    CVE-2012-1777

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in my.activation.php3 in F5 FirePass 6.0.0 through 6.1.0 and 7.0.0 allows remote attackers to execute arbitrary SQL commands via the state parameter.

    Published: 4 Apr 2012
    3.5
    Low

    CVE-2012-1982

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in my_admin/admin1_list_pages.php in SocialCMS 1.0.2 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the TR_title parameter in an edit action.

    Published: 4 Apr 2012
    7.5
    High

    CVE-2012-2055

    Last Modified: 11 Apr 2025

    GitHub Enterprise before 20120304 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the public_key[user_id] value via a modified URL for the public-key update form, related to a "mass assignment" vulnerability.

    Published: 4 Apr 2012
    7.2
    High

    CVE-2012-2053

    Last Modified: 11 Apr 2025

    The sudoers file in the Linux system configuration in F5 FirePass 6.0.0 through 6.1.0 and 7.0.0 does not require a password for executing commands as root, which allows local users to gain privileges via the sudo program, as demonstrated by the user account that executes PHP scripts, a different vulnerability than CVE-2012-1777.

    Published: 4 Apr 2012
    5
    Medium

    CVE-2012-2054

    Last Modified: 11 Apr 2025

    Redmine before 1.3.2 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set attributes in the (1) Comment, (2) Document, (3) IssueCategory, (4) MembersController, (5) Message, (6) News, (7) TimeEntry, (8) Version, (9) Wiki, (10) UserPreference, or (11) Board model via a modified URL, related to a "mass assignment" vulnerability, a different vulnerability than CVE-2012-0327.

    Published: 4 Apr 2012
    6.8
    Medium

    CVE-2012-1173

    Last Modified: 11 Apr 2025

    Multiple integer overflows in tiff_getimage.c in LibTIFF 3.9.4 allow remote attackers to execute arbitrary code via a crafted tile size in a TIFF file, which is not properly handled by the (1) gtTileSeparate or (2) gtStripSeparate function, leading to a heap-based buffer overflow.

    Published: 4 Apr 2012
    5
    Medium

    CVE-2012-4517

    Last Modified: 11 Apr 2025

    ibacm before 1.0.6 does not properly manage reference counts for multicast connections, which allows remote attackers to cause a denial of service (ibacm service crash) via a crafted join response.

    Published: 4 Apr 2012
    4
    Medium

    CVE-2012-2749

    Last Modified: 11 Apr 2025

    MySQL 5.1.x before 5.1.63 and 5.5.x before 5.5.24 allows remote authenticated users to cause a denial of service (mysqld crash) via vectors related to incorrect calculation and a sort order index.

    Published: 4 Apr 2012
    10
    Critical

    CVE-2012-0131

    Last Modified: 11 Apr 2025

    Distributed Computing Environment (DCE) 1.8 and 1.9 on HP HP-UX B.11.11 and B.11.23 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 3 Apr 2012
    9.3
    Critical

    CVE-2011-4042

    Last Modified: 11 Apr 2025

    An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code by using a crafted HTML document to obtain control of a function pointer.

    Published: 3 Apr 2012
    9.3
    Critical

    CVE-2011-4043

    Last Modified: 11 Apr 2025

    Integer overflow in an unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code via a large value for an integer parameter, leading to a buffer overflow.

    Published: 3 Apr 2012
    6.8
    Medium

    CVE-2011-4535

    Last Modified: 11 Apr 2025

    Buffer overflow in TurboPower Abbrevia before 4.0, as used in ScadaTEC ScadaPhone 5.3.11.1230 and earlier, ScadaTEC ModbusTagServer 4.1.1.81 and earlier, and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ZIP file.

    Published: 3 Apr 2012
    4.3
    Medium

    CVE-2011-4045

    Last Modified: 11 Apr 2025

    Buffer overflow in an unspecified ActiveX control in aipgctl.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to cause a denial of service via a crafted HTML document.

    Published: 3 Apr 2012
    5.8
    Medium

    CVE-2011-4044

    Last Modified: 11 Apr 2025

    An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to modify files via calls to unknown methods.

    Published: 3 Apr 2012
    6.8
    Medium

    CVE-2012-0815

    Last Modified: 11 Apr 2025

    The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.

    Published: 3 Apr 2012
    6.8
    Medium

    CVE-2012-0061

    Last Modified: 11 Apr 2025

    The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly validate region tags, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large region size in a package header.

    Published: 3 Apr 2012
    6.8
    Medium

    CVE-2012-0060

    Last Modified: 11 Apr 2025

    RPM before 4.9.1.3 does not properly validate region tags, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an invalid region tag in a package header to the (1) headerLoad, (2) rpmReadSignature, or (3) headerVerify function.

    Published: 3 Apr 2012
    7.5
    High

    CVE-2012-0226

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Invensys Wonderware Information Server 4.0 SP1 and 4.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 2 Apr 2012
    7.5
    High

    CVE-2012-0228

    Last Modified: 11 Apr 2025

    Invensys Wonderware Information Server 4.0 SP1 and 4.5 does not properly implement client controls, which allows remote attackers to bypass intended access restrictions via unspecified vectors.

    Published: 2 Apr 2012
    4.3
    Medium

    CVE-2012-0225

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Invensys Wonderware Information Server 4.0 SP1 and 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 2 Apr 2012
    6.8
    Medium

    CVE-2012-0257

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit 3.2 and earlier, and InTouch 10.0 through 10.5 might allow remote attackers to execute arbitrary code via a long string to the Open member, leading to a function-pointer overwrite.

    Published: 2 Apr 2012
    6.8
    Medium

    CVE-2012-0258

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit 3.2 and earlier, and InTouch 10.0 through 10.5 might allow remote attackers to execute arbitrary code via a long string to the AddFile member.

    Published: 2 Apr 2012
    4.3
    Medium

    CVE-2011-5084

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Movable Type 4.x before 4.36 and 5.x before 5.05 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 2 Apr 2012
    7.5
    High

    CVE-2011-5085

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Movable Type 4.x before 4.36 and 5.x before 5.05 allows remote attackers to read or modify data via unknown vectors.

    Published: 2 Apr 2012
    5
    Medium

    CVE-2012-0221

    Last Modified: 11 Apr 2025

    The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 does not properly handle the return value from an unspecified function, which allows remote attackers to cause a denial of service (service outage) via a crafted packet.

    Published: 2 Apr 2012