4.3
    Medium

    CVE-2012-1912

    Last Modified: 18 Dec 2016

    Cross-site scripting (XSS) vulnerability in preferences.php in PHP Address Book 7.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the from parameter. NOTE: the index.php vector is already covered by CVE-2008-2566.

    Source:Stefan Schurtz
    Published:9 Sept 2012
    7.5
    High

    CVE-2012-1911

    Last Modified: 18 Dec 2016

    Multiple SQL injection vulnerabilities in PHP Address Book 6.2.12 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) to_group parameter to group.php or (2) id parameter to vcard.php. NOTE: the edit.php vector is already covered by CVE-2008-2565.

    Source:Stefan Schurtz
    Published:9 Sept 2012
    4.3
    Medium

    CVE-2012-1904

    Last Modified: 24 Mar 2012

    mp4fformat.dll in the QuickTime File Format plugin in RealNetworks RealPlayer 15 and earlier, and RealPlayer SP 1.1.4 Build 12.0.0.756 and earlier, allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted MP4 file.

    Source:Senator of Pirates
    Published:28 Mar 2012
    6.8
    Medium

    CVE-2012-1901

    Last Modified: 17 Mar 2012

    Multiple cross-site request forgery (CSRF) vulnerabilities in FlexCMS 3.2.1 and earlier allow remote attackers to (1) hijack the authentication of users for requests that change account settings via a request to index.php/profile-edit-save or (2) hijack the authentication of administrators for requests that add a new page via a request to admin/pages-new-save.

    Source:Ivano Binetti
    Published:18 Sept 2012
    6.8
    Medium

    CVE-2012-1900

    Last Modified: 10 Mar 2012

    Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary web pages via a showcats action.

    Source:Ivano Binetti
    Published:22 Oct 2012
    4.3
    Medium

    CVE-2012-1898

    Last Modified: 23 Mar 2012

    Multiple cross-site scripting (XSS) vulnerabilities in wolfcms/admin/user/add in Wolf CMS 0.75 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user[name], (2) user[email], or (3) user[username] parameters.

    Source:Ivano Binetti
    Published:1 Oct 2012
    6.8
    Medium

    CVE-2012-1897

    Last Modified: 23 Mar 2012

    Multiple cross-site request forgery (CSRF) vulnerabilities in Wolf CMS 0.75 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) delete users via the user id number to admin/user/delete; (2) delete pages via the page id number to admin/page/delete; delete the (3) images or (4) themes directory via the directory name to admin/plugin/file_manager/delete, and possibly other directories; or (5) logout the user via a request to admin/login/logout.

    Source:Ivano Binetti
    Published:1 Oct 2012
    8.8
    High

    CVE-2012-1889

    Last Modified: 16 Jun 2012

    Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

    Source:Metasploit
    Published:13 Jun 2012
    9.3
    Critical

    CVE-2012-1876

    Last Modified: 2 Aug 2012

    Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access a nonexistent object, leading to a heap-based buffer overflow, aka "Col Element Remote Code Execution Vulnerability," as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.

    Source:Metasploit
    Published:12 Jun 2012
    9.3
    Critical

    CVE-2012-1875

    Last Modified: 14 Jun 2012

    Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Same ID Property Remote Code Execution Vulnerability."

    Source:Metasploit
    Published:12 Jun 2012
    4.3
    Medium

    CVE-2012-1870

    Last Modified: 11 Apr 2025

    The CBC mode in the TLS protocol, as used in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and other products, allows remote web servers to obtain plaintext data by triggering multiple requests to a third-party HTTPS server and sniffing the network during the resulting HTTPS session, aka "TLS Protocol Vulnerability."

    Published:10 Jul 2012
    4.3
    Medium

    CVE-2012-1858

    Last Modified: 12 Jul 2012

    The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document, aka "HTML Sanitization Vulnerability."

    Source:Adi Cohen
    Published:12 Jun 2012
    4.3
    Medium

    CVE-2012-1835

    Last Modified: 21 May 2015

    Multiple cross-site scripting (XSS) vulnerabilities in the All-in-One Event Calendar plugin 1.4 and 1.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to app/view/agenda-widget-form.php; (2) args, (3) title, (4) before_title, or (5) after_title parameter to app/view/agenda-widget.php; (6) button_value parameter to app/view/box_publish_button.php; or (7) msg parameter to /app/view/save_successful.php.

    Source:High-Tech Bridge SA
    Published:14 Aug 2012
    10
    Critical

    CVE-2012-1831

    Last Modified: 5 Jul 2012

    Heap-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 555.

    Source:Carlos Mario Penagos Hollmann
    Published:5 Jul 2012
    10
    Critical

    CVE-2012-1830

    Last Modified: 5 Jul 2012

    Stack-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 555.

    Source:Carlos Mario Penagos Hollmann
    Published:5 Jul 2012
    9.8
    Critical

    CVE-2012-1823

    Last Modified: 16 May 2014

    sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.

    Source:kingcope
    Published:3 May 2012
    8.5
    High

    CVE-2012-1803

    Last Modified: 24 Apr 2012

    RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the banner, which makes it easier for remote attackers to obtain access by performing a calculation on this address value, and then establishing a (1) TELNET, (2) remote shell (aka rsh), or (3) serial-console session.

    Source:jc
    Published:28 Apr 2012
    5
    Medium

    CVE-2012-1790

    Last Modified: 16 Mar 2012

    Absolute path traversal vulnerability in Webgrind 1.0 and 1.0.2 allows remote attackers to read arbitrary files via a full pathname in the file parameter to index.php.

    Source:LiquidWorm
    Published:19 Mar 2012
    4.3
    Medium

    CVE-2012-1787

    Last Modified: 1 May 2015

    Multiple cross-site scripting (XSS) vulnerabilities in wgarcmin.cgi in Webglimpse 2.20.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) URL, (2) FILE, or (3) DOMAIN parameters.

    Source:MustLive
    Published:19 Mar 2012
    7.5
    High

    CVE-2012-1784

    Last Modified: 1 May 2015

    SQL injection vulnerability in MyJobList 0.1.3 allows remote attackers to execute arbitrary SQL commands via the eid parameter in a profile action to index.php.

    Source:Red Security TEAM
    Published:19 Mar 2012
    7.8
    High

    CVE-2012-1783

    Last Modified: 16 Mar 2012

    Tiny Server 1.1.9 and earlier allows remote attackers to cause a denial of service (crash) via a long string in a GET request without an HTTP version number.

    Source:localh0t
    Published:19 Mar 2012
    4.3
    Medium

    CVE-2012-1782

    Last Modified: 2 May 2015

    Multiple cross-site scripting (XSS) vulnerabilities in questions/ask in OSQA 3b allow remote attackers to inject arbitrary web script or HTML via the (1) url bar or (2) picture bar.

    Source:Ucha Gobejishvili
    Published:19 Mar 2012
    7.5
    High

    CVE-2012-1778

    Last Modified: 24 Jan 2017

    SQL injection vulnerability in artykul_print.php in CreateVision CMS allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Zwierzchowski Oskar
    Published:19 Mar 2012
    9.3
    Critical

    CVE-2012-1775

    Last Modified: 15 Nov 2016

    Stack-based buffer overflow in VideoLAN VLC media player before 2.0.1 allows remote attackers to execute arbitrary code via a crafted MMS:// stream.

    Source:Metasploit
    Published:19 Mar 2012
    10
    Critical

    CVE-2012-1774

    Last Modified: 21 Apr 2015

    Unspecified vulnerability in the Open URL feature in Gretech GOM Media Player before 2.1.39.5101 has unknown impact and attack vectors, a different vulnerability than CVE-2007-5779 and CVE-2012-1264.

    Source:longrifle0x
    Published:18 Mar 2012
    2.1
    Low

    CVE-2012-1770

    Last Modified: 20 Jul 2012

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-1766, CVE-2012-1767, CVE-2012-1769, CVE-2012-1771, CVE-2012-1772, CVE-2012-1773, CVE-2012-3106, CVE-2012-3107, CVE-2012-3108, and CVE-2012-3110.

    Source:Francis Provencher
    Published:17 Jul 2012
    2.1
    Low

    CVE-2012-1769

    Last Modified: 20 Jul 2012

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-1766, CVE-2012-1767, CVE-2012-1770, CVE-2012-1771, CVE-2012-1772, CVE-2012-1773, CVE-2012-3106, CVE-2012-3107, CVE-2012-3108, and CVE-2012-3110.

    Source:Francis Provencher
    Published:17 Jul 2012
    2.1
    Low

    CVE-2012-1744

    Last Modified: 20 Jul 2012

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent users to affect availability via unknown vectors related to Outside In Filters.

    Source:Francis Provencher
    Published:17 Jul 2012
    9.8
    Critical

    CVE-2012-1723

    Last Modified: 11 Jul 2012

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

    Source:Metasploit
    Published:12 Jun 2012
    7.5
    High

    CVE-2012-1675

    Last Modified: 11 Apr 2025

    The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.0.5, as used in Oracle Fusion Middleware, Enterprise Manager, E-Business Suite, and possibly other products, allows remote attackers to execute arbitrary database commands by performing a remote registration of a database (1) instance or (2) service name that already exists, then conducting a man-in-the-middle (MITM) attack to hijack database connections, aka "TNS Poison."

    Published:8 May 2012
    7.5
    High

    CVE-2012-1673

    Last Modified: 4 Apr 2012

    SQL injection vulnerability in loginscript.php in e-ticketing allows remote attackers to execute arbitrary SQL commands via the password parameter.

    Source:Mark Stanislav
    Published:11 Apr 2012
    7.5
    High

    CVE-2012-1672

    Last Modified: 4 Apr 2012

    SQL injection vulnerability in getcity.php in Hotel Booking Portal 0.1 allows remote attackers to execute arbitrary SQL commands via the country parameter.

    Source:Mark Stanislav
    Published:11 Apr 2012
    6.8
    Medium

    CVE-2012-1671

    Last Modified: 4 Apr 2012

    Directory traversal vulnerability in index.php in phpPaleo 4.8b155 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

    Source:Mark Stanislav
    Published:8 Oct 2012
    5
    Medium

    CVE-2012-1670

    Last Modified: 22 Mar 2012

    admin/index.php in PHP Grade Book before 1.9.5 BETA allows remote attackers to read the database via a SaveSQL action.

    Source:Mark Stanislav
    Published:31 Mar 2012
    4.3
    Medium

    CVE-2012-1669

    Last Modified: 22 Mar 2012

    Directory traversal vulnerability in index.php in phpMoneyBooks before 1.0.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter.

    Source:Mark Stanislav
    Published:17 Nov 2014
    6.9
    Medium

    CVE-2012-1666

    Last Modified: 16 Aug 2015

    Untrusted search path vulnerability in VMware Tools in VMware Workstation before 8.0.4, VMware Player before 4.0.4, VMware Fusion before 4.1.2, VMware View before 5.1, and VMware ESX 4.1 before U3 and 5.0 before P03 allows local users to gain privileges via a Trojan horse tpfc.dll file in the current working directory.

    Source:Moshe Zioni
    Published:8 Sept 2012
    7.5
    High

    CVE-2012-1665

    Last Modified: 18 May 2015

    Multiple SQL injection vulnerabilities in the admin panel in osCMax before 2.5.1 allow (1) remote attackers to execute arbitrary SQL commands via the username parameter in a process action to admin/login.php or (2) remote administrators to execute arbitrary SQL commands via the status parameter to admin/stats_monthly_sales.php or (3) country parameter in a process action to admin/create_account_process.php.

    Source:High-Tech Bridge SA
    Published:20 May 2015
    4.3
    Medium

    CVE-2012-1664

    Last Modified: 18 May 2015

    Multiple cross-site scripting (XSS) vulnerabilities in the admin panel in osCMax before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter in a process action to admin/login.php; (2) pageTitle, (3) current_product_id, or (4) cPath parameter to admin/new_attributes_include.php; (5) sb_id, (6) sb_key, (7) gc_id, (8) gc_key, or (9) path parameter to admin/htaccess.php; (10) title parameter to admin/information_form.php; (11) search parameter to admin/xsell.php; (12) gross or (13) max parameter to admin/stats_products_purchased.php; (14) status parameter to admin/stats_monthly_sales.php; (15) sorted parameter to admin/stats_customers.php; (16) information_id parameter to /admin/information_manager.php; or (17) zID parameter to /admin/geo_zones.php.

    Source:High-Tech Bridge SA
    Published:20 May 2015
    7.5
    High

    CVE-2012-1663

    Last Modified: 22 Mar 2013

    Double free vulnerability in libgnutls in GnuTLS before 3.0.14 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted certificate list.

    Source:Shawn the R0ck
    Published:19 Feb 2012
    9.3
    Critical

    CVE-2012-1661

    Last Modified: 14 Jun 2012

    ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assisted remote attackers to execute arbitrary VBA code via a crafted map (.mxd) file.

    Source:Boston Cyber Defense
    Published:12 Jul 2012
    6.4
    Medium

    CVE-2012-1617

    Last Modified: 6 May 2015

    Directory traversal vulnerability in combine.php in OSClass before 2.3.6 allows remote attackers to read and write arbitrary files via a .. (dot dot) in the type parameter. NOTE: this vulnerability can be leveraged to upload arbitrary files.

    Source:Filippo Cavallarin
    Published:26 Sept 2012
    5
    Medium

    CVE-2012-1614

    Last Modified: 30 Mar 2012

    Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/index.php, an invalid (2) page or (3) cat parameter to thumbnails.php, an invalid (4) page parameter to usermgr.php, or an invalid (5) newer_than or (6) older_than parameter to search.inc.php, which reveals the installation path in an error message.

    Source:waraxe
    Published:4 Sept 2012
    3.5
    Low

    CVE-2012-1613

    Last Modified: 30 Mar 2012

    Cross-site scripting (XSS) vulnerability in edit_one_pic.php in Coppermine Photo Gallery before 1.5.20 allows remote authenticated users with certain privileges to inject arbitrary web script or HTML via the keywords parameter.

    Source:waraxe
    Published:4 Sept 2012
    4.3
    Medium

    CVE-2012-1604

    Last Modified: 14 May 2015

    Cross-site scripting (XSS) vulnerability in NextBBS 0.6 allows remote attackers to inject arbitrary web script or HTML via the do parameter to index.php.

    Source:waraxe
    Published:1 Oct 2012
    7.5
    High

    CVE-2012-1603

    Last Modified: 14 May 2015

    Multiple SQL injection vulnerabilities in ajaxserver.php in NextBBS 0.6 allow remote attackers to execute arbitrary SQL commands via the (1) curstr parameter in the findUsers function, (2) id parameter in the isIdAvailable function, or (3) username parameter in the getGreetings function.

    Source:waraxe
    Published:1 Oct 2012
    2.6
    Low

    CVE-2012-1597

    Last Modified: 4 Jan 2017

    Cross-site scripting (XSS) vulnerability in the textEncode function in classes/ezjscajaxcontent.php in eZ JS Core in eZ Publish before 1.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Source:Yann MICHARD
    Published:17 Aug 2012
    3.3
    Low

    CVE-2012-1593

    Last Modified: 12 Nov 2016

    epan/dissectors/packet-ansi_a.c in the ANSI A dissector in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed packet.

    Source:Wireshark
    Published:10 Feb 2012
    8.8
    High

    CVE-2012-1592

    Last Modified: 10 Oct 2016

    A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files.

    Source:voidloafer
    Published:22 Mar 2012
    2.1
    Low

    CVE-2012-1586

    Last Modified: 25 Apr 2012

    mount.cifs in cifs-utils 2.6 allows local users to determine the existence of arbitrary files or directories via the file path in the second argument, which reveals their existence in an error message.

    Source:Sha0
    Published:21 Mar 2012
    7.5
    High

    CVE-2012-1563

    Last Modified: 26 Jan 2017

    Joomla! before 2.5.3 allows Admin Account Creation.

    Source:Charles Fol
    Published:15 Jan 2020