5
    Medium

    CVE-2012-5067

    Last Modified: 13 Nov 2012

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Deployment.

    Source:Metasploit
    Published:16 Oct 2012
    7.8
    High

    CVE-2012-5049

    Last Modified: 14 Nov 2011

    APIFTP Server in Optimalog Optima PLC 1.5.2 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

    Source:Luigi Auriemma
    Published:28 Sept 2012
    7.8
    High

    CVE-2012-5048

    Last Modified: 14 Nov 2011

    APIFTP Server in Optimalog Optima PLC 1.5.2 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted packet.

    Source:Luigi Auriemma
    Published:28 Sept 2012
    6.8
    Medium

    CVE-2012-5005

    Last Modified: 26 Jan 2012

    Cross-site request forgery (CSRF) vulnerability in admin/admin_options.php in VR GPub 4.0 allows remote attackers to hijack the authentication of admins for requests that add admin accounts via an add action.

    Source:Cyber-Crystal
    Published:19 Sept 2012
    6.8
    Medium

    CVE-2012-5002

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file name option is enabled, allows remote attackers to execute arbitrary code via a long USER FTP command.

    Source:Julien Ahrens
    Published:19 Sept 2012
    7.5
    High

    CVE-2012-5000

    Last Modified: 4 Mar 2012

    SQL injection vulnerability in jokes/index.php in the Witze addon 0.9 for deV!L'z Clanportal allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action.

    Source:Easy Laster
    Published:19 Sept 2012
    6.1
    Medium

    CVE-2012-4999

    Last Modified: 30 Apr 2015

    Mercury MR804 Router 8.0 3.8.1 Build 101220 Rel.53006nB allows remote attackers to cause a denial of service (service hang) via a crafted string in HTTP header fields such as (1) If-Modified-Since, (2) If-None-Match, or (3) If-Unmodified-Since. NOTE: some of these details are obtained from third party information.

    Source:demonalex
    Published:19 Sept 2012
    4.3
    Medium

    CVE-2012-4998

    Last Modified: 4 May 2015

    Cross-site scripting (XSS) vulnerability in index.php in starCMS allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Source:Am!r
    Published:19 Sept 2012
    7.5
    High

    CVE-2012-4997

    Last Modified: 16 Mar 2012

    Directory traversal vulnerability in acp/index.php in AneCMS allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter.

    Source:I2sec-Jong Hwan Park
    Published:19 Sept 2012
    7.5
    High

    CVE-2012-4996

    Last Modified: 16 Mar 2012

    Multiple SQL injection vulnerabilities in RivetTracker 1.03 and earlier allow remote attackers to execute arbitrary SQL commands via the hash parameter to (1) dltorrent.php or (2) torrent_functions.php.

    Source:Ali Raheem
    Published:19 Sept 2012
    7.5
    High

    CVE-2012-4993

    Last Modified: 16 Mar 2012

    torrent_functions.php in RivetTracker 1.03 and earlier does not properly restrict access, which allows remote attackers to have an unspecified impact.

    Source:Ali Raheem
    Published:19 Sept 2012
    9
    Critical

    CVE-2012-4992

    Last Modified: 3 Mar 2012

    Multiple buffer overflows in FlashFXP.exe in FlashFXP 4.2 allow remote authenticated users to execute arbitrary code via a long unicode string to (1) TListbox or (2) TComboBox.

    Source:Vulnerability-Lab
    Published:19 Sept 2012
    8.5
    High

    CVE-2012-4991

    Last Modified: 12 Dec 2012

    Multiple directory traversal vulnerabilities in Axway SecureTransport 5.1 SP2 and earlier allow remote authenticated users to (1) read, (2) delete, or (3) create files, or (4) list directories, via a ..%5C (encoded dot dot backslash) in a URI.

    Source:Sebastian Perez
    Published:13 Dec 2012
    4.3
    Medium

    CVE-2012-4989

    Last Modified: 23 Dec 2016

    Cross-site scripting (XSS) vulnerability in admin/plugin-index.php in OpenX 2.8.10 before revision 81823 allows remote attackers to inject arbitrary web script or HTML via the parent parameter in an info action.

    Source:High-Tech Bridge
    Published:22 Oct 2012
    9.3
    Critical

    CVE-2012-4988

    Last Modified: 4 Oct 2012

    Heap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99.1 allows remote attackers to execute arbitrary code via a crafted JLS image file.

    Source:Joseph Sheridan
    Published:9 Jul 2014
    5.8
    Medium

    CVE-2012-4982

    Last Modified: 2 Sept 2015

    Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the a parameter.

    Source:Joseph Sheridan
    Published:5 Dec 2012
    8.1
    High

    CVE-2012-4969

    Last Modified: 10 Oct 2012

    Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in September 2012.

    Source:Metasploit
    Published:18 Sept 2012
    6.5
    Medium

    CVE-2012-4960

    Last Modified: 30 Aug 2015

    The Huawei NE5000E, MA5200G, NE40E, NE80E, ATN, NE40, NE80, NE20E-X6, NE20, ME60, CX600, CX200, CX300, ACU, WLAN AC 6605, S9300, S7700, S2300, S3300, S5300, S3300HI, S5300HI, S5306, S6300, S2700, S3700, S5700, S6700, AR G3, H3C AR(OEM IN), AR 19, AR 29, AR 49, Eudemon100E, Eudemon200, Eudemon300, Eudemon500, Eudemon1000, Eudemon1000E-U/USG5300, Eudemon1000E-X/USG5500, Eudemon8080E/USG9300, Eudemon8160E/USG9300, Eudemon8000E-X/USG9500, E200E-C/USG2200, E200E-X3/USG2200, E200E-X5/USG2200, E200E-X7/USG2200, E200E-C/USG5100, E200E-X3/USG5100, E200E-X5/USG5100, E200E-X7/USG5100, E200E-B/USG2100, E200E-X1/USG2100, E200E-X2/USG2100, SVN5300, SVN2000, SVN5000, SVN3000, NIP100, NIP200, NIP1000, NIP2100, NIP2200, and NIP5100 use the DES algorithm for stored passwords, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.

    Source:Roberto Paleari
    Published:20 Jun 2013
    10
    Critical

    CVE-2012-4959

    Last Modified: 27 Oct 2016

    Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and execute files via a 130 /FSF/CMD request with a .. (dot dot) in a FILE element of an FSFUI record.

    Source:Abysssec
    Published:18 Nov 2012
    7.8
    High

    CVE-2012-4958

    Last Modified: 27 Oct 2016

    Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a 126 /FSF/CMD request with a .. (dot dot) in a FILE element of an FSFUI record.

    Source:Abysssec
    Published:18 Nov 2012
    7.8
    High

    CVE-2012-4957

    Last Modified: 27 Oct 2016

    Absolute path traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a /FSF/CMD request with a full pathname in a PATH element of an SRS record.

    Source:Abysssec
    Published:18 Nov 2012
    7.5
    High

    CVE-2012-4951

    Last Modified: 29 Aug 2015

    Multiple SQL injection vulnerabilities in terminal/paramedit.aspx in VeriFone VeriCentre Web Console before 2.2 build 36 allow remote attackers to execute arbitrary SQL commands via the (1) TerminalId, (2) ModelName, or (3) ApplicationName parameter.

    Source:Cory Eubanks
    Published:15 Nov 2012
    6.5
    Medium

    CVE-2012-4949

    Last Modified: 9 Nov 2017

    SQL injection vulnerability in ESRI ArcGIS 10.1 allows remote authenticated users to execute arbitrary SQL commands via the where parameter to a query URI for a REST service.

    Source:anonymous
    Published:14 Nov 2012
    6.4
    Medium

    CVE-2012-4940

    Last Modified: 28 Aug 2015

    Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote attackers to read or delete arbitrary files via a .. (dot dot) in (1) the fileName parameter in a download action to source/loggin/page_log_dwn_file.hsp, or the fileName parameter in (2) an edit action or (3) a delete action to the default URI.

    Source:Zhao Liang
    Published:31 Oct 2012
    4.3
    Medium

    CVE-2012-4939

    Last Modified: 24 Jan 2017

    Cross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface before 3.0-HotFix1 in SolarWinds Orion Network Performance Monitor might allow remote attackers to inject arbitrary web script or HTML via the "Search for an IP address" field.

    Source:Anthony Trummer
    Published:31 Oct 2012
    4.3
    Medium

    CVE-2012-4932

    Last Modified: 9 Sept 2015

    Multiple cross-site scripting (XSS) vulnerabilities in SimpleInvoices before stable-2012-1-CIS3000 allow remote attackers to inject arbitrary web script or HTML via (1) the having parameter in a manage action to index.php; (2) the Email field in an Add User action; (3) the Customer Name field in an Add Customer action; the (4) Street address, (5) Street address 2, (6) City, (7) Zip code, (8) State, (9) Country, (10) Mobile Phone, (11) Phone, (12) Fax, (13) Email, (14) PayPal business name, (15) PayPal notify url, (16) PayPal return url, (17) Eway customer ID, (18) Custom field 1, (19) Custom field 2, (20) Custom field 3, or (21) Custom field 4 field in an Add Biller action; (22) the Customer field in an Add Invoice action; the (23) Invoice or (24) Notes field in a Process Payment action; (25) the Payment type description field in a Payment Types action; (26) the Description field in an Invoice Preferences action; (27) the Description field in a Manage Products action; or (28) the Description field in a Tax Rates action.

    Source:tommccredie
    Published:28 Dec 2012
    2.6
    Low

    CVE-2012-4929

    Last Modified: 11 Apr 2025

    The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.

    Published:13 Sept 2012
    4.3
    Medium

    CVE-2012-4928

    Last Modified: 1 May 2015

    Cross-site scripting (XSS) vulnerability in ow_updates/index.php in Oxwall 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the plugin parameter.

    Source:Ariko-Security
    Published:15 Sept 2012
    7.5
    High

    CVE-2012-4927

    Last Modified: 22 Feb 2012

    SQL injection vulnerability in Limesurvey (a.k.a PHPSurveyor) before 1.91+ Build 120224 and earlier allows remote attackers to execute arbitrary SQL commands via the fieldnames parameter to index.php.

    Source:TorTukiTu
    Published:15 Sept 2012
    6.4
    Medium

    CVE-2012-4926

    Last Modified: 29 Feb 2012

    approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activation of administrators via the u parameter in an (1) app0 (disable) or (2) app1 (enable) action.

    Source:CorryL
    Published:15 Sept 2012
    7.5
    High

    CVE-2012-4925

    Last Modified: 29 Feb 2012

    Multiple SQL injection vulnerabilities in approve.php in Img Pals Photo Host 1.0 allow remote attackers to execute arbitrary SQL commands via the u parameter in a (1) app0 or (2) app1 action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:CorryL
    Published:15 Sept 2012
    9.3
    Critical

    CVE-2012-4924

    Last Modified: 29 Feb 2012

    Buffer overflow in the CxDbgPrint function in the ipswcom.dll ActiveX component 1.0.0.1 for ASUS Net4Switch 1.0.0020 allows remote attackers to execute arbitrary code via a long parameter to the Alert method.

    Source:Metasploit
    Published:15 Sept 2012
    4.3
    Medium

    CVE-2012-4923

    Last Modified: 27 Apr 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Endian Firewall 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) createrule parameter to dnat.cgi, (2) addrule parameter to dansguardian.cgi, or (3) PATH_INFO to openvpn_users.cgi.

    Source:Vulnerability Research Laboratory
    Published:15 Sept 2012
    5
    Medium

    CVE-2012-4915

    Last Modified: 8 Jan 2013

    Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to libs/pdf.php.

    Source:Metasploit
    Published:29 May 2014
    9.3
    Critical

    CVE-2012-4914

    Last Modified: 8 Feb 2013

    Stack-based buffer overflow in the reader in CoolPDF 3.0.2.256 allows remote attackers to execute arbitrary code via a PDF document with a crafted stream.

    Source:Chris Gabriel
    Published:26 Jan 2013
    4.3
    Medium

    CVE-2012-4909

    Last Modified: 16 Aug 2015

    Google Chrome before 18.0.1025308 on Android allows remote attackers to obtain cookie information via a crafted application.

    Source:Artem Chaykin
    Published:13 Sept 2012
    7.5
    High

    CVE-2012-4908

    Last Modified: 16 Aug 2015

    Google Chrome before 18.0.1025308 on Android allows remote attackers to bypass the Same Origin Policy and obtain access to local files via vectors involving a symlink.

    Source:Artem Chaykin
    Published:13 Sept 2012
    5
    Medium

    CVE-2012-4906

    Last Modified: 16 Aug 2015

    Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by obtaining credential data, a different vulnerability than CVE-2012-4903.

    Source:Artem Chaykin
    Published:13 Sept 2012
    4.3
    Medium

    CVE-2012-4905

    Last Modified: 10 Oct 2016

    Cross-site scripting (XSS) vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inject arbitrary web script or HTML via an extra in an Intent object, aka "Universal XSS (UXSS)."

    Source:Artem Chaykin
    Published:13 Sept 2012
    6.8
    Medium

    CVE-2012-4902

    Last Modified: 4 Oct 2017

    Multiple cross-site request forgery (CSRF) vulnerabilities in Template CMS 2.1.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator user via an add action to admin/index.php or (2) conduct static PHP code injection attacks via the themes_editor parameter in an edit_template action to admin/index.php.

    Source:High-Tech Bridge SA
    Published:20 May 2015
    4.3
    Medium

    CVE-2012-4901

    Last Modified: 4 Oct 2017

    Cross-site scripting (XSS) vulnerability in Template CMS 2.1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the themes_editor parameter in an add_template action to admin/index.php.

    Source:High-Tech Bridge SA
    Published:20 May 2015
    4.3
    Medium

    CVE-2012-4891

    Last Modified: 29 Jan 2015

    Cross-site scripting (XSS) vulnerability in fw/index2.do in ManageEngine Firewall Analyzer 7.2 allows remote attackers to inject arbitrary web script or HTML via the url parameter, a different vector than CVE-2012-4889. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Ertebat Gostar Co
    Published:10 Sept 2012
    4.3
    Medium

    CVE-2012-4889

    Last Modified: 29 Jan 2015

    Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Firewall Analyzer 7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) subTab or (2) tab parameter to createAnomaly.do; (3) url, (4) subTab, or (5) tab parameter to mindex.do; (6) tab parameter to index2.do; or (7) port parameter to syslogViewer.do.

    Source:Ertebat Gostar Co
    Published:10 Sept 2012
    10
    Critical

    CVE-2012-4886

    Last Modified: 3 May 2013

    Stack-based buffer overflow in wpsio.dll in Kingsoft WPS Office 2012 possibly 8.1.0.3238 allows remote attackers to execute arbitrary code via a long BSTR string.

    Source:Zhangjiantao
    Published:24 Mar 2014
    5
    Medium

    CVE-2012-4878

    Last Modified: 5 Jan 2017

    Absolute path traversal vulnerability in controlcenter.php in FlatnuX CMS 2011 08.09.2 allows remote administrators to read arbitrary files via a full pathname in the dir parameter in a contents/Files action.

    Source:Vulnerability Laboratory
    Published:6 Sept 2012
    6.8
    Medium

    CVE-2012-4877

    Last Modified: 17 May 2015

    Cross-site request forgery (CSRF) vulnerability in controlcenter.php in FlatnuX CMS 2011 08.09.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that add user accounts.

    Source:Vulnerability Laboratory
    Published:6 Sept 2012
    10
    Critical

    CVE-2012-4876

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in the UltraMJCam ActiveX Control in TRENDnet SecurView TV-IP121WN Wireless Internet Camera allows remote attackers to execute arbitrary code via a long string to the OpenFileDlg method.

    Source:rgod
    Published:6 Sept 2012
    4.3
    Medium

    CVE-2012-4873

    Last Modified: 11 May 2015

    Cross-site scripting (XSS) vulnerability in the file_download function in GNUBoard before 4.34.21 allows remote attackers to inject arbitrary web script or HTML via the filename parameter.

    Source:wh1ant
    Published:6 Sept 2012
    4.3
    Medium

    CVE-2012-4871

    Last Modified: 23 Aug 2015

    Cross-site scripting (XSS) vulnerability in service/graph_html.php in the administrator panel in LiteSpeed Web Server 4.1.11 allows remote attackers to inject arbitrary web script or HTML via the gtitle parameter.

    Source:K1P0D
    Published:6 Sept 2012
    4.3
    Medium

    CVE-2012-4870

    Last Modified: 22 Mar 2012

    Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) context parameter to panel/index_amp.php or (2) panel/dhtml/index.php; (3) clid or (4) clidname parameters to panel/flash/mypage.php; (5) PATH_INFO to admin/views/freepbx_reload.php; or (6) login parameter to recordings/index.php.

    Source:Martin Tschirsich
    Published:6 Sept 2012