Skip to main content

Year archive

CVEs published in 2012

Archive summary

5,288 CVEs published in 2012 — 950 Critical, 794 High, 3,036 Medium, 506 Low, 2 Unrated.

CVE-2012-1080

Published Feb 14, 2012

Cross-site scripting (XSS) vulnerability in the Euro Calculator (skt_eurocalc) extension 0.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vecto…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1079

Published Feb 14, 2012

Unspecified vulnerability in the Webservices for TYPO3 (typo3_webservice) extension before 0.3.8 for TYPO3 allows remote authenticated users to execute arbitrary code via unknown…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1078

Published Feb 14, 2012

The System Utilities (sysutils) extension 1.0.3 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unspecified vectors related to improper "protecti…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1077

Published Feb 14, 2012

SQL injection vulnerability in the Post data records to facebook (bc_post2facebook) extension before 0.2.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1076

Published Feb 14, 2012

Cross-site scripting (XSS) vulnerability in the Documents download (rtg_files) extension before 1.5.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1075

Published Feb 14, 2012

SQL injection vulnerability in the Documents download (rtg_files) extension before 1.5.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vector…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1074

Published Feb 14, 2012

SQL injection vulnerability in the White Papers (mm_whtppr) extension 0.0.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1073

Published Feb 14, 2012

Cross-site scripting (XSS) vulnerability in the Category-System (toi_category) extension 0.6.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1072

Published Feb 14, 2012

SQL injection vulnerability in the Category-System (toi_category) extension 0.6.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1071

Published Feb 14, 2012

SQL injection vulnerability in the Kitchen recipe (mv_cooking) extension before 0.4.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1070

Published Feb 14, 2012

Cross-site scripting (XSS) vulnerability in the Modern FAQ (irfaq) extension 1.1.2 and other versions before 1.1.4 for TYPO3 allows remote attackers to inject arbitrary web script…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1069

Published Feb 14, 2012

Cross-site scripting (XSS) vulnerability in module/kb/search_word in the search module in lknSupport allows remote attackers to inject arbitrary web script or HTML via the PATH_IN…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1068

Published Feb 14, 2012

Cross-site scripting (XSS) vulnerability in the rc_ajax function in core.php in the WP-RecentComments plugin before 2.0.7 for WordPress allows remote attackers to inject arbitrary…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1067

Published Feb 14, 2012

SQL injection vulnerability in the WP-RecentComments plugin 2.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter in an rc-content act…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1066

Published Feb 14, 2012

Cross-site scripting (XSS) vulnerability in the template module in SmartyCMS 0.9.4 allows remote attackers to inject arbitrary web script or HTML via the title bar.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1065

Published Feb 14, 2012

Insecure method vulnerability in TuxScripting.dll in the TuxSystem ActiveX control in 2X ApplicationServer 10.1 Build 1224 allows remote attackers to create or overwrite arbitrary…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1009

Published Feb 14, 2012

NetSarang Xlpd 4 Build 0100 and NetSarang Xmanager Enterprise 4 Build 0186 allow remote attackers to cause a denial of service (daemon crash) via a malformed LPD request.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5080

Published Feb 14, 2012

Cross-site scripting (XSS) vulnerability in lib/class.tx_jftcaforms_tceFunc.php in the Additional TCA Forms (jftcaforms) extension before 0.2.1 for TYPO3 allows remote attackers t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5079

Published Feb 14, 2012

Open redirect vulnerability in the Modern FAQ (irfaq) extension 1.1.2 and other versions before 1.1.4 for TYPO3 allows remote attackers to redirect users to arbitrary web sites an…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0789

Published Feb 14, 2012

Memory leak in the timezone functionality in PHP before 5.3.9 allows remote attackers to cause a denial of service (memory consumption) by triggering many strtotime function calls…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0788

Published Feb 14, 2012

The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of service (application crash) v…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1063

Published Feb 14, 2012

Multiple SQL injection vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to execute arbitrary SQL commands via the (1) viewId parameter to f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1062

Published Feb 14, 2012

Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to inject arbitrary web script or HTML via the (1) per…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1061

Published Feb 14, 2012

SQL injection vulnerability in GForge Advanced Server 6.0.0 and other versions before 6.0.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1060

Published Feb 14, 2012

Multiple cross-site scripting (XSS) vulnerabilities in revisioning_theme.inc in the Taxonomy module in the Revisioning module 6.x-3.13 and other versions before 6.x-3.14 for Drupa…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 4,801-4,825 of 5,288 CVEsPage 193 of 212