CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2012-0902

    Last Modified: 11 Apr 2025

    AirTies Air 4450 1.1.2.18 allows remote attackers to cause a denial of service (reboot) via a direct request to cgi-bin/loader.

    Published: 20 Jan 2012
    7.5
    High

    CVE-2012-0905

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in deV!L'z Clanportal (DZCP) Gamebase addon allows remote attackers to execute arbitrary SQL commands via the gameid parameter in a detail action to index.php.

    Published: 20 Jan 2012
    7.5
    High

    CVE-2012-0906

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Moviebase addon for deV!L'z Clanportal (DZCP) 1.5.5 allows remote attackers to execute arbitrary SQL commands via the id parameter in a showkat action to index.php.

    Published: 20 Jan 2012
    5.8
    Medium

    CVE-2012-0907

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the web player in NeoAxis NeoAxis web player 1.4 and earlier allows user-assisted remote attackers to write arbitrary files via a .. (dot dot) in a filename in the neoaxis_web_application_win32.zip ZIP archive.

    Published: 20 Jan 2012
    6.8
    Medium

    CVE-2012-0897

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.

    Published: 20 Jan 2012
    4.3
    Medium

    CVE-2012-0904

    Last Modified: 11 Apr 2025

    VLC media player 1.1.11 allows remote attackers to cause a denial of service (crash) via a long string in an amr file.

    Published: 20 Jan 2012
    4.3
    Medium

    CVE-2012-0903

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Desktop 7.1.2 b10978 allow remote attackers to inject arbitrary web script or HTML via the (1) Username or (2) MailBox Name.

    Published: 20 Jan 2012
    4.3
    Medium

    CVE-2012-0895

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in map/map.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map parameter.

    Published: 20 Jan 2012
    5
    Medium

    CVE-2012-0896

    Last Modified: 11 Apr 2025

    Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter.

    Published: 20 Jan 2012
    4.3
    Medium

    CVE-2012-0900

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Beehive Forum 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) forum/register.php or (2) forum/logon.php.

    Published: 20 Jan 2012
    5
    Medium

    CVE-2012-0193

    Last Modified: 11 Apr 2025

    IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.43, 6.1 before 6.1.0.43, 7.0 before 7.0.0.23, and 8.0 before 8.0.0.3 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

    Published: 20 Jan 2012
    10
    Critical

    CVE-2011-1389

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in the vendor daemon in Rational Common Licensing in Telelogic License Server 2.0, Rational License Server 7.x, and ibmratl in IBM Rational License Key Server (RLKS) 8.0 through 8.1.2 allow remote attackers to execute arbitrary code via vectors related to save, rename, and load operations on log files. NOTE: this might overlap CVE-2011-4135.

    Published: 19 Jan 2012
    2.1
    Low

    CVE-2007-6744

    Last Modified: 11 Apr 2025

    Flexera Macrovision InstallShield before 2008 sends a digital-signature password to an unintended application during certain signature operations involving .spc and .pvk files, which might allow local users to obtain sensitive information via unspecified vectors, related to an incorrect interaction between InstallShield and Signcode.exe.

    Published: 19 Jan 2012
    10
    Critical

    CVE-2011-4134

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in lmadmin in Flexera FlexNet Publisher 11.10 (aka FlexNet License Server Manager) allows remote attackers to execute arbitrary code via a crafted 0x2f packet.

    Published: 19 Jan 2012
    10
    Critical

    CVE-2011-4135

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in lmgrd in Flexera FlexNet Publisher 11.10 (aka FlexNet License Server Manager) allow remote attackers to execute arbitrary code via vectors related to save, rename, and load operations on log files. NOTE: this might overlap CVE-2011-1389.

    Published: 19 Jan 2012
    5
    Medium

    CVE-2011-4873

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the server in Certec EDV atvise before 2.1 allows remote attackers to cause a denial of service (daemon crash) via crafted requests to TCP port 4840.

    Published: 19 Jan 2012
    5.1
    Medium

    CVE-2012-0268

    Last Modified: 11 Apr 2025

    Integer overflow in the CYImage::LoadJPG method in YImage.dll in Yahoo! Messenger before 11.5.0.155, when photo sharing is enabled, might allow remote attackers to execute arbitrary code via a crafted JPG image that triggers a heap-based buffer overflow.

    Published: 19 Jan 2012
    10
    Critical

    CVE-2011-4659

    Last Modified: 11 Apr 2025

    Cisco TelePresence Software before TE 4.1.1 on the Cisco IP Video Phone E20 has a default password for the root account after an upgrade to TE 4.1.0, which makes it easier for remote attackers to modify the configuration via an SSH session, aka Bug ID CSCtw69889, a different vulnerability than CVE-2011-2555.

    Published: 19 Jan 2012
    9.3
    Critical

    CVE-2011-4053

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in 7-Technologies (7T) Interactive Graphical SCADA System (IGSS) before 9.0.0.11291 allows local users to gain privileges via a Trojan horse DLL in the current working directory.

    Published: 19 Jan 2012
    9
    Critical

    CVE-2012-0329

    Last Modified: 11 Apr 2025

    Cisco Digital Media Manager 5.2.2 and earlier, and 5.2.3, allows remote authenticated users to execute arbitrary code via vectors involving a URL and an administrative resource, aka Bug ID CSCts63878.

    Published: 19 Jan 2012
    4.6
    Medium

    CVE-2011-1376

    Last Modified: 11 Apr 2025

    iscdeploy in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 on the IBM i platform sets weak permissions under systemapps/isclite.ear/ and bin/client_ffdc/, which allows local users to read or modify files via standard filesystem operations.

    Published: 19 Jan 2012
    2.1
    Low

    CVE-2011-4142

    Last Modified: 11 Apr 2025

    The Web Search feature in EMC SourceOne Email Management 6.5 before 6.5.2.4033, 6.6 before 6.6.1.2194, and 6.7 before 6.7.2.2033 places cleartext credentials in log files, which allows local users to obtain sensitive information by reading these files.

    Published: 19 Jan 2012
    4.6
    Medium

    CVE-2012-0064

    Last Modified: 11 Apr 2025

    xkeyboard-config before 2.5 in X.Org before 7.6 enables certain XKB debugging functions by default, which allows physically proximate attackers to bypass an X screen lock via keyboard combinations that break the input grab.

    Published: 19 Jan 2012
    4
    Medium

    CVE-2011-2317

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allows remote authenticated users to affect integrity, related to Enterprise Infrastucture SEC (JDNET).

    Published: 18 Jan 2012
    4
    Medium

    CVE-2011-2321

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allows remote authenticated users to affect confidentiality, related to Enterprise Infrastructure SEC (JDNET).

    Published: 18 Jan 2012
    5
    Medium

    CVE-2011-2324

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allows remote attackers to affect availability, related to Enterprise Infrastructure SEC (JDENET).

    Published: 18 Jan 2012
    4
    Medium

    CVE-2011-2325

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allows remote authenticated users to affect confidentiality, related to Enterprise Infrastructure SEC (JDENET), a different vulnerability than CVE-2011-2326, CVE-2011-3509, and CVE-2011-3524.

    Published: 18 Jan 2012
    4
    Medium

    CVE-2011-3514

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allows remote authenticated users to affect integrity, related to Enterprise Infrastructure SEC (JDENET).

    Published: 18 Jan 2012
    5
    Medium

    CVE-2011-3531

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Web Services Manager component in Oracle Fusion Middleware 11.1.1.3, 11.1.1.4, and 11.1.1.5 allows remote attackers to affect availability via unknown vectors related to Web Services Security.

    Published: 18 Jan 2012
    4.6
    Medium

    CVE-2011-3565

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Communications Unified 7.0 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Calendar Server.

    Published: 18 Jan 2012
    5.5
    Medium

    CVE-2011-3568

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Web Services Manager component in Oracle Fusion Middleware 11.1.1.3, 11.1.1.4, and 11.1.1.5 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Web Services Security.

    Published: 18 Jan 2012
    5
    Medium

    CVE-2011-3569

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Web Services Manager component in Oracle Fusion Middleware 11.1.1.3, 11.1.1.4, and 11.1.1.5 allows remote attackers to affect confidentiality via unknown vectors related to Web Services Security.

    Published: 18 Jan 2012
    2.1
    Low

    CVE-2011-3570

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Communications Unified 7.0 allows local users to affect confidentiality via unknown vectors related to Calendar Server.

    Published: 18 Jan 2012
    4
    Medium

    CVE-2011-3573

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Communications Unified 7.0 allows remote authenticated users to affect availability via unknown vectors related to Calendar Server.

    Published: 18 Jan 2012
    5
    Medium

    CVE-2012-0072

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Listener component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.2 allows remote attackers to affect availability via unknown vectors.

    Published: 18 Jan 2012
    4.3
    Medium

    CVE-2012-0073

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Forms component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors.

    Published: 18 Jan 2012
    4
    Medium

    CVE-2012-0074

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise CRM component in Oracle PeopleSoft Products 8.9 allows remote authenticated users to affect integrity via unknown vectors related to Sales.

    Published: 18 Jan 2012
    4
    Medium

    CVE-2012-0076

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.0 and 9.1 allows remote authenticated users to affect confidentiality via unknown vectors related to ePerformance.

    Published: 18 Jan 2012
    3.5
    Low

    CVE-2012-0077

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.2.4, 10.0.2, 10.3.3, 10.3.4, and 10.3.5 allows remote authenticated users to affect integrity, related to WLS-Console.

    Published: 18 Jan 2012
    5.5
    Medium

    CVE-2012-0080

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Talent Acquisition Management.

    Published: 18 Jan 2012
    5.5
    Medium

    CVE-2012-0082

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect integrity and availability via unknown vectors.

    Published: 18 Jan 2012
    6.4
    Medium

    CVE-2012-0083

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 7.5.2, 10.1.3.5.1, 11.1.1.3, 11.1.1.4, and 11.1.1.5 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Search.

    Published: 18 Jan 2012
    3.5
    Low

    CVE-2012-0084

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 7.5.2, 10.1.3.5.1, 11.1.1.3, 11.1.1.4, and 11.1.1.5 allows remote authenticated users to affect integrity via unknown vectors related to Content Server.

    Published: 18 Jan 2012
    4.3
    Medium

    CVE-2012-0085

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 7.5.2 and 10.1.3.5.1 allows remote attackers to affect integrity via unknown vectors related to Content Server.

    Published: 18 Jan 2012
    4
    Medium

    CVE-2012-0088

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 8.9, 9.0, and 9.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Benefits Administration.

    Published: 18 Jan 2012
    4
    Medium

    CVE-2012-0089

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.1 allows remote authenticated users to affect confidentiality via unknown vectors related to ePerformance.

    Published: 18 Jan 2012
    2.7
    Low

    CVE-2012-0091

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52.05 allows remote authenticated users to affect integrity and availability via unknown vectors related to Upgrade Change Assistance.

    Published: 18 Jan 2012
    5
    Medium

    CVE-2012-0096

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to Network.

    Published: 18 Jan 2012
    2.1
    Low

    CVE-2012-0097

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 11 Express allows local users to affect confidentiality via unknown vectors related to ksh93 Shell.

    Published: 18 Jan 2012
    1.9
    Low

    CVE-2012-0098

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect availability via unknown vectors related to Kernel, a different vulnerability than CVE-2011-0813.

    Published: 18 Jan 2012