Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2012-0821 | 1 Joomla | 1 Joomla\! | 2012-09-12 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2012-0819. | |||||
CVE-2012-0836 | 1 Joomla | 1 Joomla\! | 2012-09-12 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in Joomla! 1.7.x before 1.7.5 allows attackers to read the error log via unknown vectors. | |||||
CVE-2012-1467 | 1 Pkp | 1 Open Journal Systems | 2012-09-12 | 6.5 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in the iBrowser plugin library, as used in Open Journal Systems before 2.3.7, allow remote authenticated users to (1) delete or (2) rename arbitrary files via a .. (dot dot) in the param parameter to lib/pkp/lib/tinymce/jscripts/tiny_mce/plugins/ibrowser/scripts/rfiles.php. | |||||
CVE-2012-2740 | 1 Phplist | 1 Phplist | 2012-09-12 | 7.5 HIGH | N/A |
SQL injection vulnerability in public_html/lists/admin in phpList before 2.10.18 allows remote attackers to execute arbitrary SQL commands via the sortby parameter in a find action. | |||||
CVE-2012-2741 | 1 Phplist | 1 Phplist | 2012-09-12 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in public_html/lists/admin/ in phpList before 2.10.18 allows remote attackers to inject arbitrary web script or HTML via the num parameter in a reconcileusers action. | |||||
CVE-2012-3012 | 1 Arbiter | 2 Power Sentinel, Power Sentinel 1133a Firmware | 2012-09-12 | 7.8 HIGH | N/A |
The Arbiter Power Sentinel 1133A device with firmware before 11Jun2012 Rev 421 allows remote attackers to cause a denial of service (Ethernet outage) via unspecified Ethernet traffic that fills a buffer, as demonstrated by a port scan. | |||||
CVE-2012-4010 | 1 Opera | 1 Opera Browser | 2012-09-12 | 5.0 MEDIUM | N/A |
Opera before 11.60 allows remote attackers to spoof the address bar via unspecified homograph characters, a different vulnerability than CVE-2010-2660. | |||||
CVE-2012-4389 | 1 Owncloud | 1 Owncloud | 2012-09-12 | 6.8 MEDIUM | N/A |
Incomplete blacklist vulnerability in lib/migrate.php in ownCloud before 4.0.7 allows remote attackers to execute arbitrary code by uploading a crafted .htaccess file in an import.zip file and accessing an uploaded PHP file. | |||||
CVE-2012-4390 | 1 Owncloud | 1 Owncloud | 2012-09-12 | 4.0 MEDIUM | N/A |
(1) apps/calendar/appinfo/remote.php and (2) apps/contacts/appinfo/remote.php in ownCloud before 4.0.7 allows remote authenticated users to enumerate the registered users via unspecified vectors. | |||||
CVE-2012-4392 | 1 Owncloud | 1 Owncloud | 2012-09-12 | 7.5 HIGH | N/A |
index.php in ownCloud 4.0.7 does not properly validate the oc_token cookie, which allows remote attackers to bypass authentication via a crafted oc_token cookie value. | |||||
CVE-2012-4865 | 1 Oreans | 1 Themida | 2012-09-12 | 9.3 HIGH | N/A |
Buffer overflow in Oreans Themida 2.1.8.0 allows remote attackers to execute arbitrary code via a crafted .TMD file. | |||||
CVE-2009-2259 | 2012-09-12 | N/A | N/A | ||
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-2608. Reason: This candidate is a duplicate of CVE-2009-2608. Notes: All CVE users should reference CVE-2009-2608 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. | |||||
CVE-2012-3572 | 2 Nurul Hidayah Hamazulan, Oscc | 2 Mymesyuarat, Mymeeting | 2012-09-12 | 6.0 MEDIUM | N/A |
Open Source Competency Center (OSCC) MyMeeting 3.0.1 and earlier, and MyMesyuarat 09b-1, does not properly verify uploaded documents, which allows remote authenticated users to execute arbitrary PHP code via a crafted document. | |||||
CVE-2012-4893 | 1 Gentoo | 1 Webmin | 2012-09-12 | 6.8 MEDIUM | N/A |
Multiple cross-site request forgery (CSRF) vulnerabilities in file/show.cgi in Webmin 1.590 and earlier allow remote attackers to hijack the authentication of privileged users for requests that (1) read files or execute (2) tar, (3) zip, or (4) gzip commands, a different issue than CVE-2012-2982. | |||||
CVE-2012-2975 | 1 F5 | 1 Application Security Manager Appliance | 2012-09-12 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the traffic overview page on the F5 ASM appliance 10.0.0 through 11.2.0 HF2 allows remote attackers to inject arbitrary web script or HTML via crafted requests that are later listed on a summary page. | |||||
CVE-2012-4238 | 1 Tecnick | 1 Tcexam | 2012-09-11 | 2.1 LOW | N/A |
Cross-site scripting (XSS) vulnerability in admin/code/tce_edit_answer.php in TCExam before 11.3.008 allows remote authenticated users with level 5 or greater permissions to inject arbitrary web script or HTML via the question_subject_id parameter. | |||||
CVE-2010-5197 | 1 Pixia | 1 Pixia | 2012-09-10 | 6.9 MEDIUM | N/A |
Untrusted search path vulnerability in Pixia 4.70j allows local users to gain privileges via a Trojan horse wintab32.dll file in the current working directory, as demonstrated by a directory that contains a .pxa file. NOTE: some of these details are obtained from third party information. | |||||
CVE-2010-5230 | 1 Bentley | 1 Microstation | 2012-09-10 | 6.9 MEDIUM | N/A |
Multiple untrusted search path vulnerabilities in MicroStation 7.1 allow local users to gain privileges via a Trojan horse (1) mptools.dll, (2) baseman.dll, (3) wintab32.dll, or (4) wintab.dll file in the current working directory, as demonstrated by a directory that contains a .hln or .rdl file. NOTE: some of these details are obtained from third party information. | |||||
CVE-2010-5259 | 1 Isobuster | 1 Isobuster | 2012-09-10 | 6.9 MEDIUM | N/A |
Multiple untrusted search path vulnerabilities in IsoBuster 2.8 allow local users to gain privileges via a Trojan horse (1) wnaspi32.dll or (2) ntaspi32.dll file in the current working directory, as demonstrated by a directory that contains a .img file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2012-2306 | 2 Drupal, Willem Van Der Plaat | 2 Drupal, Addressbook | 2012-09-10 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Addressbook module for Drupal 6.x-4.2 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors. |