LiveActive security incident?Get immediate response
CVE archive

November 2012

Browse CVE records published in November 2012, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 483 matching CVEs · Page 9 of 10.

Unknown · CVSS Not scored

CVE-2012-3446: Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the serve...

Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

Published Nov 4, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-3315: The Java servlets in the management console in IBM Tivoli Federated Identity Manager (TFIM) through 6.2.2 a...

The Java servlets in the management console in IBM Tivoli Federated Identity Manager (TFIM) through 6.2.2 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) before 6.2.2 do not require authentication for all resource downloads, which allows remote attackers to bypass intended J2EE security constraints, and obtain sensitive information related to (1) federation metadata or (2) a web plugin configuration template, via a crafted request.

Published Nov 8, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-3026: rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Porta...

rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remote attackers to cause a denial of service (memory corruption and service crash) or possibly execute arbitrary code via long input data, a different vulnerability than CVE-2012-3010 and CVE-2012-3021.

Published Nov 1, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-3021: rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Porta...

rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remote attackers to cause a denial of service (memory corruption and service crash) or possibly execute arbitrary code via long input data, a different vulnerability than CVE-2012-3010 and CVE-2012-3026.

Published Nov 1, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-3010: rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Porta...

rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remote attackers to cause a denial of service (memory corruption and service crash) or possibly execute arbitrary code via long input data, a different vulnerability than CVE-2012-3021 and CVE-2012-3026.

Published Nov 1, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-2733: java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x be...

java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not properly restrict the request-header size, which allows remote attackers to cause a denial of service (memory consumption) via a large amount of header data.

Published Nov 16, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-2739: Oracle Java SE before 7 Update 6, and OpenJDK 7 before 7u6 build 12 and 8 before build 39, computes hash va...

Oracle Java SE before 7 Update 6, and OpenJDK 7 before 7u6 build 12 and 8 before build 39, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

Published Nov 28, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-2530: Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3,...

Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, aka "Win32k Use After Free Vulnerability."

Published Nov 14, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-2519: Untrusted search path vulnerability in Entity Framework in ADO.NET in Microsoft .NET Framework 1.0 SP3, 1.1...

Untrusted search path vulnerability in Entity Framework in ADO.NET in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, and 4 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .NET application, aka ".NET Framework Insecure Library Loading Vulnerability."

Published Nov 14, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-2377: JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, an...

JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent networks to read diagnostics information via a crafted IP multicast.

Published Nov 23, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-2243: Cross-site scripting (XSS) vulnerability in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote...

Cross-site scripting (XSS) vulnerability in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to inject arbitrary web script or HTML by uploading an XML file with the xhtml extension, which is rendered inline as script. NOTE: this can be leveraged with CVE-2012-2244 to execute arbitrary code without authentication, as demonstrated by modifying the clamav path.

Published Nov 24, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-2237: Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 all...

Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as used when generating login forms, (2) links or (3) resources URLs, and (4) the Display name in a user profile.

Published Nov 13, 2019 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-1895: The reflection implementation in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4 does not...

The reflection implementation in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4 does not properly enforce object permissions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka "Reflection Bypass Vulnerability."

Published Nov 14, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2012-1896: Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly consider trust levels during construction of o...

Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly consider trust levels during construction of output data, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka "Code Access Security Info Disclosure Vulnerability."

Published Nov 14, 2012 · Updated Aug 6, 2024