Skip to main content

Year archive

CVEs published in 2012

Archive summary

5,288 CVEs published in 2012 — 950 Critical, 794 High, 3,036 Medium, 506 Low, 2 Unrated.

CVE-2012-5452

Published Oct 22, 2012

Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS 2.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) multi_title parameter to blocks/…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5169

Published Oct 22, 2012

Multiple cross-site scripting (XSS) vulnerabilities in file_manager/preview_top.php in ATutor AContent before 1.2-2 allow remote attackers to inject arbitrary web script or HTML v…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5168

Published Oct 22, 2012

ATutor AContent before 1.2-1 allows remote attackers to modify arbitrary user passwords or category names via a direct request to (1) user/index_inline_editor_submit.php or (2) co…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5167

Published Oct 22, 2012

Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands via the (1) field parameter to course_category/inde…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4990

Published Oct 22, 2012

SQL injection vulnerability in admin/campaign-zone-link.php in OpenX 2.8.10 before revision 81823 allows remote attackers to execute arbitrary SQL commands via the ids[] parameter…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4989

Published Oct 22, 2012

Cross-site scripting (XSS) vulnerability in admin/plugin-index.php in OpenX 2.8.10 before revision 81823 allows remote attackers to inject arbitrary web script or HTML via the par…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4773

Published Oct 22, 2012

Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack the authentication of administrators for requests that add,…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4772

Published Oct 22, 2012

SQL injection vulnerability in register/ in Subrion CMS before 2.2.3 allows remote attackers to execute arbitrary SQL commands via the plan_id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4771

Published Oct 22, 2012

Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) admin/acc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4518

Published Oct 22, 2012

ibacm 1.0.7 creates files with world-writable permissions, which allows local users to overwrite the ib_acm daemon log or ibacm.port file.

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-4517

Published Oct 22, 2012

ibacm before 1.0.6 does not properly manage reference counts for multicast connections, which allows remote attackers to cause a denial of service (ibacm service crash) via a craf…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4516

Published Oct 22, 2012

librdmacm 1.0.16, when ibacm.port is not specified, connects to port 6125, which allows remote attackers to specify the address resolution information for the application via a ma…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4511

Published Oct 22, 2012

services/flickr/flickr.c in libsocialweb before 0.25.21 automatically connects to Flickr when no Flickr account is set, which might allow remote attackers to obtain sensitive info…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4507

Published Oct 22, 2012

The strchr function in procmime.c in Claws Mail (aka claws-mail) 3.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted emai…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4506

Published Oct 22, 2012

Directory traversal vulnerability in gitolite 3.x before 3.1, when wild card repositories and a pattern matching "../" are enabled, allows remote authenticated users to create arb…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4436

Published Oct 22, 2012

Buffer overflow in the run_last_args function in client/fwknop.c in fwknop before 2.0.3, when processing --last, might allow local users to cause a denial of service (client crash…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4435

Published Oct 22, 2012

fwknop before 2.0.3 does not properly validate IP addresses, which allows remote authenticated users to cause a denial of service (server crash) via a long IP address.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4232

Published Oct 22, 2012

SQL injection vulnerability in admin/index.php in jCore before 1.0pre2 allows remote attackers to execute arbitrary SQL commands via the memberloginid cookie.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4231

Published Oct 22, 2012

Cross-site scripting (XSS) vulnerability in admin/index.php in jCore before 1.0pre2 allows remote attackers to inject arbitrary web script or HTML via the path parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3466

Published Oct 22, 2012

GNOME gnome-keyring 3.4.0 through 3.4.1, when gpg-cache-method is set to "idle" or "timeout," does not properly limit the amount of time a passphrase is cached, which allows attac…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2679

Published Oct 22, 2012

Red Hat Network (RHN) Configuration Client (rhncfg-client) in rhncfg before 5.10.27-8 uses weak permissions (world-readable) for /var/log/rhncfg-actions, which allows local users…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-1900

Published Oct 22, 2012

Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators for request…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5212

Published Oct 22, 2012

SQL injection vulnerability in admin/index.php in Subrion CMS 2.0.4 allows remote attackers to execute arbitrary SQL commands via the (1) user name or (2) password field.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 776-800 of 5,288 CVEsPage 32 of 212