Skip to main content

Year archive

CVEs published in 2012

Archive summary

5,288 CVEs published in 2012 — 950 Critical, 794 High, 3,036 Medium, 506 Low, 2 Unrated.

CVE-2011-5211

Published Oct 22, 2012

Cross-site scripting (XSS) vulnerability in the poll module in Subrion CMS 2.0.4 allows remote attackers to inject arbitrary web script or HTML via the title field. NOTE: some of…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4129

Published Oct 22, 2012

(1) services/twitter/twitter-contact-view.c and (2) services/twitter/twitter-item-view.c in libsocialweb before 0.25.20 automatically connect to Twitter when no Twitter account is…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4821

Published Oct 22, 2012

Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.6.9 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4751

Published Oct 22, 2012

Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.15, 3.0.x before 3.0.17, and 3.1.x before 3.1.11 allows remote attackers t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3001

Published Oct 22, 2012

Mutiny Standard before 4.5-1.12 allows remote attackers to execute arbitrary commands via the network-interface menu, related to a "command injection vulnerability."

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4933

Published Oct 20, 2012

The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username of Ivanhoe and a hard-coded password of Scott for the (1) Ge…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4845

Published Oct 20, 2012

The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC environment, which allows attackers to bypass intended file-rea…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4826

Published Oct 20, 2012

Stack-based buffer overflow in the SQL/PSM (aka SQL Persistent Stored Module) Stored Procedure (SP) infrastructure in IBM DB2 9.1, 9.5, 9.7 before FP7, 9.8, and 10.1 might allow r…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-2972

Published Oct 20, 2012

The (1) server and (2) agent components in CA ARCserve Backup r12.5, r15, and r16 on Windows do not properly validate RPC requests, which allows remote attackers to cause a denial…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2971

Published Oct 20, 2012

The server in CA ARCserve Backup r12.5, r15, and r16 on Windows does not properly process RPC requests, which allows remote attackers to execute arbitrary code or cause a denial o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-0306

Published Oct 18, 2012

Symantec Ghost Solution Suite 2.x through 2.5.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted backup file.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5095

Published Oct 17, 2012

Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to inetd.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5094

Published Oct 17, 2012

Unspecified vulnerability in the Oracle Agile PLM for Process component in Oracle Supply Chain Products Suite 5.2.2 and 6.1.0.0 allows remote attackers to affect confidentiality v…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5093

Published Oct 17, 2012

Unspecified vulnerability in the Oracle Agile PLM for Process component in Oracle Supply Chain Products Suite 5.2.2 and 6.1.0.0 allows remote attackers to affect integrity via unk…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5092

Published Oct 17, 2012

Unspecified vulnerability in the Oracle Agile PLM for Process component in Oracle Supply Chain Products Suite 5.2.2 and 6.1.0.0 allows remote authenticated users to affect confide…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5091

Published Oct 17, 2012

Unspecified vulnerability in the Oracle Agile Product Supplier Collaboration for Process component in Oracle Supply Chain Products Suite 5.2.2 and 6.1.0.0 allows remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5090

Published Oct 17, 2012

Unspecified vulnerability in the Oracle Agile PLM for Process component in Oracle Supply Chain Products Suite 5.2.2 and 6.1.0.0 allows remote authenticated users to affect confide…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5066

Published Oct 17, 2012

Unspecified vulnerability in the Oracle Central Designer component in Oracle Industry Applications 1.3, 1.4, and 1.4.2 allows remote attackers to affect confidentiality, integrity…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5065

Published Oct 17, 2012

Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2, and 11.1.1.6.0 allows loc…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-5064

Published Oct 17, 2012

Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0, 10.0.2, 10.1.0, 10.2.0, 10.2.2, 10.3.0, 10.5.0, and 11.0…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-5063

Published Oct 17, 2012

Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0, 10.0.2, 10.1.0, 10.2.0, 10.2.2, 10.3.0, 10.5.0, 11.0.0 t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5061

Published Oct 17, 2012

Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0, 10.0.2, 10.1.0, 10.2.0, 10.2.2, 10.3.0, 10.5.0, 11.0.0 t…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 801-825 of 5,288 CVEsPage 33 of 212