Skip to main content

Year archive

CVEs published in 2012

Archive summary

5,288 CVEs published in 2012 — 950 Critical, 794 High, 3,036 Medium, 506 Low, 2 Unrated.

CVE-2012-5907

Published Nov 17, 2012

Directory traversal vulnerability in json.php in TomatoCart 1.2.0 Alpha 2 and possibly earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the module par…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5906

Published Nov 17, 2012

Multiple cross-site scripting (XSS) vulnerabilities in GreenBrowser 6.1.0117 and 6.1.0216 allow remote attackers to inject arbitrary web script or HTML via (1) the URI in an about…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5905

Published Nov 17, 2012

Buffer overflow in KnFTPd 1.0.0 allows remote authenticated users to cause a denial of service (crash) via a long string in a FEAT command.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5904

Published Nov 17, 2012

Heap-based buffer overflow in IrfanView before 4.33 allows remote attackers to execute arbitrary code via a crafted RLE compressed bitmap file such as a DIB, RLE, or BMP image.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5903

Published Nov 17, 2012

Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the scheduled parameter to index.p…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5902

Published Nov 17, 2012

Cross-site scripting (XSS) vulnerability in ptk/lib/modal_bookmark.php in DFLabs PTK 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the arg4 parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5901

Published Nov 17, 2012

DFLabs PTK 1.0.5 stores data files with predictable names under the web document root with insufficient access control, which allows remote attackers to read logs, images, or repo…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5900

Published Nov 17, 2012

Multiple SQL injection vulnerabilities in SAMEDIA LandShop 0.9.2 allow remote attackers to execute arbitrary SQL commands via the (1) OB_ID parameter in a single action to admin/a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5899

Published Nov 17, 2012

Cross-site scripting (XSS) vulnerability in admin/action/objects.php in SAMEDIA LandShop 0.9.2 allows remote attackers to inject arbitrary web script or HTML via the OTR_HEADS[] p…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5898

Published Nov 17, 2012

Cross-site request forgery (CSRF) vulnerability in SAMEDIA LandShop 0.9.2 allows remote attackers to hijack the authentication of administrators for requests that change account s…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5897

Published Nov 17, 2012

The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and earlier do not properly implement the SaveToFile method, whi…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-5896

Published Nov 17, 2012

The Annotation Objects Extension ActiveX control in AnnotateX.dll in Quest InTrust 10.4.0.853 and earlier does not properly implement the Add method, which allows remote attackers…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-5895

Published Nov 17, 2012

Multiple unspecified vulnerabilities in iRODS before 3.1 have unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-5894

Published Nov 17, 2012

SQL injection vulnerability in hava_post.php in Havalite CMS 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the postId parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5893

Published Nov 17, 2012

Unrestricted file upload vulnerability in hava_upload.php in Havalite CMS 1.1.0 and earlier allows remote attackers to execute arbitrary code by uploading a file with a .php;.gif…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5892

Published Nov 17, 2012

Havalite CMS 1.1.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the configuration databa…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5891

Published Nov 17, 2012

Multiple cross-site request forgery (CSRF) vulnerabilities in photo/pass.php in DAlbum 1.44 build 174 and earlier allow remote attackers to hijack the authentication of administra…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5889

Published Nov 17, 2012

Cross-site scripting (XSS) vulnerability in the powermail extension before 1.6.5 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5888

Published Nov 17, 2012

Cross-site scripting (XSS) vulnerability in Basic SEO Features (seo_basics) extension before 0.8.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via uns…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5887

Published Nov 17, 2012

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5886

Published Nov 17, 2012

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5885

Published Nov 17, 2012

The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 trac…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5172

Published Nov 16, 2012

The Asial Monaca Debugger application before 1.4.2 for Android allows remote attackers to obtain sensitive (1) account or (2) session ID information in a system log file via a cra…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 476-500 of 5,288 CVEsPage 20 of 212