Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2012-3807

    Samsung Kies before 2.5.0.12094_27_11 has arbitrary file execution.... Read more

    Affected Products : kies
    • EPSS Score: %34.86
    • Published: Jan. 09, 2020
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2012-3806

    Samsung Kies before 2.5.0.12094_27_11 contains a NULL pointer dereference vulnerability which could allow remote attackers to perform a denial of service.... Read more

    Affected Products : kies
    • EPSS Score: %2.37
    • Published: Jan. 09, 2020
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2012-3543

    mono 2.10.x ASP.NET Web Form Hash collision DoS... Read more

    Affected Products : ubuntu_linux debian_linux mono
    • EPSS Score: %1.15
    • Published: Nov. 21, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-3536

    Two XSS vulnerabilities were fixed in message list and view in the Hupa Webmail application from the Apache James project. An attacker could send a carefully crafted email to a user of Hupa which would trigger a XSS when the email was opened or when a lis... Read more

    Affected Products : hupa
    • EPSS Score: %1.35
    • Published: Feb. 27, 2018
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2012-3490

    The (1) my_popenv_impl and (2) my_spawnv functions in src/condor_utils/my_popen.cpp and the (3) systemCommand function in condor_vm-gahp/vmgahp_common.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the return value of set... Read more

    Affected Products : htcondor
    • EPSS Score: %2.63
    • Published: Jan. 09, 2020
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2012-3462

    A flaw was found in SSSD version 1.9.0. The SSSD's access-provider logic causes the result of the HBAC rule processing to be ignored in the event that the access-provider is also handling the setup of the user's SELinux user context.... Read more

    Affected Products : sssd
    • EPSS Score: %0.33
    • Published: Dec. 26, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2012-3460

    cumin: At installation postgresql database user created without password... Read more

    • EPSS Score: %0.39
    • Published: Nov. 21, 2019
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2012-3409

    ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation... Read more

    Affected Products : debian_linux ecryptfs-utils
    • EPSS Score: %0.08
    • Published: Dec. 20, 2019
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2012-3407

    plow has local buffer overflow vulnerability... Read more

    Affected Products : plow
    • EPSS Score: %0.22
    • Published: Nov. 22, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2012-3353

    The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the content repository, including local files, causing potential information leaks. Users should upgrade to versi... Read more

    Affected Products : sling_jcr_contentloader sling_i18n
    • EPSS Score: %0.32
    • Published: Jan. 09, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-3351

    Multiple cross-site scripting (XSS) vulnerabilities in LongTail Video JW Player through 5.10.2295 allow remote attackers to inject arbitrary web script or HTML via the (1) link, (2) logo.link, or (3) aboutlink parameter, or a nested URI scheme name for (4... Read more

    Affected Products : jw_player
    • EPSS Score: %1.68
    • Published: Feb. 20, 2020
    • Modified: Nov. 21, 2024
  • 6.4

    MEDIUM
    CVE-2012-3341

    IBM InfoSphere Guardium 7.0, 8.0, 8.01, and 8.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's W... Read more

    Affected Products : infosphere_guardium
    • EPSS Score: %0.24
    • Published: Sep. 01, 2020
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2012-3340

    IBM InfoSphere Guardium 8.0, 8.01, and 8.2 is vulnerable to XML external entity injection, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ... Read more

    Affected Products : infosphere_guardium
    • EPSS Score: %0.20
    • Published: Sep. 01, 2020
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2012-3338

    IBM InfoSphere Guardium 8.0, 8.01, and 8.2 could allow a remote attacker to bypass security restrictions, caused by improper restrictions on the create new user account functionality. An attacker could exploit this vulnerability to create unprivileged use... Read more

    Affected Products : infosphere_guardium
    • EPSS Score: %0.30
    • Published: Sep. 01, 2020
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2012-3337

    IBM InfoSphere Guardium 8.0, 8.01, and 8.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to download arbitrary files on the syste... Read more

    Affected Products : infosphere_guardium
    • EPSS Score: %0.54
    • Published: Sep. 01, 2020
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2012-3336

    IBM InfoSphere Guardium 8.0, 8.01, and 8.2 is vulnerable to SQL injection. A remote authenticated attacker could send specially-crafted SQL statements to multiple scripts, which could allow the attacker to view, add, modify or delete information in the ba... Read more

    Affected Products : linux_kernel infosphere_guardium
    • EPSS Score: %0.47
    • Published: Sep. 01, 2020
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2012-3331

    IBM Sametime allows remote attackers to obtain sensitive information from the Sametime Log database via a direct request to STLOG.NSF. IBM X-Force ID: 78048.... Read more

    Affected Products : sametime
    • EPSS Score: %0.16
    • Published: Feb. 08, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2012-2979

    FreeBSD NSD before 3.2.13 allows remote attackers to crash a NSD child server process (SIGSEGV) and cause a denial of service in the NSD server.... Read more

    Affected Products : name_server_daemon
    • EPSS Score: %0.75
    • Published: Nov. 01, 2019
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2012-2950

    Gateway Geomatics MapServer for Windows before 3.0.6 contains a Local File Include Vulnerability which allows remote attackers to execute local PHP code and obtain sensitive information.... Read more

    Affected Products : windows mapserver
    • EPSS Score: %5.38
    • Published: Jan. 09, 2020
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2012-2945

    Hadoop 1.0.3 contains a symlink vulnerability.... Read more

    Affected Products : hadoop
    • EPSS Score: %1.71
    • Published: Oct. 29, 2019
    • Modified: Nov. 21, 2024
Showing 20 of 291741 Results