Total
13251 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2012-5610 | 1 Owncloud | 2 Owncloud, Owncloud Server | 2026-06-16 | 6.5 MEDIUM | N/A |
| Incomplete blacklist vulnerability in lib/filesystem.php in ownCloud before 4.0.9 and 4.5.x before 4.5.2 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a special crafted name. | |||||
| CVE-2012-5582 | 1 Opendnssec | 1 Opendnssec | 2026-06-16 | 7.5 HIGH | 9.8 CRITICAL |
| opendnssec misuses libcurl API | |||||
| CVE-2012-5572 | 1 Dancer | 1 Dancer | 2026-06-16 | 5.0 MEDIUM | N/A |
| CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie.pm) in Dancer before 1.3114 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a cookie name, a different vulnerability than CVE-2012-5526. | |||||
| CVE-2012-5536 | 2 Fedora Project, Redhat | 2 Fedora Release Rawhide, Enterprise Linux | 2026-06-16 | 6.2 MEDIUM | N/A |
| A certain Red Hat build of the pam_ssh_agent_auth module on Red Hat Enterprise Linux (RHEL) 6 and Fedora Rawhide calls the glibc error function instead of the error function in the OpenSSH codebase, which allows local users to obtain sensitive information from process memory or possibly gain privileges via crafted use of an application that relies on this module, as demonstrated by su and sudo. | |||||
| CVE-2012-5534 | 1 Flashtux | 1 Weechat | 2026-06-16 | 7.5 HIGH | N/A |
| The hook_process function in the plugin API for WeeChat 0.3.0 through 0.3.9.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a command from a plugin, related to "shell expansion." | |||||
| CVE-2012-5524 | 1 Gajim | 1 Gajim | 2026-06-16 | 4.3 MEDIUM | N/A |
| The _ssl_verify_callback function in tls_nb.py in Gajim before 0.15.3 does not properly verify SSL certificates, which allows remote attackers to conduct man-in-the-middle (MITM) attacks and spoof servers via an arbitrary certificate from a trusted CA. | |||||
| CVE-2012-5520 | 1 Openvas | 1 Openvas Manager | 2026-06-16 | 7.5 HIGH | N/A |
| The send_to_sourcefire function in manage_sql.c in OpenVAS Manager 3.x before 3.0.4 allows remote attackers to execute arbitrary commands via the (1) IP address or (2) port number field in an OMP request. | |||||
| CVE-2012-5513 | 1 Xen | 1 Xen | 2026-06-16 | 6.9 MEDIUM | N/A |
| The XENMEM_exchange handler in Xen 4.2 and earlier does not properly check the memory address, which allows local PV guest OS administrators to cause a denial of service (crash) or possibly gain privileges via unspecified vectors that overwrite memory in the hypervisor reserved range. | |||||
| CVE-2012-5445 | 1 Cisco | 3 Skinny Client Control Protocol Software, Unified Ip Phone, Unified Ip Phone 7906g | 2026-06-16 | 6.8 MEDIUM | N/A |
| The kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software before 9.3.1-ES10 does not properly validate unspecified system calls, which allows attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a crafted binary. | |||||
| CVE-2012-5427 | 1 Cisco | 1 Ios | 2026-06-16 | 4.0 MEDIUM | N/A |
| Cisco IOS Unified Border Element (CUBE) in Cisco IOS before 15.3(2)T allows remote authenticated users to cause a denial of service (input queue wedge) via a crafted series of RTCP packets, aka Bug ID CSCuc42518. | |||||
| CVE-2012-5424 | 1 Cisco | 1 Secure Access Control Server | 2026-06-16 | 5.0 MEDIUM | N/A |
| Cisco Secure Access Control System (ACS) 5.x before 5.2 Patch 11 and 5.3 before 5.3 Patch 7, when a certain configuration involving TACACS+ and LDAP is used, does not properly validate passwords, which allows remote attackers to bypass authentication by sending a valid username and a crafted password string, aka Bug ID CSCuc65634. | |||||
| CVE-2012-5360 | 1 Ffmpeg | 1 Ffmpeg | 2026-06-16 | 9.3 HIGH | 8.8 HIGH |
| Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted QT file. | |||||
| CVE-2012-5359 | 1 Ffmpeg | 1 Ffmpeg | 2026-06-16 | 9.3 HIGH | 8.8 HIGH |
| Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted ASF file. | |||||
| CVE-2012-5356 | 1 Canonical | 1 Ubuntu Software Properties | 2026-06-16 | 5.8 MEDIUM | N/A |
| The apt-add-repository tool in Ubuntu Software Properties 0.75.x before 0.75.10.3, 0.80.x before 0.80.9.2, 0.81.x before 0.81.13.5, 0.82.x before 0.82.7.3, and 0.92.x before 0.92.8 does not properly check PPA GPG keys imported from a keyserver, which allows remote attackers to install arbitrary package repository GPG keys via a man-in-the-middle (MITM) attack. | |||||
| CVE-2012-5338 | 1 Jforum | 1 Jforum | 2026-06-16 | 5.8 MEDIUM | N/A |
| Open redirect vulnerability in JForum 2.1.9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the returnPath parameter in a validateLogin action to jforum.page. | |||||
| CVE-2012-5336 | 1 Owncloud | 2 Owncloud, Owncloud Server | 2026-06-16 | 4.0 MEDIUM | N/A |
| lib/base.php in ownCloud before 4.0.8 does not properly validate the user_id session variable, which allows remote authenticated users to read arbitrary files via vectors related to WebDAV. | |||||
| CVE-2012-5321 | 1 Tiki | 1 Tikiwiki Cms\/groupware | 2026-06-16 | 5.8 MEDIUM | N/A |
| tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attacks via the url parameter, aka "frame injection." | |||||
| CVE-2012-5234 | 1 Ocportal | 1 Ocportal | 2026-06-16 | 5.8 MEDIUM | N/A |
| Open redirect vulnerability in index.php in ocPortal before 7.1.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter. | |||||
| CVE-2012-5170 | 1 Simon Brown | 1 Pebble | 2026-06-16 | 5.8 MEDIUM | N/A |
| Open redirect vulnerability in Pebble before 2.6.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |||||
| CVE-2012-5148 | 2 Google, Opensuse | 2 Chrome, Opensuse | 2026-06-16 | 7.5 HIGH | N/A |
| The hyphenation functionality in Google Chrome before 24.0.1312.52 does not properly validate file names, which has unspecified impact and attack vectors. | |||||
