LiveActive security incident?Get immediate response
CVE archive

July 2012

Browse CVE records published in July 2012, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 491 matching CVEs · Page 7 of 10.

Unknown · CVSS Not scored

CVE-2012-2841: Integer underflow in the exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka...

Integer underflow in the exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 might allow remote attackers to execute arbitrary code via vectors involving a crafted buffer-size parameter during the formatting of an EXIF tag, leading to a heap-based buffer overflow.

Published Jul 13, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-2748: Unspecified vulnerability in Joomla!

Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allows remote attackers to obtain sensitive information via vectors related to "Inadequate filtering" and a "SQL error."

Published Jul 3, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-2837: The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry.c in the EXIF Tag Parsing Library...

The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (divide-by-zero error) via an image with crafted EXIF tags that are not properly handled during the formatting of EXIF maker note tags.

Published Jul 13, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-2747: Unspecified vulnerability in Joomla!

Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allows remote attackers to gain privileges via unknown attack vectors related to "Inadequate checking."

Published Jul 3, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-2751: ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning o...

ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in the Content-Disposition field of a request with a multipart/form-data Content-Type header, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-5031.

Published Jul 22, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-2673: Multiple integer overflows in the (1) GC_generic_malloc and (2) calloc functions in malloc.c, and the (3) G...

Multiple integer overflows in the (1) GC_generic_malloc and (2) calloc functions in malloc.c, and the (3) GC_generic_malloc_ignore_off_page function in mallocx.c in Boehm-Demers-Weiser GC (libgc) before 7.2 make it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, which causes less memory to be allocated than expected.

Published Jul 25, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-2645: The Yahoo!

The Yahoo! Japan Yahoo! Browser application 1.2.0 and earlier for Android does not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application.

Published Jul 16, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-2361: Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation i...

Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php.

Published Jul 21, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-2364: Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1....

Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via an assignment submission with zip compression, leading to text/html rendering during a "download all" action.

Published Jul 21, 2012 · Updated Aug 6, 2024