Skip to main content

Year archive

CVEs published in 2012

Archive summary

5,288 CVEs published in 2012 — 950 Critical, 794 High, 3,036 Medium, 506 Low, 2 Unrated.

CVE-2012-5519

Published Nov 20, 2012

CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, wh…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4566

Published Nov 20, 2012

The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4563

Published Nov 20, 2012

Cross-site scripting (XSS) vulnerability in Google Web Toolkit (GWT) 2.4 Beta and release candidates before 2.4.0 allows remote attackers to inject arbitrary web script or HTML vi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4523

Published Nov 20, 2012

radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the ce…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4510

Published Nov 20, 2012

cups-pk-helper before 0.2.3 does not properly wrap the (1) cupsGetFile and (2) cupsPutFile function calls, which allows user-assisted remote attackers to read or overwrite sensiti…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3354

Published Nov 20, 2012

doku.php in DokuWiki, as used in Fedora 16, 17, and 18, when certain PHP error levels are set, allows remote attackers to obtain sensitive information via the prefix parameter, wh…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4612

Published Nov 20, 2012

icecast before 2.3.3 allows remote attackers to inject control characters such as newlines into the error loc (error.log) via a crafted URL.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5919

Published Nov 19, 2012

Multiple cross-site scripting (XSS) vulnerabilities in Havalite 1.0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) find or (2) replace fie…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5918

Published Nov 19, 2012

razorCMS 1.2 allows remote authenticated users to access administrator directories and files by creating and deleting a directory.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5854

Published Nov 19, 2012

Heap-based buffer overflow in WeeChat 0.3.6 through 0.3.9 allows remote attackers to cause a denial of service (crash or hang) and possibly execute arbitrary code via crafted IRC…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4541

Published Nov 19, 2012

Cross-site scripting (XSS) vulnerability in Piwik before 1.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4423

Published Nov 19, 2012

The virNetServerProgramDispatchCall function in libvirt before 0.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and segmentation fault) via an…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4233

Published Nov 19, 2012

LibreOffice 3.5.x before 3.5.7.2 and 3.6.x before 3.6.1, and OpenOffice.org (OOo), allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted (1…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4225

Published Nov 19, 2012

NVIDIA UNIX graphics driver before 295.71 and before 304.32 allows local users to write to arbitrary physical memory locations and gain privileges by modifying the VGA window usin…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2011-5244

Published Nov 19, 2012

Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other produ…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2486

Published Nov 19, 2012

nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prevent Firefox plugins from determining if they should run in…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0433

Published Nov 19, 2012

Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allows remote attackers to cause a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4533

Published Nov 19, 2012

Cross-site scripting (XSS) vulnerability in the "extra" details in the DiffSource._get_row function in lib/viewvc.py in ViewVC 1.0.x before 1.0.13 and 1.1.x before 1.1.16 allows r…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4552

Published Nov 18, 2012

Stack-based buffer overflow in the error function in ssg/ssgParser.cxx in PLIB 1.8.5 allows remote attackers to execute arbitrary code via a crafted 3d model file that triggers a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4520

Published Nov 18, 2012

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted userna…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4433

Published Nov 18, 2012

Multiple integer overflows in operations/external/ppm-load.c in GEGL (Generic Graphics Library) 0.2.0 allow remote attackers to cause a denial of service (application crash) or po…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4417

Published Nov 18, 2012

GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-4950

Published Nov 18, 2012

Cross-site scripting (XSS) vulnerability in the Keyword Search page in the web interface in Pattern Insight 2.3 allows remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 426-450 of 5,288 CVEsPage 18 of 212