Skip to main content

Year archive

CVEs published in 2012

Archive summary

5,288 CVEs published in 2012 — 950 Critical, 794 High, 3,036 Medium, 506 Low, 2 Unrated.

CVE-2012-5479

Published Nov 21, 2012

The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute files via a modified Portfoli…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5473

Published Nov 21, 2012

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to read activity entries of a different gro…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5472

Published Nov 21, 2012

lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5471

Published Nov 21, 2012

The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to access the Dropbox of a different…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4217

Published Nov 21, 2012

Use-after-free vulnerability in the nsViewManager::ProcessPendingUpdates function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote…

CVSS 9.3 · Critical

CVE-2012-4215

Published Nov 21, 2012

Use-after-free vulnerability in the nsPlaintextEditor::FireClipboardEvent function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunde…

CVSS 9.3 · Critical

CVE-2012-4214

Published Nov 21, 2012

Use-after-free vulnerability in the nsTextEditorState::PrepareEditor function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird…

CVSS 9.3 · Critical

CVE-2012-4213

Published Nov 21, 2012

Use-after-free vulnerability in the nsEditor::FindNextLeafNode function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers…

CVSS 9.3 · Critical

CVE-2012-4210

Published Nov 21, 2012

The Style Inspector in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 does not properly restrict the context of HTML markup and Cascading Style Sheets (CSS) token…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-4209

Published Nov 21, 2012

Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 do not prevent use of a "top"…

CVSS 4.3 · Medium

CVE-2012-4206

Published Nov 21, 2012

Untrusted search path vulnerability in the installer in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 on Windows allows local users to gain privileges via a Troj…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4203

Published Nov 21, 2012

The New Tab page in Mozilla Firefox before 17.0 uses a privileged context for execution of JavaScript code by bookmarklets, which allows user-assisted remote attackers to run arbi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4202

Published Nov 21, 2012

Heap-based buffer overflow in the image::RasterImage::DrawFrameTo function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ES…

CVSS 9.3 · Critical

CVE-2012-5703

Published Nov 20, 2012

The vSphere API in VMware ESXi 4.1 and ESX 4.1 allows remote attackers to cause a denial of service (host daemon crash) via an invalid value in a (1) RetrieveProp or (2) RetrieveP…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2012-5674

Published Nov 20, 2012

Unspecified vulnerability in Adobe ColdFusion 10 before Update 5, when Internet Information Services (IIS) is used, allows attackers to cause a denial of service via unknown vecto…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2012-5920

Published Nov 20, 2012

Cross-site scripting (XSS) vulnerability in Google Web Toolkit (GWT) 2.4 through 2.5 Final, as used in JBoss Operations Network (ON) 3.1.1 and possibly other products, allows remo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5529

Published Nov 20, 2012

TraceManager in Firebird 2.5.0 and 2.5.1, when trace is enabled, allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) by preparing a…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 401-425 of 5,288 CVEsPage 17 of 212