Skip to main content

Year archive

CVEs published in 2012

Archive summary

5,288 CVEs published in 2012 — 950 Critical, 794 High, 3,036 Medium, 506 Low, 2 Unrated.

CVE-2012-3523

Published Nov 11, 2012

The STARTTLS implementation in nnrpd in INN before 2.5.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted sessi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2455

Published Nov 10, 2012

Advanced Productivity Software DTE Axiom before 12.3.3 does not validate the registration ID, which allows remote attackers to bypass authentication and read or modify data about…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3758

Published Nov 9, 2012

Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted transform attribut…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2012-3757

Published Nov 9, 2012

Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted PICT file.

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2012-3756

Published Nov 9, 2012

Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted rnet box in an MP4…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2012-3755

Published Nov 9, 2012

Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Targa image.

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2012-3754

Published Nov 9, 2012

Use-after-free vulnerability in the Clear method in the ActiveX control in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of serv…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2012-3753

Published Nov 9, 2012

Buffer overflow in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MIME…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2012-3752

Published Nov 9, 2012

Multiple buffer overflows in Apple QuickTime before 7.7.3 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted style ele…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2012-3751

Published Nov 9, 2012

Use-after-free vulnerability in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2011-1374

Published Nov 9, 2012

Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted REGION record in a…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2012-5171

Published Nov 8, 2012

Directory traversal vulnerability in Be Graph BeZIP before 3.10 allows remote attackers to create or overwrite arbitrary files via a crafted archive file.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4023

Published Nov 8, 2012

CRLF injection vulnerability in Pebble before 2.6.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4022

Published Nov 8, 2012

Pebble before 2.6.4 allows remote attackers to trigger loss of blog-entry viewability via a crafted comment.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4021

Published Nov 8, 2012

MosP kintai kanri before 4.1.0 does not properly perform authentication, which allows remote authenticated users to impersonate arbitrary user accounts, and consequently obtain se…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4020

Published Nov 8, 2012

MosP kintai kanri before 4.1.0 does not enforce privilege requirements, which allows remote authenticated users to read other users' information via unspecified vectors.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5424

Published Nov 7, 2012

Cisco Secure Access Control System (ACS) 5.x before 5.2 Patch 11 and 5.3 before 5.3 Patch 7, when a certain configuration involving TACACS+ and LDAP is used, does not properly val…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3270

Published Nov 7, 2012

Unspecified vulnerability in HP Performance Insight 5.31, 5.40, and 5.41, when Sybase is used, allows remote attackers to obtain sensitive information, modify data, or cause a den…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-3269

Published Nov 7, 2012

Unspecified vulnerability in HP Performance Insight 5.31, 5.40, and 5.41, when Sybase is used, allows remote attackers to obtain sensitive information, modify data, or cause a den…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5127

Published Nov 7, 2012

Integer overflow in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a cra…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5126

Published Nov 7, 2012

Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors relate…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5125

Published Nov 7, 2012

Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors relate…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5124

Published Nov 7, 2012

Google Chrome before 23.0.1271.64 does not properly handle textures, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified ot…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 576-600 of 5,288 CVEsPage 24 of 212