Skip to main content

Year archive

CVEs published in 2012

Archive summary

5,288 CVEs published in 2012 — 950 Critical, 794 High, 3,036 Medium, 506 Low, 2 Unrated.

CVE-2012-2733

Published Nov 16, 2012

java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not properly restrict the request…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5884

Published Nov 16, 2012

The User.get method in Bugzilla/WebService/User.pm in Bugzilla 4.3.2 allows remote attackers to obtain sensitive information about the saved searches of arbitrary users via an XML…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5883

Published Nov 16, 2012

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.9.0, as used in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5882

Published Nov 16, 2012

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vector…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5881

Published Nov 16, 2012

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vector…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4199

Published Nov 16, 2012

template/en/default/bug/field-events.js.tmpl in Bugzilla 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 generates…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4198

Published Nov 16, 2012

The User.get method in Bugzilla/WebService/User.pm in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 has a different outcom…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4197

Published Nov 16, 2012

Bugzilla/Attachment.pm in attachment.cgi in Bugzilla 2.x and 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 allow…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4189

Published Nov 16, 2012

Cross-site scripting (XSS) vulnerability in Bugzilla 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1, allows remote attackers to inject arbitrary web script or HTM…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5777

Published Nov 16, 2012

Eval injection vulnerability in the ReplaceListVars function in the template parser in e/class/connect.php in EmpireCMS 6.6 allows user-assisted remote attackers to execute arbitr…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5523

Published Nov 16, 2012

core/email_api.php in MantisBT before 1.2.12 does not properly manage the sending of e-mail notifications about restricted bugs, which might allow remote authenticated users to ob…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5522

Published Nov 16, 2012

MantisBT before 1.2.12 does not use an expected default value during decisions about whether a user may modify the status of a bug, which allows remote authenticated users to bypa…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4613

Published Nov 16, 2012

EMC RSA Data Protection Manager Appliance 2.7.x and 3.x before 3.2.1 does not properly restrict the number of authentication attempts by a user account, which makes it easier for…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5851

Published Nov 15, 2012

html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which make…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4955

Published Nov 15, 2012

Cross-site scripting (XSS) vulnerability in Dell OpenManage Server Administrator (OMSA) before 6.5.0.1, 7.0 before 7.0.0.1, and 7.1 before 7.1.0.1 allows remote attackers to injec…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4951

Published Nov 15, 2012

Multiple SQL injection vulnerabilities in terminal/paramedit.aspx in VeriFone VeriCentre Web Console before 2.2 build 36 allow remote attackers to execute arbitrary SQL commands v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5860

Published Nov 14, 2012

Unspecified vulnerability on Oberthur ID-One COSMO 5.2, 5.2a, and 64 smart cards makes it easier for attackers to defeat cryptographic protection mechanisms by leveraging the gene…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4949

Published Nov 14, 2012

SQL injection vulnerability in ESRI ArcGIS 10.1 allows remote authenticated users to execute arbitrary SQL commands via the where parameter to a query URI for a REST service.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4853

Published Nov 14, 2012

Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Application Server 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows rem…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 501-525 of 5,288 CVEsPage 21 of 212