Skip to main content

Year archive

CVEs published in 2012

Archive summary

5,288 CVEs published in 2012 — 950 Critical, 794 High, 3,036 Medium, 506 Low, 2 Unrated.

CVE-2012-0994

Published Feb 21, 2012

SQL injection vulnerability in the Manage Albums feature in zp-core/admin-albumsort.php in ZENphoto 1.4.2 allows remote authenticated users to execute arbitrary SQL commands via t…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0993

Published Feb 21, 2012

Eval injection vulnerability in zp-core/zp-extensions/viewer_size_image.php in ZENphoto 1.4.2, when the viewer_size_image plugin is enabled, allows remote attackers to execute arb…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0865

Published Feb 21, 2012

Multiple open redirect vulnerabilities in CubeCart 3.0.20 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0224

Published Feb 21, 2012

Untrusted search path vulnerability in 7-Technologies (7T) AQUIS 1.5 and earlier allows local users to gain privileges via a Trojan horse DLL in the current working directory, a d…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-4187

Published Feb 21, 2012

Buffer overflow in the GetDriverSettings function in nipplib.dll in Novell iPrint Client before 5.78 on Windows allows remote attackers to execute arbitrary code via a long realm…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-4186

Published Feb 21, 2012

Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.78 on Windows allows remote attackers to execute arbitrary code via a crafted client-file-name parameter…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-4185

Published Feb 21, 2012

The GetPrinterURLList2 method in the ActiveX control in Novell iPrint Client before 5.78 on Windows allows remote attackers to execute arbitrary code or cause a denial of service…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1217

Published Feb 21, 2012

Multiple cross-site scripting (XSS) vulnerabilities in STHS v2 Web Portal 2.2 allow remote attackers to inject arbitrary web script or HTML via the team parameter to (1) prospects…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1216

Published Feb 21, 2012

Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in PBBoard 2.1.4 allow remote attackers to hijack the authentication of administrators for requests that (1…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1215

Published Feb 21, 2012

Cross-site scripting (XSS) vulnerability in the Add friends module in the Yoono extension before 7.7.8 for Firefox allows remote attackers to inject arbitrary web script or HTML v…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1214

Published Feb 21, 2012

Cross-site scripting (XSS) vulnerability in the Add friends module in Yoono Desktop Application before 1.8.21 allows remote attackers to inject arbitrary web script or HTML via th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1200

Published Feb 18, 2012

Multiple PHP remote file inclusion vulnerabilities in Nova CMS allow remote attackers to execute arbitrary PHP code via a URL in the (1) fileType parameter to optimizer/index.php,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1197

Published Feb 18, 2012

Integer overflow in the IDE_ACDStd.apl module for ACDSee 14.1 Build 137 allows remote attackers to execute arbitrary code via crafted "image dimension values" in a BMP file, which…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1196

Published Feb 18, 2012

Directory traversal vulnerability in the VulCore web service (WSVulnerabilityCore/VulCore.asmx) in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to delete arbitrary…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1195

Published Feb 18, 2012

Unrestricted file upload vulnerability in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup web service in Lenovo ThinkManagement Console 9.0.3 allows…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-5081

Published Feb 18, 2012

Cross-site scripting (XSS) vulnerability in RestoreFile.pm in BackupPC 3.1.0, 3.2.1, and possibly other earlier versions allows remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4923

Published Feb 18, 2012

Cross-site scripting (XSS) vulnerability in View.pm in BackupPC 3.0.0, 3.1.0, 3.2.0, 3.2.1, and possibly earlier allows remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4614

Published Feb 18, 2012

PHP remote file inclusion vulnerability in Classes/Controller/AbstractController.php in the workspaces system extension in TYPO3 4.5.x before 4.5.9, 4.6.x before 4.6.2, and develo…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4320

Published Feb 18, 2012

The mod_pubsub module (mod_pubsub.erl) in ejabberd 2.1.8 and 3.0.0-alpha-3 allows remote authenticated users to cause a denial of service (infinite loop) via a stanza with a publi…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3361

Published Feb 18, 2012

Cross-site scripting (XSS) vulnerability in CGI/Browse.pm in BackupPC 3.2.0 and possibly other versions before 3.2.1 allows remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4113

Published Feb 17, 2012

SQL injection vulnerability in the Views module before 6.x-2.13 for Drupal allows remote attackers to execute arbitrary SQL commands via vectors related to "filters/arguments on c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4105

Published Feb 17, 2012

LightDM before 1.0.6 allows local users to change ownership of arbitrary files via a symlink attack on ~/.Xauthority.

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-1194

Published Feb 17, 2012

The resolver in the DNS Server service in Microsoft Windows Server 2008 before R2 overwrites cached server names and TTL values in NS records during the processing of a response t…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 4,701-4,725 of 5,288 CVEsPage 189 of 212