CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2012-1069

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in module/kb/search_word in the search module in lknSupport allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Published: 14 Feb 2012
    7.5
    High

    CVE-2012-1072

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Category-System (toi_category) extension 0.6.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 14 Feb 2012
    4.3
    Medium

    CVE-2012-1073

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Category-System (toi_category) extension 0.6.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Feb 2012
    7.5
    High

    CVE-2012-1074

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the White Papers (mm_whtppr) extension 0.0.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 14 Feb 2012
    7.5
    High

    CVE-2012-1075

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Documents download (rtg_files) extension before 1.5.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 14 Feb 2012
    4.3
    Medium

    CVE-2012-1076

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Documents download (rtg_files) extension before 1.5.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Feb 2012
    6.5
    Medium

    CVE-2012-1079

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Webservices for TYPO3 (typo3_webservice) extension before 0.3.8 for TYPO3 allows remote authenticated users to execute arbitrary code via unknown vectors.

    Published: 14 Feb 2012
    4.3
    Medium

    CVE-2012-1080

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Euro Calculator (skt_eurocalc) extension 0.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Feb 2012
    4.3
    Medium

    CVE-2012-1081

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Yet another Google search (ya_googlesearch) extension before 0.3.10 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Feb 2012
    3.5
    Low

    CVE-2012-1082

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Terminal PHP Shell (terminal) extension 0.3.2 and earlier for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Feb 2012
    6.8
    Medium

    CVE-2012-1083

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Terminal PHP Shell (terminal) extension 0.3.2 and earlier for TYPO3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 14 Feb 2012
    4.3
    Medium

    CVE-2012-1084

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the BE User Switch (beuserswitch) extension 0.0.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Feb 2012
    5
    Medium

    CVE-2012-1085

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the BE User Switch (beuserswitch) extension 0.0.1 for TYPO3 allows remote attackers to obtain sensitive information via unknown vectors.

    Published: 14 Feb 2012
    4.3
    Medium

    CVE-2012-1086

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the UrlTool (aeurltool) extension 0.1.0 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Feb 2012
    4.3
    Medium

    CVE-2012-1070

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Modern FAQ (irfaq) extension 1.1.2 and other versions before 1.1.4 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to the "return url parameter."

    Published: 14 Feb 2012
    7.5
    High

    CVE-2012-1071

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Kitchen recipe (mv_cooking) extension before 0.4.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, as exploited in the wild as of February 2012.

    Published: 14 Feb 2012
    7.5
    High

    CVE-2012-1077

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Post data records to facebook (bc_post2facebook) extension before 0.2.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 14 Feb 2012
    4.3
    Medium

    CVE-2012-1087

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Post data records to facebook (bc_post2facebook) extension before 0.2.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Feb 2012
    7.5
    High

    CVE-2012-1067

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the WP-RecentComments plugin 2.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter in an rc-content action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 14 Feb 2012
    5
    Medium

    CVE-2012-1078

    Last Modified: 11 Apr 2025

    The System Utilities (sysutils) extension 1.0.3 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unspecified vectors related to improper "protection" of the "backup output directory."

    Published: 14 Feb 2012
    9.8
    Critical

    CVE-2012-0507

    Last Modified: 22 Apr 2026

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.

    Published: 14 Feb 2012
    6.4
    Medium

    CVE-2011-3563

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote attackers to affect confidentiality and availability via unknown vectors related to Sound.

    Published: 14 Feb 2012
    10
    Critical

    CVE-2012-0497

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, and 6 Update 30 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

    Published: 14 Feb 2012
    10
    Critical

    CVE-2012-0498

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

    Published: 14 Feb 2012
    10
    Critical

    CVE-2012-0499

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier; and JavaFX 2.0.2 and earlier; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

    Published: 14 Feb 2012
    10
    Critical

    CVE-2012-0500

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and JavaFX 2.0.2 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

    Published: 14 Feb 2012
    9.3
    Critical

    CVE-2012-0504

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, and 6 Update 30 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install and the Java Update mechanism.

    Published: 14 Feb 2012
    4.3
    Medium

    CVE-2012-0506

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect integrity via unknown vectors related to CORBA.

    Published: 14 Feb 2012
    6.8
    Medium

    CVE-2012-1055

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in PhotoLine 17.01 and possibly other versions before 17.02 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.

    Published: 14 Feb 2012
    6
    Medium

    CVE-2012-1058

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Flyspray 0.9.9.6 allows remote attackers to hijack the authentication of admins for requests that add admin accounts via an admin.newuser action to index.php.

    Published: 14 Feb 2012
    2.1
    Low

    CVE-2012-1060

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in revisioning_theme.inc in the Taxonomy module in the Revisioning module 6.x-3.13 and other versions before 6.x-3.14 for Drupal allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via the (1) tags or (2) term parameters.

    Published: 14 Feb 2012
    7.5
    High

    CVE-2012-1061

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in GForge Advanced Server 6.0.0 and other versions before 6.0.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 14 Feb 2012
    6.4
    Medium

    CVE-2012-0502

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality and availability, related to AWT.

    Published: 14 Feb 2012
    7.5
    High

    CVE-2012-0503

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability, related to I18n.

    Published: 14 Feb 2012
    6
    Medium

    CVE-2012-1057

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the clickthrough tracking functionality in the Forward module 6.x-1.x before 6.x-1.21 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of administrators for requests that increase node rankings via the tracking code, possibly related to improper "flood control."

    Published: 14 Feb 2012
    7.5
    High

    CVE-2012-1063

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to execute arbitrary SQL commands via the (1) viewId parameter to fault/AlarmView.do or (2) period parameter to showHistoryData.do.

    Published: 14 Feb 2012
    4.3
    Medium

    CVE-2012-2664

    Last Modified: 11 Apr 2025

    The sosreport utility in the Red Hat sos package before 2.2-29 does not remove the root user password information from the Kickstart configuration file (/root/anaconda-ks.cfg) when creating an archive of debugging information, which might allow attackers to obtain passwords or password hashes.

    Published: 14 Feb 2012
    5
    Medium

    CVE-2012-0501

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect availability via unknown vectors.

    Published: 14 Feb 2012
    7.5
    High

    CVE-2012-0505

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Serialization.

    Published: 14 Feb 2012
    6
    Medium

    CVE-2012-0829

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Mibew Messenger 1.6.4 and earlier allow remote attackers to hijack the authentication of operators for requests that insert cross-site scripting (XSS) sequences via the (1) address or (2) threadid parameters to operator/ban.php; or (3) geolinkparams, (4) title, or (5) chattitle parameters to operator/settings.php.

    Published: 14 Feb 2012
    5
    Medium

    CVE-2012-1056

    Last Modified: 11 Apr 2025

    The Forward module 6.x-1.x before 6.x-1.21 and 7.x-1.x before 7.x-1.3 for Drupal does not properly enforce permissions for (1) Recent forwards, (2) Most forwarded, or (3) Dynamic blocks, which allows remote attackers to obtain node titles via unspecified vectors.

    Published: 14 Feb 2012
    4.3
    Medium

    CVE-2012-1059

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Cart/pages/main.php in OSCommerce Online Merchant 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the value_title parameter, as demonstrated using the "Front" field in the shirt module.

    Published: 14 Feb 2012
    4.3
    Medium

    CVE-2012-1062

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to inject arbitrary web script or HTML via the (1) period parameter to showHistoryData.do; (2) selectedNetwork, (3) network, or (4) group parameters to showresource.do; (5) header parameter to AlarmView.do; or (6) attName parameter to jsp/PopUp_Graph.jsp. NOTE: the Search.do/query vector is already covered by CVE-2008-1566, and the jsp/ThresholdActionConfiguration.jsp redirectto vector is already covered by CVE-2008-0474.

    Published: 14 Feb 2012
    4.3
    Medium

    CVE-2012-0340

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the management interface on the Cisco IronPort Encryption Appliance with software before 6.5.3 allows remote attackers to inject arbitrary web script or HTML via the header parameter to the default URI under admin/, aka bug ID 72410.

    Published: 13 Feb 2012
    4.3
    Medium

    CVE-2012-1050

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Mathopd 1.4.x and 1.5.x before 1.5p7, when configured with the * construct for mass virtual hosting, allows remote attackers to read arbitrary files via a crafted Host header.

    Published: 13 Feb 2012
    6.8
    Medium

    CVE-2012-1051

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Xjp2.dll in the JPEG2000 plug-in in XnView 1.98.5 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.

    Published: 13 Feb 2012
    6.8
    Medium

    CVE-2012-1052

    Last Modified: 11 Apr 2025

    Buffer overflow in IvanView 1.2.15 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.

    Published: 13 Feb 2012
    4.3
    Medium

    CVE-2012-1049

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ADManager Plus 5.2 Build 5210 allow remote attackers to inject arbitrary web script or HTML via the (1) domainName parameter to jsp/AddDC.jsp or (2) operation parameter to DomainConfig.do.

    Published: 13 Feb 2012
    7.5
    High

    CVE-2012-1047

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the WWWHELP Service (js/html/wwhelp.htm) in Cyberoam Central Console (CCC) 2.00.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter in an Online_help action.

    Published: 12 Feb 2012
    4.3
    Medium

    CVE-2012-1048

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in communityplusplus/www/administrator.php in eFront Community++ edition 3.6.10, and possibly other editions, allows remote attackers to inject arbitrary web script or HTML via the filter parameter.

    Published: 12 Feb 2012