CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2012-1099

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_options_helper.rb in the select helper in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving certain generation of OPTION elements within SELECT elements.

    Published: 1 Mar 2012
    5.8
    Medium

    CVE-2012-1172

    Last Modified: 11 Apr 2025

    The file-upload implementation in rfc1867.c in PHP before 5.4.0 does not properly handle invalid [ (open square bracket) characters in name values, which makes it easier for remote attackers to cause a denial of service (malformed $_FILES indexes) or conduct directory traversal attacks during multi-file uploads by leveraging a script that lacks its own filename restrictions.

    Published: 1 Mar 2012
    9.3
    Critical

    CVE-2012-1142

    Last Modified: 11 Apr 2025

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph-outline data in a font.

    Published: 1 Mar 2012
    Unknown

    CVE-2012-1091

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-1410. Reason: This candidate is a reservation duplicate of CVE-2012-1410. Notes: All CVE users should reference CVE-2012-1410 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 29 Feb 2012
    Unknown

    CVE-2012-1092

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-1410. Reason: This candidate is a reservation duplicate of CVE-2012-1410. Notes: All CVE users should reference CVE-2012-1410 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 29 Feb 2012
    10
    Critical

    CVE-2012-1418

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 17.0.963.60 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.

    Published: 29 Feb 2012
    Unknown

    CVE-2006-7249

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-7250, CVE-2012-1410. Reason: this candidate was intended for one issue, but CVE users may have associated it with multiple unrelated issues. Notes: All CVE users should consult CVE-2006-7250 for the OpenSSL candidate or CVE-2012-1410 for the Kadu candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 29 Feb 2012
    4.3
    Medium

    CVE-2012-1410

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the History Window implementation in Kadu 0.9.0 through 0.11.0 allow remote attackers to inject arbitrary web script or HTML via a crafted (1) SMS message, (2) presence message, or (3) status description.

    Published: 29 Feb 2012
    4.3
    Medium

    CVE-2012-6684

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the RedCloth library 4.2.9 for Ruby and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI.

    Published: 29 Feb 2012
    5.5
    Medium

    CVE-2012-1096

    Last Modified: 21 Nov 2024

    NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.

    Published: 29 Feb 2012
    9.3
    Critical

    CVE-2012-1139

    Last Modified: 11 Apr 2025

    Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid stack read operation and memory corruption) or possibly execute arbitrary code via crafted glyph data in a BDF font.

    Published: 28 Feb 2012
    9.3
    Critical

    CVE-2012-1140

    Last Modified: 11 Apr 2025

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted PostScript font object.

    Published: 28 Feb 2012
    5.8
    Medium

    CVE-2012-1100

    Last Modified: 11 Apr 2025

    Red Hat JBoss Operations Network (JON) 3.0.x before 3.0.1, 2.4.2, and earlier, when LDAP authentication is enabled and the LDAP bind account credentials are invalid, allows remote attackers to login to LDAP-based accounts via an arbitrary password in a login request.

    Published: 28 Feb 2012
    9.3
    Critical

    CVE-2012-1141

    Last Modified: 11 Apr 2025

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted ASCII string in a BDF font.

    Published: 28 Feb 2012
    4.3
    Medium

    CVE-2012-1143

    Last Modified: 11 Apr 2025

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted font.

    Published: 28 Feb 2012
    6.8
    Medium

    CVE-2012-0868

    Last Modified: 11 Apr 2025

    CRLF injection vulnerability in pg_dump in PostgreSQL 8.3.x before 8.3.18, 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows user-assisted remote attackers to execute arbitrary SQL commands via a crafted file containing object names with newlines, which are inserted into an SQL script that is used when the database is restored.

    Published: 27 Feb 2012
    9.3
    Critical

    CVE-2012-1136

    Last Modified: 11 Apr 2025

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph or bitmap data in a BDF font that lacks an ENCODING field.

    Published: 27 Feb 2012
    9.3
    Critical

    CVE-2012-1137

    Last Modified: 11 Apr 2025

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted header in a BDF font.

    Published: 27 Feb 2012
    9.3
    Critical

    CVE-2012-1138

    Last Modified: 11 Apr 2025

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors involving the MIRP instruction in a TrueType font.

    Published: 27 Feb 2012
    5
    Medium

    CVE-2012-1151

    Last Modified: 11 Apr 2025

    Multiple format string vulnerabilities in dbdimp.c in DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.19.0 for Perl allow remote PostgreSQL database servers to cause a denial of service (process crash) via format string specifiers in (1) a crafted database warning to the pg_warn function or (2) a crafted DBD statement to the dbd_st_prepare function.

    Published: 27 Feb 2012
    4.3
    Medium

    CVE-2012-0867

    Last Modified: 11 Apr 2025

    PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof connections when the host name is exactly 32 characters.

    Published: 27 Feb 2012
    9.3
    Critical

    CVE-2012-1135

    Last Modified: 11 Apr 2025

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors involving the NPUSHB and NPUSHW instructions in a TrueType font.

    Published: 27 Feb 2012
    6.5
    Medium

    CVE-2012-0866

    Last Modified: 11 Apr 2025

    CREATE TRIGGER in PostgreSQL 8.3.x before 8.3.18, 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 does not properly check the execute permission for trigger functions marked SECURITY DEFINER, which allows remote authenticated users to execute otherwise restricted triggers on arbitrary data by installing the trigger on an attacker-owned table.

    Published: 27 Feb 2012
    5.5
    Medium

    CVE-2013-1820

    Last Modified: 21 Nov 2024

    tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.

    Published: 26 Feb 2012
    9.3
    Critical

    CVE-2012-1131

    Last Modified: 11 Apr 2025

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, on 64-bit platforms allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors related to the cell table of a font.

    Published: 26 Feb 2012
    9
    Critical

    CVE-2012-0365

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Local TFTP file-upload application on Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allows remote authenticated users to upload software to arbitrary directories via unspecified vectors, aka Bug ID CSCtw56009.

    Published: 25 Feb 2012
    5.1
    Medium

    CVE-2012-0453

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in xmlrpc.cgi in Bugzilla 4.0.2 through 4.0.4 and 4.1.1 through 4.2rc2, when mod_perl is used, allows remote attackers to hijack the authentication of arbitrary users for requests that modify the product's installation via the XML-RPC API.

    Published: 25 Feb 2012
    7.8
    High

    CVE-2012-0364

    Last Modified: 11 Apr 2025

    Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allow remote attackers to replace the configuration file via an upload request to an unspecified URL, aka Bug ID CSCtw55495.

    Published: 25 Feb 2012
    9
    Critical

    CVE-2012-0363

    Last Modified: 11 Apr 2025

    The web interface on Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allows remote authenticated users to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability," aka Bug ID CSCtt46871.

    Published: 25 Feb 2012
    5.5
    Medium

    CVE-2012-1146

    Last Modified: 11 Apr 2025

    The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 does not properly handle multiple events that are attached to the same eventfd, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by registering memory threshold events.

    Published: 24 Feb 2012
    7.5
    High

    CVE-2012-1294

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in CONTIMEX Impulsio CMS allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Published: 23 Feb 2012
    4.3
    Medium

    CVE-2012-0873

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Boonex Dolphin before 7.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) explain parameter to explanation.php or the (2) photos_only, (3) online_only, or (4) mode parameters to viewFriends.php.

    Published: 23 Feb 2012
    4.3
    Medium

    CVE-2012-1290

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in b2b/auction/container.jsp in the Internet Sales (crm.b2b) module in SAP NetWeaver 7.0 allows remote attackers to inject arbitrary web script or HTML via the _loadPage parameter.

    Published: 23 Feb 2012
    5
    Medium

    CVE-2012-1292

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MessagingSystem servlet in SAP NetWeaver 7.0 allows remote attackers to obtain sensitive information about the MessagingSystem Performance Data via unspecified vectors.

    Published: 23 Feb 2012
    4
    Medium

    CVE-2012-1289

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in SAP NetWeaver 7.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the logfilename parameter to (1) b2b/admin/log.jsp or (2) b2b/admin/log_view.jsp in the Internet Sales (crm.b2b) component, or (3) ipc/admin/log.jsp or (4) ipc/admin/log_view.jsp in the Application Administration (com.sap.ipc.webapp.ipc) component.

    Published: 23 Feb 2012
    5
    Medium

    CVE-2012-1291

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the com.sap.aii.mdt.amt.web.AMTPageProcessor servlet in SAP NetWeaver 7.0 allows remote attackers to obtain sensitive information about the Adapter Monitor via unspecified vectors, possibly related to the EnableInvokerServletGlobally property in the servlet_jsp service.

    Published: 23 Feb 2012
    4.3
    Medium

    CVE-2012-0707

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Lombardi Edition 7.2 allows remote attackers to inject arbitrary web script or HTML via crafted text input to a coach that is configured with a document attachment control section.

    Published: 23 Feb 2012
    10
    Critical

    CVE-2012-1288

    Last Modified: 11 Apr 2025

    The UTC Fire & Security GE-MC100-NTP/GPS-ZB Master Clock device uses hardcoded credentials for an administrative account, which makes it easier for remote attackers to obtain access via an HTTP session.

    Published: 23 Feb 2012
    9.3
    Critical

    CVE-2012-1132

    Last Modified: 11 Apr 2025

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted dictionary data in a Type 1 font.

    Published: 23 Feb 2012
    5.5
    Medium

    CVE-2012-0810

    Last Modified: 21 Nov 2024

    The int3 handler in the Linux kernel before 3.3 relies on a per-CPU debug stack, which allows local users to cause a denial of service (stack corruption and panic) via a crafted application that triggers certain lock contention.

    Published: 23 Feb 2012
    10
    Critical

    CVE-2012-1126

    Last Modified: 11 Apr 2025

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted property data in a BDF font.

    Published: 23 Feb 2012
    9.3
    Critical

    CVE-2012-1127

    Last Modified: 11 Apr 2025

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted glyph or bitmap data in a BDF font.

    Published: 23 Feb 2012
    9.3
    Critical

    CVE-2012-1128

    Last Modified: 11 Apr 2025

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and memory corruption) or possibly execute arbitrary code via a crafted TrueType font.

    Published: 23 Feb 2012
    9.3
    Critical

    CVE-2012-1129

    Last Modified: 11 Apr 2025

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted SFNT string in a Type 42 font.

    Published: 23 Feb 2012
    9.3
    Critical

    CVE-2012-1133

    Last Modified: 11 Apr 2025

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph or bitmap data in a BDF font.

    Published: 23 Feb 2012
    5.5
    Medium

    CVE-2012-1090

    Last Modified: 11 Apr 2025

    The cifs_lookup function in fs/cifs/dir.c in the Linux kernel before 3.2.10 allows local users to cause a denial of service (OOPS) via attempted access to a special file, as demonstrated by a FIFO.

    Published: 23 Feb 2012
    9.3
    Critical

    CVE-2012-1130

    Last Modified: 11 Apr 2025

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted property data in a PCF font.

    Published: 23 Feb 2012
    9.3
    Critical

    CVE-2012-1134

    Last Modified: 11 Apr 2025

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted private-dictionary data in a Type 1 font.

    Published: 23 Feb 2012
    9.3
    Critical

    CVE-2012-0315

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in ALFTP before 5.31 allows local users to gain privileges via a Trojan horse executable file in a directory that is accessed for reading an extensionless file, as demonstrated by executing the README.exe file when a user attempts to access the README file.

    Published: 22 Feb 2012
    5
    Medium

    CVE-2012-0291

    Last Modified: 11 Apr 2025

    Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) allow remote attackers to cause a denial of service (application crash or hang) via (1) malformed data from a client, (2) malformed data from a server, or (3) an invalid response.

    Published: 22 Feb 2012