CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2012-1514

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in VMware vShield Manager (vSM) 1.0.1 before Update 2 and 4.1.0 before Update 2 allows remote attackers to hijack the authentication of arbitrary users.

    Published: 16 Mar 2012
    7.2
    High

    CVE-2012-1510

    Last Modified: 11 Apr 2025

    Buffer overflow in the WDDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS privileges via unspecified vectors.

    Published: 16 Mar 2012
    4.3
    Medium

    CVE-2012-1512

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the internal browser in vSphere Client in VMware vSphere 4.1 before Update 2 and 5.0 before Update 1 allows remote attackers to inject arbitrary web script or HTML via a crafted log-file entry.

    Published: 16 Mar 2012
    7.2
    High

    CVE-2012-1508

    Last Modified: 11 Apr 2025

    The XPDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.

    Published: 16 Mar 2012
    7.2
    High

    CVE-2012-1509

    Last Modified: 11 Apr 2025

    Buffer overflow in the XPDM display driver in VMware View before 4.6.1 allows guest OS users to gain guest OS privileges via unspecified vectors.

    Published: 16 Mar 2012
    5
    Medium

    CVE-2012-6113

    Last Modified: 11 Apr 2025

    The openssl_encrypt function in ext/openssl/openssl.c in PHP 5.3.9 through 5.3.13 does not initialize a certain variable, which allows remote attackers to obtain sensitive information from process memory by providing zero bytes of input data.

    Published: 16 Mar 2012
    10
    Critical

    CVE-2012-0229

    Last Modified: 11 Apr 2025

    The Data Archiver service in GE Intelligent Platforms Proficy Historian 4.5 and earlier allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted session on TCP port 14000 to (1) ihDataArchiver.exe or (2) ihDataArchiver_x64.exe.

    Published: 15 Mar 2012
    10
    Critical

    CVE-2012-0230

    Last Modified: 11 Apr 2025

    PRRDS.exe in the Proficy Remote Data Service in GE Intelligent Platforms Proficy Plant Applications 5.0 and earlier allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted TCP session on port 12299.

    Published: 15 Mar 2012
    10
    Critical

    CVE-2012-0231

    Last Modified: 11 Apr 2025

    PRLicenseMgr.exe in the Proficy Server License Manager in GE Intelligent Platforms Proficy Plant Applications 5.0 and earlier allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted TCP session on port 12401.

    Published: 15 Mar 2012
    6.4
    Medium

    CVE-2012-0232

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6, 3.0, 3.0 SP1, and 3.5 allows remote attackers to modify the configuration via crafted strings.

    Published: 15 Mar 2012
    10
    Critical

    CVE-2012-1481

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Textdroid (com.app.android.textdroid) application 2.5.2 for Android has unknown impact and attack vectors.

    Published: 15 Mar 2012
    10
    Critical

    CVE-2012-1482

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the TouchPal Contacts (com.cootek.smartdialer) application 3.3.1 and 4.0.1 for Android has unknown impact and attack vectors.

    Published: 15 Mar 2012
    10
    Critical

    CVE-2012-1484

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the WaliSMS CN (cn.com.wali.walisms) application 2.9.2 and 3.7.0 for Android has unknown impact and attack vectors.

    Published: 15 Mar 2012
    10
    Critical

    CVE-2012-1485

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the NetFront Life Browser (com.access_company.android.nflifebrowser.lite) application 2.2.0 and 2.3.0 for Android has unknown impact and attack vectors.

    Published: 15 Mar 2012
    10
    Critical

    CVE-2012-1483

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Message Forwarder (com.gmail.zbnetium) application 1.12.20110409.1 for Android has unknown impact and attack vectors.

    Published: 15 Mar 2012
    7.8
    High

    CVE-2012-0355

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.4 before 8.4(2.11) and 8.5 before 8.5(1.4) allow remote attackers to cause a denial of service (device reload) via (1) IPv4 or (2) IPv6 packets that trigger syslog message 305006, aka Bug ID CSCts39634.

    Published: 15 Mar 2012
    4.3
    Medium

    CVE-2012-0404

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in EMC Documentum eRoom before 7.4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Mar 2012
    5.2
    Medium

    CVE-2012-1179

    Last Modified: 11 Apr 2025

    The Linux kernel before 3.3.1, when KVM is used, allows guest OS users to cause a denial of service (host OS crash) by leveraging administrative access to the guest OS, related to the pmd_none_or_clear_bad function and page faults for huge pages.

    Published: 15 Mar 2012
    7.1
    High

    CVE-2012-0353

    Last Modified: 11 Apr 2025

    The UDP inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.0 before 8.0(5.25), 8.1 before 8.1(2.50), 8.2 before 8.2(5.5), 8.3 before 8.3(2.22), 8.4 before 8.4(2.1), and 8.5 before 8.5(1.2) does not properly handle flows, which allows remote attackers to cause a denial of service (device reload) via a crafted series of (1) IPv4 or (2) IPv6 UDP packets, aka Bug ID CSCtq10441.

    Published: 15 Mar 2012
    7.1
    High

    CVE-2012-0354

    Last Modified: 11 Apr 2025

    The Threat Detection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.0 through 8.2 before 8.2(5.20), 8.3 before 8.3(2.29), 8.4 before 8.4(3), 8.5 before 8.5(1.6), and 8.6 before 8.6(1.1) allows remote attackers to cause a denial of service (device reload) via (1) IPv4 or (2) IPv6 packets that trigger a shun event, aka Bug ID CSCtw35765.

    Published: 15 Mar 2012
    9.3
    Critical

    CVE-2012-0358

    Last Modified: 11 Apr 2025

    Buffer overflow in the Cisco Port Forwarder ActiveX control in cscopf.ocx, as distributed through the Clientless VPN feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.0 through 7.2 before 7.2(5.6), 8.0 before 8.0(5.26), 8.1 before 8.1(2.53), 8.2 before 8.2(5.18), 8.3 before 8.3(2.28), 8.2 before 8.4(2.16), and 8.6 before 8.6(1.1), allows remote attackers to execute arbitrary code via unspecified vectors, aka Bug ID CSCtr00165.

    Published: 15 Mar 2012
    7.8
    High

    CVE-2012-0356

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 7.0 through 7.2 before 7.2(5.7), 8.0 before 8.0(5.27), 8.1 before 8.1(2.53), 8.2 before 8.2(5.8), 8.3 before 8.3(2.25), 8.4 before 8.4(2.5), and 8.5 before 8.5(1.2) and the Firewall Services Module (FWSM) 3.1 and 3.2 before 3.2(23) and 4.0 and 4.1 before 4.1(8) in Cisco Catalyst 6500 series devices, when multicast routing is enabled, allow remote attackers to cause a denial of service (device reload) via a crafted IPv4 PIM message, aka Bug IDs CSCtr47517 and CSCtu97367.

    Published: 15 Mar 2012
    7.5
    High

    CVE-2012-0398

    Last Modified: 11 Apr 2025

    EMC Documentum eRoom before 7.4.4 does not properly validate session cookies, which allows remote attackers to hijack or replay sessions via unspecified vectors.

    Published: 15 Mar 2012
    7.5
    High

    CVE-2012-0454

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 on 32-bit Windows 7 platforms allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving use of the file-open dialog in a child window, related to the IUnknown_QueryService function in the Windows shlwapi.dll library.

    Published: 14 Mar 2012
    7.5
    High

    CVE-2012-0463

    Last Modified: 11 Apr 2025

    The nsWindow implementation in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 does not check the validity of an instance after event dispatching, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, as demonstrated by Mobile Firefox on Android.

    Published: 14 Mar 2012
    10
    Critical

    CVE-2012-0124

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Data Protector Express (aka DPX) 5.0.00 before build 59287 and 6.0.00 before build 11974 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors.

    Published: 14 Mar 2012
    10
    Critical

    CVE-2012-0121

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Data Protector Express (aka DPX) 5.0.00 before build 59287 and 6.0.00 before build 11974 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1392.

    Published: 14 Mar 2012
    10
    Critical

    CVE-2012-1408

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the App Lock (com.cc.applock) application 1.7.5 and 1.7.6 for Android has unknown impact and attack vectors.

    Published: 14 Mar 2012
    10
    Critical

    CVE-2012-1409

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Tiny Password (com.tinycouch.android.freepassword) application 1.64 for Android has unknown impact and attack vectors.

    Published: 14 Mar 2012
    10
    Critical

    CVE-2012-1476

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the KKtalk (com.kkliaotian.android) application 4.0.0 and 4.1.5 for Android has unknown impact and attack vectors.

    Published: 14 Mar 2012
    10
    Critical

    CVE-2012-1477

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Cnectd (mci.cnectd) application 3.1.0 for Android has unknown impact and attack vectors.

    Published: 14 Mar 2012
    10
    Critical

    CVE-2012-1478

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the UCMobile BloveStorm (com.blovestorm) application 2.2.0 and 3.2.1 for Android has unknown impact and attack vectors.

    Published: 14 Mar 2012
    10
    Critical

    CVE-2012-1479

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the AContact (com.movester.quickcontact) application 1.8.2 for Android has unknown impact and attack vectors.

    Published: 14 Mar 2012
    10
    Critical

    CVE-2012-1480

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Pansi SMS (com.pansi.msg) application 1.97, 2.01, and 2.07 for Android has unknown impact and attack vectors.

    Published: 14 Mar 2012
    10
    Critical

    CVE-2012-0123

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Data Protector Express (aka DPX) 5.0.00 before build 59287 and 6.0.00 before build 11974 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1498.

    Published: 14 Mar 2012
    10
    Critical

    CVE-2012-0122

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Data Protector Express (aka DPX) 5.0.00 before build 59287 and 6.0.00 before build 11974 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1393.

    Published: 14 Mar 2012
    10
    Critical

    CVE-2012-1475

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the YagattaTalk Messenger (com.iskoot.yagatta.yagattatalk) application 1.00.01.08 for Android has unknown impact and attack vectors.

    Published: 14 Mar 2012
    10
    Critical

    CVE-2012-1474

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Youni SMS (com.snda.youni) application 2.1.0c and 2.1.0d for Android has unknown impact and attack vectors.

    Published: 14 Mar 2012
    5
    Medium

    CVE-2012-2139

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in lib/mail/network/delivery_methods/file_delivery.rb in the Mail gem before 2.4.4 for Ruby allows remote attackers to read arbitrary files via a .. (dot dot) in the to parameter.

    Published: 14 Mar 2012
    7.5
    High

    CVE-2012-2140

    Last Modified: 11 Apr 2025

    The Mail gem before 2.4.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) sendmail or (2) exim delivery.

    Published: 14 Mar 2012
    5
    Medium

    CVE-2012-0770

    Last Modified: 11 Apr 2025

    Adobe ColdFusion 8.0, 8.0.1, 9.0, and 9.0.1 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

    Published: 13 Mar 2012
    6.9
    Medium

    CVE-2012-0008

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Microsoft Visual Studio 2008 SP1, 2010, and 2010 SP1 allows local users to gain privileges via a Trojan horse add-in in an unspecified directory, aka "Visual Studio Add-In Vulnerability."

    Published: 13 Mar 2012
    9.3
    Critical

    CVE-2012-0016

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Microsoft Expression Design; Expression Design SP1; and Expression Design 2, 3, and 4 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .xpr or .DESIGN file, aka "Expression Design Insecure Library Loading Vulnerability."

    Published: 13 Mar 2012
    4.3
    Medium

    CVE-2012-0152

    Last Modified: 11 Apr 2025

    The Remote Desktop Protocol (RDP) service in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (application hang) via a series of crafted packets, aka "Terminal Server Denial of Service Vulnerability."

    Published: 13 Mar 2012
    9.3
    Critical

    CVE-2012-0002

    Last Modified: 11 Apr 2025

    The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remote attackers to execute arbitrary code by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, aka "Remote Desktop Protocol Vulnerability."

    Published: 13 Mar 2012
    5
    Medium

    CVE-2012-0006

    Last Modified: 11 Apr 2025

    The DNS server in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 does not properly handle objects in memory during record lookup, which allows remote attackers to cause a denial of service (daemon restart) via a crafted query, aka "DNS Denial of Service Vulnerability."

    Published: 13 Mar 2012
    4.3
    Medium

    CVE-2012-0156

    Last Modified: 11 Apr 2025

    DirectWrite in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly render Unicode characters, which allows remote attackers to cause a denial of service (application hang) via a (1) instant message or (2) web site, aka "DirectWrite Application Denial of Service Vulnerability."

    Published: 13 Mar 2012
    8.4
    High

    CVE-2012-0157

    Last Modified: 11 Apr 2025

    win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle window messaging, which allows local users to gain privileges via a crafted application that calls the PostMessage function, aka "PostMessage Function Vulnerability."

    Published: 13 Mar 2012
    5
    Medium

    CVE-2012-0689

    Last Modified: 11 Apr 2025

    The server in TIBCO ActiveMatrix Platform in TIBCO Silver Fabric ActiveMatrix Service Grid Distribution 3.1.3, Service Grid and Service Bus 3.x before 3.1.5, BusinessWorks Service Engine 5.9.x before 5.9.3, and BPM before 1.3.0 allows remote attackers to discover credentials via unspecified vectors.

    Published: 13 Mar 2012
    5
    Medium

    CVE-2012-0687

    Last Modified: 11 Apr 2025

    TIBCO ActiveMatrix Runtime Platform in Service Grid and Service Bus 2.x before 2.3.2 and BusinessWorks Service Engine before 5.8.2; TIBCO ActiveMatrix Platform in TIBCO Silver Fabric ActiveMatrix Service Grid Distribution 3.1.3, Service Grid and Service Bus 3.x before 3.1.5, BusinessWorks Service Engine 5.9.x before 5.9.3, and BPM before 1.3.0; TIBCO BusinessEvents Runtime in Enterprise and Inference Editions 3.x before 3.0.3, Standard Edition 4.x before 4.0.2, and Standard Edition and Express 5.0.0; and TIBCO BusinessWorks Engine in TIBCO Silver Fabric ActiveMatrix BusinessWorks Distribution 5.9.2 and ActiveMatrix BusinessWorks before 5.9.3 allow remote attackers to obtain sensitive information via a crafted URL.

    Published: 13 Mar 2012