9.3
    Critical

    CVE-2012-0985

    Last Modified: 31 May 2012

    Multiple buffer overflows in the Wireless Manager ActiveX control 4.0.0.0 in WifiMan.dll in Sony VAIO PC Wireless LAN Wizard 1.0; VAIO Wireless Wizard 1.00, 1.00_64, 1.0.1, 2.0, and 3.0; SmartWi Connection Utility 4.7, 4.7.4, 4.8, 4.9, 4.10, and 4.11; and VAIO Easy Connect software 1.0.0 and 1.1.0 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the second argument of the (1) SetTmpProfileOption or (2) ConnectToNetwork method.

    Source:High-Tech Bridge SA
    Published:7 Jun 2012
    4.3
    Medium

    CVE-2012-0984

    Last Modified: 24 May 2015

    Multiple cross-site scripting (XSS) vulnerabilities in XOOPS before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via the (1) to_userid parameter to modules/pm/pmlite.php or the (2) current_file, (3) imgcat_id, or (4) target parameter to class/xoopseditor/tinymce/tinymce/jscripts/tiny_mce/plugins/xoopsimagemanager/xoopsimagebrowser.php.

    Source:High-Tech Bridge SA
    Published:11 Sept 2014
    7.5
    High

    CVE-2012-0983

    Last Modified: 31 Jan 2012

    SQL injection vulnerability in Scriptsez.net Ez Album allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.

    Source:Red Security TEAM
    Published:2 Feb 2012
    7.5
    High

    CVE-2012-0982

    Last Modified: 31 Jan 2012

    SQL injection vulnerability in search.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the price_from parameter.

    Source:Cagri Tepebasili
    Published:2 Feb 2012
    5
    Medium

    CVE-2012-0981

    Last Modified: 31 Jan 2012

    Directory traversal vulnerability in phpShowtime 2.0 allows remote attackers to list arbitrary directories and image files via a .. (dot dot) in the r parameter to index.php. NOTE: Some of these details are obtained from third party information.

    Source:Red Security TEAM
    Published:2 Feb 2012
    7.5
    High

    CVE-2012-0980

    Last Modified: 6 May 2012

    SQL injection vulnerability in download.php in phux Download Manager allows remote attackers to execute arbitrary SQL commands via the file parameter.

    Source:Red Security TEAM
    Published:2 Feb 2012
    4.3
    Medium

    CVE-2012-0974

    Last Modified: 3 Apr 2015

    Multiple cross-site scripting (XSS) vulnerabilities in the getParam function in oc-includes/osclass/core/Params.php in OSClass before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) sCity, (2) sPattern, (3) sPriceMax, and (4) sPriceMin parameters in a search action to index.php.

    Source:High-Tech Bridge SA
    Published:25 Sept 2012
    7.5
    High

    CVE-2012-0973

    Last Modified: 3 Apr 2015

    Multiple SQL injection vulnerabilities in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the sCategory parameter to index.php, which is not properly handled by the (1) osc_search_category_id function in oc-includes/osclass/helpers/hSearch.php and (2) findBySlug function oc-includes/osclass/model/Category.php. NOTE: some of these details are obtained from third party information.

    Source:High-Tech Bridge SA
    Published:25 Sept 2012
    4.9
    Medium

    CVE-2012-0957

    Last Modified: 22 Aug 2015

    The override_release function in kernel/sys.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive information from kernel stack memory via a uname system call in conjunction with a UNAME26 personality.

    Source:Brad Spengler
    Published:9 Oct 2012
    4.6
    Medium

    CVE-2012-0946

    Last Modified: 2 Aug 2012

    The NVIDIA UNIX driver before 295.40 allows local users to access arbitrary memory locations by leveraging GPU device-node read/write privileges.

    Source:anonymous
    Published:22 Apr 2012
    2.1
    Low

    CVE-2012-0943

    Last Modified: 8 May 2015

    debian/guest-account in Light Display Manager (lightdm) 1.0.x before 1.0.6 and 1.1.x before 1.1.7, as used in Ubuntu Linux 11.10, allows local users to delete arbitrary files via a space in the name of a file in /tmp. NOTE: this identifier was SPLIT per ADT1/ADT2 due to different codebases and affected versions. CVE-2012-6648 has been assigned for the gdm-guest-session issue.

    Source:Ryan Lortie
    Published:22 May 2014
    5
    Medium

    CVE-2012-0937

    Last Modified: 4 May 2017

    wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not limit the number of MySQL queries sent to external MySQL database servers, which allows remote attackers to use WordPress as a proxy for brute-force attacks or denial of service attacks via the dbhost parameter, a different vulnerability than CVE-2011-4898. NOTE: the vendor disputes the significance of this issue because an incomplete WordPress installation might be present on the network for only a short time

    Source:Trustwave's SpiderLabs
    Published:30 Jan 2012
    7.5
    High

    CVE-2012-0935

    Last Modified: 21 Jan 2012

    SQL injection vulnerability in Default.aspx in Aryadad CMS allows remote attackers to execute arbitrary SQL commands via the PageID parameter.

    Source:Red Security TEAM
    Published:29 Jan 2012
    2.6
    Low

    CVE-2012-0933

    Last Modified: 1 Apr 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Acidcat CMS 3.5.1, 3.5.2, 3.5.6, and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin_colors.asp, (2) admin_config.asp, and (3) admin_cat_add.asp in admin/.

    Source:Avram Marius
    Published:29 Jan 2012
    4.3
    Medium

    CVE-2012-0932

    Last Modified: 6 Apr 2015

    Cross-site scripting (XSS) vulnerability in admin/login.php in Lead Capture Page System allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Source:HashoR
    Published:29 Jan 2012
    7.5
    High

    CVE-2012-0913

    Last Modified: 20 Jan 2012

    SQL injection vulnerability in checklogin.aspx in ICloudCenter ICTimeAttendance 1.0 allows remote attackers to execute arbitrary SQL commands via the passw parameter. NOTE: Some of these details are obtained from third party information.

    Source:v3n0m
    Published:24 Jan 2012
    9.8
    Critical

    CVE-2012-0911

    Last Modified: 13 Aug 2012

    TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1) cookieName to lib/banners/bannerlib.php; (2) printpages or (3) printstructures parameter to (a) tiki-print_multi_pages.php or (b) tiki-print_pages.php; or (4) sendpages, (5) sendstructures, or (6) sendarticles parameter to tiki-send_objects.php, which is not properly handled when processed by the unserialize function.

    Source:EgiX
    Published:12 Jul 2012
    7.5
    High

    CVE-2012-0906

    Last Modified: 18 Jan 2012

    SQL injection vulnerability in the Moviebase addon for deV!L'z Clanportal (DZCP) 1.5.5 allows remote attackers to execute arbitrary SQL commands via the id parameter in a showkat action to index.php.

    Source:Easy Laster
    Published:20 Jan 2012
    7.5
    High

    CVE-2012-0905

    Last Modified: 18 Jan 2012

    SQL injection vulnerability in deV!L'z Clanportal (DZCP) Gamebase addon allows remote attackers to execute arbitrary SQL commands via the gameid parameter in a detail action to index.php.

    Source:Easy Laster
    Published:20 Jan 2012
    4.3
    Medium

    CVE-2012-0904

    Last Modified: 4 Jan 2012

    VLC media player 1.1.11 allows remote attackers to cause a denial of service (crash) via a long string in an amr file.

    Source:Fabi@habsec
    Published:20 Jan 2012
    5
    Medium

    CVE-2012-0902

    Last Modified: 8 Jan 2012

    AirTies Air 4450 1.1.2.18 allows remote attackers to cause a denial of service (reboot) via a direct request to cgi-bin/loader.

    Source:rigan
    Published:20 Jan 2012
    4.3
    Medium

    CVE-2012-0901

    Last Modified: 3 Apr 2015

    Cross-site scripting (XSS) vulnerability in yousaytoo.php in YouSayToo auto-publishing plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit parameter.

    Source:H4ckCity Security Team
    Published:20 Jan 2012
    4.3
    Medium

    CVE-2012-0900

    Last Modified: 31 Mar 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Beehive Forum 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) forum/register.php or (2) forum/logon.php.

    Source:Stefan Schurtz
    Published:20 Jan 2012
    4.3
    Medium

    CVE-2012-0899

    Last Modified: 31 Mar 2015

    Cross-site scripting (XSS) vulnerability in referencement/sites_inscription.php in Annuaire PHP allows remote attackers to inject arbitrary web script or HTML via the url parameter and possibly the nom parameter.

    Source:Atmon3r
    Published:20 Jan 2012
    6.8
    Medium

    CVE-2012-0897

    Last Modified: 31 Oct 2016

    Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.

    Source:Metasploit
    Published:20 Jan 2012
    5
    Medium

    CVE-2012-0896

    Last Modified: 30 Oct 2016

    Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter.

    Source:6Scan
    Published:20 Jan 2012
    4.3
    Medium

    CVE-2012-0895

    Last Modified: 30 Oct 2016

    Cross-site scripting (XSS) vulnerability in map/map.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map parameter.

    Source:6Scan
    Published:20 Jan 2012
    6.8
    Medium

    CVE-2012-0874

    Last Modified: 11 Dec 2013

    The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 do not require authentication by default in certain profiles, which might allow remote attackers to invoke MBean methods and execute arbitrary code via unspecified vectors. NOTE: this issue can only be exploited when the interceptor is not properly configured with a "second layer of authentication," or when used in conjunction with other vulnerabilities that bypass this second layer.

    Source:rgod
    Published:24 Jan 2013
    4.3
    Medium

    CVE-2012-0873

    Last Modified: 29 Apr 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Boonex Dolphin before 7.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) explain parameter to explanation.php or the (2) photos_only, (3) online_only, or (4) mode parameters to viewFriends.php.

    Source:Aung Khant
    Published:23 Feb 2012
    4.3
    Medium

    CVE-2012-0869

    Last Modified: 29 Apr 2015

    Cross-site scripting (XSS) vulnerability in fup in Frams' Fast File EXchange (F*EX, aka fex) before 20120215 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Source:muuratsalo
    Published:25 Sept 2012
    5.8
    Medium

    CVE-2012-0865

    Last Modified: 9 Apr 2015

    Multiple open redirect vulnerabilities in CubeCart 3.0.20 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) r parameter to switch.php or (2) goto parameter to admin/login.php.

    Source:Aung Khant
    Published:21 Feb 2012
    5
    Medium

    CVE-2012-0840

    Last Modified: 9 Apr 2015

    tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

    Source:Moritz Muehlenhoff
    Published:5 Jan 2012
    4.3
    Medium

    CVE-2012-0834

    Last Modified: 6 Jan 2017

    Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the base parameter in a query_engine action to cmd.php.

    Source:andsarmiento
    Published:11 Feb 2012
    7.5
    High

    CVE-2012-0830

    Last Modified: 25 Apr 2017

    The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4885.

    Source:Stefan Esser
    Published:2 Feb 2012
    7.2
    High

    CVE-2012-0809

    Last Modified: 31 Jan 2012

    Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8.3p1 allows local users to execute arbitrary code via format string sequences in the program name for sudo.

    Source:joernchen
    Published:30 Jan 2012
    5
    Medium

    CVE-2012-0789

    Last Modified: 17 Apr 2015

    Memory leak in the timezone functionality in PHP before 5.3.9 allows remote attackers to cause a denial of service (memory consumption) by triggering many strtotime function calls, which are not properly handled by the php_date_parse_tzfile cache.

    Source:anonymous
    Published:11 Jan 2012
    5
    Medium

    CVE-2012-0788

    Last Modified: 9 Apr 2015

    The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of service (application crash) via a crafted application that uses a PDO driver for a fetch and then calls the session_start function, as demonstrated by a crash of the Apache HTTP Server.

    Source:anonymous
    Published:11 Jan 2012
    4.3
    Medium

    CVE-2012-0782

    Last Modified: 4 May 2017

    Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dbhost, (2) dbname, or (3) uname parameter. NOTE: the vendor disputes the significance of this issue; also, it is unclear whether this specific XSS scenario has security relevance

    Source:Trustwave's SpiderLabs
    Published:30 Jan 2012
    5
    Medium

    CVE-2012-0781

    Last Modified: 14 Jan 2012

    The tidy_diagnose function in PHP 5.3.8 might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that attempts to perform Tidy::diagnose operations on invalid objects, a different vulnerability than CVE-2011-4153.

    Source:Maksymilian Arciemowicz
    Published:10 Jan 2012
    10
    Critical

    CVE-2012-0780

    Last Modified: 14 Jun 2012

    Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2023, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.

    Source:Felipe Andres Manzano
    Published:9 May 2012
    9.3
    Critical

    CVE-2012-0779

    Last Modified: 25 Jun 2012

    Adobe Flash Player before 10.3.183.19 and 11.x before 11.2.202.235 on Windows, Mac OS X, and Linux; before 11.1.111.9 on Android 2.x and 3.x; and before 11.1.115.8 on Android 4.x allows remote attackers to execute arbitrary code via a crafted file, related to an "object confusion vulnerability," as exploited in the wild in May 2012.

    Source:Metasploit
    Published:4 May 2012
    7.8
    High

    CVE-2012-0754

    Last Modified: 8 Mar 2012

    Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Source:Metasploit
    Published:15 Feb 2012
    5
    Medium

    CVE-2012-0744

    Last Modified: 18 Dec 2016

    IBM Rational ClearQuest 7.1.x through 7.1.2.7 and 8.x through 8.0.0.3 allows remote attackers to obtain potentially sensitive information via a request to a (1) snoop, (2) hello, (3) ivt/, (4) hitcount, (5) HitCount.jsp, (6) HelloHTMLError.jsp, (7) HelloHTML.jsp, (8) HelloVXMLError.jsp, (9) HelloVXML.jsp, (10) HelloWMLError.jsp, (11) HelloWML.jsp, or (12) cqweb/j_security_check sample script.

    Source:anonymous
    Published:17 Aug 2012
    Low

    CVE-2012-0722

    Last Modified: 7 Jan 2013

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-0722. Reason: This candidate is a duplicate of CVE-2013-0722. A year-transition issue caused the wrong ID to be used. Notes: All CVE users should reference CVE-2013-0722 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Sajjad Pourali
    Published:11 Jan 2013
    9.3
    Critical

    CVE-2012-0708

    Last Modified: 5 Jul 2012

    Heap-based buffer overflow in the Ole API in the CQOle ActiveX control in cqole.dll in IBM Rational ClearQuest 7.1.1 before 7.1.1.9, 7.1.2 before 7.1.2.6, and 8.0.0 before 8.0.0.2 allows remote attackers to execute arbitrary code via a crafted web page that leverages a RegisterSchemaRepoFromFileByDbSet function-prototype mismatch.

    Source:Metasploit
    Published:22 Apr 2012
    8.8
    High

    CVE-2012-0699

    Last Modified: 27 Oct 2016

    Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add news via an add action to familynews.php or (2) add a prayer via an add action to prayers.php.

    Source:Ahmed Elhady Mohamed
    Published:11 Jan 2018
    5
    Medium

    CVE-2012-0698

    Last Modified: 23 Nov 2012

    tcsd in TrouSerS before 0.3.10 allows remote attackers to cause a denial of service (daemon crash) via a crafted type_offset value in a TCP packet to port 30003.

    Source:Andy Lutomirski
    Published:13 Jan 2012
    9.8
    Critical

    CVE-2012-0694

    Last Modified: 23 Jun 2012

    SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code.

    Source:EgiX
    Published:29 Oct 2019
    9.3
    Critical

    CVE-2012-0677

    Last Modified: 13 Jun 2012

    Heap-based buffer overflow in Apple iTunes before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted .m3u playlist.

    Source:LiquidWorm
    Published:12 Jun 2012
    9.3
    Critical

    CVE-2012-0663

    Last Modified: 28 Jun 2012

    Multiple stack-based buffer overflows in Apple QuickTime before 7.7.2 on Windows allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TeXML file.

    Source:Metasploit
    Published:16 May 2012