CVE Feed

    Dashboard / CVE

    4.9
    Medium

    CVE-2012-0118

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect confidentiality and availability via unknown vectors, a different vulnerability than CVE-2012-0113.

    Published: 18 Jan 2012
    4
    Medium

    CVE-2012-0487

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0117, CVE-2012-0486, CVE-2012-0488, CVE-2012-0489, CVE-2012-0491, CVE-2012-0493, and CVE-2012-0495.

    Published: 18 Jan 2012
    1.7
    Low

    CVE-2012-0494

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows local users to affect availability via unknown vectors.

    Published: 18 Jan 2012
    9.3
    Critical

    CVE-2010-5082

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in colorcpl.exe 6.0.6000.16386 in the Color Control Panel in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges via a Trojan horse sti.dll file in the current working directory, as demonstrated by a directory that contains a .camp, .cdmp, .gmmp, .icc, or .icm file, aka "Color Control Panel Insecure Library Loading Vulnerability."

    Published: 17 Jan 2012
    5
    Medium

    CVE-2011-3375

    Last Modified: 11 Apr 2025

    Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP address and HTTP header information in opportunistic circumstances by reading TCP data.

    Published: 17 Jan 2012
    5
    Medium

    CVE-2012-0022

    Last Modified: 11 Apr 2025

    Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.

    Published: 17 Jan 2012
    9.8
    Critical

    CVE-2012-0828

    Last Modified: 21 Nov 2024

    Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial of service (xchat client crash) or execute arbitrary code via a UTF-8 line from server containing characters outside of the Basic Multilingual Plane (BMP).

    Published: 17 Jan 2012
    5
    Medium

    CVE-2012-1178

    Last Modified: 11 Apr 2025

    The msn_oim_report_to_user function in oim.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.2 allows remote servers to cause a denial of service (application crash) via an OIM message that lacks UTF-8 encoding.

    Published: 17 Jan 2012
    4.3
    Medium

    CVE-2011-5065

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 allows remote attackers to inject arbitrary web script or HTML via vectors related to web messaging.

    Published: 15 Jan 2012
    2.1
    Low

    CVE-2011-5066

    Last Modified: 11 Apr 2025

    The SibRaRecoverableSiXaResource class in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 does not properly handle a Service Integration Bus (SIB) dump operation involving the First Failure Data Capture (FFDC) introspection code, which allows local users to obtain sensitive information by reading the FFDC log file.

    Published: 15 Jan 2012
    9.3
    Critical

    CVE-2012-0267

    Last Modified: 11 Apr 2025

    The StopModule method in the NTR ActiveX control before 2.0.4.8 allows remote attackers to execute arbitrary code via a crafted lModule parameter that triggers use of an arbitrary memory address as a function pointer.

    Published: 15 Jan 2012
    4.3
    Medium

    CVE-2011-1362

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 and 7.0 before 7.0.0.19 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1308.

    Published: 15 Jan 2012
    9.3
    Critical

    CVE-2012-0266

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in the NTR ActiveX control before 2.0.4.8 allow remote attackers to execute arbitrary code via (1) a long bstrUrl parameter to the StartModule method, (2) a long bstrParams parameter to the Check method, a long bstrUrl parameter to the (3) Download or (4) DownloadModule method during construction of a .ntr pathname, or a long bstrUrl parameter to the (5) Download or (6) DownloadModule method during construction of a URL.

    Published: 15 Jan 2012
    10
    Critical

    CVE-2011-1377

    Last Modified: 11 Apr 2025

    The Web Services Security component in the Web Services Feature Pack before 6.1.0.41 for IBM WebSphere Application Server (WAS) 6.1 does not properly handle the enabling of WS-Security for a JAX-WS application, which has unspecified impact and attack vectors.

    Published: 15 Jan 2012
    4.4
    Medium

    CVE-2012-2736

    Last Modified: 21 Nov 2024

    In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.

    Published: 15 Jan 2012
    7.5
    High

    CVE-2011-5061

    Last Modified: 11 Apr 2025

    functions.php in WHMCompleteSolution (WHMCS) 4.0.x through 5.0.x allows remote attackers to trigger arbitrary code execution in the Smarty templating system by submitting a crafted ticket, related to improper handling of characters in the subject field.

    Published: 14 Jan 2012
    5
    Medium

    CVE-2012-0693

    Last Modified: 11 Apr 2025

    submitticket.php in WHMCompleteSolution (WHMCS) 5.03 allows remote attackers to inject arbitrary code into a subject field via crafted ticket data, a different vulnerability than CVE-2011-5061. NOTE: the vendor disputes this issue, noting that some of the details overlap CVE-2011-5061, but that it "says it affects V5.0.3, and the submitticket.php file, both of which are wrong.

    Published: 14 Jan 2012
    3.3
    Low

    CVE-2011-5060

    Last Modified: 11 Apr 2025

    The par_mktmpdir function in the PAR module before 1.003 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program, a different vulnerability in a different package than CVE-2011-4114.

    Published: 13 Jan 2012
    5
    Medium

    CVE-2011-4057

    Last Modified: 11 Apr 2025

    Wibu-Systems AG CodeMeter Runtime 4.30c, 4.10b, and possibly other versions before 4.40 allows remote attackers to cause a denial of service (CodeMeter.exe crash) via certain crafted packets to TCP port 22350.

    Published: 13 Jan 2012
    4.4
    Medium

    CVE-2011-2776

    Last Modified: 11 Apr 2025

    Buffer overflow in the Error function in super.c in Super 3.30.0 might allow local users to execute arbitrary code via vectors related to syslog logging. NOTE: some of these details are obtained from third party information.

    Published: 13 Jan 2012
    3.3
    Low

    CVE-2011-4114

    Last Modified: 11 Apr 2025

    The par_mktmpdir function in the PAR::Packer module before 1.012 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program. NOTE: a similar vulnerability was reported for PAR, but this has been assigned a different CVE identifier.

    Published: 13 Jan 2012
    4.9
    Medium

    CVE-2012-0030

    Last Modified: 11 Apr 2025

    Nova 2011.3 and Essex, when using the OpenStack API, allows remote authenticated users to bypass access restrictions for tenants of other users via an OSAPI request with a modified project_id URI parameter.

    Published: 13 Jan 2012
    10
    Critical

    CVE-2011-4789

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in magentservice.exe in the server in HP LoadRunner 11.00 before patch 4 allows remote attackers to execute arbitrary code via a crafted size value in a packet. NOTE: it was originally reported that the affected product is HP Diagnostics Server, but HP states that "the vulnerable product is actually HP LoadRunner."

    Published: 13 Jan 2012
    4.9
    Medium

    CVE-2011-4925

    Last Modified: 11 Apr 2025

    Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 2.5.9, when munge authentication is used, allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors.

    Published: 13 Jan 2012
    4.3
    Medium

    CVE-2012-0309

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cogent DataHub 7.1.2 and earlier, Cascade DataHub 6.4.20 and earlier, and OPC DataHub 6.4.20 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 13 Jan 2012
    5.8
    Medium

    CVE-2012-0310

    Last Modified: 11 Apr 2025

    CRLF injection vulnerability in Cogent DataHub 7.1.2 and earlier, Cascade DataHub 6.4.20 and earlier, and OPC DataHub 6.4.20 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

    Published: 13 Jan 2012
    4.3
    Medium

    CVE-2012-0696

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Executive Viewer (EV) in IBM Cognos TM1 before 9.5 FP1 allow remote attackers to inject arbitrary web script or HTML via unspecified requests to (1) aspnet_client or (2) evserver/createcontrol.js.

    Published: 13 Jan 2012
    7.8
    High

    CVE-2011-4788

    Last Modified: 11 Apr 2025

    Absolute path traversal vulnerability in the web interface on HP StorageWorks P2000 G3 MSA array systems allows remote attackers to read arbitrary files via a pathname in the URI.

    Published: 13 Jan 2012
    10
    Critical

    CVE-2012-0697

    Last Modified: 11 Apr 2025

    HP StorageWorks P2000 G3 MSA array systems have a default account, which makes it easier for remote attackers to perform administrative tasks via unspecified vectors, a different vulnerability than CVE-2011-4788.

    Published: 13 Jan 2012
    5
    Medium

    CVE-2012-0698

    Last Modified: 11 Apr 2025

    tcsd in TrouSerS before 0.3.10 allows remote attackers to cause a denial of service (daemon crash) via a crafted type_offset value in a TCP packet to port 30003.

    Published: 13 Jan 2012
    9.3
    Critical

    CVE-2011-4786

    Last Modified: 11 Apr 2025

    A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via unspecified vectors, a different vulnerability than CVE-2011-2404 and CVE-2011-4787.

    Published: 12 Jan 2012
    9.3
    Critical

    CVE-2011-4787

    Last Modified: 11 Apr 2025

    A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via unspecified vectors, a different vulnerability than CVE-2011-2404 and CVE-2011-4786.

    Published: 12 Jan 2012
    10
    Critical

    CVE-2012-0695

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 17.0.963.27 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.

    Published: 12 Jan 2012
    6.1
    Medium

    CVE-2011-4868

    Last Modified: 11 Apr 2025

    The logging functionality in dhcpd in ISC DHCP before 4.2.3-P2, when using Dynamic DNS (DDNS) and issuing IPv6 addresses, does not properly handle the DHCPv6 lease structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted packets related to a lease-status update.

    Published: 12 Jan 2012
    4.6
    Medium

    CVE-2012-0065

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the receive_packet function in libusbmuxd/libusbmuxd.c in usbmuxd 1.0.5 through 1.0.7 allows physically proximate attackers to execute arbitrary code via a long SerialNumber field in a property list.

    Published: 12 Jan 2012
    Unknown

    CVE-2012-0653

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 12 Jan 2012
    Unknown

    CVE-2012-0673

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 12 Jan 2012
    6.4
    Medium

    CVE-2012-0057

    Last Modified: 11 Apr 2025

    PHP before 5.3.9 has improper libxslt security settings, which allows remote attackers to create arbitrary files via a crafted XSLT stylesheet that uses the libxslt output extension.

    Published: 11 Jan 2012
    4.6
    Medium

    CVE-2012-0031

    Last Modified: 11 Apr 2025

    scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, leading to an invalid call to the free function.

    Published: 11 Jan 2012
    5
    Medium

    CVE-2012-0789

    Last Modified: 11 Apr 2025

    Memory leak in the timezone functionality in PHP before 5.3.9 allows remote attackers to cause a denial of service (memory consumption) by triggering many strtotime function calls, which are not properly handled by the php_date_parse_tzfile cache.

    Published: 11 Jan 2012
    5
    Medium

    CVE-2012-0788

    Last Modified: 11 Apr 2025

    The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of service (application crash) via a crafted application that uses a PDO driver for a fetch and then calls the session_start function, as demonstrated by a crash of the Apache HTTP Server.

    Published: 11 Jan 2012
    6.4
    Medium

    CVE-2011-5058

    Last Modified: 11 Apr 2025

    The CmbWebserver.dll module of the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to create arbitrary directories under the web root by specifying a non-existent directory using \ (backslash) characters in an HTTP GET request.

    Published: 10 Jan 2012
    10
    Critical

    CVE-2011-5059

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Final Draft 8 before 8.02 allows remote attackers to execute arbitrary code via a crafted SmartType element, a different vulnerability than CVE-2011-5002. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Jan 2012
    7.5
    High

    CVE-2011-4370

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-4372 and CVE-2011-4373.

    Published: 10 Jan 2012
    9.8
    Critical

    CVE-2011-4373

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-4370 and CVE-2011-4372.

    Published: 10 Jan 2012
    9.3
    Critical

    CVE-2012-0004

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in DirectShow in DirectX in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted media file, related to Quartz.dll, Qdvd.dll, closed captioning, and the Line21 DirectShow filter, aka "DirectShow Remote Code Execution Vulnerability."

    Published: 10 Jan 2012
    4.3
    Medium

    CVE-2012-0007

    Last Modified: 11 Apr 2025

    The Microsoft Anti-Cross Site Scripting (AntiXSS) Library 3.x and 4.0 does not properly evaluate characters after the detection of a Cascading Style Sheets (CSS) escaped character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML input, aka "AntiXSS Library Bypass Vulnerability."

    Published: 10 Jan 2012
    9.3
    Critical

    CVE-2012-0009

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in the Windows Object Packager configuration in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a Trojan horse executable file in the current working directory, as demonstrated by a directory that contains a file with an embedded packaged object, aka "Object Packager Insecure Executable Launching Vulnerability."

    Published: 10 Jan 2012
    9.8
    Critical

    CVE-2011-4372

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-4370 and CVE-2011-4373.

    Published: 10 Jan 2012
    9.3
    Critical

    CVE-2012-0013

    Last Modified: 11 Apr 2025

    Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted ClickOnce application in a Microsoft Office document, related to .application files, aka "Assembly Execution Vulnerability."

    Published: 10 Jan 2012