Skip to main content

Year archive

CVEs published in 2012

Archive summary

5,288 CVEs published in 2012 — 950 Critical, 794 High, 3,036 Medium, 506 Low, 2 Unrated.

CVE-2012-1813

Published Nov 13, 2012

eosfailoverservice.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to cause a denial of service by sending a large amount of data to TCP port 12000.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1812

Published Nov 13, 2012

eosfailoverservice.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to obtain sensitive cleartext information via a session on TCP port 12000.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1811

Published Nov 13, 2012

EOSDataServer.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to cause a denial of service by sending a large amount of data to TCP port 24006.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1810

Published Nov 13, 2012

EOSCoreScada.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to cause a denial of service (daemon restart) by sending data to TCP port (1) 5050 or (2) 24004.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5827

Published Nov 11, 2012

Joomla! 2.5.x before 2.5.8 and 3.0.x before 3.0.2 allows remote attackers to conduct clickjacking attacks via unspecified vectors involving "Inadequate protection."

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4884

Published Nov 11, 2012

Argument injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to create arbitrary files via unspecified vectors relat…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4734

Published Nov 11, 2012

Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to conduct a "confused deputy" attack to bypass the CSRF warning protection mechanism and c…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4732

Published Nov 11, 2012

Cross-site request forgery (CSRF) vulnerability in Request Tracker (RT) 3.8.12 and other versions before 3.8.15, and 4.0.6 and other versions before 4.0.8, allows remote attackers…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4731

Published Nov 11, 2012

FAQ manager for Request Tracker (RTFM) before 2.4.5 does not properly check user rights, which allows remote authenticated users to create arbitrary articles in arbitrary classes…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4730

Published Nov 11, 2012

Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote authenticated users with ModifySelf or AdminUser privileges to inject arbitrary email headers and con…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-4554

Published Nov 11, 2012

The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE declaration in an XRDS file.

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2012-4553

Published Nov 11, 2012

Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an external database server, relat…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4548

Published Nov 11, 2012

Argument injection vulnerability in syntax-highlighting.sh in cgit 9.0.3 and earlier allows remote authenticated users with permissions to add files to execute arbitrary commands…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4540

Published Nov 11, 2012

Off-by-one error in the invoke function in IcedTeaScriptablePluginObject.cc in IcedTea-Web 1.1.x before 1.1.7, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.x before 1.4.1 allow…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4515

Published Nov 11, 2012

Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows remote attackers to cause a denial of service…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4514

Published Nov 11, 2012

rendering/render_replaced.cpp in Konqueror in KDE before 4.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted web page, related to "…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4513

Published Nov 11, 2012

khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via large canvas dimensions, which…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4505

Published Nov 11, 2012

Heap-based buffer overflow in the px_pac_reload function in lib/pac.c in libproxy 0.2.x and 0.3.x allows remote servers to have an unspecified impact via a crafted Content-Length…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-4504

Published Nov 11, 2012

Stack-based buffer overflow in the url::get_pac function in url.cpp in libproxy 0.4.x before 0.4.9 allows remote servers to have an unspecified impact via a large proxy.pac file.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 551-575 of 5,288 CVEsPage 23 of 212