6.9
    Medium

    CVE-2012-0056

    Last Modified: 10 May 2017

    The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when writing to /proc/<pid>/mem, which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper.

    Source:zx2c4
    Published:18 Jan 2012
    7.8
    High

    CVE-2012-0055

    Last Modified: 31 Mar 2015

    OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions.

    Source:Gary Poster
    Published:19 Feb 2020
    4.3
    Medium

    CVE-2012-0053

    Last Modified: 31 Jan 2012

    protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.

    Source:pilate
    Published:23 Jan 2012
    4.7
    Medium

    CVE-2012-0045

    Last Modified: 30 Mar 2015

    The em_syscall function in arch/x86/kvm/emulate.c in the KVM implementation in the Linux kernel before 3.2.14 does not properly handle the 0f05 (aka syscall) opcode, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application, as demonstrated by an NASM file.

    Source:Stephan Sattler
    Published:29 Dec 2011
    4.6
    Medium

    CVE-2012-0031

    Last Modified: 30 Mar 2017

    scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, leading to an invalid call to the free function.

    Source:halfdog
    Published:11 Jan 2012
    6.8
    Medium

    CVE-2012-0025

    Last Modified: 31 Oct 2016

    Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the FlashPix PlugIn 4.2.2.0 for IrfanView, allows remote attackers to cause a denial of service (crash) via a crafted FPX image.

    Source:Francis Provencher
    Published:2 Nov 2012
    9.3
    Critical

    CVE-2012-0016

    Last Modified: 27 Nov 2013

    Untrusted search path vulnerability in Microsoft Expression Design; Expression Design SP1; and Expression Design 2, 3, and 4 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .xpr or .DESIGN file, aka "Expression Design Insecure Library Loading Vulnerability."

    Source:Metasploit
    Published:13 Mar 2012
    9.3
    Critical

    CVE-2012-0013

    Last Modified: 11 Jun 2012

    Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted ClickOnce application in a Microsoft Office document, related to .application files, aka "Assembly Execution Vulnerability."

    Source:Metasploit
    Published:10 Jan 2012
    4.3
    Medium

    CVE-2012-0007

    Last Modified: 27 Mar 2015

    The Microsoft Anti-Cross Site Scripting (AntiXSS) Library 3.x and 4.0 does not properly evaluate characters after the detection of a Cascading Style Sheets (CSS) escaped character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML input, aka "AntiXSS Library Bypass Vulnerability."

    Source:Adi Cohen
    Published:10 Jan 2012
    8.1
    High

    CVE-2012-0003

    Last Modified: 28 Jan 2012

    Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via a crafted MIDI file, aka "MIDI Remote Code Execution Vulnerability."

    Source:Metasploit
    Published:10 Jan 2012
    9.3
    Critical

    CVE-2012-0002

    Last Modified: 16 Mar 2012

    The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remote attackers to execute arbitrary code by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, aka "Remote Desktop Protocol Vulnerability."

    Source:Luigi Auriemma
    Published:13 Mar 2012
    9.8
    Critical

    CVE-2011-5331

    Last Modified: 21 Nov 2024

    Distributed Ruby (aka DRuby) 1.8 mishandles instance_eval.

    Published:18 Nov 2019
    6.8
    Medium

    CVE-2011-5318

    Last Modified: 11 Jan 2011

    Multiple cross-site request forgery (CSRF) vulnerabilities in diafan.CMS before 5.1 allow remote attackers to hijack the authentication of administrators for requests that (1) modify articles via a save_post action to admin/news/saveNEWS_ID/, (2) modify settings via a save_post action to admin/site/save2/, or (3) modify credentials via a save_post action to admin/usersite/save2/.

    Source:High-Tech Bridge SA
    Published:1 Jan 2015
    7.5
    High

    CVE-2011-5313

    Last Modified: 2 Feb 2011

    Multiple SQL injection vulnerabilities in includes/password.php in Redaxscript 0.3.2 allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) password parameter to the password_reset program.

    Source:High-Tech Bridge SA
    Published:1 Jan 2015
    6.4
    Medium

    CVE-2011-5289

    Last Modified: 12 Apr 2025

    The SaveDecrypted method in the ChilkatCrypt2.ChilkatOmaDrm.1 ActiveX control in ChilkatCrypt2.dll in aTube Catcher 2.3.570 allows remote attackers to write to arbitrary files via a pathname in the argument.

    Source:shinnai
    Published:1 Jan 2015
    7.5
    High

    CVE-2011-5286

    Last Modified: 5 Aug 2011

    SQL injection vulnerability in social-slider-2/ajax.php in the Social Slider plugin before 7.4.2 for WordPress allows remote attackers to execute arbitrary SQL commands via the rA array parameter.

    Source:Miroslav Stampar
    Published:1 Jan 2015
    6.8
    Medium

    CVE-2011-5284

    Last Modified: 17 Jan 2011

    Cross-site request forgery (CSRF) vulnerability in the web management interface in httpd/cgi-bin/shutdown.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier allows remote attackers to hijack the authentication of administrators for requests that perform a reboot via a request to cgi-bin/shutdown.cgi.

    Source:dave b
    Published:31 Dec 2014
    4.3
    Medium

    CVE-2011-5283

    Last Modified: 17 Jan 2011

    Cross-site scripting (XSS) vulnerability in the web management interface in httpd/cgi-bin/ipinfo.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier allows remote attackers to inject arbitrary web script or HTML via the IP parameter in a Run action.

    Source:dave b
    Published:31 Dec 2014
    7.5
    High

    CVE-2011-5278

    Last Modified: 13 Oct 2011

    SQL injection vulnerability in signature.php in Advanced Forum Signatures plugin (aka afsignatures) 2.0.4 for MyBB allows remote attackers to execute arbitrary SQL commands via the afs_bar_right parameter.

    Source:Mario_Vs
    Published:8 Apr 2014
    7.5
    High

    CVE-2011-5277

    Last Modified: 13 Oct 2011

    Multiple SQL injection vulnerabilities in signature.php in the Advanced Forum Signatures (aka afsignatures) plugin 2.0.4 for MyBB allow remote attackers to execute arbitrary SQL commands via the (1) afs_type, (2) afs_background, (3) afs_showonline, (4) afs_bar_left, (5) afs_bar_center, (6) afs_full_line1, (7) afs_full_line2, (8) afs_full_line3, (9) afs_full_line4, (10) afs_full_line5, or (11) afs_full_line6 parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Mario_Vs
    Published:8 Apr 2014
    4.3
    Medium

    CVE-2011-5267

    Last Modified: 16 Mar 2011

    Multiple cross-site scripting (XSS) vulnerabilities in spell-check-savedicts.php in the SpellChecker module in Xinha, as used in WikiWig 5.01 and possibly other products, allow remote attackers to inject arbitrary web script or HTML via the (1) to_p_dict or (2) to_r_list parameter. NOTE: this issue might be related to the htmlarea plugin and CVE-2013-5670.

    Source:AutoSec Tools
    Published:5 Nov 2013
    4.3
    Medium

    CVE-2011-5265

    Last Modified: 12 Mar 2015

    Cross-site scripting (XSS) vulnerability in cached_image.php in the Featurific For WordPress plugin 1.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the snum parameter. NOTE: this has been disputed by a third party.

    Source:Amir
    Published:12 Feb 2013
    7.5
    High

    CVE-2011-5262

    Last Modified: 16 Nov 2011

    SQL injection vulnerability in prodpage.cfm in SonicWALL Aventail allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.

    Source:Asheesh kumar
    Published:12 Feb 2013
    4.3
    Medium

    CVE-2011-5261

    Last Modified: 19 Mar 2015

    Cross-site scripting (XSS) vulnerability in serverreport.cgi in Axis M10 Series Network Cameras M1054 firmware 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML via the pageTitle parameter to admin/showReport.shtml.

    Source:Matt Metzger
    Published:12 Feb 2013
    6.8
    Medium

    CVE-2011-5259

    Last Modified: 16 Mar 2015

    SQL injection vulnerability in lib/controllers/CentralController.php in OrangeHRM before 2.6.11.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:High-Tech Bridge SA
    Published:12 Feb 2013
    4.3
    Medium

    CVE-2011-5258

    Last Modified: 16 Mar 2015

    Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.6.11.2 allow remote attackers to inject arbitrary web script or HTML via the (1) uniqcode or (2) isAdmin parameter to index.php; or the (3) PATH_INFO to lib/controllers/centralcontroller.php.

    Source:High-Tech Bridge SA
    Published:12 Feb 2013
    4.3
    Medium

    CVE-2011-5257

    Last Modified: 31 Oct 2011

    Multiple cross-site scripting (XSS) vulnerabilities in the Classipress theme before 3.1.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) twitter_id parameter related to the Twitter widget and (2) facebook_id parameter related to the Facebook widget.

    Source:Paul Loftness
    Published:12 Feb 2013
    5.8
    Medium

    CVE-2011-5252

    Last Modified: 17 Aug 2017

    Open redirect vulnerability in Users/Account/LogOff in Orchard 1.0.x before 1.0.21, 1.1.x before 1.1.31, 1.2.x before 1.2.42, and 1.3.x before 1.3.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the ReturnUrl parameter.

    Source:Mesut Timur
    Published:12 Jan 2013
    4.3
    Medium

    CVE-2011-5233

    Last Modified: 31 Oct 2016

    Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows Per Strip" and "Samples Per Pixel" values in a TIFF image file.

    Source:Francis Provencher
    Published:25 Oct 2012
    Low

    CVE-2011-5232

    Last Modified: 31 Oct 2016

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-0025. Reason: This candidate is a duplicate of CVE-2012-0025. Notes: All CVE users should reference CVE-2012-0025 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Francis Provencher
    Published:25 Oct 2012
    7.5
    High

    CVE-2011-5230

    Last Modified: 1 Nov 2017

    Multiple SQL injection vulnerabilities in the selectUserIdByLoginPass function in seotoaster_core/application/models/LoginModel.php in Seotoaster 1.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login parameter to sys/login/index or (2) memberLoginName parameter to sys/login/member.

    Source:Stefan Schurtz
    Published:25 Oct 2012
    7.5
    High

    CVE-2011-5229

    Last Modified: 2 Jan 2014

    SQL injection vulnerability in quickstart/profile/index.php in the Forum module in appRain CMF 0.1.5 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.

    Source:Vulnerability-Lab
    Published:25 Oct 2012
    4.3
    Medium

    CVE-2011-5228

    Last Modified: 2 Jan 2014

    Cross-site scripting (XSS) vulnerability in the Search module (quickstart/search) in appRain CMF 0.1.5 allows remote attackers to inject arbitrary web script or HTML via the ss parameter.

    Source:Vulnerability-Lab
    Published:25 Oct 2012
    10
    Critical

    CVE-2011-5227

    Last Modified: 4 Jan 2013

    Stack-based buffer overflow in the Syslog service (nssyslogd.exe) in Enterasys Network Management Suite (NMS) before 4.1.0.80 allows remote attackers to execute arbitrary code via a long PRIO field in a message to UDP port 514.

    Source:Metasploit
    Published:25 Oct 2012
    7.5
    High

    CVE-2011-5222

    Last Modified: 20 Mar 2015

    SQL injection vulnerability in rub2_w.php in PHP Flirt-Projekt 4.8 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the rub parameter.

    Source:Lazmania61
    Published:25 Oct 2012
    5
    Medium

    CVE-2011-5219

    Last Modified: 16 Dec 2011

    Directory traversal vulnerability in examples/show_code.php in mPDF 5.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

    Source:ZadYree
    Published:25 Oct 2012
    7.5
    High

    CVE-2011-5218

    Last Modified: 19 Dec 2011

    SQL injection vulnerability in DotA OpenStats 1.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Source:HvM17
    Published:25 Oct 2012
    4.3
    Medium

    CVE-2011-5214

    Last Modified: 5 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) modules/admin/admin_module_index.php, or (3) modules/calendar/customise_calendar_times.php; login[] parameter to (4) index.php or (5) pub/clients.php; or framed parameter to (6) licence/index.php or (7) licence/view.php.

    Source:High-Tech Bridge SA
    Published:25 Oct 2012
    7.5
    High

    CVE-2011-5213

    Last Modified: 5 Dec 2016

    Multiple SQL injection vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login[username] parameter to index.php, (2) parent_id parameter to modules/Documents/version_list.php, or (3) contact_id parameter to modules/Documents/index.php.

    Source:High-Tech Bridge SA
    Published:25 Oct 2012
    7.5
    High

    CVE-2011-5212

    Last Modified: 11 Jun 2011

    SQL injection vulnerability in admin/index.php in Subrion CMS 2.0.4 allows remote attackers to execute arbitrary SQL commands via the (1) user name or (2) password field.

    Source:Karthik R
    Published:22 Oct 2012
    4.3
    Medium

    CVE-2011-5211

    Last Modified: 11 Jun 2011

    Cross-site scripting (XSS) vulnerability in the poll module in Subrion CMS 2.0.4 allows remote attackers to inject arbitrary web script or HTML via the title field. NOTE: some of these details are obtained from third party information. NOTE: this might overlap CVE-2012-5452.

    Source:Karthik R
    Published:22 Oct 2012
    4.3
    Medium

    CVE-2011-5209

    Last Modified: 26 Mar 2015

    Cross-site scripting (XSS) vulnerability in search/ in GraphicsClone Script, possibly 1.11, allows remote attackers to inject arbitrary web script or HTML via the term parameter.

    Source:Mr.PaPaRoSSe
    Published:9 Oct 2012
    4.3
    Medium

    CVE-2011-5207

    Last Modified: 25 Mar 2015

    Cross-site scripting (XSS) vulnerability in admin/OptionsPostsList.php in the TheCartPress plugin for WordPress before 1.1.6 before 2011-12-31 allows remote attackers to inject arbitrary web script or HTML via the tcp_name_post_XXXXX parameter.

    Source:6Scan
    Published:4 Oct 2012
    1.9
    Low

    CVE-2011-5204

    Last Modified: 30 Dec 2011

    Akiva WebBoard 8.x stores passwords in plaintext, which allows local users to obtain sensitive information by reading from the database.

    Source:Alexander Fuchs
    Published:4 Oct 2012
    7.5
    High

    CVE-2011-5203

    Last Modified: 30 Dec 2011

    SQL injection vulnerability in WB/Default.asp in Akiva WebBoard before 8 SR 1 allows remote attackers to execute arbitrary SQL commands via the name parameter. NOTE: some of these details are obtained from third party information.

    Source:Alexander Fuchs
    Published:4 Oct 2012
    7.5
    High

    CVE-2011-5200

    Last Modified: 30 Dec 2011

    Multiple SQL injection vulnerabilities in DeDeCMS, possibly 5.6, allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) list.php, (2) members.php, or (3) book.php.

    Source:CWH & Nafsh
    Published:23 Sept 2012
    6.8
    Medium

    CVE-2011-5197

    Last Modified: 12 Jul 2015

    Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Harvester Systems 2.3.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload PHP files.

    Source:mr_me
    Published:23 Sept 2012
    6.8
    Medium

    CVE-2011-5196

    Last Modified: 12 Jul 2015

    Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Journal Systems 2.3.6 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload PHP files.

    Source:mr_me
    Published:23 Sept 2012
    6.8
    Medium

    CVE-2011-5195

    Last Modified: 12 Jul 2015

    Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Conference Systems 2.3.4 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload a PHP file.

    Source:mr_me
    Published:23 Sept 2012
    2.6
    Low

    CVE-2011-5193

    Last Modified: 25 Mar 2015

    Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin 1.4.2.3 for WordPress, when the WHOIS widget is enabled, allows remote attackers to inject arbitrary web script or HTML via the domain parameter to index.php, a different vulnerability than CVE-2011-5194.

    Source:Atmon3r
    Published:23 Sept 2012