Skip to main content

Year archive

CVEs published in 2012

Archive summary

5,288 CVEs published in 2012 — 950 Critical, 794 High, 3,036 Medium, 506 Low, 2 Unrated.

CVE-2012-4938

Published Nov 18, 2012

Cross-site scripting (XSS) vulnerability in the web interface in Pattern Insight 2.3 allows remote authenticated administrators to inject arbitrary web script or HTML via the bann…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-4937

Published Nov 18, 2012

Session fixation vulnerability in the web interface in Pattern Insight 2.3 allows remote attackers to hijack web sessions via a jsession_id cookie.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4936

Published Nov 18, 2012

The web interface in Pattern Insight 2.3 allows remote attackers to conduct clickjacking attacks via a FRAME element.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4935

Published Nov 18, 2012

Cross-site request forgery (CSRF) vulnerability in the web interface in Pattern Insight 2.3 allows remote attackers to hijack the authentication of arbitrary users.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4959

Published Nov 18, 2012

Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and execute files via a 130 /FSF/CMD request with a .. (dot dot)…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-4958

Published Nov 18, 2012

Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a 126 /FSF/CMD request with a .. (dot dot) in a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4957

Published Nov 18, 2012

Absolute path traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a /FSF/CMD request with a full pathname in…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4956

Published Nov 18, 2012

Heap-based buffer overflow in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to execute arbitrary code via a large number of VOL elements in an SRS record.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-5917

Published Nov 17, 2012

SnackAmp 3.1.3 allows remote attackers to cause a denial of service (application crash) via a long string in an aiff file.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5916

Published Nov 17, 2012

Neocrome Seditio build 161 allows remote attackers to obtain sensitive information via a direct request to (1) docs/new/seditio-createnew-160.sql, (2) docs/upgrade/sedito_convert_…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5915

Published Nov 17, 2012

Neocrome Seditio build 161 and earlier allows remote attackers to obtain sensitive information via direct request to (1) view.php, (2) plugins/contact/lang/contact.en.lang.php, (3…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5914

Published Nov 17, 2012

Multiple cross-site scripting (XSS) vulnerabilities in the sed_import function in system/functions.php in Neocrome Seditio build 160 and 161 allow remote attackers to inject arbit…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-5912

Published Nov 17, 2012

Multiple SQL injection vulnerabilities in PicoPublisher 2.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) page.php or (2) single.php.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5911

Published Nov 17, 2012

Cross-site scripting (XSS) vulnerability in blogs/blog1.php in b2evolution 4.1.3 allows remote attackers to inject arbitrary web script or HTML via the message body.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5910

Published Nov 17, 2012

SQL injection vulnerability in blogs/htsrv/viewfile.php in b2evolution 4.1.3 allows remote authenticated users to execute arbitrary SQL commands via the root parameter.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5909

Published Nov 17, 2012

SQL injection vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to execute arbitrary SQL commands via the conditions[usergr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5908

Published Nov 17, 2012

Cross-site scripting (XSS) vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to inject arbitrary web script or HTML via the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 451-475 of 5,288 CVEsPage 19 of 212