Skip to main content

Year archive

CVEs published in 2012

Archive summary

5,288 CVEs published in 2012 — 950 Critical, 794 High, 3,036 Medium, 506 Low, 2 Unrated.

CVE-2012-4194

Published Oct 29, 2012

Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 do not prevent use of t…

CVSS 4.3 · Medium

CVE-2012-4447

Published Oct 28, 2012

Heap-based buffer overflow in tif_pixarlog.c in LibTIFF before 4.0.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code v…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5470

Published Oct 26, 2012

libpng_plugin in VideoLAN VLC media player 2.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted PNG file.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4729

Published Oct 26, 2012

Wing FTP Server before 4.1.1 allows remote authenticated users to cause a denial of service (daemon crash) via two zip commands.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4501

Published Oct 26, 2012

Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API c…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-4019

Published Oct 26, 2012

Cross-site scripting (XSS) vulnerability in tokyo_bbs.cgi in Come on Girls Interface (CGI) Tokyo BBS allows remote attackers to inject arbitrary web script or HTML via vectors rel…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5235

Published Oct 25, 2012

SQL injection vulnerability in mnoGoSearch before 3.3.12 allows remote attackers to execute arbitrary SQL commands via the hostname in a hypertext link.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-5233

Published Oct 25, 2012

Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows Per Strip" and "Samples Per Pixel" values in a TIFF image f…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5230

Published Oct 25, 2012

Multiple SQL injection vulnerabilities in the selectUserIdByLoginPass function in seotoaster_core/application/models/LoginModel.php in Seotoaster 1.9 and earlier allow remote atta…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-5229

Published Oct 25, 2012

SQL injection vulnerability in quickstart/profile/index.php in the Forum module in appRain CMF 0.1.5 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-5228

Published Oct 25, 2012

Cross-site scripting (XSS) vulnerability in the Search module (quickstart/search) in appRain CMF 0.1.5 allows remote attackers to inject arbitrary web script or HTML via the ss pa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5227

Published Oct 25, 2012

Stack-based buffer overflow in the Syslog service (nssyslogd.exe) in Enterasys Network Management Suite (NMS) before 4.1.0.80 allows remote attackers to execute arbitrary code via…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-5226

Published Oct 25, 2012

Cross-site request forgery (CSRF) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to hijack the authentication of an adm…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5225

Published Oct 25, 2012

Cross-site scripting (XSS) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via un…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5223

Published Oct 25, 2012

Cross-site request forgery (CSRF) vulnerability in logout.php in Cacti before 0.8.7i allows remote attackers to hijack the authentication of unspecified victims via unknown vector…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5222

Published Oct 25, 2012

SQL injection vulnerability in rub2_w.php in PHP Flirt-Projekt 4.8 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the rub parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-5221

Published Oct 25, 2012

Cross-site scripting (XSS) vulnerability in the getLog function in svnlook.php in WebSVN before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the path p…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5220

Published Oct 25, 2012

Cross-site scripting (XSS) vulnerability in templates/default/Admin/Login.html in PHP-SCMS 1.6.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5219

Published Oct 25, 2012

Directory traversal vulnerability in examples/show_code.php in mPDF 5.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5218

Published Oct 25, 2012

SQL injection vulnerability in DotA OpenStats 1.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-5216

Published Oct 25, 2012

SQL injection vulnerability in ajax.php in SCORM Cloud For WordPress plugin before 1.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the active par…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 726-750 of 5,288 CVEsPage 30 of 212