Skip to main content

Year archive

CVEs published in 2012

Archive summary

5,288 CVEs published in 2012 — 950 Critical, 794 High, 3,036 Medium, 506 Low, 2 Unrated.

CVE-2011-5214

Published Oct 25, 2012

Multiple cross-site scripting (XSS) vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5213

Published Oct 25, 2012

Multiple SQL injection vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login[username] parameter to index.p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-3941

Published Oct 25, 2012

Heap-based buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 before LD SP32 EP10 and T28 before T28.4 allows remote attackers to execute arbitrary code via a cr…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-3940

Published Oct 25, 2012

Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 before LD SP32 EP10 and T28 before T28.4 allows remote attackers to execute arbitrary code via a crafted WRF f…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-3939

Published Oct 25, 2012

Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 before LD SP32 EP10 and T28 before T28.4 allows remote attackers to execute arbitrary code or cause a denial o…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-3938

Published Oct 25, 2012

Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 before LD SP32 EP10 and T28 before T28.4 allows remote attackers to execute arbitrary code via a crafted WRF f…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-3937

Published Oct 25, 2012

Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 before LD SP32 EP10 and T28 before T28.4 allows remote attackers to execute arbitrary code via a crafted WRF f…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-3936

Published Oct 25, 2012

Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 before LD SP32 EP10 and T28 before T28.4 allows remote attackers to execute arbitrary code via a crafted WRF f…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-5368

Published Oct 25, 2012

phpMyAdmin 3.5.x before 3.5.3 uses JavaScript code that is obtained through an HTTP session to phpmyadmin.net without SSL, which allows man-in-the-middle attackers to conduct cros…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5339

Published Oct 25, 2012

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.3 allow remote authenticated users to inject arbitrary web script or HTML via a crafted name of…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-3506

Published Oct 25, 2012

Unspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-5456

Published Oct 24, 2012

The Zoner AntiVirus Free application for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, w…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5302

Published Oct 24, 2012

The server in TIBCO Formvine 3.1.x and 3.2.x before 3.2.1 does not properly implement access control, which allows remote attackers to obtain sensitive information or modify data…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5273

Published Oct 23, 2012

Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4172, CVE-2…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2012-4176

Published Oct 23, 2012

Array index error in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors.

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2012-4175

Published Oct 23, 2012

Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4172, CVE-2…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2012-4174

Published Oct 23, 2012

Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4172, CVE-2…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2012-4173

Published Oct 23, 2012

Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4172, CVE-2…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2012-4172

Published Oct 23, 2012

Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4173, CVE-2…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2012-5455

Published Oct 22, 2012

Cross-site scripting (XSS) vulnerability in the language search component in Joomla! before 3.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified ve…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5454

Published Oct 22, 2012

user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arbitrary user passwords via a cr…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5453

Published Oct 22, 2012

SQL injection vulnerability in user/index_inline_editor_submit.php in ATutor AContent 1.2-1 allows remote authenticated users to execute arbitrary SQL commands via the field param…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 751-775 of 5,288 CVEsPage 31 of 212