CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2011-3035

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG use elements.

    Published: 5 Mar 2012
    6.8
    Medium

    CVE-2011-3036

    Last Modified: 11 Apr 2025

    Google Chrome before 17.0.963.65 does not properly perform a cast of an unspecified variable during handling of line boxes, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.

    Published: 5 Mar 2012
    6.8
    Medium

    CVE-2011-3037

    Last Modified: 11 Apr 2025

    Google Chrome before 17.0.963.65 does not properly perform casts of unspecified variables during the splitting of anonymous blocks, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.

    Published: 5 Mar 2012
    6.8
    Medium

    CVE-2011-3038

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to multi-column handling.

    Published: 5 Mar 2012
    6.8
    Medium

    CVE-2011-3039

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to quote handling.

    Published: 5 Mar 2012
    6.8
    Medium

    CVE-2011-3042

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of table sections.

    Published: 5 Mar 2012
    6.8
    Medium

    CVE-2011-3044

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG animation elements.

    Published: 5 Mar 2012
    7.5
    High

    CVE-2011-3033

    Last Modified: 11 Apr 2025

    Buffer overflow in Skia, as used in Google Chrome before 17.0.963.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 5 Mar 2012
    4.3
    Medium

    CVE-2011-3040

    Last Modified: 11 Apr 2025

    Google Chrome before 17.0.963.65 does not properly handle text, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted document.

    Published: 5 Mar 2012
    6.8
    Medium

    CVE-2011-3041

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of class attributes.

    Published: 5 Mar 2012
    6.8
    Medium

    CVE-2011-3043

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a flexbox (aka flexible box) in conjunction with the floating of elements.

    Published: 5 Mar 2012
    6.8
    Medium

    CVE-2011-3032

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of SVG values.

    Published: 5 Mar 2012
    5
    Medium

    CVE-2012-0769

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.183.16 and 11.x before 11.1.102.63 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.7 on Android 2.x and 3.x; and before 11.1.115.7 on Android 4.x does not properly handle integers, which allows attackers to obtain sensitive information via unspecified vectors.

    Published: 5 Mar 2012
    10
    Critical

    CVE-2012-0768

    Last Modified: 11 Apr 2025

    The Matrix3D component in Adobe Flash Player before 10.3.183.16 and 11.x before 11.1.102.63 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.7 on Android 2.x and 3.x; and before 11.1.115.7 on Android 4.x allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 5 Mar 2012
    4.3
    Medium

    CVE-2012-1107

    Last Modified: 11 Apr 2025

    The analyzeCurrent function in ape/apeproperties.cpp in TagLib 1.7 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a crafted sampleRate in an ape file, which triggers a divide-by-zero error.

    Published: 4 Mar 2012
    4.3
    Medium

    CVE-2012-1584

    Last Modified: 11 Apr 2025

    Integer overflow in the mid function in toolkit/tbytevector.cpp in TagLib 1.7 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a crafted file header field in a media file, which triggers a large memory allocation.

    Published: 4 Mar 2012
    4.4
    Medium

    CVE-2012-6076

    Last Modified: 11 Apr 2025

    Inkscape before 0.48.4 reads .eps files from /tmp instead of the current directory, which might cause Inkspace to process unintended files, allow local users to obtain sensitive information, and possibly have other unspecified impacts.

    Published: 4 Mar 2012
    4.3
    Medium

    CVE-2012-1108

    Last Modified: 11 Apr 2025

    The parse function in ogg/xiphcomment.cpp in TagLib 1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted vendorLength field in an ogg file.

    Published: 4 Mar 2012
    6.8
    Medium

    CVE-2012-0317

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackers to hijack the authentication of arbitrary users for requests that modify data via the (1) commenting feature or (2) community script.

    Published: 3 Mar 2012
    4.3
    Medium

    CVE-2012-0318

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackers to inject arbitrary web script or HTML via vectors involving templates, a different issue than CVE-2012-1262.

    Published: 3 Mar 2012
    6.5
    Medium

    CVE-2012-0319

    Last Modified: 11 Apr 2025

    The file-management system in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote authenticated users to execute arbitrary commands by leveraging the file-upload feature, related to an "OS Command Injection" issue.

    Published: 3 Mar 2012
    7.5
    High

    CVE-2012-0320

    Last Modified: 11 Apr 2025

    Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote attackers to take control of sessions via unspecified vectors related to the (1) commenting feature and (2) community script.

    Published: 3 Mar 2012
    4.3
    Medium

    CVE-2012-1262

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in cgi-bin/mt/mt-wizard.cgi in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13, when the product is incompletely installed, allows remote attackers to inject arbitrary web script or HTML via the dbuser parameter, a different vulnerability than CVE-2012-0318.

    Published: 3 Mar 2012
    4
    Medium

    CVE-2012-1497

    Last Modified: 11 Apr 2025

    The default configuration of Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 supports the "mt:Include file=" attribute, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files by leveraging the template-designer role.

    Published: 3 Mar 2012
    4.3
    Medium

    CVE-2012-1147

    Last Modified: 11 Apr 2025

    readfilemap.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (file descriptor consumption) via a large number of crafted XML files.

    Published: 3 Mar 2012
    4.3
    Medium

    CVE-2012-0876

    Last Modified: 11 Apr 2025

    The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.

    Published: 3 Mar 2012
    4.3
    Medium

    CVE-2012-0451

    Last Modified: 11 Apr 2025

    CRLF injection vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote web servers to bypass intended Content Security Policy (CSP) restrictions and possibly conduct cross-site scripting (XSS) attacks via crafted HTTP headers.

    Published: 3 Mar 2012
    7.8
    High

    CVE-2012-1097

    Last Modified: 11 Apr 2025

    The regset (aka register set) feature in the Linux kernel before 3.2.10 does not properly handle the absence of .get and .set methods, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a (1) PTRACE_GETREGSET or (2) PTRACE_SETREGSET ptrace call.

    Published: 3 Mar 2012
    5
    Medium

    CVE-2012-1148

    Last Modified: 11 Apr 2025

    Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause improperly-handled reallocation failures when expanding entities.

    Published: 3 Mar 2012
    7.8
    High

    CVE-2011-1385

    Last Modified: 11 Apr 2025

    IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.1.x and 2.2.x, allows remote attackers to cause a denial of service (system crash) via an ICMP Echo Reply packet that contains 1 in the Identifier field, a different vulnerability than CVE-2012-0194.

    Published: 2 Mar 2012
    7.5
    High

    CVE-2011-4189

    Last Modified: 11 Apr 2025

    The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via a long e-mail address in an Address Book (aka .NAB) file.

    Published: 2 Mar 2012
    2.1
    Low

    CVE-2012-0321

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the device driver in Kingsoft Internet Security 2011 allows local users to cause a denial of service via a crafted application.

    Published: 2 Mar 2012
    4.3
    Medium

    CVE-2012-0715

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Gantt applet viewer in IBM Tivoli Change and Configuration Management Database (CCMDB) 7.2.1 and IBM ILOG JViews Gantt allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 2 Mar 2012
    9.3
    Critical

    CVE-2012-0201

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in pcspref.dll in pcsws.exe in IBM Personal Communications 5.9.x before 5.9.8 and 6.0.x before 6.0.4 might allow remote attackers to execute arbitrary code via a long profile string in a WorkStation (aka .ws) file.

    Published: 2 Mar 2012
    7.5
    High

    CVE-2011-3443

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via vectors related to improper list management for Cascading Style Sheets (CSS) @font-face rules.

    Published: 2 Mar 2012
    5
    Medium

    CVE-2012-0316

    Last Modified: 11 Apr 2025

    The Cookpad 1.5.16 and earlier and Cookpad Noseru 1.1.1 and earlier applications for Android do not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application.

    Published: 2 Mar 2012
    6.9
    Medium

    CVE-2012-0883

    Last Modified: 11 Apr 2025

    envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.

    Published: 2 Mar 2012
    9.3
    Critical

    CVE-2012-1144

    Last Modified: 11 Apr 2025

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via a crafted TrueType font.

    Published: 2 Mar 2012
    6.8
    Medium

    CVE-2011-4487

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before 8.0(3a)su3, and 8.5 and 8.6 before 8.6(2a)su1 and Cisco Business Edition 3000 with software before 8.6.3 and 5000 and 6000 with software before 8.6(2a)su1 allows remote attackers to execute arbitrary SQL commands via a crafted SCCP registration, aka Bug ID CSCtu73538.

    Published: 1 Mar 2012
    7.5
    High

    CVE-2012-0331

    Last Modified: 11 Apr 2025

    Cisco TelePresence Video Communication Server with software before X7.0.1 allows remote attackers to cause a denial of service (device crash) via a crafted SIP packet, as demonstrated by a SIP INVITE message from a Tandberg device, aka Bug ID CSCtq73319.

    Published: 1 Mar 2012
    7.8
    High

    CVE-2012-0359

    Last Modified: 11 Apr 2025

    The Cisco Cius with software before 9.2(1) SR2 allows remote attackers to cause a denial of service (device crash or hang) via malformed network traffic, aka Bug ID CSCto71445.

    Published: 1 Mar 2012
    9
    Critical

    CVE-2012-0366

    Last Modified: 11 Apr 2025

    Cisco Unity Connection before 7.1.3b(Su2) allows remote authenticated users to change the administrative password by leveraging the Help Desk Administrator role, aka Bug ID CSCtd45141.

    Published: 1 Mar 2012
    7.8
    High

    CVE-2012-0367

    Last Modified: 11 Apr 2025

    Cisco Unity Connection before 7.1.5b(Su5), 8.0 and 8.5 before 8.5.1(Su3), and 8.6 before 8.6.2 allows remote attackers to cause a denial of service (services crash) via a series of crafted TCP segments, aka Bug ID CSCtq67899.

    Published: 1 Mar 2012
    9.3
    Critical

    CVE-2012-0371

    Last Modified: 11 Apr 2025

    Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.4, when CPU-based ACLs are enabled, allow remote attackers to read or modify the configuration via unspecified vectors, aka Bug ID CSCtu56709.

    Published: 1 Mar 2012
    7.8
    High

    CVE-2012-0330

    Last Modified: 11 Apr 2025

    Cisco TelePresence Video Communication Server with software before X7.0.1 allows remote attackers to cause a denial of service (device crash) via a malformed SIP message, aka Bug ID CSCtr20426.

    Published: 1 Mar 2012
    7.8
    High

    CVE-2012-0370

    Last Modified: 11 Apr 2025

    Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.0 and 7.1 before 7.1.91.0, when WebAuth is enabled, allow remote attackers to cause a denial of service (device reload) via a sequence of (1) HTTP or (2) HTTPS packets, aka Bug ID CSCtt47435.

    Published: 1 Mar 2012
    7.8
    High

    CVE-2011-4486

    Last Modified: 11 Apr 2025

    Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before 8.0(3a)su3, and 8.5 and 8.6 before 8.6(2a)su1 and Cisco Business Edition 3000 with software before 8.6.3 and 5000 and 6000 with software before 8.6(2a)su1 allow remote attackers to cause a denial of service (device reload) via a crafted SCCP registration, aka Bug ID CSCtu73538.

    Published: 1 Mar 2012
    7.8
    High

    CVE-2012-0368

    Last Modified: 11 Apr 2025

    The administrative management interface on Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.0, 7.1 before 7.1.91.0, and 7.2 before 7.2.103.0 allows remote attackers to cause a denial of service (device crash) via a malformed URL in an HTTP request, aka Bug ID CSCts81997.

    Published: 1 Mar 2012
    7.8
    High

    CVE-2012-0369

    Last Modified: 11 Apr 2025

    Cisco Wireless LAN Controller (WLC) devices with software 6.0 and 7.0 before 7.0.220.0, 7.1 before 7.1.91.0, and 7.2 before 7.2.103.0 allow remote attackers to cause a denial of service (device reload) via a sequence of IPv6 packets, aka Bug ID CSCtt07949.

    Published: 1 Mar 2012
    4.3
    Medium

    CVE-2012-1098

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving a SafeBuffer object that is manipulated through certain methods.

    Published: 1 Mar 2012