LiveActive security incident?Get immediate response
CVE archive

February 2012

Browse CVE records published in February 2012, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 424 matching CVEs · Page 7 of 9.

Unknown · CVSS Not scored

CVE-2012-0941: Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiGate UTM WAF appliances with FortiOS 4...

Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiGate UTM WAF appliances with FortiOS 4.3.x before 4.3.6 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) Endpoint Monitor, (2) Dialup List, or (3) Log&Report Display modules, or the fields_sorted_opt parameter to (4) user/auth/list or (5) endpointcompliance/app_detect/predefined_sig_list.

Published Feb 8, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-0870: Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the Bl...

Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other products, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a Batched (aka AndX) request that triggers infinite recursion.

Published Feb 23, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-0829: Multiple cross-site request forgery (CSRF) vulnerabilities in Mibew Messenger 1.6.4 and earlier allow remot...

Multiple cross-site request forgery (CSRF) vulnerabilities in Mibew Messenger 1.6.4 and earlier allow remote attackers to hijack the authentication of operators for requests that insert cross-site scripting (XSS) sequences via the (1) address or (2) threadid parameters to operator/ban.php; or (3) geolinkparams, (4) title, or (5) chattitle parameters to operator/settings.php.

Published Feb 14, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-0874: The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Pl...

The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 do not require authentication by default in certain profiles, which might allow remote attackers to invoke MBean methods and execute arbitrary code via unspecified vectors. NOTE: this issue can only be exploited when the interceptor is not properly configured with a "second layer of authentication," or when used in conjunction with other vulnerabilities that bypass this second layer.

Published Feb 5, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-0831: PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the...

PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related to main/php_variables.c, sapi/cgi/cgi_main.c, and sapi/fpm/fpm/fpm_main.c.

Published Feb 10, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-0840: tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without r...

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

Published Feb 10, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-0788: The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which al...

The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of service (application crash) via a crafted application that uses a PDO driver for a fetch and then calls the session_start function, as demonstrated by a crash of the Apache HTTP Server.

Published Feb 14, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-0756: Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris;...

Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2012-0755.

Published Feb 16, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-0755: Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris;...

Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2012-0756.

Published Feb 16, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-0766: The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute ar...

The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0761, CVE-2012-0762, CVE-2012-0763, and CVE-2012-0764.

Published Feb 15, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-0764: The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute ar...

The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0761, CVE-2012-0762, CVE-2012-0763, and CVE-2012-0766.

Published Feb 15, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-0761: The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute ar...

The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0762, CVE-2012-0763, CVE-2012-0764, and CVE-2012-0766.

Published Feb 15, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-0762: The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute ar...

The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, CVE-2012-0761, CVE-2012-0763, CVE-2012-0764, and CVE-2012-0766.

Published Feb 15, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-0752: Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris;...

Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to execute arbitrary code or cause a denial of service (memory corruption) by leveraging an unspecified "type confusion."

Published Feb 16, 2012 · Updated Aug 6, 2024