CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2012-0402

    Last Modified: 11 Apr 2025

    EMC RSA enVision 4.x before 4.1 Patch 4 uses unspecified hardcoded credentials, which makes it easier for remote attackers to obtain access via unknown vectors.

    Published: 20 Mar 2012
    6.3
    Medium

    CVE-2012-0403

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in EMC RSA enVision 4.x before 4.1 Patch 4 allows remote authenticated users to have an unspecified impact via unknown vectors.

    Published: 20 Mar 2012
    4.3
    Medium

    CVE-2012-0399

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA enVision 4.x before 4.1 Patch 4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 20 Mar 2012
    6.8
    Medium

    CVE-2012-1163

    Last Modified: 11 Apr 2025

    Integer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to execute arbitrary code via the size and offset values for the central directory in a zip archive, which triggers "improper restrictions of operations within the bounds of a memory buffer" and an information leak.

    Published: 20 Mar 2012
    9.3
    Critical

    CVE-2012-1499

    Last Modified: 11 Apr 2025

    The JPEG 2000 codec (jp2.c) in OpenJPEG before 1.5 allows remote attackers to execute arbitrary code via a crafted palette index in a CMAP record of a JPEG image, which triggers memory corruption, aka "out-of heap-based buffer write."

    Published: 20 Mar 2012
    3.7
    Low

    CVE-2012-0032

    Last Modified: 12 Apr 2025

    Red Hat JBoss Operations Network (JON) before 3.0.1 uses 0777 permissions for the root directory when installing a remote client, which allows local users to read or modify subdirectories and files within the root directory, as demonstrated by obtaining JON credentials.

    Published: 20 Mar 2012
    7.5
    High

    CVE-2012-1162

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a zip archive with the number of directories set to 0, related to an "incorrect loop construct."

    Published: 20 Mar 2012
    5
    Medium

    CVE-2012-0328

    Last Modified: 11 Apr 2025

    Janetter before 3.3.0.0 (aka 3.3.0) allows remote attackers to obtain session information for twitter.com web sites via unspecified vectors.

    Published: 19 Mar 2012
    5
    Medium

    CVE-2012-1181

    Last Modified: 11 Apr 2025

    fcgid_spawn_ctl.c in the mod_fcgid module 2.3.6 for the Apache HTTP Server does not recognize the FcgidMaxProcessesPerClass directive for a virtual host, which makes it easier for remote attackers to cause a denial of service (memory consumption) via a series of HTTP requests that triggers a process count higher than the intended limit.

    Published: 19 Mar 2012
    6.8
    Medium

    CVE-2012-1236

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Janetter before 3.3.0.0 (aka 3.3.0) allow remote attackers to hijack the authentication of arbitrary users for requests that (1) tweet, (2) upload an image file, or (3) execute arbitrary commands.

    Published: 19 Mar 2012
    3.3
    Low

    CVE-2012-0054

    Last Modified: 11 Apr 2025

    libs/updater.py in GoLismero 0.6.3, and other versions before Git revision 2b3bb43d6867, as used in backtrack and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on GoLismero-controlled files, as demonstrated using Admin/changes.dat.

    Published: 19 Mar 2012
    3.6
    Low

    CVE-2012-0808

    Last Modified: 11 Apr 2025

    as31 2.3.1-4 does not seed the random number generator and generates predictable temporary file names, which makes it easier for local users to create or truncate files via a symlink attack.

    Published: 19 Mar 2012
    4.3
    Medium

    CVE-2012-1039

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) login_data parameter to admin/auth.php; (2) nb parameter to admin/blogs.php; (3) type, (4) sortby, (5) order, or (6) status parameters to admin/comments.php; or (7) page parameter to admin/plugin.php.

    Published: 19 Mar 2012
    5
    Medium

    CVE-2012-1464

    Last Modified: 11 Apr 2025

    Dashboard Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the installation path via a request with a trailing "?" character, which causes Dashboard to attempt to access a non-existent resource. NOTE: some of these details are obtained from third party information.

    Published: 19 Mar 2012
    4.3
    Medium

    CVE-2012-1465

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the HTTP Server in NetMechanica NetDecision before 4.6.1 allows remote attackers to cause a denial of service (application crash) via a long URL in an HTTP request. NOTE: some of these details are obtained from third party information.

    Published: 19 Mar 2012
    4.3
    Medium

    CVE-2012-0872

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in OxWall 1.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) captchaField, (2) email, (3) form_name, (4) password, (5) realname, (6) repeatPassword, or (7) username parameters to Oxwall/join; (8) captcha, (9) email, (10) form_name, (11) from, or (12) subject parameters to Oxwall/contact; (13) tag parameter to Oxwall/blogs/browse-by-tag; or (14) PATH_INFO to Oxwall/photo/viewlist/tagged, (15) Oxwall/photo/viewlist, or (16) Oxwall/video/viewlist.

    Published: 19 Mar 2012
    5
    Medium

    CVE-2012-1466

    Last Modified: 11 Apr 2025

    The Traffic Grapher Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the source code of NtDecision script files with a .nd extension via an invalid version number in an HTTP request, as demonstrated using default.nd. NOTE: some of these details are obtained from third party information.

    Published: 19 Mar 2012
    6.8
    Medium

    CVE-2012-1498

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Webfolio CMS 1.1.4 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator via an add action to admin/users/add or (2) modify a web page via a save action to admin/pages/edit/web_page_name.

    Published: 19 Mar 2012
    5
    Medium

    CVE-2009-5112

    Last Modified: 11 Apr 2025

    wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to obtain the installation path via a crafted request.

    Published: 19 Mar 2012
    5
    Medium

    CVE-2009-5114

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the DOC parameter.

    Published: 19 Mar 2012
    5
    Medium

    CVE-2010-5086

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in wiki/rankings.php in Bitweaver 2.7 and 2.8.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the style parameter.

    Published: 19 Mar 2012
    7.5
    High

    CVE-2012-1778

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in artykul_print.php in CreateVision CMS allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 19 Mar 2012
    4.3
    Medium

    CVE-2012-1779

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IDevSpot idev-BusinessDirectory 3.0 allows remote attackers to inject arbitrary web script or HTML via the SEARCH parameter to index.php.

    Published: 19 Mar 2012
    4.3
    Medium

    CVE-2012-1782

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in questions/ask in OSQA 3b allow remote attackers to inject arbitrary web script or HTML via the (1) url bar or (2) picture bar.

    Published: 19 Mar 2012
    7.8
    High

    CVE-2012-1783

    Last Modified: 11 Apr 2025

    Tiny Server 1.1.9 and earlier allows remote attackers to cause a denial of service (crash) via a long string in a GET request without an HTTP version number.

    Published: 19 Mar 2012
    7.5
    High

    CVE-2012-1784

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in MyJobList 0.1.3 allows remote attackers to execute arbitrary SQL commands via the eid parameter in a profile action to index.php.

    Published: 19 Mar 2012
    5
    Medium

    CVE-2012-1786

    Last Modified: 11 Apr 2025

    The Media Upload form in the Video Embed & Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to obtain the installation path via unknown vectors.

    Published: 19 Mar 2012
    4.3
    Medium

    CVE-2012-1787

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in wgarcmin.cgi in Webglimpse 2.20.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) URL, (2) FILE, or (3) DOMAIN parameters.

    Published: 19 Mar 2012
    4.3
    Medium

    CVE-2012-1789

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Kongreg8 1.7.3 allow remote attackers to inject arbitrary web script or HTML via the (1) surname or (2) firstname parameters to modules/members/addmember.php; or (3) groupdescription or (4) groupname parameters to modules/groups/addgroupform.php.

    Published: 19 Mar 2012
    4.3
    Medium

    CVE-2009-5113

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the DOC parameter.

    Published: 19 Mar 2012
    7.5
    High

    CVE-2011-5083

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary code by uploading a file with an executable PHP extension, then accessing it via a direct request to the file in an unspecified directory.

    Published: 19 Mar 2012
    6.8
    Medium

    CVE-2012-1297

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in main.php in Contao (formerly TYPOlight) 2.11.0 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) delete users via a delete action in the user module, (2) delete news via a delete action in the news module, or (3) delete newsletters via a delete action in the newsletters module.

    Published: 19 Mar 2012
    4.3
    Medium

    CVE-2012-1781

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ajax/commentajax.php in SocialCMS 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) TREF_email_address or (2) TR_name parameters.

    Published: 19 Mar 2012
    5
    Medium

    CVE-2012-1790

    Last Modified: 11 Apr 2025

    Absolute path traversal vulnerability in Webgrind 1.0 and 1.0.2 allows remote attackers to read arbitrary files via a full pathname in the file parameter to index.php.

    Published: 19 Mar 2012
    4.3
    Medium

    CVE-2011-5082

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code field).

    Published: 19 Mar 2012
    7.5
    High

    CVE-2012-1780

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in search.php in SocialCMS 1.0.5 allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Published: 19 Mar 2012
    7.5
    High

    CVE-2012-1785

    Last Modified: 11 Apr 2025

    kg_callffmpeg.php in the Video Embed & Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to execute arbitrary commands via unspecified vectors.

    Published: 19 Mar 2012
    4.3
    Medium

    CVE-2012-1788

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in wonderdesk.cgi in WonderDesk SQL 4.14 allow remote attackers to inject arbitrary web script or HTML via the (1) cus_email parameter in a cust_lostpw action; or (2) help_name, (3) help_email, (4) help_website, or (5) help_example_url parameters in an hd_modify_record action.

    Published: 19 Mar 2012
    9.3
    Critical

    CVE-2012-1775

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in VideoLAN VLC media player before 2.0.1 allows remote attackers to execute arbitrary code via a crafted MMS:// stream.

    Published: 19 Mar 2012
    9.3
    Critical

    CVE-2012-1776

    Last Modified: 11 Apr 2025

    Multiple heap-based buffer overflows in VideoLAN VLC media player before 2.0.1 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Real RTSP stream.

    Published: 19 Mar 2012
    5.5
    Medium

    CVE-2012-1186

    Last Modified: 11 Apr 2025

    Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted IOP tag offsets in the IFD in an image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0248.

    Published: 19 Mar 2012
    5
    Medium

    CVE-2012-1569

    Last Modified: 11 Apr 2025

    The asn1_get_length_der function in decoding.c in GNU Libtasn1 before 2.12, as used in GnuTLS before 3.0.16 and other products, does not properly handle certain large length values, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly have unspecified other impact via a crafted ASN.1 structure.

    Published: 19 Mar 2012
    7.8
    High

    CVE-2012-1185

    Last Modified: 11 Apr 2025

    Multiple integer overflows in (1) magick/profile.c or (2) magick/property.c in ImageMagick 6.7.5 and earlier allow remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset value in the ResolutionUnit tag in the EXIF IFD0 of an image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0247.

    Published: 19 Mar 2012
    9.3
    Critical

    CVE-2012-1264

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Gretech GOM Media Player before 2.1.37.5091 allows remote attackers to execute arbitrary code via a crafted AVI file.

    Published: 18 Mar 2012
    10
    Critical

    CVE-2012-1774

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Open URL feature in Gretech GOM Media Player before 2.1.39.5101 has unknown impact and attack vectors, a different vulnerability than CVE-2007-5779 and CVE-2012-1264.

    Published: 18 Mar 2012
    6.8
    Medium

    CVE-2012-0293

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Symantec Altiris WISE Package Studio before 8.0MR1 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 17 Mar 2012
    5
    Medium

    CVE-2012-0326

    Last Modified: 11 Apr 2025

    The twicca application 0.7.0 through 0.9.30 for Android does not properly restrict the use of network privileges, which allows remote attackers to read media files on an SD card via a crafted application.

    Published: 17 Mar 2012
    1.9
    Low

    CVE-2012-1568

    Last Modified: 11 Apr 2025

    The ExecShield feature in a certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux (RHEL) 5 and 6 and Fedora 15 and 16 does not properly handle use of many shared libraries by a 32-bit executable file, which makes it easier for context-dependent attackers to bypass the ASLR protection mechanism by leveraging a predictable base address for one of these libraries.

    Published: 17 Mar 2012
    4.3
    Medium

    CVE-2012-1511

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in View Manager Portal in VMware View before 4.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 16 Mar 2012
    4
    Medium

    CVE-2012-1513

    Last Modified: 11 Apr 2025

    The Web Configuration tool in VMware vCenter Orchestrator (vCO) 4.0 before Update 4, 4.1 before Update 2, and 4.2 before Update 1 places the vCenter Server password in an HTML document, which allows remote authenticated administrators to obtain sensitive information by reading this document.

    Published: 16 Mar 2012