CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2012-0644

    Last Modified: 11 Apr 2025

    Race condition in the Passcode Lock feature in Apple iOS before 5.1 allows physically proximate attackers to bypass intended passcode requirements via a slide-to-dial gesture.

    Published: 8 Mar 2012
    9.3
    Critical

    CVE-2011-2870

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.

    Published: 8 Mar 2012
    9.3
    Critical

    CVE-2012-0593

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.

    Published: 8 Mar 2012
    9.3
    Critical

    CVE-2012-0601

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.

    Published: 8 Mar 2012
    9.3
    Critical

    CVE-2012-0609

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.

    Published: 8 Mar 2012
    9.3
    Critical

    CVE-2012-0617

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.

    Published: 8 Mar 2012
    9.3
    Critical

    CVE-2012-0625

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.

    Published: 8 Mar 2012
    9.3
    Critical

    CVE-2012-0633

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.

    Published: 8 Mar 2012
    5
    Medium

    CVE-2012-0641

    Last Modified: 11 Apr 2025

    CFNetwork in Apple iOS before 5.1 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensitive information via a malformed URL, a different vulnerability than CVE-2011-3447.

    Published: 8 Mar 2012
    5
    Medium

    CVE-2012-0292

    Last Modified: 11 Apr 2025

    The awhost32 service in Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) allows remote attackers to cause a denial of service (daemon crash) via a crafted TCP session on port 5631.

    Published: 8 Mar 2012
    4.3
    Medium

    CVE-2011-3844

    Last Modified: 11 Apr 2025

    Apple Safari 5.0.5 does not properly implement the setInterval function, which allows remote attackers to spoof the address bar via a crafted web page.

    Published: 8 Mar 2012
    7.6
    High

    CVE-2011-3845

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Apple Safari 5.1.2, when a plug-in with a blocking function is installed, allows user-assisted remote attackers to execute arbitrary code via a crafted web page that is accessed during user interaction with the plug-in, leading to improper coordination between an API call and the plug-in unloading functionality, as demonstrated by the Adobe Flash and RealPlayer plug-ins.

    Published: 8 Mar 2012
    7.5
    High

    CVE-2012-1502

    Last Modified: 11 Apr 2025

    Double free vulnerability in the PyPAM_conv in PAMmodule.c in PyPam 0.5.0 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a NULL byte in a password string.

    Published: 8 Mar 2012
    8.8
    High

    CVE-2011-3045

    Last Modified: 9 Jun 2025

    Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.

    Published: 8 Mar 2012
    10
    Critical

    CVE-2012-1381

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the NetEase CloudAlbum (com.netease.cloudalbum) application 2.0.0 and 2.2.0 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1383

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the NetEase Reader (com.netease.pris) application 1.1.2 and 1.2.0 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1384

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the NetEase Pmail (com.netease.rpmms) application 0.5.0 and 0.5.2 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1386

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the YouMail Visual Voicemail Plus (com.youmail.android.vvm) application 2.0.45 and 2.1.43 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1387

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the RealTalk (com.tmsmanager.tms) application A.0.9.250 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1388

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the XiXunTianTian (com.xixun.tiantian) application 0.6.2 beta for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1389

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Di Long Weibo (com.icekirin.weibos) application 1.9.9 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1390

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Miso (com.bazaarlabs.miso) application 2.2 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1391

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the mOffice - Outlook sync (com.innov8tion.isharesync) application 3.1 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1392

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Dolphin Browser HD (mobi.mgeek.TunnyBrowser) application 6.2.0, 7.2.1, 7.3.0, and 7.4.0 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1393

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the GO SMS Pro (com.jb.gosms) application 3.72, 4.10, and 4.35 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1395

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the GO TwiWidget (com.gau.go.launcherex.gowidget.twitterwidget) application 1.7 and 2.1 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1396

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the GO FBWidget (com.gau.go.launcherex.gowidget.fbwidget) application 1.9 and 2.1 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1397

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the GO QQWeiboWidget (com.gau.go.launcherex.gowidget.qqweibowidget) application 1.2 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1398

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the GO WeiboWidget (com.gau.go.launcherex.gowidget.weibowidget) application 2.4 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1399

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the U+Box 2.0 (lg.uplusbox) application 2.0.2 and 2.0.8.4 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1400

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the U+Box 2.0 Pad (lg.uplusbox.pad) application 2.0.8.4 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1401

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the CamScanner (com.intsig.camscanner) application 1.2.2.20110823 and 1.3.2.20120116 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1403

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Dolphin Browser CN (com.dolphin.browser.cn) application 6.3.1 and 7.2.1 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1404

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Dolphin Browser Mini (com.dolphin.browser) application 2.2 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1405

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the GO Note Widget (com.gau.go.launcherex.gowidget.notewidget) application 1.5 and 1.9 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1406

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the GO Bookmark Widget (com.gau.go.launcherex.gowidget.bookmark) application 1.1 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1407

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the GO Message Widget (com.gau.go.launcherex.gowidget.smswidget) application 1.9, 2.1, and 2.3 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1380

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the NetEaseWeibo (com.netease.wb) application 1.2.1 and 1.2.2 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1382

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Youdao Dictionary (com.youdao.dict) application 1.6.1, 2.0.1(2), and 3.0.0(1) for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1394

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the GO Email Widget (com.gau.go.launcherex.gowidget.emailwidget) application 1.3.1, 1.8, and 1.81 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1385

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the NetEase WeiboHD (com.netease.wbhd) application 1.0.0 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    10
    Critical

    CVE-2012-1402

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the QianXun YingShi (com.qianxun.yingshi) application 1.2.3 and 1.3.4 for Android has unknown impact and attack vectors.

    Published: 7 Mar 2012
    7.5
    High

    CVE-2012-0805

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in SQLAlchemy before 0.7.0b4, as used in Keystone, allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset keyword to the select function, or unspecified vectors to the (3) select.limit or (4) select.offset function.

    Published: 7 Mar 2012
    7.6
    High

    CVE-2012-0397

    Last Modified: 11 Apr 2025

    Buffer overflow in EMC RSA SecurID Software Token Converter before 2.6.1 allows remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors.

    Published: 6 Mar 2012
    9.3
    Critical

    CVE-2012-0198

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the RunAndUploadFile method in the Isig.isigCtl.1 ActiveX control in IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 allows remote attackers to execute arbitrary code via vectors related to an Asset Information file.

    Published: 6 Mar 2012
    7.5
    High

    CVE-2012-0199

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 allow remote attackers to execute arbitrary SQL commands via (1) a SOAP message to the Printer.getPrinterAgentKey function in the SoapServlet servlet, (2) the User.updateUserValue function in the register.do servlet, (3) the User.isExistingUser function in the logon.do servlet, (4) the Asset.getHWKey function in the CallHomeExec servlet, (5) the Asset.getMimeType function in the getAttachment (aka GetAttachmentServlet) servlet, (6) the addAsset.do servlet, or (7) a crafted EG2 file.

    Published: 6 Mar 2012
    4.3
    Medium

    CVE-2012-1575

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Cumin before r5238 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) widgets or (2) pages.

    Published: 6 Mar 2012
    4.3
    Medium

    CVE-2012-0322

    Last Modified: 11 Apr 2025

    The EStrongs ES File Explorer application 1.6.0.2 through 1.6.1.1 for Android does not properly restrict access, which allows remote attackers to read arbitrary files via vectors involving an unspecified function.

    Published: 5 Mar 2012
    6.8
    Medium

    CVE-2011-3031

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the element wrapper in Google V8, as used in Google Chrome before 17.0.963.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 5 Mar 2012
    6.8
    Medium

    CVE-2011-3034

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving an SVG document.

    Published: 5 Mar 2012