CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2011-3027

    Last Modified: 11 Apr 2025

    Google Chrome before 17.0.963.56 does not properly perform a cast of an unspecified variable during handling of columns, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.

    Published: 16 Feb 2012
    5
    Medium

    CVE-2011-3022

    Last Modified: 11 Apr 2025

    translate/translate_manager.cc in Google Chrome before 17.0.963.56 and 19.x before 19.0.1036.7 uses an HTTP session to exchange data for translation, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 16 Feb 2012
    10
    Critical

    CVE-2012-0751

    Last Modified: 11 Apr 2025

    The ActiveX control in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 16 Feb 2012
    6.5
    Medium

    CVE-2012-1571

    Last Modified: 4 Dec 2025

    file before 5.11 and libmagic allow remote attackers to cause a denial of service (crash) via a crafted Composite Document File (CDF) file that triggers (1) an out-of-bounds read or (2) an invalid pointer dereference.

    Published: 16 Feb 2012
    6.8
    Medium

    CVE-2011-3026

    Last Modified: 11 Apr 2025

    Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.

    Published: 16 Feb 2012
    10
    Critical

    CVE-2012-0508

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the JavaFX component in Oracle Java SE JavaFX, 1.3.0 and earlier, and 1.2.2 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 15 Feb 2012
    10
    Critical

    CVE-2012-0758

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code via unspecified vectors.

    Published: 15 Feb 2012
    10
    Critical

    CVE-2012-0759

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0771.

    Published: 15 Feb 2012
    10
    Critical

    CVE-2012-0760

    Last Modified: 11 Apr 2025

    The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0761, CVE-2012-0762, CVE-2012-0763, CVE-2012-0764, and CVE-2012-0766.

    Published: 15 Feb 2012
    10
    Critical

    CVE-2012-0762

    Last Modified: 11 Apr 2025

    The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0761, CVE-2012-0763, CVE-2012-0764, and CVE-2012-0766.

    Published: 15 Feb 2012
    10
    Critical

    CVE-2012-0763

    Last Modified: 11 Apr 2025

    The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0761, CVE-2012-0762, CVE-2012-0764, and CVE-2012-0766.

    Published: 15 Feb 2012
    10
    Critical

    CVE-2012-0764

    Last Modified: 11 Apr 2025

    The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0761, CVE-2012-0762, CVE-2012-0763, and CVE-2012-0766.

    Published: 15 Feb 2012
    4.3
    Medium

    CVE-2012-0765

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Adobe RoboHelp 8 and 9 for Word allow remote attackers to inject arbitrary web script or HTML via a crafted URL, related to certain .htm files in (1) template_stock and (2) template_csh directories.

    Published: 15 Feb 2012
    10
    Critical

    CVE-2012-0766

    Last Modified: 11 Apr 2025

    The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0761, CVE-2012-0762, CVE-2012-0763, and CVE-2012-0764.

    Published: 15 Feb 2012
    10
    Critical

    CVE-2012-0757

    Last Modified: 11 Apr 2025

    The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0760, CVE-2012-0761, CVE-2012-0762, CVE-2012-0763, CVE-2012-0764, and CVE-2012-0766.

    Published: 15 Feb 2012
    10
    Critical

    CVE-2012-0761

    Last Modified: 11 Apr 2025

    The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0762, CVE-2012-0763, CVE-2012-0764, and CVE-2012-0766.

    Published: 15 Feb 2012
    8.1
    High

    CVE-2012-0754

    Last Modified: 21 Apr 2026

    Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 15 Feb 2012
    6.1
    Medium

    CVE-2012-0767

    Last Modified: 21 Apr 2026

    Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)," as exploited in the wild in February 2012.

    Published: 15 Feb 2012
    9.3
    Critical

    CVE-2012-0756

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2012-0755.

    Published: 15 Feb 2012
    9.3
    Critical

    CVE-2012-0752

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to execute arbitrary code or cause a denial of service (memory corruption) by leveraging an unspecified "type confusion."

    Published: 15 Feb 2012
    9.3
    Critical

    CVE-2012-0753

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted MP4 data.

    Published: 15 Feb 2012
    9.3
    Critical

    CVE-2012-0755

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2012-0756.

    Published: 15 Feb 2012
    3.3
    Low

    CVE-2012-1088

    Last Modified: 11 Apr 2025

    iproute2 before 3.3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file used by (1) configure or (2) examples/dhcp-client-script.

    Published: 15 Feb 2012
    4.3
    Medium

    CVE-2012-0010

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 9 does not properly perform copy-and-paste operations, which allows user-assisted remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Copy and Paste Information Disclosure Vulnerability."

    Published: 14 Feb 2012
    9.3
    Critical

    CVE-2012-0011

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 7 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "HTML Layout Remote Code Execution Vulnerability."

    Published: 14 Feb 2012
    4.3
    Medium

    CVE-2012-0012

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 9 does not properly handle the creation and initialization of string objects, which allows remote attackers to read data from arbitrary process-memory locations via a crafted web site, aka "Null Byte Information Disclosure Vulnerability."

    Published: 14 Feb 2012
    9.3
    Critical

    CVE-2012-0015

    Last Modified: 11 Apr 2025

    Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly calculate the length of an unspecified buffer, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Heap Corruption Vulnerability."

    Published: 14 Feb 2012
    4.3
    Medium

    CVE-2012-0017

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in inplview.aspx in Microsoft SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in inplview.aspx Vulnerability."

    Published: 14 Feb 2012
    9.3
    Critical

    CVE-2012-0138

    Last Modified: 11 Apr 2025

    Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0136, and CVE-2012-0137.

    Published: 14 Feb 2012
    4.3
    Medium

    CVE-2012-0144

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in themeweb.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in themeweb.aspx Vulnerability."

    Published: 14 Feb 2012
    7.2
    High

    CVE-2012-0149

    Last Modified: 11 Apr 2025

    afd.sys in the Ancillary Function Driver in Microsoft Windows Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."

    Published: 14 Feb 2012
    9.3
    Critical

    CVE-2012-0150

    Last Modified: 11 Apr 2025

    Buffer overflow in msvcrt.dll in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted media file, aka "Msvcrt.dll Buffer Overflow Vulnerability."

    Published: 14 Feb 2012
    9.3
    Critical

    CVE-2012-0020

    Last Modified: 11 Apr 2025

    Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0136, CVE-2012-0137, and CVE-2012-0138.

    Published: 14 Feb 2012
    9.3
    Critical

    CVE-2012-0137

    Last Modified: 11 Apr 2025

    Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0136, and CVE-2012-0138.

    Published: 14 Feb 2012
    4.3
    Medium

    CVE-2012-0145

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in wizardlist.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in wizardlist.aspx Vulnerability."

    Published: 14 Feb 2012
    7.8
    High

    CVE-2012-0014

    Last Modified: 11 Apr 2025

    Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Unmanaged Objects Vulnerability."

    Published: 14 Feb 2012
    9.3
    Critical

    CVE-2012-0019

    Last Modified: 11 Apr 2025

    Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0020, CVE-2012-0136, CVE-2012-0137, and CVE-2012-0138.

    Published: 14 Feb 2012
    9.3
    Critical

    CVE-2012-0136

    Last Modified: 11 Apr 2025

    Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0137, and CVE-2012-0138.

    Published: 14 Feb 2012
    7.2
    High

    CVE-2012-0148

    Last Modified: 11 Apr 2025

    afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 on 64-bit platforms does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "AfdPoll Elevation of Privilege Vulnerability."

    Published: 14 Feb 2012
    7.2
    High

    CVE-2012-0154

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers keyboard layout errors, aka "Keyboard Layout Use After Free Vulnerability."

    Published: 14 Feb 2012
    9.3
    Critical

    CVE-2012-0155

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "VML Remote Code Execution Vulnerability."

    Published: 14 Feb 2012
    7.5
    High

    CVE-2010-5083

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url parameter in an Add action to modules.php.

    Published: 14 Feb 2012
    6.8
    Medium

    CVE-2010-5085

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in admin/update_user in Hulihan Amethyst 0.1.5, and possibly earlier, allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrative password or (2) change the site's configuration.

    Published: 14 Feb 2012
    6
    Medium

    CVE-2010-5084

    Last Modified: 11 Apr 2025

    The cross-site request forgery (CSRF) protection mechanism in e107 before 0.7.23 uses a predictable random token based on the creation date of the administrator account, which allows remote attackers to hijack the authentication of administrators for requests that add new users via e107_admin/users.php.

    Published: 14 Feb 2012
    5.8
    Medium

    CVE-2011-5079

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in the Modern FAQ (irfaq) extension 1.1.2 and other versions before 1.1.4 for TYPO3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL, probably in the "return url parameter."

    Published: 14 Feb 2012
    4.3
    Medium

    CVE-2011-5080

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in lib/class.tx_jftcaforms_tceFunc.php in the Additional TCA Forms (jftcaforms) extension before 0.2.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Feb 2012
    5
    Medium

    CVE-2012-1009

    Last Modified: 11 Apr 2025

    NetSarang Xlpd 4 Build 0100 and NetSarang Xmanager Enterprise 4 Build 0186 allow remote attackers to cause a denial of service (daemon crash) via a malformed LPD request.

    Published: 14 Feb 2012
    4.3
    Medium

    CVE-2012-1065

    Last Modified: 11 Apr 2025

    Insecure method vulnerability in TuxScripting.dll in the TuxSystem ActiveX control in 2X ApplicationServer 10.1 Build 1224 allows remote attackers to create or overwrite arbitrary files via the ExportSettings method.

    Published: 14 Feb 2012
    4.3
    Medium

    CVE-2012-1066

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the template module in SmartyCMS 0.9.4 allows remote attackers to inject arbitrary web script or HTML via the title bar.

    Published: 14 Feb 2012
    4.3
    Medium

    CVE-2012-1068

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the rc_ajax function in core.php in the WP-RecentComments plugin before 2.0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter, related to AJAX paging.

    Published: 14 Feb 2012