CVEs from 2012
Total
5,200
critical
critical 963
high
high 747
medium
medium 2,885
low
low 530
% Critical
18.5%
% with KEV
0.4%
% with exploit
8.8%
Top vendors
Top products
- chrome 7,005
- safari 6,451
- itunes 4,416
- firefox 4,272
- seamonkey 3,619
- opera_browser 3,599
- mysql 2,827
- thunderbird 2,165
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2012-3834 | medium | — | 6.5 | 14y ago | SQL injection vulnerability in forensics/base_qry_main.php in AlienVault Open Source Security Information Management (OSSIM) 3.1 allows remote authenticated users to execute arbitrary SQL commands vi… | |||
| CVE-2012-2171 | medium | — | 6.5 | 14y ago | SQL injection vulnerability in ModuleServlet.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote authenticated users to e… | |||
| CVE-2012-2670 | medium | — | 6.5 | 14y ago | manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by u… | |||
| CVE-2012-0037 | medium | 6.5 | 6.5 | 14y ago | Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read… | |||
| CVE-2012-1828 | medium | — | 6.5 | 14y ago | The administrative functions in AutoFORM PDM Archive before 7.1 do not have authorization requirements, which allows remote authenticated users to perform administrative actions by leveraging knowled… | |||
| CVE-2012-1827 | medium | — | 6.5 | 14y ago | The web service in AutoFORM PDM Archive before 7.1 does not have authorization requirements, which allows remote authenticated users to perform database operations via a SOAP request, as demonstrated… | |||
| CVE-2012-2603 | medium | — | 6.5 | 14y ago | The server in CollabNet ScrumWorks Pro before 6.0 allows remote authenticated users to gain privileges and obtain sensitive information via a modified desktop client. | |||
| CVE-2012-1798 | medium | 6.5 | 6.5 | 14y ago | The TIFFGetEXIFProperties function in coders/tiff.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted EXIF IFD in a TIFF … | |||
| CVE-2012-0260 | medium | 6.5 | 6.5 | 14y ago | The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a JPEG image with a crafted sequence of re… | |||
| CVE-2012-0259 | medium | 6.5 | 6.5 | 14y ago | The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a zero value in the component count of an EXIF XResolu… | |||
| CVE-2012-2939 | medium | — | 6.5 | 14y ago | Multiple unrestricted file upload vulnerabilities in Travelon Express 6.2.2 allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension using (1) airli… | |||
| CVE-2012-2435 | medium | — | 6.5 | 14y ago | Directory traversal vulnerability in the captcha module in Pligg CMS before 1.2.2 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the captcha para… | |||
| CVE-2012-0564 | medium | — | 6.5 | 14y ago | Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50 and 8.51 allows remote authenticated users to affect confidentiality, integrity, and av… | |||
| CVE-2012-0337 | medium | — | 6.5 | 14y ago | SQL injection vulnerability in the web component in Cisco Unified MeetingPlace 7.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCtx08939. | |||
| CVE-2012-2416 | medium | — | 6.5 | 14y ago | chan_sip.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.11.1 and 10.x before 10.3.1 and Asterisk Business Edition C.3.x before C.3.7.4, when the trustrpid option is enabled, all… | |||
| CVE-2012-2415 | medium | — | 6.5 | 14y ago | Heap-based buffer overflow in chan_skinny.c in the Skinny channel driver in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x before 10.3.1 allows remote authenticated use… | |||
| CVE-2012-2414 | medium | — | 6.5 | 14y ago | main/manager.c in the Manager Interface in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x before 10.3.1 and Asterisk Business Edition C.3.x before C.3.7.4 does not prop… | |||
| CVE-2012-2111 | medium | — | 6.5 | 14y ago | The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not p… | |||
| CVE-2012-2236 | medium | — | 6.5 | 14y ago | SQL injection vulnerability in users.php in PHP Gift Registry 1.5.5 allows remote authenticated users to execute arbitrary SQL commands via the userid parameter in an edit action. | |||
| CVE-2012-2230 | medium | — | 6.5 | 14y ago | Cloudera Manager 3.7.x before 3.7.5 and Service and Configuration Manager 3.5, when Kerberos is not enabled, does not properly install taskcontroller.cfg, which allows remote authenticated users to i… | |||
| CVE-2012-1574 | medium | — | 6.5 | 14y ago | Apache Hadoop allows impersonation of arbitrary cluster user accounts | |||
| CVE-2012-0401 | medium | — | 6.5 | 14y ago | Multiple SQL injection vulnerabilities in EMC RSA enVision 4.x before 4.1 Patch 4 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |||
| CVE-2012-0319 | medium | — | 6.5 | 14y ago | The file-management system in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote authenticated users to execute arbitrary commands by leveraging the file-upload feature, r… | |||
| CVE-2012-1234 | medium | — | 6.5 | 15y ago | SQL injection vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to execute arbitrary SQL commands via a malformed URL. NOTE: this vulnerability exists because of an… | |||
| CVE-2012-1079 | medium | — | 6.5 | 15y ago | Unspecified vulnerability in the Webservices for TYPO3 (typo3_webservice) extension before 0.3.8 for TYPO3 allows remote authenticated users to execute arbitrary code via unknown vectors. | |||
| CVE-2012-0814 | medium | 6.5 | 6.5 | 15y ago | The auth_parse_options function in auth-options.c in sshd in OpenSSH before 5.7 provides debug messages containing authorized_keys command options, which allows remote authenticated users to obtain p… | |||
| CVE-2012-0806 | medium | — | 6.5 | 15y ago | Buffer overflow in Bip 0.8.8 and earlier might allow remote authenticated users to execute arbitrary code via vectors involving a series of TCP connections that triggers use of many open file descrip… | |||
| CVE-2012-4520 | medium | — | 6.4 | 4y ago | The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host… | |||
| CVE-2012-5486 | medium | — | 6.4 | 8y ago | ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character. | |||
| CVE-2012-2660 | medium | — | 6.4 | 9y ago | Action Pack contains database-query restrictions bypass | |||
| CVE-2012-5032 | medium | — | 6.4 | 12y ago | The Flex-VPN load-balancing feature in the ipsec-ikev2 implementation in Cisco IOS before 15.1(1)SY3 does not require authentication, which allows remote attackers to trigger the forwarding of VPN tr… | |||
| CVE-2012-6619 | medium | — | 6.4 | 12y ago | The default configuration for MongoDB before 2.3.2 does not validate objects, which allows remote authenticated users to cause a denial of service (crash) or read system memory via a crafted BSON obj… | |||
| CVE-2012-6634 | medium | — | 6.4 | 13y ago | wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value. | |||
| CVE-2012-5575 | medium | — | 6.4 | 13y ago | Inadequate Encryption Strength in Apache CXF | |||
| CVE-2012-6579 | medium | — | 6.4 | 13y ago | Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, allows remote attackers to configure encryption or signing for certain outbound e-mail, and possibly cau… | |||
| CVE-2012-6531 | medium | — | 6.4 | 14y ago | Zend Framework XEE Vulnerability | |||
| CVE-2012-6102 | medium | — | 6.4 | 14y ago | lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to read or modify the submission comments (aka feedback … | |||
| CVE-2012-3190 | medium | — | 6.4 | 14y ago | Unspecified vulnerability in the Oracle Universal Work Queue component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and i… | |||
| CVE-2012-6080 | medium | — | 6.4 | 14y ago | Directory traversal vulnerability in the _do_attachment_move function in the AttachFile action (action/AttachFile.py) in MoinMoin 1.9.3 through 1.9.5 allows remote attackers to overwrite arbitrary fi… | |||
| CVE-2012-6431 | medium | — | 6.4 | 14y ago | Symfony Allows URI Restrictions Bypass Via Double-Encoded String | |||
| CVE-2012-0430 | medium | — | 6.4 | 14y ago | Unspecified vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 on Windows allows remote attackers to obtain an administrator cookie and bypass authorization checks vi… | |||
| CVE-2012-5930 | medium | — | 6.4 | 14y ago | The pa_modify_accounts function in auth.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 does not require authentication for the modifyAccounts method, which allows remote at… | |||
| CVE-2012-5954 | medium | — | 6.4 | 14y ago | Unspecified vulnerability in IBM Tivoli Storage Manager for Space Management (aka TSM HSM) before 6.2.5.0 and 6.3.x before 6.3.1.0 allows remote attackers to read or modify HSM-managed file system ob… | |||
| CVE-2012-6050 | medium | — | 6.4 | 14y ago | The winbox service in MikroTik RouterOS 5.15 and earlier allows remote attackers to cause a denial of service (CPU consumption), read the router version, and possibly have other impacts via a request… | |||
| CVE-2012-5480 | medium | — | 6.4 | 14y ago | The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended restrictions on reading other participants' entries vi… | |||
| CVE-2012-4566 | medium | — | 6.4 | 14y ago | The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the ce… | |||
| CVE-2012-4523 | medium | — | 6.4 | 14y ago | radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, whi… | |||
| CVE-2012-4513 | medium | — | 6.4 | 14y ago | khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via large canvas dimensions, which leads to an unexpect… | |||
| CVE-2012-2455 | medium | — | 6.4 | 14y ago | Advanced Productivity Software DTE Axiom before 12.3.3 does not validate the registration ID, which allows remote attackers to bypass authentication and read or modify data about users, customers, an… | |||
| CVE-2012-4022 | medium | — | 6.4 | 14y ago | Pebble before 2.6.4 allows remote attackers to trigger loss of blog-entry viewability via a crafted comment. | |||
| CVE-2012-4196 | medium | — | 6.4 | 14y ago | Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same O… | |||
| CVE-2012-3196 | medium | — | 6.4 | 14y ago | Unspecified vulnerability in the Oracle Human Resources component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and availa… | |||
| CVE-2012-3147 | medium | — | 6.4 | 14y ago | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.26 and earlier allows remote attackers to affect integrity and availability, related to MySQL Client. | |||
| CVE-2012-5074 | medium | — | 6.4 | 14y ago | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality and integrity, related to JAX-WS. | |||
| CVE-2012-5071 | medium | — | 6.4 | 14y ago | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to a… | |||
| CVE-2012-4416 | medium | — | 6.4 | 14y ago | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality and … | |||
| CVE-2012-5351 | medium | — | 6.4 | 14y ago | Improper Authentication in Apache Axis2 | |||
| CVE-2012-3492 | medium | — | 6.4 | 14y ago | The filesystem authentication (condor_io/condor_auth_fs.cpp) in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 uses authentication directories even when they have weak permissions, which allows re… | |||
| CVE-2012-1617 | medium | — | 6.4 | 14y ago | Directory traversal vulnerability in combine.php in OSClass before 2.3.6 allows remote attackers to read and write arbitrary files via a .. (dot dot) in the type parameter. NOTE: this vulnerability … | |||
| CVE-2012-3305 | medium | — | 6.4 | 14y ago | Directory traversal vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to overwrite a… | |||
| CVE-2012-3137 | medium | — | 6.4 | 14y ago | The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, wh… | |||
| CVE-2012-3732 | medium | — | 6.4 | 14y ago | Mail in Apple iOS before 6 uses an S/MIME message's From address as the displayed sender address, which allows remote attackers to spoof signed content via an e-mail message in which the From field d… | |||
| CVE-2012-2062 | medium | — | 6.4 | 14y ago | Open redirect vulnerability in the Redirecting click bouncer module for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |||
| CVE-2012-4926 | medium | — | 6.4 | 14y ago | approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activation of administrators via the u parameter in an (1) app0 (disable) or (2) app… | |||
| CVE-2012-1635 | medium | — | 6.4 | 14y ago | The hook_node_access function in the revisioning module 7.x-1.x before 7.x-1.3 for Drupal checks the permissions of the current user even when it is called to check permissions of other users, which … | |||
| CVE-2012-4670 | medium | — | 6.4 | 14y ago | Tigase XMPP Server before 5.1.0 does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via a (1) Verify Response or (2) Author… | |||
| CVE-2012-2135 | medium | — | 6.4 | 14y ago | The utf-16 decoder in Python 3.1 through 3.3 does not update the aligned_end variable after calling the unicode_decode_call_errorhandler function, which allows remote attackers to obtain sensitive in… | |||
| CVE-2012-2330 | medium | — | 6.4 | 14y ago | The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allows remote attackers to obtain sensitive informatio… | |||
| CVE-2012-3473 | medium | — | 6.4 | 14y ago | The (1) reports API and (2) administration feature in the comments API in the Ushahidi Platform before 2.5 do not require authentication, which allows remote attackers to generate reports and organiz… | |||
| CVE-2012-3472 | medium | — | 6.4 | 14y ago | The email API in application/libraries/api/MY_Email_Api_Object.php in the Ushahidi Platform before 2.5 does not require authentication, which allows remote attackers to list, delete, or organize mess… | |||
| CVE-2012-2969 | medium | — | 6.4 | 14y ago | Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to bypass intended restrictions on filename extensions for created files via a %00 sequence in a pathname within an HTTP… | |||
| CVE-2012-1950 | medium | — | 6.4 | 14y ago | The drag-and-drop implementation in Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 allows remote attackers to spoof the address bar by canceling a page load. | |||
| CVE-2012-2279 | medium | — | 6.4 | 14y ago | Open redirect vulnerability in the Security Console in EMC RSA Authentication Manager 7.1 before SP4 P14 and RSA SecurID Appliance 3.0 before SP4 P14 allows remote attackers to redirect users to arbi… | |||
| CVE-2012-2845 | medium | — | 6.4 | 14y ago | Integer overflow in the jpeg_data_load_data function in jpeg-data.c in libjpeg in exif 0.6.20 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain p… | |||
| CVE-2012-2836 | medium | — | 6.4 | 14y ago | The exif_data_load_data function in exif-data.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly obtai… | |||
| CVE-2012-2813 | medium | — | 6.4 | 14y ago | The exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possib… | |||
| CVE-2012-2812 | medium | — | 6.4 | 14y ago | The exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly obt… | |||
| CVE-2012-1119 | medium | — | 6.4 | 14y ago | MantisBT before 1.2.9 does not audit when users copy or clone a bug report, which makes it easier for remote attackers to copy bug reports without detection. | |||
| CVE-2012-1726 | medium | — | 6.4 | 14y ago | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors … | |||
| CVE-2012-1818 | medium | — | 6.4 | 14y ago | An unspecified ActiveX control in Emerson DeltaV and DeltaV Workstations 9.3.1, 10.3.1, 11.3, and 11.3.1 and DeltaV ProEssentials Scientific Graph 5.0.0.6 allows remote attackers to overwrite arbitra… | |||
| CVE-2012-2928 | medium | — | 6.4 | 14y ago | The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to re… | |||
| CVE-2012-0298 | medium | — | 6.4 | 14y ago | The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to (1) read or (2) delete arbitrary files via unspecified vectors. | |||
| CVE-2012-0655 | medium | — | 6.4 | 14y ago | libsecurity in Apple Mac OS X before 10.7.4 does not properly restrict the length of RSA keys within X.509 certificates, which makes it easier for remote attackers to defeat cryptographic protection … | |||
| CVE-2012-1694 | medium | — | 6.4 | 14y ago | Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality and integrity, related to libsasl. | |||
| CVE-2012-0537 | medium | — | 6.4 | 14y ago | Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.1.3 allows remote attackers to affect confidentiality and integrity, related to HTML pages. | |||
| CVE-2012-0511 | medium | — | 6.4 | 14y ago | Unspecified vulnerability in the OCI component in Oracle Database Server 10.2.0.3, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality and integrity via unknown vectors. | |||
| CVE-2012-0510 | medium | — | 6.4 | 14y ago | Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, and 11.1.0.7 allows remote attackers to affect integrity and availability via unknown vec… | |||
| CVE-2012-2217 | medium | — | 6.4 | 14y ago | The HTC IQRD service for Android on the HTC EVO 4G before 4.67.651.3, EVO Design 4G before 2.12.651.5, Shift 4G before 2.77.651.3, EVO 3D before 2.17.651.5, EVO View 4G before 2.23.651.1, Vivid befor… | |||
| CVE-2012-0726 | medium | — | 6.4 | 14y ago | The default configuration of TLS in IBM Tivoli Directory Server (TDS) 6.3 and earlier supports the (1) NULL-MD5 and (2) NULL-SHA ciphers, which allows remote attackers to trigger unencrypted communic… | |||
| CVE-2012-1929 | medium | — | 6.4 | 14y ago | Opera before 11.62 on Mac OS X allows remote attackers to spoof the address field and security dialogs via crafted styling that causes page content to be displayed outside of the intended content are… | |||
| CVE-2012-1928 | medium | — | 6.4 | 14y ago | Opera before 11.62 allows remote attackers to spoof the address field by triggering a page reload followed by a redirect to a different domain. | |||
| CVE-2012-1927 | medium | — | 6.4 | 14y ago | Opera before 11.62 allows remote attackers to spoof the address field by triggering the launch of a dialog window associated with a different domain. | |||
| CVE-2012-1919 | medium | — | 6.4 | 14y ago | CRLF injection vulnerability in mime.php in @Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to conduct directory traversal attacks and read arbitrary files via a %0A se… | |||
| CVE-2012-0232 | medium | — | 6.4 | 14y ago | Directory traversal vulnerability in rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6, 3.0, 3.0 SP1, and 3.5 allows remote attackers to… | |||
| CVE-2012-0460 | medium | — | 6.4 | 14y ago | Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict write access to t… | |||
| CVE-2012-1472 | medium | — | 6.4 | 14y ago | VMware vCenter Chargeback Manager (aka CBM) before 2.0.1 does not properly handle XML API requests, which allows remote attackers to read arbitrary files or cause a denial of service via unspecified … | |||
| CVE-2012-0584 | medium | — | 6.4 | 14y ago | The Internationalized Domain Name (IDN) feature in Apple Safari before 5.1.4 on Windows does not properly restrict the characters in URLs, which allows remote attackers to spoof a domain name via uns… | |||
| CVE-2012-0237 | medium | — | 6.4 | 15y ago | Advantech/BroadWin WebAccess before 7.0 allows remote attackers to (1) enable date and time syncing or (2) disable date and time syncing via a crafted URL. | |||
| CVE-2012-1194 | medium | — | 6.4 | 15y ago | The resolver in the DNS Server service in Microsoft Windows Server 2008 before R2 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query,… | |||
| CVE-2012-1193 | medium | — | 6.4 | 15y ago | The resolver in PowerDNS Recursor (aka pdns_recursor) 3.3 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote att… |