Skip to main content

Year archive

CVEs published in 2012

Archive summary

5,288 CVEs published in 2012 — 950 Critical, 794 High, 3,036 Medium, 506 Low, 2 Unrated.

CVE-2011-4791

Published Feb 3, 2012

DBServer.exe in HP Data Protector Media Operations 6.11 and earlier allows remote attackers to execute arbitrary code via a crafted request containing a large value in a length fi…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-0448

Published Feb 2, 2012

Bugzilla 2.x and 3.x before 3.4.14, 3.5.x and 3.6.x before 3.6.8, 3.7.x and 4.0.x before 4.0.4, and 4.1.x and 4.2.x before 4.2rc2 does not reject non-ASCII characters in e-mail ad…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0440

Published Feb 2, 2012

Cross-site request forgery (CSRF) vulnerability in jsonrpc.cgi in Bugzilla 3.5.x and 3.6.x before 3.6.8, 3.7.x and 4.0.x before 4.0.4, and 4.1.x and 4.2.x before 4.2rc2 allows rem…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3463

Published Feb 2, 2012

WebDAV Sharing in Apple Mac OS X 10.7.x before 10.7.3 does not properly perform authentication, which allows local users to gain privileges by leveraging access to (1) the server…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3462

Published Feb 2, 2012

Time Machine in Apple Mac OS X before 10.7.3 does not verify the unique identifier of its remote AFP volume or Time Capsule, which allows remote attackers to obtain sensitive info…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3460

Published Feb 2, 2012

Buffer overflow in QuickTime in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PNG f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3459

Published Feb 2, 2012

Off-by-one error in QuickTime in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted rdrf…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3458

Published Feb 2, 2012

QuickTime in Apple Mac OS X before 10.7.3 does not prevent access to uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of s…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3457

Published Feb 2, 2012

The OpenGL implementation in Apple Mac OS X before 10.7.3 does not properly perform OpenGL Shading Language (aka GLSL) compilation, which allows remote attackers to execute arbitr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3453

Published Feb 2, 2012

Integer overflow in libresolv in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and applicatio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3452

Published Feb 2, 2012

Internet Sharing in Apple Mac OS X before 10.7.3 does not preserve the Wi-Fi configuration across software updates, which allows remote attackers to obtain sensitive information b…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3450

Published Feb 2, 2012

CoreUI in Apple Mac OS X 10.7.x before 10.7.3 does not properly restrict the allocation of stack memory, which allows remote attackers to execute arbitrary code or cause a denial…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3449

Published Feb 2, 2012

Use-after-free vulnerability in CoreText in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a c…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3448

Published Feb 2, 2012

Heap-based buffer overflow in CoreMedia in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a cr…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3447

Published Feb 2, 2012

CFNetwork in Apple Mac OS X 10.7.x before 10.7.3 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensitive information…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3446

Published Feb 2, 2012

Apple Type Services (ATS) in Apple Mac OS X before 10.7.3 does not properly manage memory for data-font files, which allows remote attackers to execute arbitrary code or cause a d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3444

Published Feb 2, 2012

Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV da…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0983

Published Feb 2, 2012

SQL injection vulnerability in Scriptsez.net Ez Album allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-0982

Published Feb 2, 2012

SQL injection vulnerability in search.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the price_from par…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-0981

Published Feb 2, 2012

Directory traversal vulnerability in phpShowtime 2.0 allows remote attackers to list arbitrary directories and image files via a .. (dot dot) in the r parameter to index.php. NOT…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0980

Published Feb 2, 2012

SQL injection vulnerability in download.php in phux Download Manager allows remote attackers to execute arbitrary SQL commands via the file parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-0979

Published Feb 2, 2012

Cross-site scripting (XSS) vulnerability in TWiki allows remote attackers to inject arbitrary web script or HTML via the organization field in a profile, involving (1) registratio…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 4,926-4,950 of 5,288 CVEsPage 198 of 212