- EPSS 3.83%
- Published 03.12.2012 12:49:43
- Last modified 11.04.2025 00:51:21
Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with ...
CVE-2012-0867
- EPSS 1.87%
- Published 18.07.2012 23:55:01
- Last modified 11.04.2025 00:51:21
PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof connections when the host name is exactly 32 characters...
CVE-2012-0876
- EPSS 0.3%
- Published 03.07.2012 19:55:02
- Last modified 11.04.2025 00:51:21
The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file wit...
CVE-2012-1149
- EPSS 2.71%
- Published 21.06.2012 15:55:11
- Last modified 11.04.2025 00:51:21
Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a cra...
CVE-2012-0037
- EPSS 0.53%
- Published 17.06.2012 03:41:40
- Last modified 11.04.2025 00:51:21
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity ...
CVE-2012-1717
- EPSS 0.16%
- Published 16.06.2012 21:55:03
- Last modified 11.04.2025 00:51:21
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows local users to affect confidentiality via unknown ve...
- EPSS 94.08%
- Published 16.06.2012 21:55:03
- Last modified 11.04.2025 00:51:21
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrit...
CVE-2012-2313
- EPSS 0.22%
- Published 13.06.2012 10:24:55
- Last modified 11.04.2025 00:51:21
The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.
CVE-2012-2035
- EPSS 3.47%
- Published 09.06.2012 00:55:01
- Last modified 11.04.2025 00:51:21
Stack-based buffer overflow in Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on A...
CVE-2012-2036
- EPSS 4.47%
- Published 09.06.2012 00:55:01
- Last modified 11.04.2025 00:51:21
Integer overflow in Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x,...