LiveActive security incident?Get immediate response
CVE archive

April 2012

Browse CVE records published in April 2012, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 285 matching CVEs · Page 4 of 6.

Unknown · CVSS Not scored

CVE-2012-1800: Stack-based buffer overflow in the Profinet DCP protocol implementation on the Siemens Scalance S Security...

Stack-based buffer overflow in the Profinet DCP protocol implementation on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with firmware before 2.3.0.3 allows remote attackers to cause a denial of service (device outage) or possibly execute arbitrary code via a crafted DCP frame.

Published Apr 18, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-1803: RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived fr...

RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the banner, which makes it easier for remote attackers to obtain access by performing a calculation on this address value, and then establishing a (1) TELNET, (2) remote shell (aka rsh), or (3) serial-console session.

Published Apr 28, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-1802: Buffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414-3E bef...

Buffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414-3E before 3.7.1, X308-2M before 3.7.2, X-300EEC before 3.7.2, XR-300 before 3.7.2, and X-300 before 3.7.2 allows remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary code via a malformed URL.

Published Apr 18, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-1596: The mp2t_process_fragmented_payload function in epan/dissectors/packet-mp2t.c in the MP2T dissector in Wire...

The mp2t_process_fragmented_payload function in epan/dissectors/packet-mp2t.c in the MP2T dissector in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (application crash) via a packet containing an invalid pointer value that triggers an incorrect memory-allocation attempt.

Published Apr 11, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-1574: The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before...

The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through CDH3u2, Cloudera hadoop-0.20-sbin before 0.20.2+923.197, and other products, allows remote authenticated users to impersonate arbitrary cluster user accounts via unspecified vectors.

Published Apr 12, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-1595: The pcap_process_pseudo_header function in wiretap/pcap-common.c in Wireshark 1.4.x before 1.4.12 and 1.6.x...

The pcap_process_pseudo_header function in wiretap/pcap-common.c in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (application crash) via a WTAP_ENCAP_ERF file containing an Extension or Multi-Channel header with an invalid pseudoheader size, related to the pcap and pcap-ng file parsers.

Published Apr 11, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-1242: Untrusted search path vulnerability in JustSystems Ichitaro 2011 Sou, Ichitaro 2006 through 2011, Ichitaro...

Untrusted search path vulnerability in JustSystems Ichitaro 2011 Sou, Ichitaro 2006 through 2011, Ichitaro Government 2006 through 2010, Ichitaro Portable with oreplug, Ichitaro Viewer, JUST School, JUST School 2009 and 2010, JUST Jump 4, JUST Frontier, and oreplug allows local users to gain privileges via a Trojan horse DLL in the current working directory.

Published Apr 27, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-1136: FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote at...

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph or bitmap data in a BDF font that lacks an ENCODING field.

Published Apr 25, 2012 · Updated Aug 6, 2024