LiveActive security incident?Get immediate response
CVE archive

November 2012

Browse CVE records published in November 2012, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 483 matching CVEs · Page 6 of 10.

Unknown · CVSS Not scored

CVE-2012-4948: The default configuration of Fortinet Fortigate UTM appliances uses the same Certification Authority certif...

The default configuration of Fortinet Fortigate UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the Fortinet_CA_SSLProxy certificate in a list of trusted root certification authorities.

Published Nov 14, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-4953: The decomposer engine in Symantec Endpoint Protection (SEP) 11.0, Symantec Endpoint Protection Small Busine...

The decomposer engine in Symantec Endpoint Protection (SEP) 11.0, Symantec Endpoint Protection Small Business Edition 12.0, Symantec AntiVirus Corporate Edition (SAVCE) 10.x, and Symantec Scan Engine (SSE) before 5.2.8 does not properly perform bounds checks of the contents of CAB archives, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted file.

Published Nov 14, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-4777: The code-optimization feature in the reflection implementation in Microsoft .NET Framework 4 and 4.5 does n...

The code-optimization feature in the reflection implementation in Microsoft .NET Framework 4 and 4.5 does not properly enforce object permissions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka "WPF Reflection Optimization Vulnerability."

Published Nov 14, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-4776: The Web Proxy Auto-Discovery (WPAD) functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4...

The Web Proxy Auto-Discovery (WPAD) functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not validate configuration data that is returned during acquisition of proxy settings, which allows remote attackers to execute arbitrary JavaScript code by providing crafted data during execution of (1) an XAML browser application (aka XBAP) or (2) a .NET Framework application, aka "Web Proxy Auto-Discovery Vulnerability."

Published Nov 14, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-4537: Xen 3.4 through 4.2, and possibly earlier versions, does not properly synchronize the p2m and m2p tables wh...

Xen 3.4 through 4.2, and possibly earlier versions, does not properly synchronize the p2m and m2p tables when the set_p2m_entry function fails, which allows local HVM guest OS administrators to cause a denial of service (memory consumption and assertion failure), aka "Memory mapping failure DoS vulnerability."

Published Nov 21, 2012 · Updated Aug 6, 2024