CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2011-4791

    Last Modified: 11 Apr 2025

    DBServer.exe in HP Data Protector Media Operations 6.11 and earlier allows remote attackers to execute arbitrary code via a crafted request containing a large value in a length field.

    Published: 3 Feb 2012
    6.8
    Medium

    CVE-2012-0314

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities on the eAccess Pocket WiFi (aka GP02) router before 2.00 with firmware 11.203.11.05.168 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) initialize settings or (2) reboot the device.

    Published: 3 Feb 2012
    8.8
    High

    CVE-2012-0247

    Last Modified: 11 Apr 2025

    ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit tag in the EXIF IFD0 of an image.

    Published: 3 Feb 2012
    5.5
    Medium

    CVE-2012-0248

    Last Modified: 11 Apr 2025

    ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.

    Published: 3 Feb 2012
    4.3
    Medium

    CVE-2011-3447

    Last Modified: 11 Apr 2025

    CFNetwork in Apple Mac OS X 10.7.x before 10.7.3 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensitive information via a malformed URL.

    Published: 2 Feb 2012
    6.8
    Medium

    CVE-2011-3448

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in CoreMedia in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.264 encoding.

    Published: 2 Feb 2012
    6.8
    Medium

    CVE-2011-3450

    Last Modified: 11 Apr 2025

    CoreUI in Apple Mac OS X 10.7.x before 10.7.3 does not properly restrict the allocation of stack memory, which allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption and application crash) via a long URL.

    Published: 2 Feb 2012
    4.3
    Medium

    CVE-2011-3452

    Last Modified: 11 Apr 2025

    Internet Sharing in Apple Mac OS X before 10.7.3 does not preserve the Wi-Fi configuration across software updates, which allows remote attackers to obtain sensitive information by leveraging the lack of a WEP password for a Wi-Fi network.

    Published: 2 Feb 2012
    6.8
    Medium

    CVE-2011-3459

    Last Modified: 11 Apr 2025

    Off-by-one error in QuickTime in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted rdrf atom in a movie file that triggers a buffer overflow.

    Published: 2 Feb 2012
    7.5
    High

    CVE-2011-3460

    Last Modified: 11 Apr 2025

    Buffer overflow in QuickTime in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PNG file.

    Published: 2 Feb 2012
    5
    Medium

    CVE-2011-3462

    Last Modified: 11 Apr 2025

    Time Machine in Apple Mac OS X before 10.7.3 does not verify the unique identifier of its remote AFP volume or Time Capsule, which allows remote attackers to obtain sensitive information contained in new backups by spoofing this storage object, a different vulnerability than CVE-2010-1803.

    Published: 2 Feb 2012
    5.1
    Medium

    CVE-2012-0440

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in jsonrpc.cgi in Bugzilla 3.5.x and 3.6.x before 3.6.8, 3.7.x and 4.0.x before 4.0.4, and 4.1.x and 4.2.x before 4.2rc2 allows remote attackers to hijack the authentication of arbitrary users for requests that use the JSON-RPC API.

    Published: 2 Feb 2012
    4
    Medium

    CVE-2012-0448

    Last Modified: 11 Apr 2025

    Bugzilla 2.x and 3.x before 3.4.14, 3.5.x and 3.6.x before 3.6.8, 3.7.x and 4.0.x before 4.0.4, and 4.1.x and 4.2.x before 4.2rc2 does not reject non-ASCII characters in e-mail addresses of new user accounts, which makes it easier for remote authenticated users to spoof other user accounts by choosing a similar e-mail address.

    Published: 2 Feb 2012
    7.5
    High

    CVE-2011-3446

    Last Modified: 11 Apr 2025

    Apple Type Services (ATS) in Apple Mac OS X before 10.7.3 does not properly manage memory for data-font files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font that is accessed by Font Book.

    Published: 2 Feb 2012
    6.8
    Medium

    CVE-2011-3449

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in CoreText in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded font in a document.

    Published: 2 Feb 2012
    6.8
    Medium

    CVE-2011-3458

    Last Modified: 11 Apr 2025

    QuickTime in Apple Mac OS X before 10.7.3 does not prevent access to uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MP4 file.

    Published: 2 Feb 2012
    4.3
    Medium

    CVE-2011-3444

    Last Modified: 11 Apr 2025

    Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV data by terminating an encrypted connection and then sniffing the network.

    Published: 2 Feb 2012
    7.5
    High

    CVE-2011-3453

    Last Modified: 11 Apr 2025

    Integer overflow in libresolv in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via crafted DNS data.

    Published: 2 Feb 2012
    7.5
    High

    CVE-2011-3457

    Last Modified: 11 Apr 2025

    The OpenGL implementation in Apple Mac OS X before 10.7.3 does not properly perform OpenGL Shading Language (aka GLSL) compilation, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted program.

    Published: 2 Feb 2012
    7.2
    High

    CVE-2011-3463

    Last Modified: 11 Apr 2025

    WebDAV Sharing in Apple Mac OS X 10.7.x before 10.7.3 does not properly perform authentication, which allows local users to gain privileges by leveraging access to (1) the server or (2) a bound directory.

    Published: 2 Feb 2012
    7.8
    High

    CVE-2011-2393

    Last Modified: 11 Apr 2025

    The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD, NetBSD, and possibly other BSD-based operating systems allows remote attackers to cause a denial of service (CPU consumption and device hang) by sending many Router Advertisement (RA) messages with different source addresses, a similar vulnerability to CVE-2010-4670.

    Published: 2 Feb 2012
    4.3
    Medium

    CVE-2012-0975

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in misc.php in Image Hosting Script DPI 1.0, 1.3, and earlier allows remote attackers to inject arbitrary web script or HTML via the showseries parameter.

    Published: 2 Feb 2012
    9.3
    Critical

    CVE-2012-0977

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in jp2_x.dll in LuraWave JP2 ActiveX Control 2.1.5.5 and other versions before 2.1.5.11 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.

    Published: 2 Feb 2012
    6.8
    Medium

    CVE-2012-0978

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in npjp2.dll in LuraWave JP2 Browser Plug-In 1.1.1.11 and other versions before 2.1.1.11 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.

    Published: 2 Feb 2012
    4.3
    Medium

    CVE-2012-0979

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in TWiki allows remote attackers to inject arbitrary web script or HTML via the organization field in a profile, involving (1) registration or (2) editing of the user.

    Published: 2 Feb 2012
    7.5
    High

    CVE-2012-0980

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in download.php in phux Download Manager allows remote attackers to execute arbitrary SQL commands via the file parameter.

    Published: 2 Feb 2012
    7.5
    High

    CVE-2012-0982

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in search.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the price_from parameter.

    Published: 2 Feb 2012
    4.3
    Medium

    CVE-2010-4562

    Last Modified: 11 Apr 2025

    Microsoft Windows 2008, 7, Vista, 2003, 2000, and XP, when using IPv6, allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent, as demonstrated by thcping. NOTE: due to a typo, some sources map CVE-2010-4562 to a ProFTPd mod_sql vulnerability, but that issue is covered by CVE-2010-4652.

    Published: 2 Feb 2012
    2.1
    Low

    CVE-2012-0976

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/EditForm in SilverStripe 2.4.6 allows remote authenticated users with Content Authors privileges to inject arbitrary web script or HTML via the Title parameter. NOTE: some of these details are obtained from third party information.

    Published: 2 Feb 2012
    5
    Medium

    CVE-2012-0981

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in phpShowtime 2.0 allows remote attackers to list arbitrary directories and image files via a .. (dot dot) in the r parameter to index.php. NOTE: Some of these details are obtained from third party information.

    Published: 2 Feb 2012
    7.5
    High

    CVE-2012-0983

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Scriptsez.net Ez Album allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.

    Published: 2 Feb 2012
    6.8
    Medium

    CVE-2011-4144

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in EMC Documentum Content Server 6.0, 6.5 before SP2 P02, 6.5 SP3 before SP3 P02, and 6.6 before P02 allows local users to obtain "highest super user privileges" by leveraging system administrator privileges.

    Published: 2 Feb 2012
    7.5
    High

    CVE-2011-4194

    Last Modified: 11 Apr 2025

    Buffer overflow in Novell iPrint Server in Novell Open Enterprise Server 2 (OES2) through SP3 on Linux allows remote attackers to execute arbitrary code via a crafted attributes-natural-language field.

    Published: 2 Feb 2012
    9.3
    Critical

    CVE-2011-4790

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Network Automation 7.5x, 7.6x, 9.0, and 9.10 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 2 Feb 2012
    6.8
    Medium

    CVE-2012-0831

    Last Modified: 11 Apr 2025

    PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related to main/php_variables.c, sapi/cgi/cgi_main.c, and sapi/fpm/fpm/fpm_main.c.

    Published: 2 Feb 2012
    7.5
    High

    CVE-2012-0830

    Last Modified: 11 Apr 2025

    The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4885.

    Published: 2 Feb 2012
    4.3
    Medium

    CVE-2012-0446

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to inject arbitrary web script or HTML via a (1) web page or (2) Firefox extension, related to improper enforcement of XPConnect security restrictions for frame scripts that call untrusted objects.

    Published: 1 Feb 2012
    5
    Medium

    CVE-2012-0447

    Last Modified: 11 Apr 2025

    Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize data for image/vnd.microsoft.icon images, which allows remote attackers to obtain potentially sensitive information by reading a PNG image that was created through conversion from an ICO image.

    Published: 1 Feb 2012
    2.1
    Low

    CVE-2012-0450

    Last Modified: 11 Apr 2025

    Mozilla Firefox 4.x through 9.0 and SeaMonkey before 2.7 on Linux and Mac OS X set weak permissions for Firefox Recovery Key.html, which might allow local users to read a Firefox Sync key via standard filesystem operations.

    Published: 1 Feb 2012
    5
    Medium

    CVE-2012-0445

    Last Modified: 11 Apr 2025

    Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to bypass the HTML5 frame-navigation policy and replace arbitrary sub-frames by creating a form submission target with a sub-frame's name attribute.

    Published: 1 Feb 2012
    10
    Critical

    CVE-2012-0443

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 1 Feb 2012
    5.8
    Medium

    CVE-2012-0052

    Last Modified: 11 Apr 2025

    Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 does not check the JON agent key, which allows remote attackers to spoof the identity of arbitrary agents via the registered agent name.

    Published: 1 Feb 2012
    4.3
    Medium

    CVE-2012-1006

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) lastName parameter to struts2-showcase/person/editPerson.action, or the (3) clientName parameter to struts2-rest-showcase/orders.

    Published: 1 Feb 2012
    4.3
    Medium

    CVE-2012-1007

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter to struts-examples/upload/upload-submit.do, or the message parameter to (2) struts-cookbook/processSimple.do or (3) struts-cookbook/processDyna.do.

    Published: 1 Feb 2012
    7.5
    High

    CVE-2011-3464

    Last Modified: 11 Apr 2025

    Off-by-one error in the png_formatted_warning function in pngerror.c in libpng 1.5.4 through 1.5.7 might allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unspecified vectors, which trigger a stack-based buffer overflow.

    Published: 1 Feb 2012
    5.8
    Medium

    CVE-2012-0062

    Last Modified: 11 Apr 2025

    Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 allows remote attackers to hijack agent sessions via an agent registration request without a security token.

    Published: 1 Feb 2012
    9.3
    Critical

    CVE-2012-0449

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a malformed XSLT stylesheet that is embedded in a document.

    Published: 31 Jan 2012
    5
    Medium

    CVE-2011-4610

    Last Modified: 11 Apr 2025

    JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1.3, Enterprise Web Platform before 5.1.2, Enterprise Application Platform before 5.1.2, and other products, allows remote attackers to cause a denial of service (infinite loop) via vectors related to a crafted UTF-8 and a "surrogate pair character" that is "at the boundary of an internal buffer."

    Published: 31 Jan 2012
    9.3
    Critical

    CVE-2012-0442

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 31 Jan 2012
    9.3
    Critical

    CVE-2011-3659

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 might allow remote attackers to execute arbitrary code via vectors related to incorrect AttributeChildRemoved notifications that affect access to removed nsDOMAttribute child nodes.

    Published: 31 Jan 2012