CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2012-0224

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in 7-Technologies (7T) AQUIS 1.5 and earlier allows local users to gain privileges via a Trojan horse DLL in the current working directory, a different vulnerability than CVE-2012-0223.

    Published: 20 Feb 2012
    4.3
    Medium

    CVE-2012-1214

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Add friends module in Yoono Desktop Application before 1.8.21 allows remote attackers to inject arbitrary web script or HTML via the create field in a "Create a group" action.

    Published: 20 Feb 2012
    4.3
    Medium

    CVE-2012-1215

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Add friends module in the Yoono extension before 7.7.8 for Firefox allows remote attackers to inject arbitrary web script or HTML via the create field in a "Create a group" action.

    Published: 20 Feb 2012
    6.8
    Medium

    CVE-2012-1216

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in PBBoard 2.1.4 allow remote attackers to hijack the authentication of administrators for requests that (1) upload a file via an add action or (2) change the contents of a file via a dit action.

    Published: 20 Feb 2012
    4.3
    Medium

    CVE-2012-1217

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in STHS v2 Web Portal 2.2 allow remote attackers to inject arbitrary web script or HTML via the team parameter to (1) prospects.php, (2) prospect.php, or (3) team.php.

    Published: 20 Feb 2012
    5
    Medium

    CVE-2012-0996

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in 11in1 1.2.1 stable 12-31-2011 allow remote attackers to read arbitrary files via a .. (dot dot) in the class parameter to (1) index.php or (2) admin/index.php.

    Published: 20 Feb 2012
    6.8
    Medium

    CVE-2012-0997

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in admin/index.php in 11in1 1.2.1 stable 12-31-2011 allows remote attackers to hijack the authentication of administrators for requests that add new topics via an addTopic action.

    Published: 20 Feb 2012
    7.5
    High

    CVE-2012-0998

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in account/preferences.php in LEPTON before 1.1.4 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the language parameter.

    Published: 20 Feb 2012
    7.5
    High

    CVE-2012-0999

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in modules/news/rss.php in LEPTON before 1.1.4 allows remote attackers to execute arbitrary SQL commands via the group_id parameter.

    Published: 20 Feb 2012
    7.5
    High

    CVE-2012-1205

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in relocate-upload.php in Relocate Upload plugin before 0.20 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.

    Published: 20 Feb 2012
    9.3
    Critical

    CVE-2012-1206

    Last Modified: 11 Apr 2025

    Multiple integer overflows in Hancom Office 2010 SE 8.5.5 allow remote attackers to execute arbitrary code via large dimension values in a (1) JPG image to the ImportGR in the JPG image filter module (HncJpeg10.flt) or (2) PNG image to the PNG image filter module (HncPng10.flt), which triggers a heap-based buffer overflow.

    Published: 20 Feb 2012
    5
    Medium

    CVE-2012-1207

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in frontend/core/engine/javascript.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the module parameter to frontend/js.php.

    Published: 20 Feb 2012
    4.3
    Medium

    CVE-2012-1208

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) report parameter to blog/settings or (2) error parameter to users/index.

    Published: 20 Feb 2012
    4.3
    Medium

    CVE-2012-1209

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allows remote attackers to inject arbitrary web script or HTML via the highlight parameter.

    Published: 20 Feb 2012
    4.3
    Medium

    CVE-2012-1213

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in zimbra/h/calendar in Zimbra Web Client in Zimbra Collaboration Suite (ZCS) 6.x before 6.0.15 and 7.x before 7.1.3 allows remote attackers to inject arbitrary web script or HTML via the view parameter.

    Published: 20 Feb 2012
    4.3
    Medium

    CVE-2012-1000

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in LEPTON 1.1.3 and other versions before 1.1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) message parameter to admins/login/forgot/index.php, or the (2) display_name or (3) email parameter to account/preferences.php.

    Published: 20 Feb 2012
    4.3
    Medium

    CVE-2012-1211

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in pfile/kommentar.php in Powie pFile 1.02 allows remote attackers to inject arbitrary web script or HTML via the filecat parameter.

    Published: 20 Feb 2012
    4.3
    Medium

    CVE-2012-1212

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the smwfOnSfSetTargetName function in extensions/SMWHalo/includes/SMW_Initialize.php in Semantic Enterprise Wiki (SMW+) 1.5.6, 1.6.0_2 and earlier allows remote attackers to inject arbitrary web script or HTML via the target parameter to index.php/Special:FormEdit. NOTE: some of these details are obtained from third party information.

    Published: 20 Feb 2012
    7.5
    High

    CVE-2012-1210

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in pfile/file.php in Powie pFile 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 20 Feb 2012
    5.4
    Medium

    CVE-2012-0875

    Last Modified: 11 Apr 2025

    SystemTap 1.7, 1.6.7, and probably other versions, when unprivileged mode is enabled, allows local users to obtain sensitive information from kernel memory or cause a denial of service (kernel panic and crash) via vectors related to crafted DWARF data, which triggers a read of an invalid pointer.

    Published: 20 Feb 2012
    7.5
    High

    CVE-2012-1663

    Last Modified: 11 Apr 2025

    Double free vulnerability in libgnutls in GnuTLS before 3.0.14 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted certificate list.

    Published: 19 Feb 2012
    4.3
    Medium

    CVE-2011-3361

    Last Modified: 8 Sept 2025

    Cross-site scripting (XSS) vulnerability in CGI/Browse.pm in BackupPC 3.2.0 and possibly other versions before 3.2.1 allows remote attackers to inject arbitrary web script or HTML via the num parameter in a browse action to index.cgi.

    Published: 18 Feb 2012
    4
    Medium

    CVE-2011-4320

    Last Modified: 11 Apr 2025

    The mod_pubsub module (mod_pubsub.erl) in ejabberd 2.1.8 and 3.0.0-alpha-3 allows remote authenticated users to cause a denial of service (infinite loop) via a stanza with a publish tag that lacks a node attribute.

    Published: 18 Feb 2012
    6.8
    Medium

    CVE-2011-4614

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in Classes/Controller/AbstractController.php in the workspaces system extension in TYPO3 4.5.x before 4.5.9, 4.6.x before 4.6.2, and development versions of 4.7 allows remote attackers to execute arbitrary PHP code via a URL in the BACK_PATH parameter.

    Published: 18 Feb 2012
    4.3
    Medium

    CVE-2011-4923

    Last Modified: 8 Sept 2025

    Cross-site scripting (XSS) vulnerability in View.pm in BackupPC 3.0.0, 3.1.0, 3.2.0, 3.2.1, and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the num parameter in a view action to index.cgi, related to the log file viewer, a different vulnerability than CVE-2011-3361.

    Published: 18 Feb 2012
    4.3
    Medium

    CVE-2011-5081

    Last Modified: 8 Sept 2025

    Cross-site scripting (XSS) vulnerability in RestoreFile.pm in BackupPC 3.1.0, 3.2.1, and possibly other earlier versions allows remote attackers to inject arbitrary web script or HTML via the share parameter in a RestoreFile action to index.cgi.

    Published: 18 Feb 2012
    7.5
    High

    CVE-2012-1195

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup web service in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via a PutUpdateFileCore command in a RunAMTCommand SOAP request, then accessing the file via a direct request to the file in the web root.

    Published: 18 Feb 2012
    5
    Medium

    CVE-2012-1196

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the VulCore web service (WSVulnerabilityCore/VulCore.asmx) in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to delete arbitrary files via a .. (dot dot) in the filename parameter in a SetTaskLogByFile SOAP request.

    Published: 18 Feb 2012
    9.3
    Critical

    CVE-2012-1197

    Last Modified: 11 Apr 2025

    Integer overflow in the IDE_ACDStd.apl module for ACDSee 14.1 Build 137 allows remote attackers to execute arbitrary code via crafted "image dimension values" in a BMP file, which triggers a heap-based buffer overflow.

    Published: 18 Feb 2012
    7.5
    High

    CVE-2012-1198

    Last Modified: 11 Apr 2025

    base_ag_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allows remote attackers to execute arbitrary code by uploading contents of the file with an executable extension via a create action, then accessing it via a view action.

    Published: 18 Feb 2012
    7.5
    High

    CVE-2012-1200

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in Nova CMS allow remote attackers to execute arbitrary PHP code via a URL in the (1) fileType parameter to optimizer/index.php, (2) id parameter to administrator/modules/moduleslist.php, (3) filename parameter to includes/function/gets.php, or (4) conf[blockfile] parameter to includes/function/usertpl.php.

    Published: 18 Feb 2012
    7.5
    High

    CVE-2012-1199

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) BASE_path parameter to base_ag_main.php, (2) base_db_setup.php, (3) base_graph_common.php, (4) base_graph_display.php, (5) base_graph_form.php, (6) base_graph_main.php, (7) base_local_rules.php, (8) base_logout.php, (9) base_main.php, (10) base_maintenance.php, (11) base_payload.php, (12) base_qry_alert.php, (13) base_qry_common.php, (14) base_qry_main.php, (15) base_stat_alerts.php, (16) base_stat_class.php, (17) base_stat_common.php, (18) base_stat_ipaddr.php, (19) base_stat_iplink.php, (20) base_stat_ports.php, (21) base_stat_sensor.php, (22) base_stat_time.php, (23) base_stat_uaddr.php, (24) base_user.php, (25) index.php, (26) admin/base_roleadmin.php, (27) admin/base_useradmin.php, (28) admin/index.php, (29) help/base_setup_help.php, (30) includes/base_action.inc.php, (31) includes/base_cache.inc.php, (32) includes/base_db.inc.php, (33) includes/base_db.inc.php, (34) includes/base_include.inc.php, (35) includes/base_output_html.inc.php, (36) includes/base_output_query.inc.php, (37) includes/base_state_criteria.inc.php, (38) includes/base_state_query.inc.php or (39) setup/base_conf_contents.php; (40) GLOBALS[user_session_path] parameter to includes/base_state_common.inc.php; (41) BASE_Language parameter to setup/base_conf_contents.php; or (42) ado_inc_php parameter to setup/setup2.php.

    Published: 18 Feb 2012
    1.9
    Low

    CVE-2011-4105

    Last Modified: 11 Apr 2025

    LightDM before 1.0.6 allows local users to change ownership of arbitrary files via a symlink attack on ~/.Xauthority.

    Published: 17 Feb 2012
    7.5
    High

    CVE-2011-4113

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Views module before 6.x-2.13 for Drupal allows remote attackers to execute arbitrary SQL commands via vectors related to "filters/arguments on certain types of views with specific configurations of arguments."

    Published: 17 Feb 2012
    6.4
    Medium

    CVE-2012-1191

    Last Modified: 11 Apr 2025

    The resolver in dnscache in Daniel J. Bernstein djbdns 1.05 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.

    Published: 17 Feb 2012
    6.4
    Medium

    CVE-2012-1194

    Last Modified: 11 Apr 2025

    The resolver in the DNS Server service in Microsoft Windows Server 2008 before R2 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.

    Published: 17 Feb 2012
    6.4
    Medium

    CVE-2012-1193

    Last Modified: 11 Apr 2025

    The resolver in PowerDNS Recursor (aka pdns_recursor) 3.3 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.

    Published: 17 Feb 2012
    6.4
    Medium

    CVE-2012-1192

    Last Modified: 11 Apr 2025

    The resolver in Unbound before 1.4.11 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.

    Published: 17 Feb 2012
    5
    Medium

    CVE-2012-0206

    Last Modified: 11 Apr 2025

    common_startup.cc in PowerDNS (aka pdns) Authoritative Server before 2.9.22.5 and 3.x before 3.0.1 allows remote attackers to cause a denial of service (packet loop) via a crafted UDP DNS response.

    Published: 17 Feb 2012
    7.8
    High

    CVE-2012-0352

    Last Modified: 11 Apr 2025

    Cisco NX-OS 4.2.x before 4.2(1)SV1(5.1) on Nexus 1000v series switches; 4.x and 5.0.x before 5.0(2)N1(1) on Nexus 5000 series switches; and 4.2.x before 4.2.8, 5.0.x before 5.0.5, and 5.1.x before 5.1.1 on Nexus 7000 series switches allows remote attackers to cause a denial of service (netstack process crash and device reload) via a malformed IP packet, aka Bug IDs CSCti23447, CSCti49507, and CSCtj01991.

    Published: 16 Feb 2012
    6.8
    Medium

    CVE-2011-3016

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving counter nodes, related to a "read-after-free" issue.

    Published: 16 Feb 2012
    6.8
    Medium

    CVE-2011-3017

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to database handling.

    Published: 16 Feb 2012
    7.5
    High

    CVE-2011-3018

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to path rendering.

    Published: 16 Feb 2012
    6.8
    Medium

    CVE-2011-3019

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Matroska video (aka MKV) file.

    Published: 16 Feb 2012
    6.8
    Medium

    CVE-2011-3020

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Native Client validator implementation in Google Chrome before 17.0.963.56 has unknown impact and remote attack vectors.

    Published: 16 Feb 2012
    7.5
    High

    CVE-2011-3021

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to subframe loading.

    Published: 16 Feb 2012
    4.3
    Medium

    CVE-2011-3024

    Last Modified: 11 Apr 2025

    Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service (application crash) via an empty X.509 certificate.

    Published: 16 Feb 2012
    4.3
    Medium

    CVE-2011-3025

    Last Modified: 11 Apr 2025

    Google Chrome before 17.0.963.56 does not properly parse H.264 data, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 16 Feb 2012
    6.8
    Medium

    CVE-2011-3015

    Last Modified: 11 Apr 2025

    Multiple integer overflows in the PDF codecs in Google Chrome before 17.0.963.56 allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 16 Feb 2012
    6.8
    Medium

    CVE-2011-3023

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to drag-and-drop operations.

    Published: 16 Feb 2012