4.3
    Medium

    CVE-2012-4000

    Last Modified: 2 Jul 2015

    Cross-site scripting (XSS) vulnerability in the print_textinputs_var function in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php in FCKeditor 2.6.7 and earlier allows remote attackers to inject arbitrary web script or HTML via textinputs array parameters.

    Source:Emilio Pinna
    Published:12 Jul 2012
    5
    Medium

    CVE-2012-3996

    Last Modified: 13 Aug 2012

    TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (1) admin/include_calendar.php, (2) tiki-rss_error.php, or (3) tiki-watershed_service.php.

    Source:EgiX
    Published:12 Jul 2012
    9.3
    Critical

    CVE-2012-3993

    Last Modified: 1 Apr 2017

    The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not properly interact with failures of InstallTrigger methods, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site, related to an "XrayWrapper pollution" issue.

    Source:Metasploit
    Published:9 Oct 2012
    7.5
    High

    CVE-2012-3953

    Last Modified: 24 Jan 2017

    SQL injection vulnerability in admin/index.php in phpList before 2.10.19 allows remote administrators to execute arbitrary SQL commands via the delete parameter to the editattributes page.

    Source:High-Tech Bridge SA
    Published:12 Aug 2012
    2.6
    Low

    CVE-2012-3952

    Last Modified: 13 Jul 2015

    Cross-site scripting (XSS) vulnerability in admin/index.php in phpList before 2.10.19 allows remote attackers to inject arbitrary web script or HTML via the unconfirmed parameter to the user page.

    Source:High-Tech Bridge SA
    Published:12 Aug 2012
    7.5
    High

    CVE-2012-3951

    Last Modified: 8 Aug 2012

    The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (1) scrutinizer and (2) scrutremote accounts, which allows remote attackers to execute arbitrary SQL commands via a TCP session.

    Source:Metasploit
    Published:31 Jul 2012
    6.5
    Medium

    CVE-2012-3873

    Last Modified: 8 Aug 2012

    Multiple SQL injection vulnerabilities in Open Constructor 3.12.0 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) data/gallery/edit.php, (2) data/guestbook/edit.php, (3) data/file/edit.php, (4) data/htmltext/edit.php, (5) data/publication/edit.php, or (6) data/event/edit.php.

    Source:Lorenzo Cantoni
    Published:28 Dec 2012
    4.3
    Medium

    CVE-2012-3872

    Last Modified: 13 Jul 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Open Constructor 3.12.0 allow remote attackers to inject arbitrary web script or HTML via (1) the result parameter to data/file/edit.php, (2) the q parameter to confirm.php, or (3) the keyword parameter to users/users.php.

    Source:Lorenzo Cantoni
    Published:28 Dec 2012
    10
    Critical

    CVE-2012-3859

    Last Modified: 17 Sept 2012

    Unspecified vulnerability in the WebAdmin Portal in Netsweeper has unknown impact and attack vectors, a different vulnerability than CVE-2012-2446 and CVE-2012-2447.

    Source:Jacob Holcomb
    Published:9 Jul 2012
    4.3
    Medium

    CVE-2012-3848

    Last Modified: 10 Jul 2015

    Multiple cross-site scripting (XSS) vulnerabilities in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to d4d/exporters.php, (2) the HTTP Referer header to d4d/exporters.php, or (3) unspecified input to d4d/contextMenu.php.

    Source:Mario Ceballos
    Published:31 Jul 2012
    5
    Medium

    CVE-2012-3845

    Last Modified: 2 May 2012

    Buffer overflow in LAN Messenger 1.2.28 and earlier allows remote attackers to cause a denial of service (crash) via a long string in an initiation request.

    Source:Julien Ahrens
    Published:3 Jul 2012
    4.3
    Medium

    CVE-2012-3840

    Last Modified: 13 Aug 2012

    Multiple cross-site scripting (XSS) vulnerabilities in index.php/users/form/user_id in MyClientBase 0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) first_name or (2) last_name parameters.

    Source:Vulnerability-Lab
    Published:3 Jul 2012
    7.5
    High

    CVE-2012-3839

    Last Modified: 13 Aug 2012

    Multiple SQL injection vulnerabilities in application/core/MY_Model.php in MyClientBase 0.12 allow remote attackers to execute arbitrary SQL commands via the (1) invoice_number or (2) tags parameter to index.php/invoice_search.

    Source:Vulnerability-Lab
    Published:3 Jul 2012
    5
    Medium

    CVE-2012-3838

    Last Modified: 3 May 2012

    Gekko before 1.2.0 allows remote attackers to obtain the installation path via a direct request to (1) admin/templates/babygekko/index.php or (2) templates/html5demo/index.php.

    Source:LiquidWorm
    Published:3 Jul 2012
    4.3
    Medium

    CVE-2012-3837

    Last Modified: 3 May 2012

    Multiple cross-site scripting (XSS) vulnerabilities in apps/users/registration.template.php in Baby Gekko 1.2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) email_address, (3) password, (4) password_verify, (5) firstname, (6) lastname, or (7) verification_code parameter to users/action/register. NOTE: some of these details are obtained from third party information.

    Source:LiquidWorm
    Published:3 Jul 2012
    4.3
    Medium

    CVE-2012-3836

    Last Modified: 3 May 2012

    Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko before 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) groupname parameter in a savecategory in the users module; (2) virtual_filename, (3) branch, (4) contact_person, (5) street, (6) city, (7) province, (8) postal, (9) country, (10) tollfree, (11) phone, (12) fax, or (13) mobile parameter in a saveitem action in the contacts module; (14) title parameter in a savecategory action in the menus module; (15) firstname or (16) lastname in a saveitem action in the users module; (17) meta_key or (18) meta_description in a saveitem action in the blog module; or (19) the PATH_INFO to admin/index.php.

    Source:LiquidWorm
    Published:3 Jul 2012
    4.3
    Medium

    CVE-2012-3835

    Last Modified: 18 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to top.php or (2) time[0][0] parameter to forensics/base_qry_main.php, which is not properly handled in an error page.

    Source:Stefan Schurtz
    Published:3 Jul 2012
    6.5
    Medium

    CVE-2012-3834

    Last Modified: 18 Dec 2016

    SQL injection vulnerability in forensics/base_qry_main.php in AlienVault Open Source Security Information Management (OSSIM) 3.1 allows remote authenticated users to execute arbitrary SQL commands via the time[0][0] parameter.

    Source:Stefan Schurtz
    Published:3 Jul 2012
    4.3
    Medium

    CVE-2012-3831

    Last Modified: 2 May 2012

    Cross-site scripting (XSS) vulnerability in decoda/templates/video.php in Decoda before 3.3.1 allows remote attackers to inject arbitrary web script or HTML via multiple URLs in an img tag.

    Source:RedTeam Pentesting
    Published:3 Jul 2012
    4.3
    Medium

    CVE-2012-3830

    Last Modified: 2 May 2012

    Cross-site scripting (XSS) vulnerability in decoda/templates/video.php in Decoda before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via the video directive.

    Source:RedTeam Pentesting
    Published:3 Jul 2012
    3.3
    Low

    CVE-2012-3826

    Last Modified: 12 Nov 2016

    Multiple integer underflows in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allow remote attackers to cause a denial of service (loop) via vectors related to the R3 dissector, a different vulnerability than CVE-2012-2392.

    Source:Laurent Butti
    Published:16 Apr 2012
    3.3
    Low

    CVE-2012-3825

    Last Modified: 12 Nov 2016

    Multiple integer overflows in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allow remote attackers to cause a denial of service (infinite loop) via vectors related to the (1) BACapp and (2) Bluetooth HCI dissectors, a different vulnerability than CVE-2012-2392.

    Source:Laurent Butti
    Published:16 Apr 2012
    5
    Medium

    CVE-2012-3819

    Last Modified: 21 Aug 2015

    Stack consumption vulnerability in dartwebserver.dll 1.9 and earlier, as used in Dart PowerTCP WebServer for ActiveX and other products, allows remote attackers to cause a denial of service (daemon crash) via a long request.

    Source:catatonicprime
    Published:4 Oct 2012
    7.8
    High

    CVE-2012-3816

    Last Modified: 29 May 2012

    WinRadius Server 2009 allows remote attackers to cause a denial of service (crash) via a long password in an Access-Request packet.

    Source:demonalex
    Published:27 Jun 2012
    9.3
    Critical

    CVE-2012-3815

    Last Modified: 27 Jun 2012

    Buffer overflow in RunTime.exe in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 46824. NOTE: some of these details are obtained from third party information.

    Source:Luigi Auriemma
    Published:27 Jun 2012
    7.5
    High

    CVE-2012-3814

    Last Modified: 6 Jun 2012

    Unrestricted file upload vulnerability in font-upload.php in the Font Uploader plugin 1.2.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file with a .php.ttf extension, then accessing it via a direct request to the file in font-uploader/fonts.

    Source:Sammy FORGIT
    Published:27 Jun 2012
    10
    Critical

    CVE-2012-3811

    Last Modified: 10 Oct 2017

    Unrestricted file upload vulnerability in ImageUpload.ashx in the Wallboard application in Avaya IP Office Customer Call Reporter 7.0 before 7.0.5.8 Q1 2012 Maintenance Release and 8.0 before 8.0.9.13 Q1 2012 Maintenance Release allows remote attackers to execute arbitrary code by uploading an executable file and then accessing it via a direct request.

    Source:Metasploit
    Published:3 Jul 2012
    7.5
    High

    CVE-2012-3810

    Last Modified: 16 Oct 2012

    Samsung Kies before 2.5.0.12094_27_11 has registry modification.

    Source:High-Tech Bridge SA
    Published:9 Jan 2020
    7.5
    High

    CVE-2012-3809

    Last Modified: 16 Oct 2012

    Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification.

    Source:High-Tech Bridge SA
    Published:9 Jan 2020
    7.5
    High

    CVE-2012-3808

    Last Modified: 16 Oct 2012

    Samsung Kies before 2.5.0.12094_27_11 has arbitrary file modification.

    Source:High-Tech Bridge SA
    Published:9 Jan 2020
    9.8
    Critical

    CVE-2012-3807

    Last Modified: 16 Oct 2012

    Samsung Kies before 2.5.0.12094_27_11 has arbitrary file execution.

    Source:High-Tech Bridge SA
    Published:9 Jan 2020
    4.3
    Medium

    CVE-2012-3805

    Last Modified: 6 Jul 2015

    Multiple cross-site scripting (XSS) vulnerabilities in the getAllPassedParams function in system/functions.php in Kajona before 3.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) absender_name, (2) absender_email, or (3) absender_nachricht parameter to the content page; (4) comment_name, (5) comment_subject, or (6) comment_message parameter to the postacomment module; (7) module parameter to index.php; (8) action parameter to the admin login page; (9) pv or (10) pe parameter in a list action to the user module; (11) user_username, (12) user_email, (13) user_forename, (14) user_name, (15) user_street, (16) user_postal, (17) user_city, (18) user_tel, or (19) user_mobil parameter in a newUser action to the user module; (20) group_name or (21) group_desc parameter in a groupNew action to the user module; (22) name, (23) browsername, (24) seostring, (25) keywords, or (26) folder_id parameter in a newPage action to the pages module; (27) element_name or (28) element_cachetime parameter in a newElement action in the pages module; (29) aspect_name parameter in a newAspect action in the system module; (30) filemanager_name, (31) filemanager_path, (32) filemanager_upload_filter, or (33) filemanager_view_filter parameter in a NewRepo action to the filemanager module; or (34) archive_title or (35) archive_path parameter in a newArchive action to the downloads module. NOTE: some of these details are obtained from third party information.

    Source:High-Tech Bridge SA
    Published:12 Jul 2012
    10
    Critical

    CVE-2012-3797

    Last Modified: 2 Jan 2014

    Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, does not properly check packet sizes before reusing packet memory buffers, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a short crafted packet with a certain opcode.

    Source:Luigi Auriemma
    Published:25 Jun 2012
    5
    Medium

    CVE-2012-3796

    Last Modified: 2 Jan 2014

    Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to obtain sensitive information from daemon memory via a crafted packet with a certain opcode.

    Source:Luigi Auriemma
    Published:25 Jun 2012
    5
    Medium

    CVE-2012-3795

    Last Modified: 2 Jan 2014

    Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (daemon crash) via a crafted packet with a certain opcode and a large value in a size field.

    Source:Luigi Auriemma
    Published:25 Jun 2012
    5
    Medium

    CVE-2012-3794

    Last Modified: 2 Jan 2014

    Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (unhandled exception and daemon crash) via a crafted packet with a certain opcode that triggers an invalid attempt to allocate a large amount of memory.

    Source:Luigi Auriemma
    Published:25 Jun 2012
    5
    Medium

    CVE-2012-3793

    Last Modified: 2 Jan 2014

    Integer overflow in Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (daemon crash) via a crafted packet with a certain opcode that triggers an incorrect memory allocation and a buffer overflow.

    Source:Luigi Auriemma
    Published:25 Jun 2012
    5
    Medium

    CVE-2012-3792

    Last Modified: 2 Jan 2014

    Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (out-of-bounds read operation) via a crafted packet that triggers a certain Find Node check attempt.

    Source:Luigi Auriemma
    Published:25 Jun 2012
    7.5
    High

    CVE-2012-3791

    Last Modified: 31 May 2012

    Multiple SQL injection vulnerabilities in Simple Web Content Management System 1.1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) item_delete.php, (2) item_status.php, (3) item_detail.php, (4) item_modify.php, or (5) item_position.php in admin/; or (6) status parameter to admin/item_status.php.

    Source:loneferret
    Published:21 Jun 2012
    9.3
    Critical

    CVE-2012-3755

    Last Modified: 20 Nov 2012

    Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Targa image.

    Source:Senator of Pirates
    Published:9 Nov 2012
    9.3
    Critical

    CVE-2012-3753

    Last Modified: 28 Nov 2012

    Buffer overflow in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MIME type.

    Source:Metasploit
    Published:9 Nov 2012
    9.3
    Critical

    CVE-2012-3752

    Last Modified: 24 Nov 2012

    Multiple buffer overflows in Apple QuickTime before 7.7.3 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted style element in a QuickTime TeXML file.

    Source:Metasploit
    Published:9 Nov 2012
    5.1
    Medium

    CVE-2012-3748

    Last Modified: 4 Sept 2013

    Race condition in WebKit in Apple iOS before 6.0.1 and Safari before 6.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript arrays.

    Source:Vitaliy Toropov
    Published:3 Nov 2012
    7.5
    High

    CVE-2012-3716

    Last Modified: 11 Apr 2025

    CoreText in Apple Mac OS X 10.7.x before 10.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write or read) via a crafted text glyph.

    Published:20 Sept 2012
    5
    Medium

    CVE-2012-3588

    Last Modified: 8 Jun 2012

    Directory traversal vulnerability in preview.php in the Plugin Newsletter plugin 1.5 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the data parameter.

    Source:Sammy FORGIT
    Published:19 Jun 2012
    9.3
    Critical

    CVE-2012-3585

    Last Modified: 31 Oct 2016

    Heap-based buffer overflow in jpeg_ls.dll in the Jpeg_LS (aka JLS) plugin in the formats plugins in IrfanView PlugIns before 4.34 allows remote attackers to execute arbitrary code via a crafted JLS file.

    Source:Joseph Sheridan
    Published:5 Jul 2012
    7.9
    High

    CVE-2012-3579

    Last Modified: 2 Jan 2014

    Symantec Messaging Gateway (SMG) before 10.0 has a default password for an unspecified account, which makes it easier for remote attackers to obtain privileged access via an SSH session.

    Source:Metasploit
    Published:29 Aug 2012
    6.8
    Medium

    CVE-2012-3578

    Last Modified: 25 Jun 2015

    Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.1 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with a file with an executable extension followed by a safe extension, then accessing it via a direct request to the file in html/images.

    Source:Sammy FORGIT
    Published:17 Jun 2012
    7.5
    High

    CVE-2012-3577

    Last Modified: 24 Jun 2015

    Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/user_uploads.

    Source:Sammy FORGIT
    Published:17 Jun 2012
    10
    Critical

    CVE-2012-3576

    Last Modified: 8 Jun 2012

    Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/wpstorecart.

    Source:Sammy FORGIT
    Published:16 Jun 2012