CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2012-0222

    Last Modified: 11 Apr 2025

    The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted packet.

    Published: 2 Apr 2012
    8.3
    High

    CVE-2012-1515

    Last Modified: 11 Apr 2025

    VMware ESXi 3.5, 4.0, and 4.1 and ESX 3.5, 4.0, and 4.1 do not properly implement port-based I/O operations, which allows guest OS users to gain guest OS privileges by overwriting memory locations in a read-only memory block associated with the Virtual DOS Machine.

    Published: 2 Apr 2012
    9.3
    Critical

    CVE-2012-0246

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in an unspecified ActiveX control in Ecava IntegraXor before 3.71.4200 allows remote attackers to execute arbitrary code via vectors involving an HTML document on the server.

    Published: 2 Apr 2012
    10
    Critical

    CVE-2012-0127

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Performance Manager 9.00 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 31 Mar 2012
    5
    Medium

    CVE-2012-1670

    Last Modified: 11 Apr 2025

    admin/index.php in PHP Grade Book before 1.9.5 BETA allows remote attackers to read the database via a SaveSQL action.

    Published: 31 Mar 2012
    4.3
    Medium

    CVE-2011-3058

    Last Modified: 11 Apr 2025

    Google Chrome before 18.0.1025.142 does not properly handle the EUC-JP encoding system, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

    Published: 30 Mar 2012
    6.8
    Medium

    CVE-2011-3065

    Last Modified: 11 Apr 2025

    Skia, as used in Google Chrome before 18.0.1025.142, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 30 Mar 2012
    4.3
    Medium

    CVE-2011-3063

    Last Modified: 11 Apr 2025

    Google Chrome before 18.0.1025.142 does not properly validate the renderer's navigation requests, which has unspecified impact and remote attack vectors.

    Published: 30 Mar 2012
    5.8
    Medium

    CVE-2011-3061

    Last Modified: 11 Apr 2025

    Google Chrome before 18.0.1025.142 does not properly check X.509 certificates before use of a SPDY proxy, which might allow man-in-the-middle attackers to spoof servers or obtain sensitive information via a crafted certificate.

    Published: 30 Mar 2012
    6.8
    Medium

    CVE-2011-3062

    Last Modified: 11 Apr 2025

    Off-by-one error in the OpenType Sanitizer in Google Chrome before 18.0.1025.142 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted OpenType file.

    Published: 30 Mar 2012
    4.4
    Medium

    CVE-2018-5382

    Last Modified: 12 May 2025

    The default BKS keystore use an HMAC that is only 16 bits long, which can allow an attacker to compromise the integrity of a BKS keystore. Bouncy Castle release 1.47 changes the BKS format to a format which uses a 160 bit HMAC instead. This applies to any BKS keystore generated prior to BC 1.47. For situations where people need to create the files for legacy reasons a specific keystore type "BKS-V1" was introduced in 1.49. It should be noted that the use of "BKS-V1" is discouraged by the library authors and should only be used where it is otherwise safe to do so, as in where the use of a 16 bit checksum for the file integrity check is not going to cause a security issue in itself.

    Published: 30 Mar 2012
    7.2
    High

    CVE-2012-0384

    Last Modified: 11 Apr 2025

    Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS before 3.1.2S, 3.2.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.1.xSG and 3.2.xSG before 3.2.2SG, when AAA authorization is enabled, allow remote authenticated users to bypass intended access restrictions and execute commands via a (1) HTTP or (2) HTTPS session, aka Bug ID CSCtr91106.

    Published: 29 Mar 2012
    7.8
    High

    CVE-2012-0385

    Last Modified: 11 Apr 2025

    The Smart Install feature in Cisco IOS 12.2, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (device reload) by sending a malformed Smart Install message over TCP, aka Bug ID CSCtt16051.

    Published: 29 Mar 2012
    7.8
    High

    CVE-2012-0386

    Last Modified: 11 Apr 2025

    The SSHv2 implementation in Cisco IOS 12.2, 12.4, 15.0, 15.1, and 15.2 and IOS XE 2.3.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S allows remote attackers to cause a denial of service (device reload) via a crafted username in a reverse SSH login attempt, aka Bug ID CSCtr49064.

    Published: 29 Mar 2012
    7.8
    High

    CVE-2012-0387

    Last Modified: 11 Apr 2025

    Memory leak in the HTTP Inspection Engine feature in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted transit HTTP traffic, aka Bug ID CSCtq36153.

    Published: 29 Mar 2012
    7.8
    High

    CVE-2012-0388

    Last Modified: 11 Apr 2025

    Memory leak in the H.323 inspection feature in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via malformed transit H.323 traffic, aka Bug ID CSCtq45553.

    Published: 29 Mar 2012
    7.8
    High

    CVE-2012-1310

    Last Modified: 11 Apr 2025

    Memory leak in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted IP packets, aka Bug ID CSCto89536.

    Published: 29 Mar 2012
    7.8
    High

    CVE-2012-1311

    Last Modified: 11 Apr 2025

    The RSVP feature in Cisco IOS 15.0 and 15.1 and IOS XE 3.2.xS through 3.4.xS before 3.4.2S, when a VRF interface is configured, allows remote attackers to cause a denial of service (interface queue wedge and service outage) via crafted RSVP packets, aka Bug ID CSCts80643.

    Published: 29 Mar 2012
    7.1
    High

    CVE-2012-1312

    Last Modified: 11 Apr 2025

    The MACE feature in Cisco IOS 15.1 and 15.2 allows remote attackers to cause a denial of service (device reload) via crafted transit traffic, aka Bug IDs CSCtq64987 and CSCtu57226.

    Published: 29 Mar 2012
    7.8
    High

    CVE-2012-1315

    Last Modified: 11 Apr 2025

    Memory leak in the SIP inspection feature in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted transit SIP traffic, aka Bug ID CSCti46171.

    Published: 29 Mar 2012
    7.5
    High

    CVE-2012-0381

    Last Modified: 11 Apr 2025

    The IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.2.xSG before 3.2.2SG allows remote attackers to cause a denial of service (device reload) by sending IKE UDP packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCts38429.

    Published: 29 Mar 2012
    7.8
    High

    CVE-2012-0383

    Last Modified: 11 Apr 2025

    Memory leak in the NAT feature in Cisco IOS 12.4, 15.0, and 15.1 allows remote attackers to cause a denial of service (memory consumption, and device hang or reload) via SIP packets that require translation, related to a "memory starvation vulnerability," aka Bug ID CSCti35326.

    Published: 29 Mar 2012
    7.5
    High

    CVE-2012-0382

    Last Modified: 11 Apr 2025

    The Multicast Source Discovery Protocol (MSDP) implementation in Cisco IOS 12.0, 12.2 through 12.4, and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.1S and 3.1.xSG and 3.2.xSG before 3.2.2SG allows remote attackers to cause a denial of service (device reload) via encapsulated IGMP data in an MSDP packet, aka Bug ID CSCtr28857.

    Published: 29 Mar 2012
    7.8
    High

    CVE-2012-1314

    Last Modified: 11 Apr 2025

    The WAAS Express feature in Cisco IOS 15.1 and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted transit traffic, aka Bug ID CSCtt45381.

    Published: 29 Mar 2012
    5
    Medium

    CVE-2012-1145

    Last Modified: 11 Apr 2025

    spacewalk-backend in Red Hat Network Satellite 5.4 on Red Hat Enterprise Linux 6 does not properly authorize or authenticate uploads to the NULL organization when mod_wsgi is used, which allows remote attackers to cause a denial of service (/var partition disk consumption and failed updates) via a large number of package uploads.

    Published: 29 Mar 2012
    4.9
    Medium

    CVE-2012-2121

    Last Modified: 11 Apr 2025

    The KVM implementation in the Linux kernel before 3.3.4 does not properly manage the relationships between memory slots and the iommu, which allows guest OS users to cause a denial of service (memory leak and host OS crash) by leveraging administrative access to the guest OS to conduct hotunplug and hotplug operations on devices.

    Published: 29 Mar 2012
    6.8
    Medium

    CVE-2011-3048

    Last Modified: 11 Apr 2025

    The png_set_text_2 function in pngset.c in libpng 1.0.x before 1.0.59, 1.2.x before 1.2.49, 1.4.x before 1.4.11, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted text chunk in a PNG image file, which triggers a memory allocation failure that is not properly handled, leading to a heap-based buffer overflow.

    Published: 29 Mar 2012
    10
    Critical

    CVE-2012-0772

    Last Modified: 11 Apr 2025

    An unspecified ActiveX control in Adobe Flash Player before 10.3.183.18 and 11.x before 11.2.202.228, and AIR before 3.2.0.2070, on Windows does not properly perform URL security domain checking, which allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors.

    Published: 28 Mar 2012
    6.2
    Medium

    CVE-2007-6753

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Shell32.dll in Microsoft Windows 2000, Windows XP, Windows Vista, Windows Server 2008, and Windows 7, when using an environment configured with a string such as %APPDATA% or %PROGRAMFILES% in a certain way, allows local users to gain privileges via a Trojan horse DLL under the current working directory, as demonstrated by iTunes and Safari.

    Published: 28 Mar 2012
    3.3
    Low

    CVE-2012-0125

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the WBEM implementation in HP HP-UX 11.31 allows local users to obtain access to diagnostic information via unknown vectors, a related issue to CVE-2012-0126.

    Published: 28 Mar 2012
    6.8
    Medium

    CVE-2007-6752

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that end a session via the user/logout URI. NOTE: the vendor disputes the significance of this issue, by considering the "security benefit against platform complexity and performance impact" and concluding that a change to the logout behavior is not planned because "for most sites it is not worth the trade-off.

    Published: 28 Mar 2012
    5.8
    Medium

    CVE-2012-0126

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the WBEM implementation in HP HP-UX 11.11 and 11.23 allows remote attackers to obtain access to diagnostic information via unknown vectors, a related issue to CVE-2012-0125.

    Published: 28 Mar 2012
    4.3
    Medium

    CVE-2012-1907

    Last Modified: 11 Apr 2025

    The scanner engine in PrivaWall Antivirus 5.6 and earlier does not recognize the Office XML (aka Open Document XML) file format, which allows remote attackers to bypass malware detection via a crafted file embedded in a WordML document.

    Published: 28 Mar 2012
    4.3
    Medium

    CVE-2012-1904

    Last Modified: 11 Apr 2025

    mp4fformat.dll in the QuickTime File Format plugin in RealNetworks RealPlayer 15 and earlier, and RealPlayer SP 1.1.4 Build 12.0.0.756 and earlier, allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted MP4 file.

    Published: 28 Mar 2012
    Unknown

    CVE-2012-1913

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-0754. Reason: This candidate is a reservation duplicate of CVE-2010-0754. Notes: All CVE users should reference CVE-2010-0754 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Mar 2012
    4.3
    Medium

    CVE-2012-1570

    Last Modified: 11 Apr 2025

    The resolver in MaraDNS before 1.3.0.7.15 and 1.4.x before 1.4.12 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.

    Published: 28 Mar 2012
    6.8
    Medium

    CVE-2012-1924

    Last Modified: 11 Apr 2025

    Opera before 11.62 allows user-assisted remote attackers to trick users into downloading and executing arbitrary files via a small window for the download dialog.

    Published: 28 Mar 2012
    6.8
    Medium

    CVE-2012-1925

    Last Modified: 11 Apr 2025

    Opera before 11.62 does not ensure that a dialog window is placed on top of content windows, which makes it easier for user-assisted remote attackers to trick users into downloading and executing arbitrary files via a download dialog located under other windows.

    Published: 28 Mar 2012
    5
    Medium

    CVE-2012-1926

    Last Modified: 11 Apr 2025

    Opera before 11.62 allows remote attackers to bypass the Same Origin Policy via the (1) history.pushState and (2) history.replaceState functions in conjunction with cross-domain frames, leading to unintended read access to history.state information.

    Published: 28 Mar 2012
    6.4
    Medium

    CVE-2012-1927

    Last Modified: 11 Apr 2025

    Opera before 11.62 allows remote attackers to spoof the address field by triggering the launch of a dialog window associated with a different domain.

    Published: 28 Mar 2012
    6.4
    Medium

    CVE-2012-1928

    Last Modified: 11 Apr 2025

    Opera before 11.62 allows remote attackers to spoof the address field by triggering a page reload followed by a redirect to a different domain.

    Published: 28 Mar 2012
    6.4
    Medium

    CVE-2012-1929

    Last Modified: 11 Apr 2025

    Opera before 11.62 on Mac OS X allows remote attackers to spoof the address field and security dialogs via crafted styling that causes page content to be displayed outside of the intended content area.

    Published: 28 Mar 2012
    4.6
    Medium

    CVE-2012-1931

    Last Modified: 11 Apr 2025

    Opera before 11.62 on UNIX, when used in conjunction with an unspecified printing application, allows local users to overwrite arbitrary files via a symlink attack on a temporary file during printing.

    Published: 28 Mar 2012
    4.6
    Medium

    CVE-2012-1930

    Last Modified: 11 Apr 2025

    Opera before 11.62 on UNIX uses world-readable permissions for temporary files during printing, which allows local users to obtain sensitive information by reading these files.

    Published: 28 Mar 2012
    6.8
    Medium

    CVE-2011-3060

    Last Modified: 11 Apr 2025

    Google Chrome before 18.0.1025.142 does not properly handle text fragments, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 28 Mar 2012
    6.8
    Medium

    CVE-2011-3059

    Last Modified: 11 Apr 2025

    Google Chrome before 18.0.1025.142 does not properly handle SVG text elements, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 28 Mar 2012
    3.3
    Low

    CVE-2012-0250

    Last Modified: 11 Apr 2025

    Buffer overflow in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (daemon crash) via a Link State Update (aka LS Update) packet containing a network-LSA link-state advertisement for which the data-structure length is smaller than the value in the Length header field.

    Published: 28 Mar 2012
    6.5
    Medium

    CVE-2012-0259

    Last Modified: 11 Apr 2025

    The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a zero value in the component count of an EXIF XResolution tag in a JPEG file, which triggers an out-of-bounds read.

    Published: 28 Mar 2012
    7.5
    High

    CVE-2011-3064

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 18.0.1025.142 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG clipping.

    Published: 28 Mar 2012
    3.3
    Low

    CVE-2012-0249

    Last Modified: 11 Apr 2025

    Buffer overflow in the ospf_ls_upd_list_lsa function in ospf_packet.c in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a Link State Update (aka LS Update) packet that is smaller than the length specified in its header.

    Published: 28 Mar 2012