- EPSS 4.25%
- Published 29.08.2012 10:56:39
- Last modified 11.04.2025 00:51:21
Use-after-free vulnerability in the nsObjectLoadingContent::LoadObject function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attac...
- EPSS 1.28%
- Published 17.08.2012 00:55:03
- Last modified 11.04.2025 00:51:21
Unspecified vulnerability in MySQL 5.5.x before 5.5.23 has unknown impact and attack vectors related to a "Security Fix", aka Bug #59533. NOTE: this might be a duplicate of CVE-2012-1689, but as of 20120816, Oracle has not commented on this possibili...
CVE-2012-2135
- EPSS 2.18%
- Published 14.08.2012 22:55:01
- Last modified 11.04.2025 00:51:21
The utf-16 decoder in Python 3.1 through 3.3 does not update the aligned_end variable after calling the unicode_decode_call_errorhandler function, which allows remote attackers to obtain sensitive information (process memory) or cause a denial of ser...
CVE-2012-3425
- EPSS 1.64%
- Published 13.08.2012 20:55:09
- Last modified 11.04.2025 00:51:21
The png_push_read_zTXt function in pngpread.c in libpng 1.0.x before 1.0.58, 1.2.x before 1.2.48, 1.4.x before 1.4.10, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (out-of-bounds read) via a large avail_in field value ...
CVE-2012-2317
- EPSS 0.45%
- Published 07.08.2012 19:55:01
- Last modified 11.04.2025 00:51:21
The Debian php_crypt_revamped.patch patch for PHP 5.3.x, as used in the php5 package before 5.3.3-7+squeeze4 in Debian GNU/Linux squeeze, the php5 package before 5.3.2-1ubuntu4.17 in Ubuntu 10.04 LTS, and the php5 package before 5.3.5-1ubuntu7.10 in ...
CVE-2012-2665
- EPSS 5.02%
- Published 06.08.2012 18:55:01
- Last modified 11.04.2025 00:51:21
Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Do...
CVE-2012-3867
- EPSS 1.42%
- Published 06.08.2012 16:55:06
- Last modified 11.04.2025 00:51:21
lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Request (CSR), which makes it eas...
CVE-2012-3571
- EPSS 22.14%
- Published 25.07.2012 10:42:35
- Last modified 11.04.2025 00:51:21
ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed client identifier.
CVE-2012-3954
- EPSS 6.48%
- Published 25.07.2012 10:42:35
- Last modified 11.04.2025 00:51:21
Multiple memory leaks in ISC DHCP 4.1.x and 4.2.x before 4.2.4-P1 and 4.1-ESV before 4.1-ESV-R6 allow remote attackers to cause a denial of service (memory consumption) by sending many requests.
CVE-2012-4048
- EPSS 0.21%
- Published 24.07.2012 19:55:00
- Last modified 11.04.2025 00:51:21
The PPP dissector in Wireshark 1.4.x before 1.4.14, 1.6.x before 1.6.9, and 1.8.x before 1.8.1 allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via a crafted packet, as demonstrated by a usbmon ...