Skip to main content

Year archive

CVEs published in 2012

Archive summary

5,288 CVEs published in 2012 — 950 Critical, 794 High, 3,036 Medium, 506 Low, 2 Unrated.

CVE-2012-1059

Published Feb 14, 2012

Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Cart/pages/main.php in OSCommerce Online Merchant 3.0.2 allows remote attackers to inject arbi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1058

Published Feb 14, 2012

Cross-site request forgery (CSRF) vulnerability in Flyspray 0.9.9.6 allows remote attackers to hijack the authentication of admins for requests that add admin accounts via an admi…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1057

Published Feb 14, 2012

Cross-site request forgery (CSRF) vulnerability in the clickthrough tracking functionality in the Forward module 6.x-1.x before 6.x-1.21 and 7.x-1.x before 7.x-1.3 for Drupal allo…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1056

Published Feb 14, 2012

The Forward module 6.x-1.x before 6.x-1.21 and 7.x-1.x before 7.x-1.3 for Drupal does not properly enforce permissions for (1) Recent forwards, (2) Most forwarded, or (3) Dynamic…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1055

Published Feb 14, 2012

Heap-based buffer overflow in PhotoLine 17.01 and possibly other versions before 17.02 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Q…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0829

Published Feb 14, 2012

Multiple cross-site request forgery (CSRF) vulnerabilities in Mibew Messenger 1.6.4 and earlier allow remote attackers to hijack the authentication of operators for requests that…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0340

Published Feb 13, 2012

Cross-site scripting (XSS) vulnerability in the management interface on the Cisco IronPort Encryption Appliance with software before 6.5.3 allows remote attackers to inject arbitr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1052

Published Feb 13, 2012

Buffer overflow in IvanView 1.2.15 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1051

Published Feb 13, 2012

Heap-based buffer overflow in Xjp2.dll in the JPEG2000 plug-in in XnView 1.98.5 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantiza…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1050

Published Feb 13, 2012

Directory traversal vulnerability in Mathopd 1.4.x and 1.5.x before 1.5p7, when configured with the * construct for mass virtual hosting, allows remote attackers to read arbitrary…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1049

Published Feb 13, 2012

Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ADManager Plus 5.2 Build 5210 allow remote attackers to inject arbitrary web script or HTML via the (1) domainN…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1048

Published Feb 12, 2012

Cross-site scripting (XSS) vulnerability in communityplusplus/www/administrator.php in eFront Community++ edition 3.6.10, and possibly other editions, allows remote attackers to i…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1047

Published Feb 12, 2012

Directory traversal vulnerability in the WWWHELP Service (js/html/wwhelp.htm) in Cyberoam Central Console (CCC) 2.00.2 allows remote attackers to include and execute arbitrary loc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4341

Published Feb 12, 2012

Multiple SQL injection vulnerabilities in symphony/content/content.publish.php in Symphony CMS 2.2.3 and possibly other versions before 2.2.4 allow remote authenticated users with…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4340

Published Feb 12, 2012

Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.2.3 and possibly other versions before 2.2.4 allow remote authenticated users with Author privileges to injec…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-0834

Published Feb 11, 2012

Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the base param…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0831

Published Feb 10, 2012

PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote at…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1046

Published Feb 10, 2012

Cross-site scripting (XSS) vulnerability in TM1 Web in IBM Cognos TM1 9.5.2 FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0840

Published Feb 10, 2012

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which all…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4534

Published Feb 10, 2012

ZenSysSrv.exe in Ing. Punzenberger COPA-DATA zenon 6.51 SP0 allows remote attackers to cause a denial of service (service crash) or possibly execute arbitrary code via a series of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4533

Published Feb 10, 2012

zenAdminSrv.exe in Ing. Punzenberger COPA-DATA zenon 6.51 SP0 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3972

Published Feb 9, 2012

The shader translator implementation in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 4,826-4,850 of 5,288 CVEsPage 194 of 212