<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" >

<channel>
	<title>Free DNS Lookup</title>
	<atom:link href="http://www.freednslookup.net/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.freednslookup.net</link>
	<description>Free DNS Lookup for Everyone</description>
	<lastBuildDate>Wed, 16 May 2012 12:00:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>SB12-135: Vulnerability Summary for the Week of May 7, 2012</title>
		<link>http://www.freednslookup.net/2012/05/16/sb12-135-vulnerability-summary-for-the-week-of-may-7-2012/</link>
		<comments>http://www.freednslookup.net/2012/05/16/sb12-135-vulnerability-summary-for-the-week-of-may-7-2012/#comments</comments>
		<pubDate>Wed, 16 May 2012 12:00:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[US-Cert]]></category>

		<guid isPermaLink="false">http://www.freednslookup.net/2012/05/16/sb12-135-vulnerability-summary-for-the-week-of-may-7-2012/</guid>
		<description><![CDATA[The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cyber Security Division (NCSD) / United States Computer Emergency Readiness Team [...]]]></description>
			<content:encoded><![CDATA[<p><a name="top"></a></p>
<table align="center">
<tr>
<td>
<p>The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cyber Security Division (NCSD) / United States Computer Emergency Readiness Team (US-CERT). For updated or updated entries, please visit the <a href="http://nvd.nist.gov" target="_blank">NVD</a>, which contains historical vulnerability information.</p>
<p>The vulnerabilities are based on the <a href="http://cve.mitre.org/" target="_blank">CVE</a> vulnerability naming standard and are organized according to severity, determined by the <a href="http://nvd.nist.gov/cvss.cfm" target="_blank">Common Vulnerability Scoring System</a> (CVSS) standard. The division of high, medium, and low severities correspond to the following scores:</p>
<ul>
<li>
<p><strong>High</strong> &#8211; Vulnerabilities will be labeled High severity if they have a CVSS base score of 7.0 &#8211; 10.0</p>
</li>
<li>
<p><strong>Medium</strong> &#8211; Vulnerabilities will be labeled Medium severity if they have a CVSS base score of 4.0 &#8211; 6.9</p>
</li>
<li>
<p><strong>Low</strong> &#8211; Vulnerabilities will be labeled Low severity if they have a CVSS base score of 0.0 &#8211; 3.9</p>
</li>
</ul>
<p>Entries may include additional information provided by organizations and efforts sponsored by US-CERT. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletins is compiled from external, open source reports and is not a direct result of US-CERT analysis.</p>
</td>
</tr>
</table>
<p>
<a name="high"></a></p>
<div>
<table align="center" border="1" summary="High Vulnerabilities">
<thead>
<tr>
<th colspan="5">High Vulnerabilities</th>
</tr>
<tr>
<th>Primary<br />
Vendor &#8212; Product</th>
<th>Description</th>
<th>Published</th>
<th>CVSS Score</th>
<th>Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td>adobe &#8212; flash_cs3</td>
<td>Buffer overflow in Adobe Flash Professional before CS6 allows attackers to execute arbitrary code via unspecified vectors.</td>
<td>2012-05-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0778&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0778" target="_blank">CVE-2012-0778</a></td>
</tr>
<tr>
<td>adobe &#8212; illustrator</td>
<td>Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2023, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.</td>
<td>2012-05-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0780&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0780" target="_blank">CVE-2012-0780</a></td>
</tr>
<tr>
<td>adobe &#8212; illustrator</td>
<td>Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.</td>
<td>2012-05-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2023&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2023" target="_blank">CVE-2012-2023</a></td>
</tr>
<tr>
<td>adobe &#8212; illustrator</td>
<td>Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2025, and CVE-2012-2026.</td>
<td>2012-05-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2024&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2024" target="_blank">CVE-2012-2024</a></td>
</tr>
<tr>
<td>adobe &#8212; illustrator</td>
<td>Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, and CVE-2012-2026.</td>
<td>2012-05-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2025&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2025" target="_blank">CVE-2012-2025</a></td>
</tr>
<tr>
<td>adobe &#8212; illustrator</td>
<td>Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, and CVE-2012-2025.</td>
<td>2012-05-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2026&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2026" target="_blank">CVE-2012-2026</a></td>
</tr>
<tr>
<td>adobe &#8212; photoshop</td>
<td>Use-after-free vulnerability in Adobe Photoshop before CS6 allows remote attackers to execute arbitrary code via a crafted TIFF (aka .TIF) file.</td>
<td>2012-05-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2027&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2027" target="_blank">CVE-2012-2027</a></td>
</tr>
<tr>
<td>adobe &#8212; photoshop</td>
<td>Buffer overflow in Adobe Photoshop before CS6 allows remote attackers to execute arbitrary code via a crafted TIFF (aka .TIF) file.</td>
<td>2012-05-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2028&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2028" target="_blank">CVE-2012-2028</a></td>
</tr>
<tr>
<td>adobe &#8212; shockwave_player</td>
<td>Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2030, CVE-2012-2031, CVE-2012-2032, and CVE-2012-2033.</td>
<td>2012-05-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2029&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2029" target="_blank">CVE-2012-2029</a></td>
</tr>
<tr>
<td>adobe &#8212; shockwave_player</td>
<td>Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2029, CVE-2012-2031, CVE-2012-2032, and CVE-2012-2033.</td>
<td>2012-05-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2030&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2030" target="_blank">CVE-2012-2030</a></td>
</tr>
<tr>
<td>adobe &#8212; shockwave_player</td>
<td>Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2029, CVE-2012-2030, CVE-2012-2032, and CVE-2012-2033.</td>
<td>2012-05-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2031&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2031" target="_blank">CVE-2012-2031</a></td>
</tr>
<tr>
<td>adobe &#8212; shockwave_player</td>
<td>Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2029, CVE-2012-2030, CVE-2012-2031, and CVE-2012-2033.</td>
<td>2012-05-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2032&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2032" target="_blank">CVE-2012-2032</a></td>
</tr>
<tr>
<td>adobe &#8212; shockwave_player</td>
<td>Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2029, CVE-2012-2030, CVE-2012-2031, and CVE-2012-2032.</td>
<td>2012-05-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2033&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2033" target="_blank">CVE-2012-2033</a></td>
</tr>
<tr>
<td>apple &#8212; mac_os_x</td>
<td>Integer overflow in the Security Framework in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted input.</td>
<td>2012-05-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0662&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0662" target="_blank">CVE-2012-0662</a></td>
</tr>
<tr>
<td>ffmpeg &#8212; ffmpeg</td>
<td>Integer underflow in the asfrtp_parse_packet function in libavformat/rtpdec_asf.c in FFmpeg before 0.8.3 allows remote attackers to execute arbitrary code via a crafted ASF packet.</td>
<td>2012-05-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-4031&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4031" target="_blank">CVE-2011-4031</a></td>
</tr>
<tr>
<td>hp &#8212; performance_insight</td>
<td>SQL injection vulnerability in HP Performance Insight for Networks 5.3.x, 5.41, 5.41.001, and 5.41.002 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</td>
<td>2012-05-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2007&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2007" target="_blank">CVE-2012-2007</a></td>
</tr>
<tr>
<td>hp &#8212; performance_insight</td>
<td>Unspecified vulnerability in HP Performance Insight for Networks 5.3.x, 5.41, 5.41.001, and 5.41.002 allows remote authenticated users to gain privileges via unknown vectors.</td>
<td>2012-05-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2009&amp;vector=(AV:N/AC:L/Au:S/C:C/I:C/A:C)" target="_blank">9.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2009" target="_blank">CVE-2012-2009</a></td>
</tr>
<tr>
<td>microsoft &#8212; visio_viewer</td>
<td>Microsoft Visio Viewer 2010 Gold and SP1 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka &quot;VSD File Format Memory Corruption Vulnerability.&quot;</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0018&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0018" target="_blank">CVE-2012-0018</a></td>
</tr>
<tr>
<td>microsoft &#8212; excel</td>
<td>Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka &quot;Excel File Format Memory Corruption Vulnerability.&quot;</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0141&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0141" target="_blank">CVE-2012-0141</a></td>
</tr>
<tr>
<td>microsoft &#8212; excel</td>
<td>Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2008 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka &quot;Excel File Format Memory Corruption in OBJECTLINK Record Vulnerability.&quot;</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0142&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0142" target="_blank">CVE-2012-0142</a></td>
</tr>
<tr>
<td>microsoft &#8212; excel</td>
<td>Microsoft Excel 2003 SP3 and Office 2008 for Mac do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka &quot;Excel Memory Corruption Using Various Modified Bytes Vulnerability.&quot;</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0143&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0143" target="_blank">CVE-2012-0143</a></td>
</tr>
<tr>
<td>microsoft &#8212; office</td>
<td>Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview; Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Silverlight 4 before 4.1.10329; and Silverlight 5 before 5.1.10411 allow remote attackers to execute arbitrary code via a crafted TrueType font (TTF) file, aka &quot;TrueType Font Parsing Vulnerability.&quot;</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0159&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0159" target="_blank">CVE-2012-0159</a></td>
</tr>
<tr>
<td>microsoft &#8212; .net_framework</td>
<td>Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka &quot;.NET Framework Serialization Vulnerability.&quot;</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0160&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0160" target="_blank">CVE-2012-0160</a></td>
</tr>
<tr>
<td>microsoft &#8212; .net_framework</td>
<td>Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly handle an unspecified exception during use of partially trusted assemblies to serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka &quot;.NET Framework Serialization Vulnerability.&quot;</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0161&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0161" target="_blank">CVE-2012-0161</a></td>
</tr>
<tr>
<td>microsoft &#8212; .net_framework</td>
<td>Microsoft .NET Framework 4 does not properly allocate buffers, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka &quot;.NET Framework Buffer Allocation Vulnerability.&quot;</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0162&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0162" target="_blank">CVE-2012-0162</a></td>
</tr>
<tr>
<td>microsoft &#8212; office</td>
<td>GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2 and Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1 does not properly validate record types in EMF images, which allows remote attackers to execute arbitrary code via a crafted image, aka &quot;GDI+ Record Type Vulnerability.&quot;</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0165&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0165" target="_blank">CVE-2012-0165</a></td>
</tr>
<tr>
<td>microsoft &#8212; office</td>
<td>Heap-based buffer overflow in the Office GDI+ library in Microsoft Office 2003 SP3 and 2007 SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted EMF image in an Office document, aka &quot;GDI+ Heap Overflow Vulnerability.&quot;</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0167&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0167" target="_blank">CVE-2012-0167</a></td>
</tr>
<tr>
<td>microsoft &#8212; silverlight</td>
<td>Double free vulnerability in Microsoft Silverlight 4 before 4.1.10329 on Windows allows remote attackers to execute arbitrary code via vectors involving crafted XAML glyphs, aka &quot;Silverlight Double-Free Vulnerability.&quot;</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0176&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0176" target="_blank">CVE-2012-0176</a></td>
</tr>
<tr>
<td>microsoft &#8212; windows_7</td>
<td>win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input passed to kernel mode for (1) windows and (2) messages, which allows local users to gain privileges via a crafted application, aka &quot;Windows and Messages Vulnerability.&quot;</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0180&amp;vector=(AV:L/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">7.2</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0180" target="_blank">CVE-2012-0180</a></td>
</tr>
<tr>
<td>microsoft &#8212; windows_7</td>
<td>win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly manage Keyboard Layout files, which allows local users to gain privileges via a crafted application, aka &quot;Keyboard Layout File Vulnerability.&quot;</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0181&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0181" target="_blank">CVE-2012-0181</a></td>
</tr>
<tr>
<td>microsoft &#8212; office</td>
<td>Microsoft Word 2003 SP3 and 2007 SP2 and SP3, Office 2008 and 2011 for Mac, and Office Compatibility Pack SP2 and SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka &quot;RTF Mismatch Vulnerability.&quot;</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0183&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0183" target="_blank">CVE-2012-0183</a></td>
</tr>
<tr>
<td>microsoft &#8212; excel</td>
<td>Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2008 and 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka &quot;Excel SXLI Record Memory Corruption Vulnerability.&quot;</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0184&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0184" target="_blank">CVE-2012-0184</a></td>
</tr>
<tr>
<td>microsoft &#8212; excel</td>
<td>Heap-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 Gold and SP1, Excel Viewer, and Office Compatibility Pack SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers incorrect handling of memory during opening, aka &quot;Excel MergeCells Record Heap Overflow Vulnerability.&quot;</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0185&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0185" target="_blank">CVE-2012-0185</a></td>
</tr>
<tr>
<td>microsoft &#8212; excel</td>
<td>Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2008 and 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka &quot;Excel Series Record Parsing Type Mismatch Could Result in Remote Code Execution Vulnerability.&quot;</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1847&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1847" target="_blank">CVE-2012-1847</a></td>
</tr>
<tr>
<td>microsoft &#8212; windows_7</td>
<td>win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka &quot;Scrollbar Calculation Vulnerability.&quot;</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1848&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1848" target="_blank">CVE-2012-1848</a></td>
</tr>
<tr>
<td>oracle &#8212; database_10g</td>
<td>The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.0.5, as used in Oracle Fusion Middleware, Enterprise Manager, E-Business Suite, and possibly other products, allows remote attackers to execute arbitrary database commands by performing a remote registration of a database (1) instance or (2) service name that already exists, then conducting a man-in-the-middle (MITM) attack to hijack database connections, aka &quot;TNS Poison.&quot;</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1675&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1675" target="_blank">CVE-2012-1675</a></td>
</tr>
<tr>
<td>php &#8212; php</td>
<td>sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the &#039;d&#039; case.</td>
<td>2012-05-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1823&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1823" target="_blank">CVE-2012-1823</a></td>
</tr>
<tr>
<td>php &#8212; php</td>
<td>sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that contain a %3D sequence but no = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the &#039;d&#039; case. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.</td>
<td>2012-05-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2311&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2311" target="_blank">CVE-2012-2311</a></td>
</tr>
<tr>
<td>php &#8212; php</td>
<td>php-wrapper.fcgi does not properly handle command-line arguments, which allows remote attackers to bypass a protection mechanism in PHP 5.3.12 and 5.4.2 and execute arbitrary code by leveraging improper interaction between the PHP sapi/cgi/cgi_main.c component and a query string beginning with a +- sequence.</td>
<td>2012-05-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2335&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2335" target="_blank">CVE-2012-2335</a></td>
</tr>
<tr>
<td>wellintech &#8212; kingview</td>
<td>WellinTech KingSCADA 3.0 uses a cleartext base64 format for storage of passwords in user.db, which allows context-dependent attackers to obtain sensitive information by reading this file.</td>
<td>2012-05-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1977&amp;vector=(AV:N/AC:L/Au:N/C:C/I:N/A:N)" target="_blank">7.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1977" target="_blank">CVE-2012-1977</a></td>
</tr>
<tr>
<td>xnview &#8212; xnview</td>
<td>Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD record types, a different vulnerability than CVE-2012-0685.</td>
<td>2012-05-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0684&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0684" target="_blank">CVE-2012-0684</a></td>
</tr>
<tr>
<td>xnview &#8212; xnview</td>
<td>Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD record types, a different vulnerability than CVE-2012-0684.</td>
<td>2012-05-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0685&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0685" target="_blank">CVE-2012-0685</a></td>
</tr>
</tbody>
</table>
<p>
</div>
<p><a name="medium"></a></p>
<div>
<table align="center" border="1" summary="Medium Vulnerabilities">
<thead>
<tr>
<th colspan="5">Medium Vulnerabilities</th>
</tr>
<tr>
<th>Primary<br />
Vendor &#8212; Product</th>
<th>Description</th>
<th>Published</th>
<th>CVSS Score</th>
<th>Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td width="20%">N/A &#8212; N/A</td>
<td>Race condition in partmgr.sys in Windows Partition Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that makes multiple simultaneous Plug and Play (PnP) Configuration Manager function calls, aka &quot;Plug and Play (PnP) Configuration Manager Vulnerability.&quot;</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0178&amp;vector=(AV:L/AC:L/Au:S/C:C/I:C/A:C)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0178" target="_blank">CVE-2012-0178</a></td>
</tr>
<tr>
<td width="20%">apple &#8212; mac_os_x</td>
<td>Race condition in the initialization routine in blued in Bluetooth in Apple Mac OS X before 10.7.4 allows local users to gain privileges via vectors involving a temporary file.</td>
<td>2012-05-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0649&amp;vector=(AV:L/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">6.9</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0649" target="_blank">CVE-2012-0649</a></td>
</tr>
<tr>
<td width="20%">apple &#8212; mac_os_x</td>
<td>The directory server in Directory Service in Apple Mac OS X 10.6.8 allows remote attackers to obtain sensitive information from process memory via a crafted message.</td>
<td>2012-05-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0651&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0651" target="_blank">CVE-2012-0651</a></td>
</tr>
<tr>
<td width="20%">apple &#8212; mac_os_x</td>
<td>Login Window in Apple Mac OS X 10.7.3, when Legacy File Vault or networked home directories are enabled, does not properly restrict what is written to the system log for network logins, which allows local users to obtain sensitive information by reading the log.</td>
<td>2012-05-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0652&amp;vector=(AV:L/AC:L/Au:N/C:C/I:N/A:N)" target="_blank">4.9</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0652" target="_blank">CVE-2012-0652</a></td>
</tr>
<tr>
<td width="20%">apple &#8212; mac_os_x</td>
<td>libsecurity in Apple Mac OS X before 10.7.4 accesses uninitialized memory locations during the processing of X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted certificate.</td>
<td>2012-05-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0654&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0654" target="_blank">CVE-2012-0654</a></td>
</tr>
<tr>
<td width="20%">apple &#8212; mac_os_x</td>
<td>libsecurity in Apple Mac OS X before 10.7.4 does not properly restrict the length of RSA keys within X.509 certificates, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by conducting a spoofing or network-sniffing attack during communication with a site that uses a short key.</td>
<td>2012-05-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0655&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:N)" target="_blank">6.4</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0655" target="_blank">CVE-2012-0655</a></td>
</tr>
<tr>
<td width="20%">apple &#8212; mac_os_x</td>
<td>Race condition in LoginUIFramework in Apple Mac OS X 10.7.x before 10.7.4, when the Guest account is enabled, allows physically proximate attackers to login to arbitrary accounts by entering the account name and no password.</td>
<td>2012-05-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0656&amp;vector=(AV:L/AC:H/Au:N/C:C/I:C/A:C)" target="_blank">6.2</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0656" target="_blank">CVE-2012-0656</a></td>
</tr>
<tr>
<td width="20%">apple &#8212; mac_os_x</td>
<td>Buffer overflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted audio sample tables in a movie file that is progressively downloaded.</td>
<td>2012-05-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0658&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0658" target="_blank">CVE-2012-0658</a></td>
</tr>
<tr>
<td width="20%">apple &#8212; mac_os_x</td>
<td>Integer overflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG file.</td>
<td>2012-05-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0659&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0659" target="_blank">CVE-2012-0659</a></td>
</tr>
<tr>
<td width="20%">apple &#8212; mac_os_x</td>
<td>Buffer underflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG file.</td>
<td>2012-05-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0660&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0660" target="_blank">CVE-2012-0660</a></td>
</tr>
<tr>
<td width="20%">apple &#8212; mac_os_x</td>
<td>Use-after-free vulnerability in QuickTime in Apple Mac OS X 10.7.x before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with JPEG2000 encoding.</td>
<td>2012-05-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0661&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0661" target="_blank">CVE-2012-0661</a></td>
</tr>
<tr>
<td width="20%">apple &#8212; iphone_os</td>
<td>WebKit in Apple iOS before 5.1.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0672&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0672" target="_blank">CVE-2012-0672</a></td>
</tr>
<tr>
<td width="20%">apple &#8212; iphone_os</td>
<td>Safari in Apple iOS before 5.1.1 allows remote attackers to spoof the location bar&#039;s URL via a crafted web site.</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0674&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0674" target="_blank">CVE-2012-0674</a></td>
</tr>
<tr>
<td width="20%">apple &#8212; mac_os_x</td>
<td>Time Machine in Apple Mac OS X before 10.7.4 does not require continued use of SRP-based authentication after this authentication method is first used, which allows remote attackers to read Time Capsule credentials by spoofing the backup volume.</td>
<td>2012-05-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0675&amp;vector=(AV:N/AC:M/Au:N/C:P/I:N/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0675" target="_blank">CVE-2012-0675</a></td>
</tr>
<tr>
<td width="20%">apple &#8212; safari</td>
<td>WebKit in Apple Safari before 5.1.7 does not properly track state information during the processing of form input, which allows remote attackers to fill in form fields on the pages of arbitrary web sites via unspecified vectors.</td>
<td>2012-05-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0676&amp;vector=(AV:N/AC:L/Au:N/C:N/I:P/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0676" target="_blank">CVE-2012-0676</a></td>
</tr>
<tr>
<td width="20%">hp &#8212; performance_insight</td>
<td>Cross-site scripting (XSS) vulnerability in HP Performance Insight for Networks 5.3.x, 5.41, 5.41.001, and 5.41.002 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</td>
<td>2012-05-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2008&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2008" target="_blank">CVE-2012-2008</a></td>
</tr>
<tr>
<td width="20%">microsoft &#8212; .net_framework</td>
<td>Microsoft .NET Framework 4 does not properly compare index values, which allows remote attackers to cause a denial of service (application hang) via crafted requests to a Windows Presentation Foundation (WPF) application, aka &quot;.NET Framework Index Comparison Vulnerability.&quot;</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0164&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0164" target="_blank">CVE-2012-0164</a></td>
</tr>
<tr>
<td width="20%">microsoft &#8212; windows_7</td>
<td>Double free vulnerability in tcpip.sys in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that binds an IPv6 address to a local interface, aka &quot;TCP/IP Double Free Vulnerability.&quot;</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0179&amp;vector=(AV:L/AC:L/Au:S/C:C/I:C/A:C)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0179" target="_blank">CVE-2012-0179</a></td>
</tr>
<tr>
<td width="20%">php &#8212; php</td>
<td>Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote attackers to cause a denial of service (application crash) via a long string in the header of an HTTP request.</td>
<td>2012-05-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2329&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2329" target="_blank">CVE-2012-2329</a></td>
</tr>
<tr>
<td width="20%">php &#8212; php</td>
<td>sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to cause a denial of service (resource consumption) by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the &#039;T&#039; case. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.</td>
<td>2012-05-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2336&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2336" target="_blank">CVE-2012-2336</a></td>
</tr>
</tbody>
</table>
<p>
</div>
<p><a name="low"></a></p>
<div>
<table align="center" border="1" summary="Low Vulnerabilities">
<thead>
<tr>
<th colspan="5">Low Vulnerabilities</th>
</tr>
<tr>
<th>Primary<br />
Vendor &#8212; Product</th>
<th>Description</th>
<th>Published</th>
<th>CVSS Score</th>
<th>Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td width="20%">apple &#8212; mac_os_x</td>
<td>Quartz Composer in Apple Mac OS X before 10.7.4, when the RSS Visualizer screensaver is enabled, allows physically proximate attackers to bypass screen locking and launch a Safari process via unspecified vectors.</td>
<td>2012-05-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0657&amp;vector=(AV:L/AC:L/Au:N/C:N/I:P/A:N)" target="_blank">2.1</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0657" target="_blank">CVE-2012-0657</a></td>
</tr>
<tr>
<td width="20%">microsoft &#8212; windows_7</td>
<td>Windows Firewall in tcpip.sys in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly enforce firewall rules for outbound broadcast packets, which allows remote attackers to obtain potentially sensitive information by observing broadcast traffic on a local network, aka &quot;Windows Firewall Bypass Vulnerability.&quot;</td>
<td>2012-05-08</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0174&amp;vector=(AV:L/AC:L/Au:S/C:P/I:N/A:N)" target="_blank">1.7</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0174" target="_blank">CVE-2012-0174</a></td>
</tr>
</tbody>
</table>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.freednslookup.net/2012/05/16/sb12-135-vulnerability-summary-for-the-week-of-may-7-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TA12-129A: Microsoft Updates for Multiple Vulnerabilities</title>
		<link>http://www.freednslookup.net/2012/05/08/ta12-129a-microsoft-updates-for-multiple-vulnerabilities/</link>
		<comments>http://www.freednslookup.net/2012/05/08/ta12-129a-microsoft-updates-for-multiple-vulnerabilities/#comments</comments>
		<pubDate>Wed, 09 May 2012 00:00:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[US-Cert]]></category>

		<guid isPermaLink="false">http://www.freednslookup.net/2012/05/08/ta12-129a-microsoft-updates-for-multiple-vulnerabilities/</guid>
		<description><![CDATA[Original release date: May 08, 2012 &#124; Last revised: &#8211; Systems Affected Microsoft Windows Microsoft .NET Framework Microsoft Office Microsoft Silverlight Overview Select Microsoft software products contain multiple vulnerabilities.  Microsoft has released updates to address these vulnerabilities. Description The Microsoft Security Bulletin Summary for May 2012 describes multiple vulnerabilities in Microsoft software. Microsoft has released updates [...]]]></description>
			<content:encoded><![CDATA[<p>Original release date: May 08, 2012 | Last revised: &#8211;</p>
<p><a name="affected"></a></p>
<h3>Systems Affected</h3>
<ul>
<li>Microsoft Windows</li>
<li>Microsoft .NET Framework</li>
<li>Microsoft Office</li>
<li>Microsoft Silverlight</li>
</ul>
<p><a name="overview"></a></p>
<h3>Overview</h3>
<p>Select Microsoft software products contain multiple vulnerabilities.  Microsoft has released updates to address these vulnerabilities.</p>
<p><a name="description"></a></p>
<h3>Description</h3>
<p>The <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-may">Microsoft Security Bulletin Summary for May 2012</a> describes multiple vulnerabilities in Microsoft software. Microsoft has released updates to address the vulnerabilities.</p>
<p><a name="impact"></a></p>
<h3>Impact</h3>
<p>A remote, unauthenticated attacker could execute arbitrary code, cause a denial of service, or gain unauthorized access to your files or system.</p>
<p><a name="solution"></a></p>
<h3>Solution</h3>
<p><strong>Apply updates</strong></p>
<p>Microsoft has provided updates for these vulnerabilities in the <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-may">Microsoft Security Bulletin Summary for May 2012</a>, which describes any known issues related to the updates. Administrators are encouraged to note these issues and test for any potentially adverse effects. In addition, administrators should consider using an automated update distribution system such as <a href="http://technet.microsoft.com/en-us/wsus/default.aspx">Windows Server Update Services</a> (WSUS). Home users are encouraged to enable <a href="http://windows.microsoft.com/en-us/windows-vista/Turn-automatic-updating-on-or-off">automatic updates</a>.</p>
<p><a name="references"></a></p>
<h3>References</h3>
<ul>
<li>Microsoft Security Bulletin Summary for May 2012 &#8211; &lt;<a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-may">http://technet.microsoft.com/en-us/security/bulletin/ms12-may</a>&gt;</li>
<li>Microsoft Windows Server Update Services &#8211; &lt;<a href="http://technet.microsoft.com/en-us/wsus/default.aspx">http://technet.microsoft.com/en-us/wsus/default.aspx</a>&gt;</li>
<li>Microsoft Update &#8211; &lt;<a href="https://www.update.microsoft.com/">https://www.update.microsoft.com/</a>&gt;</li>
<li>Microsoft Update Overview &#8211; &lt;<a href="http://www.microsoft.com/security/updates/mu.aspx">http://www.microsoft.com/security/updates/mu.aspx</a>&gt;</li>
<li>Turn Automatic Updating On or Off &#8211; &lt;<a href="http://windows.microsoft.com/en-us/windows-vista/Turn-automatic-updating-on-or-off">http://windows.microsoft.com/en-us/windows-vista/Turn-automatic-updating-on-or-off</a>&gt;</li>
</ul>
<p><a name="revisions"></a></p>
<h3>Revision History</h3>
<ul>
<li>May 08, 2012: Initial release</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.freednslookup.net/2012/05/08/ta12-129a-microsoft-updates-for-multiple-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SB12-128: Vulnerability Summary for the Week of April 30, 2012</title>
		<link>http://www.freednslookup.net/2012/05/08/sb12-128-vulnerability-summary-for-the-week-of-april-30-2012/</link>
		<comments>http://www.freednslookup.net/2012/05/08/sb12-128-vulnerability-summary-for-the-week-of-april-30-2012/#comments</comments>
		<pubDate>Wed, 09 May 2012 00:00:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[US-Cert]]></category>

		<guid isPermaLink="false">http://www.freednslookup.net/2012/05/08/sb12-128-vulnerability-summary-for-the-week-of-april-30-2012/</guid>
		<description><![CDATA[The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cyber Security Division (NCSD) / United States Computer Emergency Readiness Team [...]]]></description>
			<content:encoded><![CDATA[<p><a name="top"></a></p>
<table align="center">
<tr>
<td>
<p>The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cyber Security Division (NCSD) / United States Computer Emergency Readiness Team (US-CERT). For updated or updated entries, please visit the <a href="http://nvd.nist.gov" target="_blank">NVD</a>, which contains historical vulnerability information.</p>
<p>The vulnerabilities are based on the <a href="http://cve.mitre.org/" target="_blank">CVE</a> vulnerability naming standard and are organized according to severity, determined by the <a href="http://nvd.nist.gov/cvss.cfm" target="_blank">Common Vulnerability Scoring System</a> (CVSS) standard. The division of high, medium, and low severities correspond to the following scores:</p>
<ul>
<li>
<p><strong>High</strong> &#8211; Vulnerabilities will be labeled High severity if they have a CVSS base score of 7.0 &#8211; 10.0</p>
</li>
<li>
<p><strong>Medium</strong> &#8211; Vulnerabilities will be labeled Medium severity if they have a CVSS base score of 4.0 &#8211; 6.9</p>
</li>
<li>
<p><strong>Low</strong> &#8211; Vulnerabilities will be labeled Low severity if they have a CVSS base score of 0.0 &#8211; 3.9</p>
</li>
</ul>
<p>Entries may include additional information provided by organizations and efforts sponsored by US-CERT. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletins is compiled from external, open source reports and is not a direct result of US-CERT analysis.</p>
</td>
</tr>
</table>
<p>
<a name="high"></a></p>
<div>
<table align="center" border="1" summary="High Vulnerabilities">
<thead>
<tr>
<th colspan="5">High Vulnerabilities</th>
</tr>
<tr>
<th>Primary<br />
Vendor &#8212; Product</th>
<th>Description</th>
<th>Published</th>
<th>CVSS Score</th>
<th>Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td>apache &#8212; qpid</td>
<td>Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messaging functionality and job functionality of a cluster by leveraging knowledge of a cluster-username.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3620&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3620" target="_blank">CVE-2011-3620</a></td>
</tr>
<tr>
<td>cisco &#8212; ios</td>
<td>Memory leak in Cisco IOS 15.1 and 15.2 allows remote attackers to cause a denial of service (memory consumption) via malformed SIP packets on a NAT interface, aka Bug ID CSCts12366.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-2578&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">7.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2578" target="_blank">CVE-2011-2578</a></td>
</tr>
<tr>
<td>cisco &#8212; ios_xr</td>
<td>The NETIO and IPV4_IO processes in Cisco IOS XR 3.8 through 4.1, as used in Cisco Carrier Routing System and other products, allow remote attackers to cause a denial of service (CPU consumption) via crafted network traffic, aka Bug ID CSCti59888.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3295&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">7.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3295" target="_blank">CVE-2011-3295</a></td>
</tr>
<tr>
<td>cisco &#8212; adaptive_security_appliance_software</td>
<td>The ESMTP inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.5 allows remote attackers to cause a denial of service (CPU consumption) via an unspecified closing sequence, aka Bug ID CSCtt32565.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-4006&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">7.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4006" target="_blank">CVE-2011-4006</a></td>
</tr>
<tr>
<td>cisco &#8212; ios</td>
<td>Cisco IOS 12.0, 15.0, and 15.1, when a Policy Feature Card 3C (PFC3C) is used, does not create a fragment entry during processing of an ICMPv6 ACL, which has unspecified impact and remote attack vectors, aka Bug ID CSCtj90091.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-4012&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4012" target="_blank">CVE-2011-4012</a></td>
</tr>
<tr>
<td>cisco &#8212; nexus_2148t_fex_switch</td>
<td>Memory leak in libcmd in Cisco NX-OS 5.0 on Nexus switches allows remote authenticated users to cause a denial of service (memory consumption) via SNMP requests, aka Bug ID CSCtr65682.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-4023&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">7.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4023" target="_blank">CVE-2011-4023</a></td>
</tr>
<tr>
<td>cisco &#8212; adaptive_security_appliance_software</td>
<td>Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 through 8.4 allow remote attackers to cause a denial of service (connection limit exceeded) by triggering a large number of stale connections that result in an incorrect value for an MPF connection count, aka Bug ID CSCtv19854.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0378&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">7.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0378" target="_blank">CVE-2012-0378</a></td>
</tr>
<tr>
<td>cisco &#8212; ios</td>
<td>Race condition in the Zone-Based Firewall in Cisco IOS 15.1 and 15.2, when IPS policies are configured, allows remote attackers to cause a denial of service (device crash) by sending IPv6 packets, aka Bug ID CSCtk53534.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1324&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:C)" target="_blank">7.1</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1324" target="_blank">CVE-2012-1324</a></td>
</tr>
<tr>
<td>google &#8212; chrome</td>
<td>Use-after-free vulnerability in Google Chrome before 18.0.1025.168 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the floating of elements, a different vulnerability than CVE-2011-3081.</td>
<td>2012-05-01</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3078&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3078" target="_blank">CVE-2011-3078</a></td>
</tr>
<tr>
<td>google &#8212; chrome</td>
<td>The Inter-process Communication (IPC) implementation in Google Chrome before 18.0.1025.168 does not properly validate messages, which has unspecified impact and attack vectors.</td>
<td>2012-05-01</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3079&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3079" target="_blank">CVE-2011-3079</a></td>
</tr>
<tr>
<td>google &#8212; chrome</td>
<td>Race condition in the Inter-process Communication (IPC) implementation in Google Chrome before 18.0.1025.168 allows attackers to bypass intended sandbox restrictions via unspecified vectors.</td>
<td>2012-05-01</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3080&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3080" target="_blank">CVE-2011-3080</a></td>
</tr>
<tr>
<td>google &#8212; chrome</td>
<td>Use-after-free vulnerability in Google Chrome before 18.0.1025.168 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the floating of elements, a different vulnerability than CVE-2011-3078.</td>
<td>2012-05-01</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3081&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3081" target="_blank">CVE-2011-3081</a></td>
</tr>
<tr>
<td>google &#8212; chrome</td>
<td>Use-after-free vulnerability in the XML parser in Google Chrome before 18.0.1025.168 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.</td>
<td>2012-05-01</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1521&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1521" target="_blank">CVE-2012-1521</a></td>
</tr>
<tr>
<td>hp &#8212; system_health_application_and_command_line_utilities</td>
<td>Multiple unspecified vulnerabilities in HP System Health Application and Command Line Utilities before 9.0.0 allow remote attackers to execute arbitrary code via unknown vectors.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2000&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2000" target="_blank">CVE-2012-2000</a></td>
</tr>
<tr>
<td>hp &#8212; snmp_agents_for_linux</td>
<td>Open redirect vulnerability in HP SNMP Agents for Linux before 9.0.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2002&amp;vector=(AV:N/AC:M/Au:N/C:C/I:P/A:P)" target="_blank">8.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2002" target="_blank">CVE-2012-2002</a></td>
</tr>
<tr>
<td>hp &#8212; insight_management_agents</td>
<td>Open redirect vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2004&amp;vector=(AV:N/AC:M/Au:N/C:C/I:P/A:P)" target="_blank">8.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2004" target="_blank">CVE-2012-2004</a></td>
</tr>
<tr>
<td>ibm &#8212; rational_appscan</td>
<td>The Enterprise Console client in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0732&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0732" target="_blank">CVE-2012-0732</a></td>
</tr>
<tr>
<td>ibm &#8212; rational_appscan</td>
<td>IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly import jobs, which allows man-in-the-middle attackers to obtain sensitive information or possibly have unspecified other impact via a crafted job.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0734&amp;vector=(AV:N/AC:H/Au:N/C:C/I:C/A:C)" target="_blank">7.6</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0734" target="_blank">CVE-2012-0734</a></td>
</tr>
<tr>
<td>ibm &#8212; rational_appscan</td>
<td>IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly scan file: URLs, which allows man-in-the-middle attackers to obtain sensitive information or possibly have unspecified other impact via a crafted URI.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0735&amp;vector=(AV:N/AC:H/Au:N/C:C/I:C/A:C)" target="_blank">7.6</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0735" target="_blank">CVE-2012-0735</a></td>
</tr>
<tr>
<td>ibm &#8212; rational_appscan</td>
<td>IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly create scan jobs, which allows remote attackers to execute arbitrary code via a crafted web site.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0736&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0736" target="_blank">CVE-2012-0736</a></td>
</tr>
<tr>
<td>justsystems &#8212; ichitaro</td>
<td>Buffer overflow in JustSystems Ichitaro 2011 Sou, Ichitaro 2006 through 2011, Ichitaro Government 2006 through 2010, Ichitaro Portable with oreplug, Ichitaro Viewer, JUST School, JUST School 2009 and 2010, JUST Jump 4, JUST Frontier, oreplug, Shuriken Pro4, Shuriken 2007 through 2010, Shuriken Pro4 Corporate Edition, Shuriken CE/2007 through CE/2009 Corporate Edition, Shuriken 2010 Corporate Edition, Rekishimail Sengokubusho no missho, and Bakumatsushishi no missho allows remote attackers to execute arbitrary code via a crafted image file.</td>
<td>2012-04-27</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0269&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0269" target="_blank">CVE-2012-0269</a></td>
</tr>
<tr>
<td>netgear &#8212; prosafe_fvs318n</td>
<td>The default configuration of the NETGEAR ProSafe FVS318N firewall enables web-based administration on the WAN interface, which allows remote attackers to establish an HTTP connection and possibly have unspecified other impact via unknown vectors.</td>
<td>2012-04-27</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2439&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2439" target="_blank">CVE-2012-2439</a></td>
</tr>
<tr>
<td>oracle &#8212; sun_products_suite</td>
<td>Unspecified vulnerability in the Oracle Grid Engine component in Oracle Sun Products Suite 6.1 and 6.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to qrsh.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0208&amp;vector=(AV:N/AC:L/Au:S/C:C/I:C/A:C)" target="_blank">9.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0208" target="_blank">CVE-2012-0208</a></td>
</tr>
<tr>
<td>oracle &#8212; database_server</td>
<td>Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.2.0.2, when running on Windows, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0519&amp;vector=(AV:N/AC:H/Au:S/C:C/I:C/A:C)" target="_blank">7.1</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0519" target="_blank">CVE-2012-0519</a></td>
</tr>
<tr>
<td>oracle &#8212; sun_products_suite</td>
<td>Unspecified vulnerability in the Oracle Grid Engine component in Oracle Sun Products Suite 6.1 and 6.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to sgepasswd.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0523&amp;vector=(AV:L/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">7.2</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0523" target="_blank">CVE-2012-0523</a></td>
</tr>
<tr>
<td>oracle &#8212; supply_chain_products_suite</td>
<td>Unspecified vulnerability in the Oracle AutoVue Office component in Oracle Supply Chain Products Suite 20.0.2 allows remote attackers to affect confidentiality, integrity, and availability, related to Desktop API.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0549&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0549" target="_blank">CVE-2012-0549</a></td>
</tr>
<tr>
<td>oracle &#8212; database_server</td>
<td>Unspecified vulnerability in the Oracle Spatial component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0552&amp;vector=(AV:N/AC:L/Au:S/C:C/I:C/A:C)" target="_blank">9.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0552" target="_blank">CVE-2012-0552</a></td>
</tr>
<tr>
<td>oracle &#8212; fusion_middleware</td>
<td>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows remote attackers to affect confidentiality, integrity, and availability, related to Outside In Image Export SDK.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0554&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0554" target="_blank">CVE-2012-0554</a></td>
</tr>
<tr>
<td>oracle &#8212; fusion_middleware</td>
<td>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows remote attackers to affect confidentiality, integrity, and availability, related to Outside In Image Export SDK.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0555&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0555" target="_blank">CVE-2012-0555</a></td>
</tr>
<tr>
<td>oracle &#8212; fusion_middleware</td>
<td>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows remote attackers to affect confidentiality, integrity, and availability, related to Outside In Image Export SDK.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0556&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0556" target="_blank">CVE-2012-0556</a></td>
</tr>
<tr>
<td>oracle &#8212; fusion_middleware</td>
<td>Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows remote attackers to affect confidentiality, integrity, and availability, related to Outside In Image Export SDK.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0557&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0557" target="_blank">CVE-2012-0557</a></td>
</tr>
<tr>
<td>oracle &#8212; fusion_middleware</td>
<td>Unspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware 28.2.2 and earlier, and JDK/JRE 5 and 6 27.7.1 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1695&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1695" target="_blank">CVE-2012-1695</a></td>
</tr>
<tr>
<td>oracle &#8212; fusion_middleware</td>
<td>Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Designer.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1709&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1709" target="_blank">CVE-2012-1709</a></td>
</tr>
<tr>
<td>oracle &#8212; fusion_middleware</td>
<td>Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Designer.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1710&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1710" target="_blank">CVE-2012-1710</a></td>
</tr>
<tr>
<td>ruggedcom &#8212; ros</td>
<td>RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the banner, which makes it easier for remote attackers to obtain access by performing a calculation on this address value, and then establishing a (1) TELNET, (2) remote shell (aka rsh), or (3) serial-console session.</td>
<td>2012-04-27</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1803&amp;vector=(AV:N/AC:M/Au:S/C:C/I:C/A:C)" target="_blank">8.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1803" target="_blank">CVE-2012-1803</a></td>
</tr>
<tr>
<td>ruggedcom &#8212; ros</td>
<td>RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address field in a banner, which makes it easier for remote attackers to obtain access by performing a calculation on this address value, and then establishing a (1) SSH or (2) HTTPS session, a different vulnerability than CVE-2012-1803.</td>
<td>2012-04-27</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2441&amp;vector=(AV:N/AC:M/Au:S/C:C/I:C/A:C)" target="_blank">8.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2441" target="_blank">CVE-2012-2441</a></td>
</tr>
<tr>
<td>tp-link &#8212; 8840t</td>
<td>The default configuration of the TP-Link 8840T router enables web-based administration on the WAN interface, which allows remote attackers to establish an HTTP connection and possibly have unspecified other impact via unknown vectors.</td>
<td>2012-04-27</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2440&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2440" target="_blank">CVE-2012-2440</a></td>
</tr>
<tr>
<td>wellintech &#8212; kingview</td>
<td>Untrusted search path vulnerability in WellinTech KingView 6.53 allows local users to gain privileges via a Trojan horse DLL in the current working directory.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1819&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1819" target="_blank">CVE-2012-1819</a></td>
</tr>
</tbody>
</table>
<p>
</div>
<p><a name="medium"></a></p>
<div>
<table align="center" border="1" summary="Medium Vulnerabilities">
<thead>
<tr>
<th colspan="5">Medium Vulnerabilities</th>
</tr>
<tr>
<th>Primary<br />
Vendor &#8212; Product</th>
<th>Description</th>
<th>Published</th>
<th>CVSS Score</th>
<th>Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td width="20%">N/A &#8212; N/A</td>
<td>Heap-based buffer overflow in chan_skinny.c in the Skinny channel driver in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x before 10.3.1 allows remote authenticated users to cause a denial of service or possibly have unspecified other impact via a series of KEYPAD_BUTTON_MESSAGE events.</td>
<td>2012-04-30</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2415&amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:P)" target="_blank">6.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2415" target="_blank">CVE-2012-2415</a></td>
</tr>
<tr>
<td width="20%">asterisk &#8212; open_source</td>
<td>main/manager.c in the Manager Interface in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x before 10.3.1 and Asterisk Business Edition C.3.x before C.3.7.4 does not properly enforce System class authorization requirements, which allows remote authenticated users to execute arbitrary commands via (1) the originate action in the MixMonitor application, (2) the SHELL and EVAL functions in the GetVar manager action, or (3) the SHELL and EVAL functions in the Status manager action.</td>
<td>2012-04-30</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2414&amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:P)" target="_blank">6.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2414" target="_blank">CVE-2012-2414</a></td>
</tr>
<tr>
<td width="20%">asterisk &#8212; open_source</td>
<td>chan_sip.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.11.1 and 10.x before 10.3.1 and Asterisk Business Edition C.3.x before C.3.7.4, when the trustrpid option is enabled, allows remote authenticated users to cause a denial of service (daemon crash) by sending a SIP UPDATE message that triggers a connected-line update attempt without an associated channel.</td>
<td>2012-04-30</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2416&amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:P)" target="_blank">6.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2416" target="_blank">CVE-2012-2416</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; unified_contact_center_express</td>
<td>Cisco Unified Contact Center Express (aka CCX) 8.0 and 8.5 allows remote attackers to cause a denial of service via network traffic, as demonstrated by an SEC-BE-STABLE test case, aka Bug ID CSCth33834.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-2583&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2583" target="_blank">CVE-2011-2583</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; ios</td>
<td>The HTTP client in Cisco IOS 12.4 and 15.0 allows user-assisted remote attackers to cause a denial of service (device crash) via a malformed HTTP response to a request for service installation, aka Bug ID CSCts12249.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-2586&amp;vector=(AV:N/AC:H/Au:N/C:N/I:N/A:C)" target="_blank">5.4</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2586" target="_blank">CVE-2011-2586</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; carrier_routing_system</td>
<td>Cisco Carrier Routing System 3.9.1 allows remote attackers to cause a denial of service (Metro subsystem crash) via a fragmented GRE packet, aka Bug ID CSCts14887.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3283&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3283" target="_blank">CVE-2011-3283</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; adaptive_security_appliance_software</td>
<td>CRLF injection vulnerability in /+CSCOE+/logon.html on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 through 8.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors, aka Bug ID CSCth63101.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3285&amp;vector=(AV:N/AC:L/Au:N/C:N/I:P/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3285" target="_blank">CVE-2011-3285</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; secure_access_control_server</td>
<td>Multiple cross-site request forgery (CSRF) vulnerabilities in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.2 allow remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences, aka Bug ID CSCtr78143.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3293&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3293" target="_blank">CVE-2011-3293</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; adaptive_security_appliance_software</td>
<td>Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.4 process IKE requests despite a vpnclient mode configuration, which allows remote attackers to obtain potentially sensitive information by reading IKE responder traffic, aka Bug ID CSCtt07749.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3309&amp;vector=(AV:N/AC:M/Au:N/C:P/I:N/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3309" target="_blank">CVE-2011-3309</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; secure_access_control_server</td>
<td>Multiple cross-site scripting (XSS) vulnerabilities in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCtr78192.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3317&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3317" target="_blank">CVE-2011-3317</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; ios</td>
<td>Cisco IOS 15.0 and 15.1 and IOS XE 3.x do not properly handle the &quot;set mpls experimental imposition&quot; command, which allows remote attackers to cause a denial of service (device crash) via network traffic that triggers (1) fragmentation or (2) reassembly, aka Bug ID CSCtr56576.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-4007&amp;vector=(AV:N/AC:H/Au:N/C:N/I:N/A:C)" target="_blank">5.4</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4007" target="_blank">CVE-2011-4007</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; wireless_control_system_software</td>
<td>The TAC Case Attachment tool in Cisco Wireless Control System (WCS) 7.0 allows remote authenticated users to read arbitrary files under webnms/Temp/ via unspecified vectors, aka Bug ID CSCtq86807.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-4014&amp;vector=(AV:N/AC:L/Au:S/C:P/I:N/A:N)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4014" target="_blank">CVE-2011-4014</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; ios</td>
<td>Cisco IOS 15.2S allows remote attackers to cause a denial of service (interface queue wedge) via malformed UDP traffic on port 465, aka Bug ID CSCts48300.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-4015&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4015" target="_blank">CVE-2011-4015</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; ios</td>
<td>The PPP implementation in Cisco IOS 12.2 and 15.0 through 15.2, when Point-to-Point Termination and Aggregation (PTA) and L2TP are used, allows remote attackers to cause a denial of service (device crash) via crafted network traffic, aka Bug ID CSCtf71673.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-4016&amp;vector=(AV:N/AC:H/Au:N/C:N/I:N/A:C)" target="_blank">5.4</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4016" target="_blank">CVE-2011-4016</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; unified_communications_manager</td>
<td>Memory leak in Cisco IOS 12.4 and 15.0 through 15.2, and Cisco Unified Communications Manager (CUCM) 7.x, allows remote attackers to cause a denial of service (memory consumption) via a crafted response to a SIP SUBSCRIBE message, aka Bug IDs CSCto93837 and CSCtj61883.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-4019&amp;vector=(AV:N/AC:H/Au:N/C:N/I:N/A:C)" target="_blank">5.4</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4019" target="_blank">CVE-2011-4019</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; intrusion_prevention_system</td>
<td>The sensor in Cisco Intrusion Prevention System (IPS) 7.0 and 7.1 allows remote attackers to cause a denial of service (file-handle exhaustion and mainApp hang) by making authentication attempts that exceed the configured limit, aka Bug ID CSCto51204.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-4022&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4022" target="_blank">CVE-2011-4022</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; ios</td>
<td>Cisco IOS 15.1 and 15.2 and IOS XE 3.x, when configured as an IPsec hub with X.509 certificates in use, allows remote authenticated users to cause a denial of service (segmentation fault and device crash) via unspecified vectors, aka Bug ID CSCtq61128.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-4231&amp;vector=(AV:N/AC:M/Au:S/C:N/I:N/A:C)" target="_blank">6.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4231" target="_blank">CVE-2011-4231</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; unified_meetingplace</td>
<td>The web server in Cisco Unified MeetingPlace 6.1 and 8.5 produces different responses for directory queries depending on whether the directory exists, which allows remote attackers to enumerate directory names via a series of queries, aka Bug ID CSCtt94070.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-4232&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4232" target="_blank">CVE-2011-4232</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; ciscoworks_common_services</td>
<td>CRLF injection vulnerability in autologin.jsp in Cisco CiscoWorks Common Services 4.0, as used in Cisco Prime LAN Management Solution and other products, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the URL parameter, aka Bug ID CSCtu18693.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-4237&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4237" target="_blank">CVE-2011-4237</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; small_business_ip_phone_firmware</td>
<td>Cisco Small Business IP phones with SPA 500 series firmware 7.4.9 and earlier do not require authentication for Push XML requests, which allows remote attackers to make telephone calls via an XML document, aka Bug ID CSCts08768.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0333&amp;vector=(AV:N/AC:L/Au:N/C:N/I:P/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0333" target="_blank">CVE-2012-0333</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; adaptive_security_appliance_software</td>
<td>Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 through 8.4 do not properly perform proxy authentication during attempts to cut through a firewall, which allows remote attackers to obtain sensitive information via a connection attempt, aka Bug ID CSCtx42746.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0335&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0335" target="_blank">CVE-2012-0335</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; unified_meetingplace</td>
<td>SQL injection vulnerability in the web component in Cisco Unified MeetingPlace 7.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCtx08939.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0337&amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:P)" target="_blank">6.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0337" target="_blank">CVE-2012-0337</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; ios</td>
<td>Cisco IOS 12.2 through 12.4 and 15.0 does not recognize the vrf-also keyword during enforcement of access-class commands, which allows remote attackers to establish SSH connections from arbitrary source IP addresses via a standard SSH client, aka Bug ID CSCsv86113.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0338&amp;vector=(AV:N/AC:L/Au:N/C:N/I:P/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0338" target="_blank">CVE-2012-0338</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; ios</td>
<td>Cisco IOS 12.2 through 12.4 and 15.0 does not recognize the vrf-also keyword during enforcement of access-class commands, which allows remote attackers to establish TELNET connections from arbitrary source IP addresses via a standard TELNET client, aka Bug ID CSCsi77774.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0339&amp;vector=(AV:N/AC:L/Au:N/C:N/I:P/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0339" target="_blank">CVE-2012-0339</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; ip_communicator</td>
<td>The sccp-protocol component in Cisco IP Communicator (CIPC) 7.0 through 8.6 does not limit the rate of SCCP messages to Cisco Unified Communications Manager (CUCM), which allows remote attackers to cause a denial of service via vectors that trigger (1) on hook and (2) off hook messages, as demonstrated by a Plantronics headset, aka Bug ID CSCti40315.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0361&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0361" target="_blank">CVE-2012-0361</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; ios</td>
<td>The extended ACL functionality in Cisco IOS 12.2(58)SE2 and 15.0(1)SE discards all lines that end with a log or time keyword, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by sending network traffic, aka Bug ID CSCts01106.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0362&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0362" target="_blank">CVE-2012-0362</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; unified_communications_manager</td>
<td>The voice-sipstack component in Cisco Unified Communications Manager (CUCM) 8.5 allows remote attackers to cause a denial of service (core dump) via vectors involving SIP messages that arrive after an upgrade, aka Bug ID CSCtj87367.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0376&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0376" target="_blank">CVE-2012-0376</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; ios</td>
<td>dot11t/t_if_dot11_hal_ath.c in Cisco IOS 12.3, 12.4, 15.0, and 15.1 allows remote attackers to cause a denial of service (assertion failure and reboot) via 802.11 wireless traffic, as demonstrated by a video call from Apple iOS 5.0 on an iPhone 4S, aka Bug ID CSCtt94391.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1327&amp;vector=(AV:A/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">6.1</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1327" target="_blank">CVE-2012-1327</a></td>
</tr>
<tr>
<td width="20%">cisco &#8212; unified_ip_phone</td>
<td>Cisco Unified IP Phones 9900 series devices with firmware 9.1 and 9.2 do not properly handle downloads of configuration information to an RT phone, which allows local users to gain privileges via unspecified injected data, aka Bug ID CSCts32237.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1328&amp;vector=(AV:L/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">4.6</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1328" target="_blank">CVE-2012-1328</a></td>
</tr>
<tr>
<td width="20%">hp &#8212; snmp_agents_for_linux</td>
<td>Cross-site scripting (XSS) vulnerability in HP SNMP Agents for Linux before 9.0.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2001&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2001" target="_blank">CVE-2012-2001</a></td>
</tr>
<tr>
<td width="20%">hp &#8212; insight_management_agents</td>
<td>Cross-site request forgery (CSRF) vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2003&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2003" target="_blank">CVE-2012-2003</a></td>
</tr>
<tr>
<td width="20%">hp &#8212; insight_management_agents</td>
<td>Cross-site scripting (XSS) vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2005&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2005" target="_blank">CVE-2012-2005</a></td>
</tr>
<tr>
<td width="20%">hp &#8212; insight_management_agents</td>
<td>Unspecified vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to modify data or cause a denial of service via unknown vectors.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2006&amp;vector=(AV:N/AC:M/Au:S/C:N/I:P/A:P)" target="_blank">4.9</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2006" target="_blank">CVE-2012-2006</a></td>
</tr>
<tr>
<td width="20%">htc &#8212; evo_3d_software</td>
<td>The HTC IQRD service for Android on the HTC EVO 4G before 4.67.651.3, EVO Design 4G before 2.12.651.5, Shift 4G before 2.77.651.3, EVO 3D before 2.17.651.5, EVO View 4G before 2.23.651.1, Vivid before 3.26.502.56, and Hero does not restrict localhost access to TCP port 2479, which allows remote attackers to (1) send SMS messages, (2) obtain the Network Access Identifier (NAI) and its password, or trigger (3) popup messages or (4) tones via a crafted application that leverages the android.permission.INTERNET permission.</td>
<td>2012-05-01</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2217&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:N)" target="_blank">6.4</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2217" target="_blank">CVE-2012-2217</a></td>
</tr>
<tr>
<td width="20%">ibm &#8212; rational_appscan</td>
<td>Unrestricted file upload vulnerability in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 allows remote authenticated users to execute arbitrary ASP.NET code by uploading a .aspx file, and then accessing it via unspecified vectors.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0729&amp;vector=(AV:N/AC:M/Au:S/C:P/I:P/A:P)" target="_blank">6.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0729" target="_blank">CVE-2012-0729</a></td>
</tr>
<tr>
<td width="20%">ibm &#8212; rational_appscan</td>
<td>Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 allow remote attackers to hijack the authentication of administrators for requests that create administrative accounts.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0730&amp;vector=(AV:N/AC:M/Au:S/C:P/I:P/A:P)" target="_blank">6.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0730" target="_blank">CVE-2012-0730</a></td>
</tr>
<tr>
<td width="20%">ibm &#8212; rational_appscan</td>
<td>IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not prevent service-account impersonation, which allows remote authenticated users to read arbitrary files via unspecified vectors.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0731&amp;vector=(AV:N/AC:L/Au:S/C:C/I:N/A:N)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0731" target="_blank">CVE-2012-0731</a></td>
</tr>
<tr>
<td width="20%">ibm &#8212; rational_appscan</td>
<td>IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1, when Integrated Windows authentication is used, allows remote authenticated users to obtain administrative privileges by hijacking a session associated with the service account.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0733&amp;vector=(AV:N/AC:M/Au:S/C:P/I:P/A:P)" target="_blank">6.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0733" target="_blank">CVE-2012-0733</a></td>
</tr>
<tr>
<td width="20%">ibm &#8212; websphere_application_server</td>
<td>The Web Server Plug-in in IBM WebSphere Application Server (WAS) 8.0 and earlier uses unencrypted HTTP communication after expiration of the plugin-key.kdb password, which allows remote attackers to obtain sensitive information by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.</td>
<td>2012-05-01</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2162&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2162" target="_blank">CVE-2012-2162</a></td>
</tr>
<tr>
<td width="20%">justsystems &#8212; ichitaro</td>
<td>Untrusted search path vulnerability in JustSystems Ichitaro 2011 Sou, Ichitaro 2006 through 2011, Ichitaro Government 2006 through 2010, Ichitaro Portable with oreplug, Ichitaro Viewer, JUST School, JUST School 2009 and 2010, JUST Jump 4, JUST Frontier, and oreplug allows local users to gain privileges via a Trojan horse DLL in the current working directory.</td>
<td>2012-04-27</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1242&amp;vector=(AV:L/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">6.9</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1242" target="_blank">CVE-2012-1242</a></td>
</tr>
<tr>
<td width="20%">mcafee &#8212; web_gateway</td>
<td>** DISPUTED ** McAfee Web Gateway 7.0 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host HTTP header. NOTE: this issue might not be reproducible, because the researcher did not provide configuration details for the vulnerable system, and the observed behavior might be consistent with a configuration that was (perhaps inadvertently) designed to allow access based on Host HTTP headers.</td>
<td>2012-04-28</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2212&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2212" target="_blank">CVE-2012-2212</a></td>
</tr>
<tr>
<td width="20%">mozilla &#8212; bugzilla</td>
<td>Bugzilla 3.5.x and 3.6.x before 3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and 4.2.x before 4.2.1, when the inbound_proxies option is enabled, does not properly validate the X-Forwarded-For HTTP header, which allows remote attackers to bypass the lockout policy via a series of authentication requests with (1) different IP address strings in this header or (2) a long string in this header.</td>
<td>2012-04-27</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0465&amp;vector=(AV:N/AC:M/Au:N/C:P/I:N/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0465" target="_blank">CVE-2012-0465</a></td>
</tr>
<tr>
<td width="20%">mozilla &#8212; bugzilla</td>
<td>template/en/default/list/list.js.tmpl in Bugzilla 2.x and 3.x before 3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and 4.2.x before 4.2.1 does not properly handle multiple logins, which allows remote attackers to conduct cross-site scripting (XSS) attacks and obtain sensitive bug information via a crafted web page.</td>
<td>2012-04-27</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0466&amp;vector=(AV:N/AC:H/Au:N/C:P/I:P/A:N)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0466" target="_blank">CVE-2012-0466</a></td>
</tr>
<tr>
<td width="20%">mysql &#8212; mysql</td>
<td>Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.60 and earlier, and 5.5.19 and earlier, allows remote authenticated users to affect availability, related to MyISAM.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0583&amp;vector=(AV:N/AC:L/Au:S/C:N/I:N/A:P)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0583" target="_blank">CVE-2012-0583</a></td>
</tr>
<tr>
<td width="20%">mysql &#8212; mysql</td>
<td>Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability, related to Server DML.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1688&amp;vector=(AV:N/AC:L/Au:S/C:N/I:N/A:P)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1688" target="_blank">CVE-2012-1688</a></td>
</tr>
<tr>
<td width="20%">mysql &#8212; mysql</td>
<td>Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1690&amp;vector=(AV:N/AC:L/Au:S/C:N/I:N/A:P)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1690" target="_blank">CVE-2012-1690</a></td>
</tr>
<tr>
<td width="20%">mysql &#8212; mysql</td>
<td>Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1696&amp;vector=(AV:N/AC:L/Au:S/C:N/I:N/A:P)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1696" target="_blank">CVE-2012-1696</a></td>
</tr>
<tr>
<td width="20%">mysql &#8212; mysql</td>
<td>Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.21 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1697&amp;vector=(AV:N/AC:L/Au:S/C:N/I:N/A:P)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1697" target="_blank">CVE-2012-1697</a></td>
</tr>
<tr>
<td width="20%">mysql &#8212; mysql</td>
<td>Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1703&amp;vector=(AV:N/AC:L/Au:S/C:N/I:N/A:C)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1703" target="_blank">CVE-2012-1703</a></td>
</tr>
<tr>
<td width="20%">nttdocomo &#8212; spmode_mail_android</td>
<td>The NTT DOCOMO sp mode mail application 5400 and earlier for Android does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.</td>
<td>2012-04-27</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1244&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:N)" target="_blank">6.4</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1244" target="_blank">CVE-2012-1244</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; database_server</td>
<td>Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, and 11.1.0.7 allows remote attackers to affect integrity and availability via unknown vectors.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0510&amp;vector=(AV:N/AC:L/Au:N/C:N/I:P/A:P)" target="_blank">6.4</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0510" target="_blank">CVE-2012-0510</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; database_server</td>
<td>Unspecified vulnerability in the OCI component in Oracle Database Server 10.2.0.3, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality and integrity via unknown vectors.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0511&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:N)" target="_blank">6.4</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0511" target="_blank">CVE-2012-0511</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; database_server</td>
<td>Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Server 11.1.0.7 and 11.2.0.2 and Oracle Enterprise Manager Grid Control allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Enterprise Config Management.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0512&amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:N)" target="_blank">5.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0512" target="_blank">CVE-2012-0512</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; peoplesoft_products</td>
<td>Unspecified vulnerability in the PeopleSoft Enterprise CRM component in Oracle PeopleSoft Products 9.1 allows remote authenticated users to affect confidentiality, related to SEC.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0514&amp;vector=(AV:N/AC:L/Au:S/C:P/I:N/A:N)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0514" target="_blank">CVE-2012-0514</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; fusion_middleware</td>
<td>Unspecified vulnerability in the Identity Manager Connector component in Oracle Fusion Middleware 9.1.0.4 allows remote authenticated users to affect integrity via unknown vectors.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0515&amp;vector=(AV:N/AC:L/Au:S/C:N/I:P/A:N)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0515" target="_blank">CVE-2012-0515</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; sun_products_suite</td>
<td>Unspecified vulnerability in the Oracle iPlanet Web Server component in Oracle Sun Products Suite 7.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Administration Console.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0516&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0516" target="_blank">CVE-2012-0516</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; peoplesoft_products</td>
<td>Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to eCompensation Manager Desktop.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0517&amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:N)" target="_blank">5.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0517" target="_blank">CVE-2012-0517</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; database_server</td>
<td>Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.2, and in Oracle Enterprise Manager Grid Control 10.2.0.5 and 11.1.0.1, allows remote attackers to affect integrity via unknown vectors related to Security Framework.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0520&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0520" target="_blank">CVE-2012-0520</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; peoplesoft_products</td>
<td>Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.1 Bundle #9 allows remote authenticated users to affect confidentiality via unknown vectors related to Human Resources.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0521&amp;vector=(AV:N/AC:L/Au:S/C:P/I:N/A:N)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0521" target="_blank">CVE-2012-0521</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; fusion_middleware</td>
<td>Unspecified vulnerability in the Oracle JDeveloper component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect integrity via unknown vectors related to Java Business Objects.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0522&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0522" target="_blank">CVE-2012-0522</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; database_server</td>
<td>Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Server 11.1.0.7, 11.2.0.2, and 11.2.0.3, and Oracle Enterprise Manager Grid Control 10.2.0.5 and 11.1.0.1, allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Enterprise Config Management.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0525&amp;vector=(AV:N/AC:M/Au:S/C:P/I:P/A:N)" target="_blank">4.9</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0525" target="_blank">CVE-2012-0525</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; database_server</td>
<td>Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3, and Oracle Enterprise Manager Grid Control 10.2.0.5, allows remote attackers to affect integrity via unknown vectors related to Schema Management.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0526&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0526" target="_blank">CVE-2012-0526</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; database_server</td>
<td>Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3, and Oracle Enterprise Manager Grid Control 10.2.0.5, allows remote attackers to affect integrity via unknown vectors related to Schema Management.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0527&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0527" target="_blank">CVE-2012-0527</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; database_server</td>
<td>Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, and 11.1.0.7, and Oracle Enterprise Manager Grid Control, allows remote attackers to affect confidentiality and integrity via unknown vectors related to Security Framework.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0528&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:N)" target="_blank">5.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0528" target="_blank">CVE-2012-0528</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; peoplesoft_products</td>
<td>Unspecified vulnerability in the PeopleSoft Enterprise SCM component in Oracle PeopleSoft Products 9.0 and 9.1 allows remote authenticated users to affect integrity via unknown vectors related to eProcurement.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0530&amp;vector=(AV:N/AC:L/Au:S/C:N/I:P/A:N)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0530" target="_blank">CVE-2012-0530</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; fusion_middleware</td>
<td>Unspecified vulnerability in the Identity Manager component in Oracle Fusion Middleware 11.1.1.3 and 11.1.1.5 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to User Config Management.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0532&amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:N)" target="_blank">5.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0532" target="_blank">CVE-2012-0532</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; peoplesoft_products</td>
<td>Unspecified vulnerability in the PeopleSoft Enterprise FCSM component in Oracle PeopleSoft Products 9.0 and 9.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Receivables.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0533&amp;vector=(AV:N/AC:L/Au:S/C:P/I:N/A:N)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0533" target="_blank">CVE-2012-0533</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; database_server</td>
<td>Unspecified vulnerability in the RDBMS Core component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect integrity via unknown vectors related to Create Session.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0534&amp;vector=(AV:N/AC:L/Au:S/C:N/I:P/A:N)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0534" target="_blank">CVE-2012-0534</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; e-business_suite</td>
<td>Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6 and 12.1.3 allows remote attackers to affect confidentiality via unknown vectors related to Change Password Page.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0535&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0535" target="_blank">CVE-2012-0535</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; peoplesoft_products</td>
<td>Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 8.9 through Bundle #26 allows remote authenticated users to affect confidentiality via unknown vectors related to eCompensation.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0536&amp;vector=(AV:N/AC:L/Au:S/C:P/I:N/A:N)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0536" target="_blank">CVE-2012-0536</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; e-business_suite</td>
<td>Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.1.3 allows remote attackers to affect confidentiality and integrity, related to HTML pages.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0537&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:N)" target="_blank">6.4</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0537" target="_blank">CVE-2012-0537</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; peoplesoft_products</td>
<td>Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Search.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0538&amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:N)" target="_blank">5.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0538" target="_blank">CVE-2012-0538</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; fusion_middleware</td>
<td>Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 10.1.3.4.1 and 10.1.3.4.2 allows remote attackers to affect integrity via unknown vectors related to Administration.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0543&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0543" target="_blank">CVE-2012-0543</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; glassfish_server</td>
<td>Unspecified vulnerability in the GlassFish Enterprise Server component in Oracle Sun Products Suite GlassFish Enterprise Server 3.1.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Web Container.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0550&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0550" target="_blank">CVE-2012-0550</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; glassfish_server</td>
<td>Unspecified vulnerability in the GlassFish Enterprise Server component in Oracle Sun Products Suite GlassFish Enterprise Server 3.1.1 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Web Container.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0551&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:N)" target="_blank">5.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0551" target="_blank">CVE-2012-0551</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; primavera_products_suite</td>
<td>Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 6.2.1, 8.0, 8.1, and 8.2 allows remote attackers to affect integrity via unknown vectors related to Web application.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0558&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0558" target="_blank">CVE-2012-0558</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; peoplesoft_products</td>
<td>Unspecified vulnerability in the PeopleSoft Enterprise SCM component in Oracle PeopleSoft Products 9.0 and 9.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Billing.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0559&amp;vector=(AV:N/AC:L/Au:S/C:P/I:N/A:N)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0559" target="_blank">CVE-2012-0559</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; peoplesoft_products</td>
<td>Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote attackers to affect integrity via unknown vectors related to Portal.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0560&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0560" target="_blank">CVE-2012-0560</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; peoplesoft_products</td>
<td>Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Candidate Gateway.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0562&amp;vector=(AV:N/AC:L/Au:S/C:P/I:N/A:N)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0562" target="_blank">CVE-2012-0562</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; peoplesoft_products</td>
<td>Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50 and 8.51 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Query.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0564&amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:P)" target="_blank">6.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0564" target="_blank">CVE-2012-0564</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; supply_chain_products_suite</td>
<td>Unspecified vulnerability in the Oracle Agile component in Oracle Supply Chain Products Suite 6.0.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Install.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0565&amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:N)" target="_blank">5.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0565" target="_blank">CVE-2012-0565</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; supply_chain_products_suite</td>
<td>Unspecified vulnerability in the Oracle Agile component in Oracle Supply Chain Products Suite 6.0.0 allows remote attackers to affect integrity via unknown vectors related to Supplier Portal.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0566&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0566" target="_blank">CVE-2012-0566</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; financial_services_software</td>
<td>Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through 11.2.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Core.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0567&amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:N)" target="_blank">5.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0567" target="_blank">CVE-2012-0567</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; financial_services_software</td>
<td>Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through 11.4.0 allows remote authenticated users to affect integrity via unknown vectors related to Core.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0571&amp;vector=(AV:N/AC:L/Au:S/C:N/I:P/A:N)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0571" target="_blank">CVE-2012-0571</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; financial_services_software</td>
<td>Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through 11.4.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Core.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0573&amp;vector=(AV:N/AC:M/Au:S/C:P/I:P/A:N)" target="_blank">4.9</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0573" target="_blank">CVE-2012-0573</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; financial_services_software</td>
<td>Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through 11.2.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Core.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0575&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0575" target="_blank">CVE-2012-0575</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; financial_services_software</td>
<td>Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 6.0.1 and 6.2.0 allows remote authenticated users to affect integrity via unknown vectors related to Core-Help.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0576&amp;vector=(AV:N/AC:L/Au:S/C:N/I:P/A:N)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0576" target="_blank">CVE-2012-0576</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; supply_chain_products_suite</td>
<td>Unspecified vulnerability in the Oracle Agile PLM for Process component in Oracle Supply Chain Products Suite 6.0.0 allows remote attackers to affect integrity via unknown vectors related to Supplier Portal.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0580&amp;vector=(AV:N/AC:L/Au:N/C:N/I:P/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0580" target="_blank">CVE-2012-0580</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; supply_chain_products_suite</td>
<td>Unspecified vulnerability in the Oracle Agile component in Oracle Supply Chain Products Suite 6.0.0 allows remote attackers to affect integrity, related to SCRM &#8211; Company Profiles.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0581&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0581" target="_blank">CVE-2012-0581</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; industry_applications</td>
<td>Unspecified vulnerability in the Siebel Clinical component in Oracle Industry Applications 7.7, 7.8, 8.0.0.x, 8.1.1.x, and 8.2.2.x allows remote authenticated users to affect integrity via unknown vectors related to Web UI.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0582&amp;vector=(AV:N/AC:L/Au:S/C:N/I:P/A:N)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0582" target="_blank">CVE-2012-0582</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; industry_applications</td>
<td>Unspecified vulnerability in the Siebel Clinical component in Oracle Industry Applications 7.7, 7.8, 8.0.0.x, 8.1.1.x, and 8.2.2.x allows remote authenticated users to affect integrity via unknown vectors related to Web UI.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1674&amp;vector=(AV:N/AC:L/Au:S/C:N/I:P/A:N)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1674" target="_blank">CVE-2012-1674</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; financial_services_software</td>
<td>Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Logging.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1706&amp;vector=(AV:N/AC:L/Au:M/C:P/I:P/A:N)" target="_blank">4.7</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1706" target="_blank">CVE-2012-1706</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; financial_services_software</td>
<td>Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Core-Base.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1707&amp;vector=(AV:N/AC:L/Au:S/C:P/I:N/A:N)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1707" target="_blank">CVE-2012-1707</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; database_server</td>
<td>Unspecified vulnerability in the Application Express component in Oracle Database Server 4.0 and 4.1 allows remote attackers to affect integrity via unknown vectors.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1708&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1708" target="_blank">CVE-2012-1708</a></td>
</tr>
<tr>
<td width="20%">osqa &#8212; osqa</td>
<td>Cross-site scripting (XSS) vulnerability in the cleanup_urls function in forum/utils/html.py in OSQA before 1234, and 0.9.0 Beta 3 and earlier, allows remote attackers to inject arbitrary web script or HTML via vectors related to a crafted URI.</td>
<td>2012-04-27</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1245&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1245" target="_blank">CVE-2012-1245</a></td>
</tr>
<tr>
<td width="20%">phpmyadmin &#8212; phpmyadmin</td>
<td>Cross-site scripting (XSS) vulnerability in the replication-setup functionality in js/replication.js in phpMyAdmin 3.4.x before 3.4.10.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted database name.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1190&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1190" target="_blank">CVE-2012-1190</a></td>
</tr>
<tr>
<td width="20%">pythonpaste &#8212; paste</td>
<td>Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem.</td>
<td>2012-05-01</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0878&amp;vector=(AV:N/AC:H/Au:N/C:P/I:P/A:P)" target="_blank">5.1</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0878" target="_blank">CVE-2012-0878</a></td>
</tr>
<tr>
<td width="20%">quest &#8212; toad_for_data_analysts</td>
<td>Quest Toad for Data Analysts 3.0.1 uses weak permissions (Everyone: Full Control) for the %COMMONPROGRAMFILES%\Quest Shared directory, which allows local users to gain privileges via a Trojan horse file.</td>
<td>2012-05-01</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0279&amp;vector=(AV:L/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">6.9</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0279" target="_blank">CVE-2012-0279</a></td>
</tr>
<tr>
<td width="20%">samba &#8212; samba</td>
<td>The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the &quot;take ownership&quot; privilege via an LSA connection.</td>
<td>2012-04-30</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2111&amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:P)" target="_blank">6.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2111" target="_blank">CVE-2012-2111</a></td>
</tr>
<tr>
<td width="20%">squid-cache &#8212; squid</td>
<td>** DISPUTED ** Squid 3.1.9 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host HTTP header. NOTE: this issue might not be reproducible, because the researcher is unable to provide a squid.conf file for a vulnerable system, and the observed behavior is consistent with a squid.conf file that was (perhaps inadvertently) designed to allow access based on a &quot;req_header Host&quot; acl regex that matches www.uol.com.br.</td>
<td>2012-04-28</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2213&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2213" target="_blank">CVE-2012-2213</a></td>
</tr>
<tr>
<td width="20%">sun &#8212; sunos</td>
<td>Unspecified vulnerability in Oracle Sun Solaris 8, 9, and 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to (1) bsmconv and (2) bsmunconv.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0539&amp;vector=(AV:L/AC:H/Au:N/C:C/I:C/A:C)" target="_blank">6.2</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0539" target="_blank">CVE-2012-0539</a></td>
</tr>
<tr>
<td width="20%">sun &#8212; sunos</td>
<td>Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect availability via unknown vectors related to Kernel/sockfs.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1681&amp;vector=(AV:L/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">4.9</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1681" target="_blank">CVE-2012-1681</a></td>
</tr>
<tr>
<td width="20%">sun &#8212; sunos</td>
<td>Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to gssd.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1683&amp;vector=(AV:L/AC:H/Au:M/C:C/I:C/A:C)" target="_blank">5.9</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1683" target="_blank">CVE-2012-1683</a></td>
</tr>
<tr>
<td width="20%">sun &#8212; sunos</td>
<td>Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Password Policy.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1684&amp;vector=(AV:L/AC:L/Au:S/C:P/I:P/A:P)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1684" target="_blank">CVE-2012-1684</a></td>
</tr>
<tr>
<td width="20%">sun &#8212; sunos</td>
<td>Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel/Privileges.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1691&amp;vector=(AV:L/AC:M/Au:S/C:C/I:C/A:C)" target="_blank">6.6</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1691" target="_blank">CVE-2012-1691</a></td>
</tr>
<tr>
<td width="20%">sun &#8212; sunos</td>
<td>Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect availability, related to SCTP.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1692&amp;vector=(AV:L/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">4.9</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1692" target="_blank">CVE-2012-1692</a></td>
</tr>
<tr>
<td width="20%">sun &#8212; sunos</td>
<td>Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality and integrity, related to libsasl.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1694&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:N)" target="_blank">6.4</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1694" target="_blank">CVE-2012-1694</a></td>
</tr>
<tr>
<td width="20%">wordpress &#8212; wordpress</td>
<td>** DISPUTED ** The wp_create_nonce function in wp-includes/pluggable.php in WordPress 3.3.1 and earlier associates a nonce with a user account instead of a user session, which might make it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks on specific actions and objects by sniffing the network, as demonstrated by attacks against the wp-admin/admin-ajax.php and wp-admin/user-new.php scripts. NOTE: the vendor reportedly disputes the significance of this issue because wp_create_nonce operates as intended, even if it is arguably inconsistent with certain CSRF protection details advocated by external organizations.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1936&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1936" target="_blank">CVE-2012-1936</a></td>
</tr>
</tbody>
</table>
<p>
</div>
<p><a name="low"></a></p>
<div>
<table align="center" border="1" summary="Low Vulnerabilities">
<thead>
<tr>
<th colspan="5">Low Vulnerabilities</th>
</tr>
<tr>
<th>Primary<br />
Vendor &#8212; Product</th>
<th>Description</th>
<th>Published</th>
<th>CVSS Score</th>
<th>Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td width="20%">cisco &#8212; ios</td>
<td>Cisco IOS 12.4 and 15.0 through 15.2 allows physically proximate attackers to bypass the No Service Password-Recovery feature and read the start-up configuration via unspecified vectors, aka Bug ID CSCtr97640.</td>
<td>2012-05-02</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3289&amp;vector=(AV:L/AC:L/Au:N/C:P/I:P/A:N)" target="_blank">3.6</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3289" target="_blank">CVE-2011-3289</a></td>
</tr>
<tr>
<td width="20%">ibm &#8212; rational_appscan</td>
<td>Cross-site scripting (XSS) vulnerability in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0737&amp;vector=(AV:N/AC:M/Au:S/C:N/I:P/A:N)" target="_blank">3.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0737" target="_blank">CVE-2012-0737</a></td>
</tr>
<tr>
<td width="20%">mumble &#8212; mumble</td>
<td>Mumble 1.2.3 and earlier uses world-readable permissions for .local/share/data/Mumble/.mumble.sqlite files in home directories, which might allow local users to obtain a cleartext password and configuration data by reading a file.</td>
<td>2012-04-30</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0863&amp;vector=(AV:L/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">2.1</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0863" target="_blank">CVE-2012-0863</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; financial_services_software</td>
<td>Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2 and 5.3.0 through 5.3.4 allows remote authenticated users to affect integrity via unknown vectors related to Core-Base.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0509&amp;vector=(AV:N/AC:M/Au:S/C:N/I:P/A:N)" target="_blank">3.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0509" target="_blank">CVE-2012-0509</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; e-business_suite</td>
<td>Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6 and 12.1.3 allows remote attackers to affect integrity, related to REST Services.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0513&amp;vector=(AV:N/AC:H/Au:N/C:N/I:P/A:N)" target="_blank">2.6</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0513" target="_blank">CVE-2012-0513</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; peoplesoft_products</td>
<td>Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows local users to affect confidentiality and integrity via unknown vectors related to File Processing.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0524&amp;vector=(AV:L/AC:L/Au:S/C:P/I:P/A:N)" target="_blank">3.2</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0524" target="_blank">CVE-2012-0524</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; peoplesoft_products</td>
<td>Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51 allows remote authenticated users to affect integrity via unknown vectors related to core.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0529&amp;vector=(AV:N/AC:M/Au:S/C:N/I:P/A:N)" target="_blank">3.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0529" target="_blank">CVE-2012-0529</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; peoplesoft_products</td>
<td>Unspecified vulnerability in the PeopleSoft Enterprise Portal component in Oracle PeopleSoft Products 9.1 allows remote authenticated users to affect integrity via unknown vectors related to Enterprise Portal.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0531&amp;vector=(AV:N/AC:M/Au:S/C:N/I:P/A:N)" target="_blank">3.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0531" target="_blank">CVE-2012-0531</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; financial_services_software</td>
<td>Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Core-My Services.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0541&amp;vector=(AV:N/AC:M/Au:S/C:P/I:N/A:N)" target="_blank">3.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0541" target="_blank">CVE-2012-0541</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; e-business_suite</td>
<td>Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 11.5.10.2, 12.0.4, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Runtime Catalog.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0542&amp;vector=(AV:N/AC:H/Au:N/C:N/I:P/A:N)" target="_blank">2.6</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0542" target="_blank">CVE-2012-0542</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; financial_services_software</td>
<td>Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through 11.4.0 allows remote authenticated users to affect integrity via unknown vectors related to Core.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0544&amp;vector=(AV:N/AC:M/Au:S/C:N/I:P/A:N)" target="_blank">3.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0544" target="_blank">CVE-2012-0544</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; financial_services_software</td>
<td>Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through 11.2.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Core.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0545&amp;vector=(AV:N/AC:H/Au:S/C:P/I:P/A:N)" target="_blank">3.6</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0545" target="_blank">CVE-2012-0545</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; financial_services_software</td>
<td>Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through 11.2.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Core.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0546&amp;vector=(AV:N/AC:H/Au:S/C:P/I:P/A:N)" target="_blank">3.6</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0546" target="_blank">CVE-2012-0546</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; xcp</td>
<td>Unspecified vulnerability in Oracle SPARC Enterprise M Series Servers XCP 1110 and earlier allows local users to affect confidentiality, related to XSCF Control Package (XCP).</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0548&amp;vector=(AV:L/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">2.1</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0548" target="_blank">CVE-2012-0548</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; peoplesoft_products</td>
<td>Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect integrity, related to PIA Core Technology.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0561&amp;vector=(AV:N/AC:M/Au:S/C:N/I:P/A:N)" target="_blank">3.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0561" target="_blank">CVE-2012-0561</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; financial_services_software</td>
<td>Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through 11.4.0 allows remote authenticated users to affect availability via unknown vectors related to Core.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0577&amp;vector=(AV:N/AC:M/Au:S/C:N/I:N/A:P)" target="_blank">3.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0577" target="_blank">CVE-2012-0577</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; financial_services_software</td>
<td>Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through 11.4.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Core.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0579&amp;vector=(AV:N/AC:M/Au:S/C:P/I:N/A:N)" target="_blank">3.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0579" target="_blank">CVE-2012-0579</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; financial_services_software</td>
<td>Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Virtual Banking.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1676&amp;vector=(AV:N/AC:M/Au:S/C:P/I:N/A:N)" target="_blank">3.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1676" target="_blank">CVE-2012-1676</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; financial_services_software</td>
<td>Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect integrity via unknown vectors related to Core-Base.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1679&amp;vector=(AV:N/AC:M/Au:S/C:N/I:P/A:N)" target="_blank">3.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1679" target="_blank">CVE-2012-1679</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; xcp</td>
<td>Unspecified vulnerability in Oracle SPARC Enterprise M Series Servers XCP 1110 allows remote attackers to affect availability, related to XSCF Control Package (XCP).</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1693&amp;vector=(AV:N/AC:H/Au:N/C:N/I:N/A:P)" target="_blank">2.6</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1693" target="_blank">CVE-2012-1693</a></td>
</tr>
<tr>
<td width="20%">oracle &#8212; financial_services_software</td>
<td>Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Core-Base.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1704&amp;vector=(AV:N/AC:M/Au:S/C:P/I:N/A:N)" target="_blank">3.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1704" target="_blank">CVE-2012-1704</a></td>
</tr>
<tr>
<td width="20%">sun &#8212; sunos</td>
<td>Unspecified vulnerability in Oracle Sun Solaris 11 allows remote authenticated users to affect confidentiality, related to Kernel/GLD.</td>
<td>2012-05-03</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1698&amp;vector=(AV:N/AC:H/Au:S/C:P/I:N/A:N)" target="_blank">2.1</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1698" target="_blank">CVE-2012-1698</a></td>
</tr>
</tbody>
</table>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.freednslookup.net/2012/05/08/sb12-128-vulnerability-summary-for-the-week-of-april-30-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SB12-121: Vulnerability Summary for the Week of April 23, 2012</title>
		<link>http://www.freednslookup.net/2012/05/01/sb12-121-vulnerability-summary-for-the-week-of-april-23-2012/</link>
		<comments>http://www.freednslookup.net/2012/05/01/sb12-121-vulnerability-summary-for-the-week-of-april-23-2012/#comments</comments>
		<pubDate>Tue, 01 May 2012 12:00:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[US-Cert]]></category>

		<guid isPermaLink="false">http://www.freednslookup.net/2012/05/01/sb12-121-vulnerability-summary-for-the-week-of-april-23-2012/</guid>
		<description><![CDATA[The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cyber Security Division (NCSD) / United States Computer Emergency Readiness Team [...]]]></description>
			<content:encoded><![CDATA[<p><a name="top"></a></p>
<table align="center">
<tr>
<td>
<p>The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cyber Security Division (NCSD) / United States Computer Emergency Readiness Team (US-CERT). For updated or updated entries, please visit the <a href="http://nvd.nist.gov" target="_blank">NVD</a>, which contains historical vulnerability information.</p>
<p>The vulnerabilities are based on the <a href="http://cve.mitre.org/" target="_blank">CVE</a> vulnerability naming standard and are organized according to severity, determined by the <a href="http://nvd.nist.gov/cvss.cfm" target="_blank">Common Vulnerability Scoring System</a> (CVSS) standard. The division of high, medium, and low severities correspond to the following scores:</p>
<ul>
<li>
<p><strong>High</strong> &#8211; Vulnerabilities will be labeled High severity if they have a CVSS base score of 7.0 &#8211; 10.0</p>
</li>
<li>
<p><strong>Medium</strong> &#8211; Vulnerabilities will be labeled Medium severity if they have a CVSS base score of 4.0 &#8211; 6.9</p>
</li>
<li>
<p><strong>Low</strong> &#8211; Vulnerabilities will be labeled Low severity if they have a CVSS base score of 0.0 &#8211; 3.9</p>
</li>
</ul>
<p>Entries may include additional information provided by organizations and efforts sponsored by US-CERT. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletins is compiled from external, open source reports and is not a direct result of US-CERT analysis.</p>
</td>
</tr>
</table>
<p>
<a name="high"></a></p>
<div>
<table align="center" border="1" summary="High Vulnerabilities">
<thead>
<tr>
<th colspan="5">High Vulnerabilities</th>
</tr>
<tr>
<th>Primary<br />
Vendor &#8212; Product</th>
<th>Description</th>
<th>Published</th>
<th>CVSS Score</th>
<th>Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td>freetype &#8212; freetype</td>
<td>FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted property data in a BDF font.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1126&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1126" target="_blank">CVE-2012-1126</a></td>
</tr>
<tr>
<td>freetype &#8212; freetype</td>
<td>FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted glyph or bitmap data in a BDF font.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1127&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1127" target="_blank">CVE-2012-1127</a></td>
</tr>
<tr>
<td>freetype &#8212; freetype</td>
<td>FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and memory corruption) or possibly execute arbitrary code via a crafted TrueType font.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1128&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1128" target="_blank">CVE-2012-1128</a></td>
</tr>
<tr>
<td>freetype &#8212; freetype</td>
<td>FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted SFNT string in a Type 42 font.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1129&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1129" target="_blank">CVE-2012-1129</a></td>
</tr>
<tr>
<td>freetype &#8212; freetype</td>
<td>FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted property data in a PCF font.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1130&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1130" target="_blank">CVE-2012-1130</a></td>
</tr>
<tr>
<td>freetype &#8212; freetype</td>
<td>FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, on 64-bit platforms allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors related to the cell table of a font.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1131&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1131" target="_blank">CVE-2012-1131</a></td>
</tr>
<tr>
<td>freetype &#8212; freetype</td>
<td>FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted dictionary data in a Type 1 font.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1132&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1132" target="_blank">CVE-2012-1132</a></td>
</tr>
<tr>
<td>freetype &#8212; freetype</td>
<td>FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph or bitmap data in a BDF font.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1133&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1133" target="_blank">CVE-2012-1133</a></td>
</tr>
<tr>
<td>freetype &#8212; freetype</td>
<td>FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted private-dictionary data in a Type 1 font.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1134&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1134" target="_blank">CVE-2012-1134</a></td>
</tr>
<tr>
<td>freetype &#8212; freetype</td>
<td>FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors involving the NPUSHB and NPUSHW instructions in a TrueType font.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1135&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1135" target="_blank">CVE-2012-1135</a></td>
</tr>
<tr>
<td>freetype &#8212; freetype</td>
<td>FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph or bitmap data in a BDF font that lacks an ENCODING field.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1136&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1136" target="_blank">CVE-2012-1136</a></td>
</tr>
<tr>
<td>freetype &#8212; freetype</td>
<td>FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted header in a BDF font.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1137&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1137" target="_blank">CVE-2012-1137</a></td>
</tr>
<tr>
<td>freetype &#8212; freetype</td>
<td>FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors involving the MIRP instruction in a TrueType font.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1138&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1138" target="_blank">CVE-2012-1138</a></td>
</tr>
<tr>
<td>freetype &#8212; freetype</td>
<td>Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid stack read operation and memory corruption) or possibly execute arbitrary code via crafted glyph data in a BDF font.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1139&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1139" target="_blank">CVE-2012-1139</a></td>
</tr>
<tr>
<td>freetype &#8212; freetype</td>
<td>FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted PostScript font object.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1140&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1140" target="_blank">CVE-2012-1140</a></td>
</tr>
<tr>
<td>freetype &#8212; freetype</td>
<td>FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted ASCII string in a BDF font.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1141&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1141" target="_blank">CVE-2012-1141</a></td>
</tr>
<tr>
<td>freetype &#8212; freetype</td>
<td>FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph-outline data in a font.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1142&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1142" target="_blank">CVE-2012-1142</a></td>
</tr>
<tr>
<td>freetype &#8212; freetype</td>
<td>FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via a crafted TrueType font.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1144&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1144" target="_blank">CVE-2012-1144</a></td>
</tr>
<tr>
<td>ibm &#8212; rational_clearquest</td>
<td>Heap-based buffer overflow in the Ole API in the CQOle ActiveX control in cqole.dll in IBM Rational ClearQuest 7.1.1 before 7.1.1.9, 7.1.2 before 7.1.2.6, and 8.0.0 before 8.0.0.2 allows remote attackers to execute arbitrary code via a crafted web page that leverages a RegisterSchemaRepoFromFileByDbSet function-prototype mismatch.</td>
<td>2012-04-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0708&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0708" target="_blank">CVE-2012-0708</a></td>
</tr>
<tr>
<td>maian &#8212; gallery</td>
<td>Gallery 2 before 2.3.2 and 3 before 3.0.3 does not properly implement encryption, which has unspecified impact and attack vectors, a different vulnerability than CVE-2012-1113.</td>
<td>2012-04-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2405&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2405" target="_blank">CVE-2012-2405</a></td>
</tr>
<tr>
<td>mozilla &#8212; firefox</td>
<td>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0467&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0467" target="_blank">CVE-2012-0467</a></td>
</tr>
<tr>
<td>mozilla &#8212; firefox</td>
<td>The browser engine in Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey before 2.9 allows remote attackers to cause a denial of service (assertion failure and memory corruption) or possibly execute arbitrary code via vectors related to jsval.h and the js::array_shift function.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0468&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0468" target="_blank">CVE-2012-0468</a></td>
</tr>
<tr>
<td>mozilla &#8212; firefox</td>
<td>Use-after-free vulnerability in the mozilla::dom::indexedDB::IDBKeyRange::cycleCollection::Trace function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to execute arbitrary code via vectors related to crafted IndexedDB data.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0469&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0469" target="_blank">CVE-2012-0469</a></td>
</tr>
<tr>
<td>mozilla &#8212; firefox</td>
<td>Heap-based buffer overflow in the nsSVGFEDiffuseLightingElement::LightPixel function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to cause a denial of service (invalid gfxImageSurface free operation) or possibly execute arbitrary code by leveraging the use of &quot;different number systems.&quot;</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0470&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0470" target="_blank">CVE-2012-0470</a></td>
</tr>
<tr>
<td>mozilla &#8212; firefox</td>
<td>The cairo-dwrite implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9, when certain Windows Vista and Windows 7 configurations are used, does not properly restrict font-rendering attempts, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0472&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0472" target="_blank">CVE-2012-0472</a></td>
</tr>
<tr>
<td>mozilla &#8212; firefox</td>
<td>The texImage2D implementation in the WebGL subsystem in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 does not properly restrict JSVAL_TO_OBJECT casts, which might allow remote attackers to execute arbitrary code via a crafted web page.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0478&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0478" target="_blank">CVE-2012-0478</a></td>
</tr>
<tr>
<td>openssl &#8212; openssl</td>
<td>Multiple integer signedness errors in crypto/buffer/buffer.c in OpenSSL 0.9.8v allow remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-2110.</td>
<td>2012-04-24</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2131&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2131" target="_blank">CVE-2012-2131</a></td>
</tr>
<tr>
<td>wordpress &#8212; wordpress</td>
<td>Unspecified vulnerability in wp-includes/js/swfupload/swfupload.swf in WordPress before 3.3.2 has unknown impact and attack vectors.</td>
<td>2012-04-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2399&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2399" target="_blank">CVE-2012-2399</a></td>
</tr>
<tr>
<td>wordpress &#8212; wordpress</td>
<td>Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors.</td>
<td>2012-04-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2400&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2400" target="_blank">CVE-2012-2400</a></td>
</tr>
</tbody>
</table>
<p>
</div>
<p><a name="medium"></a></p>
<div>
<table align="center" border="1" summary="Medium Vulnerabilities">
<thead>
<tr>
<th colspan="5">Medium Vulnerabilities</th>
</tr>
<tr>
<th>Primary<br />
Vendor &#8212; Product</th>
<th>Description</th>
<th>Published</th>
<th>CVSS Score</th>
<th>Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td width="20%">debian &#8212; apache2</td>
<td>The default configuration of the apache2 package in Debian GNU/Linux squeeze before 2.2.16-6+squeeze7, wheezy before 2.2.22-4, and sid before 2.2.22-4, when mod_php or mod_rivet is used, provides example scripts under the doc/ URI, which might allow local users to conduct cross-site scripting (XSS) attacks, gain privileges, or obtain sensitive information via vectors involving localhost HTTP requests to the Apache HTTP Server.</td>
<td>2012-04-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0216&amp;vector=(AV:L/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">4.4</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0216" target="_blank">CVE-2012-0216</a></td>
</tr>
<tr>
<td width="20%">freetype &#8212; freetype</td>
<td>FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted font.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1143&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:P)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1143" target="_blank">CVE-2012-1143</a></td>
</tr>
<tr>
<td width="20%">ibm &#8212; tivoli_directory_server</td>
<td>The default configuration of TLS in IBM Tivoli Directory Server (TDS) 6.3 and earlier supports the (1) NULL-MD5 and (2) NULL-SHA ciphers, which allows remote attackers to trigger unencrypted communication via the TLS Handshake Protocol.</td>
<td>2012-04-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0726&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:N)" target="_blank">6.4</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0726" target="_blank">CVE-2012-0726</a></td>
</tr>
<tr>
<td width="20%">ibm &#8212; tivoli_directory_server</td>
<td>Cross-site scripting (XSS) vulnerability in the Web Admin Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.22 and 6.3 before 6.3.0.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</td>
<td>2012-04-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0740&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0740" target="_blank">CVE-2012-0740</a></td>
</tr>
<tr>
<td width="20%">ibm &#8212; tivoli_directory_server</td>
<td>IBM Tivoli Directory Server (TDS) 6.3 and earlier allows remote attackers to cause a denial of service (daemon crash) via a malformed LDAP paged search request.</td>
<td>2012-04-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0743&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0743" target="_blank">CVE-2012-0743</a></td>
</tr>
<tr>
<td width="20%">intuit &#8212; quickbooks</td>
<td>Heap-based buffer overflow in the intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a URI with a % (percent) character as its (1) last or (2) second-to-last character.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2418&amp;vector=(AV:A/AC:H/Au:N/C:C/I:C/A:C)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2418" target="_blank">CVE-2012-2418</a></td>
</tr>
<tr>
<td width="20%">maian &#8212; gallery</td>
<td>Multiple cross-site scripting (XSS) vulnerabilities in the administration subsystem in Gallery 2 before 2.3.2 and 3 before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</td>
<td>2012-04-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1113&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1113" target="_blank">CVE-2012-1113</a></td>
</tr>
<tr>
<td width="20%">mozilla &#8212; firefox</td>
<td>Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to inject arbitrary web script or HTML via a multibyte character set.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0471&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0471" target="_blank">CVE-2012-0471</a></td>
</tr>
<tr>
<td width="20%">mozilla &#8212; firefox</td>
<td>The WebGLBuffer::FindMaxUshortElement function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 calls the FindMaxElementInSubArray function with incorrect template arguments, which allows remote attackers to obtain sensitive information from video memory via a crafted WebGL.drawElements call.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0473&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0473" target="_blank">CVE-2012-0473</a></td>
</tr>
<tr>
<td width="20%">mozilla &#8212; firefox</td>
<td>Cross-site scripting (XSS) vulnerability in the docshell implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to inject arbitrary web script or HTML via vectors related to short-circuited page loads, aka &quot;Universal XSS (UXSS).&quot;</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0474&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0474" target="_blank">CVE-2012-0474</a></td>
</tr>
<tr>
<td width="20%">mozilla &#8212; firefox</td>
<td>Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to inject arbitrary web script or HTML via the (1) ISO-2022-KR or (2) ISO-2022-CN character set.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0477&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0477" target="_blank">CVE-2012-0477</a></td>
</tr>
<tr>
<td width="20%">mozilla &#8212; firefox</td>
<td>Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to spoof the address bar via an https URL for invalid (1) RSS or (2) Atom XML content.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0479&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0479" target="_blank">CVE-2012-0479</a></td>
</tr>
<tr>
<td width="20%">nvidia &#8212; unix_driver</td>
<td>The NVIDIA UNIX driver before 295.40 allows local users to access arbitrary memory locations by leveraging GPU device-node read/write privileges.</td>
<td>2012-04-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0946&amp;vector=(AV:L/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">4.6</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0946" target="_blank">CVE-2012-0946</a></td>
</tr>
<tr>
<td width="20%">owncloud &#8212; owncloud</td>
<td>Open redirect vulnerability in index.php (aka the Login Page) in ownCloud 3.0.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter.</td>
<td>2012-04-20</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2270&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:N)" target="_blank">5.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2270" target="_blank">CVE-2012-2270</a></td>
</tr>
<tr>
<td width="20%">plupload &#8212; plupload</td>
<td>Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was loaded, which allows remote attackers to bypass the Same Origin Policy via crafted content.</td>
<td>2012-04-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2401&amp;vector=(AV:N/AC:L/Au:N/C:N/I:P/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2401" target="_blank">CVE-2012-2401</a></td>
</tr>
<tr>
<td width="20%">studiohitori &#8212; twitrocker2_android</td>
<td>The TwitRocker2 application before 1.0.23 for Android does not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application.</td>
<td>2012-04-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1243&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1243" target="_blank">CVE-2012-1243</a></td>
</tr>
<tr>
<td width="20%">teampass &#8212; teampass</td>
<td>Cross-site scripting (XSS) vulnerability in sources/users.queries.php in TeamPass before 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the login parameter in an add_new_user action.</td>
<td>2012-04-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2234&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2234" target="_blank">CVE-2012-2234</a></td>
</tr>
<tr>
<td width="20%">trevor_mckay &#8212; cumin</td>
<td>Multiple cross-site scripting (XSS) vulnerabilities in Cumin before r5238 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) widgets or (2) pages.</td>
<td>2012-04-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1575&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1575" target="_blank">CVE-2012-1575</a></td>
</tr>
<tr>
<td width="20%">wordpress &#8212; wordpress</td>
<td>wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and deactivate network-wide plugins via unspecified vectors.</td>
<td>2012-04-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2402&amp;vector=(AV:N/AC:L/Au:S/C:N/I:P/A:P)" target="_blank">5.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2402" target="_blank">CVE-2012-2402</a></td>
</tr>
<tr>
<td width="20%">wordpress &#8212; wordpress</td>
<td>wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickable links inside attributes, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.</td>
<td>2012-04-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2403&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2403" target="_blank">CVE-2012-2403</a></td>
</tr>
<tr>
<td width="20%">wordpress &#8212; wordpress</td>
<td>wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.</td>
<td>2012-04-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2404&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2404" target="_blank">CVE-2012-2404</a></td>
</tr>
</tbody>
</table>
<p>
</div>
<p><a name="low"></a></p>
<div>
<table align="center" border="1" summary="Low Vulnerabilities">
<thead>
<tr>
<th colspan="5">Low Vulnerabilities</th>
</tr>
<tr>
<th>Primary<br />
Vendor &#8212; Product</th>
<th>Description</th>
<th>Published</th>
<th>CVSS Score</th>
<th>Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td width="20%">intuit &#8212; quickbooks</td>
<td>Memory leak in the intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, allows remote attackers to cause a denial of service (memory consumption) via a URI with multiple references to the same name-value pair.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2419&amp;vector=(AV:A/AC:H/Au:N/C:N/I:N/A:P)" target="_blank">1.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2419" target="_blank">CVE-2012-2419</a></td>
</tr>
<tr>
<td width="20%">intuit &#8212; quickbooks</td>
<td>The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, might allow remote attackers to obtain sensitive information via a URI with a % (percent) character as its (1) last or (2) second-to-last character, in situations where a certain &quot;post-URL data&quot; buffer contains a 0&#215;0000 character but a buffer overflow does not occur.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2420&amp;vector=(AV:A/AC:H/Au:N/C:P/I:N/A:N)" target="_blank">1.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2420" target="_blank">CVE-2012-2420</a></td>
</tr>
<tr>
<td width="20%">intuit &#8212; quickbooks</td>
<td>Absolute path traversal vulnerability in the intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, might allow remote attackers to read arbitrary files in ZIP archives via a full pathname in the URI.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2421&amp;vector=(AV:A/AC:H/Au:N/C:P/I:N/A:N)" target="_blank">1.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2421" target="_blank">CVE-2012-2421</a></td>
</tr>
<tr>
<td width="20%">intuit &#8212; quickbooks</td>
<td>Intuit QuickBooks 2009 through 2012 might allow remote attackers to obtain pathname information via the qbwc://docontrol/GetCompanyFile functionality.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2422&amp;vector=(AV:A/AC:M/Au:N/C:P/I:N/A:N)" target="_blank">2.9</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2422" target="_blank">CVE-2012-2422</a></td>
</tr>
<tr>
<td width="20%">intuit &#8212; quickbooks</td>
<td>The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, provide different responses to remote requests depending on whether a ZIP pathname is valid, which allows remote attackers to obtain potentially sensitive information about the installation path and product version via a series of requests involving the Msxml2.XMLHTTP object.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2423&amp;vector=(AV:A/AC:H/Au:N/C:P/I:N/A:N)" target="_blank">1.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2423" target="_blank">CVE-2012-2423</a></td>
</tr>
<tr>
<td width="20%">intuit &#8212; quickbooks</td>
<td>The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a URI that lacks a required delimiter.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2424&amp;vector=(AV:A/AC:H/Au:N/C:N/I:N/A:P)" target="_blank">1.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2424" target="_blank">CVE-2012-2424</a></td>
</tr>
<tr>
<td width="20%">intuit &#8212; quickbooks</td>
<td>The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, allow remote attackers to cause a denial of service (application crash) via a long URI.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2425&amp;vector=(AV:A/AC:H/Au:N/C:N/I:N/A:P)" target="_blank">1.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2425" target="_blank">CVE-2012-2425</a></td>
</tr>
<tr>
<td width="20%">mozilla &#8212; firefox</td>
<td>Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey before 2.9 do not properly construct the Origin and Sec-WebSocket-Origin HTTP headers, which might allow remote attackers to bypass an IPv6 literal ACL via a cross-site (1) XMLHttpRequest or (2) WebSocket operation involving a nonstandard port number and an IPv6 address that contains certain zero fields.</td>
<td>2012-04-25</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0475&amp;vector=(AV:N/AC:H/Au:N/C:N/I:P/A:N)" target="_blank">2.6</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0475" target="_blank">CVE-2012-0475</a></td>
</tr>
</tbody>
</table>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.freednslookup.net/2012/05/01/sb12-121-vulnerability-summary-for-the-week-of-april-23-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SB12-114: Vulnerability Summary for the Week of April 16, 2012</title>
		<link>http://www.freednslookup.net/2012/04/23/sb12-114-vulnerability-summary-for-the-week-of-april-16-2012/</link>
		<comments>http://www.freednslookup.net/2012/04/23/sb12-114-vulnerability-summary-for-the-week-of-april-16-2012/#comments</comments>
		<pubDate>Tue, 24 Apr 2012 00:00:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[US-Cert]]></category>

		<guid isPermaLink="false">http://www.freednslookup.net/2012/04/23/sb12-114-vulnerability-summary-for-the-week-of-april-16-2012/</guid>
		<description><![CDATA[The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cyber Security Division (NCSD) / United States Computer Emergency Readiness Team [...]]]></description>
			<content:encoded><![CDATA[<p><a name="top"></a></p>
<table align="center">
<tr>
<td>
<p>The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cyber Security Division (NCSD) / United States Computer Emergency Readiness Team (US-CERT). For updated or updated entries, please visit the <a href="http://nvd.nist.gov" target="_blank">NVD</a>, which contains historical vulnerability information.</p>
<p>The vulnerabilities are based on the <a href="http://cve.mitre.org/" target="_blank">CVE</a> vulnerability naming standard and are organized according to severity, determined by the <a href="http://nvd.nist.gov/cvss.cfm" target="_blank">Common Vulnerability Scoring System</a> (CVSS) standard. The division of high, medium, and low severities correspond to the following scores:</p>
<ul>
<li>
<p><strong>High</strong> &#8211; Vulnerabilities will be labeled High severity if they have a CVSS base score of 7.0 &#8211; 10.0</p>
</li>
<li>
<p><strong>Medium</strong> &#8211; Vulnerabilities will be labeled Medium severity if they have a CVSS base score of 4.0 &#8211; 6.9</p>
</li>
<li>
<p><strong>Low</strong> &#8211; Vulnerabilities will be labeled Low severity if they have a CVSS base score of 0.0 &#8211; 3.9</p>
</li>
</ul>
<p>Entries may include additional information provided by organizations and efforts sponsored by US-CERT. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletins is compiled from external, open source reports and is not a direct result of US-CERT analysis.</p>
</td>
</tr>
</table>
<p>
<a name="high"></a></p>
<div>
<table align="center" border="1" summary="High Vulnerabilities">
<thead>
<tr>
<th colspan="5">High Vulnerabilities</th>
</tr>
<tr>
<th>Primary<br />
Vendor &#8212; Product</th>
<th>Description</th>
<th>Published</th>
<th>CVSS Score</th>
<th>Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td>abb &#8212; interlink_module</td>
<td>Multiple stack-based buffer overflows in (1) COM and (2) ActiveX controls in ABB WebWare Server, WebWare SDK, Interlink Module, S4 OPC Server, QuickTeach, RobotStudio S4, and RobotStudio Lite allow remote attackers to execute arbitrary code via crafted input data.</td>
<td>2012-04-18</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1801&amp;vector=(AV:A/AC:L/Au:S/C:C/I:C/A:C)" target="_blank">7.7</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1801" target="_blank">CVE-2012-1801</a></td>
</tr>
<tr>
<td>artonx.org &#8212; activescriptruby</td>
<td>GRScript18.dll before 1.2.2.0 in ActiveScriptRuby (ASR) before 1.8.7 does not properly restrict interaction with an Internet Explorer ActiveX environment, which allows remote attackers to execute arbitrary Ruby code via a crafted HTML document.</td>
<td>2012-04-16</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1241&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1241" target="_blank">CVE-2012-1241</a></td>
</tr>
<tr>
<td>curl &#8212; curl</td>
<td>curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows remote attackers to conduct data-injection attacks via a crafted URL, as demonstrated by a CRLF injection attack on the (1) IMAP, (2) POP3, or (3) SMTP protocol.</td>
<td>2012-04-13</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0036&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0036" target="_blank">CVE-2012-0036</a></td>
</tr>
<tr>
<td>emc &#8212; data_protection_advisor</td>
<td>The DPA_Utilities.cProcessAuthenticationData function in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an AUTHENTICATECONNECTION command that (1) lacks a password field or (2) has an empty password.</td>
<td>2012-04-20</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0406&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">7.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0406" target="_blank">CVE-2012-0406</a></td>
</tr>
<tr>
<td>freebsd &#8212; libarchive</td>
<td>Buffer overflow in libarchive 3.0 pre-release code allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CAB file, which is not properly handled during the reading of Huffman code data within LZX compressed data.</td>
<td>2012-04-13</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2010-4666&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4666" target="_blank">CVE-2010-4666</a></td>
</tr>
<tr>
<td>freebsd &#8212; libarchive</td>
<td>Multiple use-after-free vulnerabilities in libarchive 2.8.4 and 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted (1) TAR archive or (2) ISO9660 image.</td>
<td>2012-04-13</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-1779&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1779" target="_blank">CVE-2011-1779</a></td>
</tr>
<tr>
<td>google &#8212; sketchup</td>
<td>Google SketchUp before 8 does not properly handle edge geometry in SketchUp (aka .SKP) files, which allows remote attackers to execute arbitrary code via a crafted file.</td>
<td>2012-04-17</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-2478&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2478" target="_blank">CVE-2011-2478</a></td>
</tr>
<tr>
<td>iconics &#8212; bizviz</td>
<td>The GENESIS32 IcoSetServer ActiveX control in ICONICS GENESIS32 9.21 and BizViz 9.21 configures the trusted zone on the basis of user input, which allows remote attackers to execute arbitrary code via a crafted web site, related to a &quot;Workbench32/WebHMI component SetTrustedZone Policy vulnerability.&quot;</td>
<td>2012-04-18</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-5088&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-5088" target="_blank">CVE-2011-5088</a></td>
</tr>
<tr>
<td>iconics &#8212; bizviz</td>
<td>Buffer overflow in the Security Login ActiveX controls in ICONICS GENESIS32 8.05, 9.0, 9.1, and 9.2 and BizViz 8.05, 9.0, 9.1, and 9.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long password.</td>
<td>2012-04-18</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-5089&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-5089" target="_blank">CVE-2011-5089</a></td>
</tr>
<tr>
<td>irfanview &#8212; flashpix_plugin</td>
<td>Heap-based buffer overflow in the FlashPix PlugIn before 4.3.4.0 for IrfanView might allow remote attackers to execute arbitrary code via a .fpx file containing a crafted FlashPix image that is not properly handled during decompression.</td>
<td>2012-04-18</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0278&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0278" target="_blank">CVE-2012-0278</a></td>
</tr>
<tr>
<td>koyo &#8212; h0-ecom</td>
<td>Buffer overflow in the ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 allows remote attackers to execute arbitrary code via long strings in unspecified parameters.</td>
<td>2012-04-13</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1805&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1805" target="_blank">CVE-2012-1805</a></td>
</tr>
<tr>
<td>koyo &#8212; h0-ecom</td>
<td>The ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 supports a maximum password length of 8 bytes, which makes it easier for remote attackers to obtain access via a brute-force attack.</td>
<td>2012-04-13</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1806&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1806" target="_blank">CVE-2012-1806</a></td>
</tr>
<tr>
<td>koyo &#8212; h0-ecom</td>
<td>The web server in the ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 does not require authentication, which allows remote attackers to perform unspecified functions via unknown vectors.</td>
<td>2012-04-13</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1808&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1808" target="_blank">CVE-2012-1808</a></td>
</tr>
<tr>
<td>openssl &#8212; openssl</td>
<td>The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key.</td>
<td>2012-04-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2110&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2110" target="_blank">CVE-2012-2110</a></td>
</tr>
<tr>
<td>realnetworks &#8212; helix_mobile_server</td>
<td>Buffer overflow in rn5auth.dll in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to execute arbitrary code via crafted authentication credentials.</td>
<td>2012-04-17</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0942&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0942" target="_blank">CVE-2012-0942</a></td>
</tr>
<tr>
<td>siemens &#8212; scalance_s_firmware</td>
<td>The web server on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with firmware before 2.3.0.3 does not limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack on the administrative password.</td>
<td>2012-04-18</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1799&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1799" target="_blank">CVE-2012-1799</a></td>
</tr>
<tr>
<td>siemens &#8212; scalance_x-300_firmware</td>
<td>Buffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414-3E before 3.7.1, X308-2M before 3.7.2, X-300EEC before 3.7.2, XR-300 before 3.7.2, and X-300 before 3.7.2 allows remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary code via a malformed URL.</td>
<td>2012-04-18</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1802&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">7.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1802" target="_blank">CVE-2012-1802</a></td>
</tr>
<tr>
<td>vmware &#8212; fusion</td>
<td>VMware Workstation 8.x before 8.0.2, VMware Player 4.x before 4.0.2, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 use an incorrect ACL for the VMware Tools folder, which allows guest OS users to gain guest OS privileges via unspecified vectors.</td>
<td>2012-04-17</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1518&amp;vector=(AV:A/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">8.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1518" target="_blank">CVE-2012-1518</a></td>
</tr>
</tbody>
</table>
<p>
</div>
<p><a name="medium"></a></p>
<div>
<table align="center" border="1" summary="Medium Vulnerabilities">
<thead>
<tr>
<th colspan="5">Medium Vulnerabilities</th>
</tr>
<tr>
<th>Primary<br />
Vendor &#8212; Product</th>
<th>Description</th>
<th>Published</th>
<th>CVSS Score</th>
<th>Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td width="20%">adastra &#8212; trace_mode_data_center</td>
<td>Unspecified vulnerability in AdAstrA TRACE MODE Data Center allows remote attackers to read arbitrary files via unknown vectors, as demonstrated by the GLEG Agora SCADA+ Exploit Pack for Immunity CANVAS.</td>
<td>2012-04-18</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-5087&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-5087" target="_blank">CVE-2011-5087</a></td>
</tr>
<tr>
<td width="20%">apache &#8212; http_server</td>
<td>envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.</td>
<td>2012-04-18</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0883&amp;vector=(AV:L/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">6.9</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0883" target="_blank">CVE-2012-0883</a></td>
</tr>
<tr>
<td width="20%">comodo &#8212; comodo_internet_security</td>
<td>Comodo Internet Security before 5.10.228257.2253 on Windows 7 x64 allows local users to cause a denial of service (system crash) via a crafted 32-bit Portable Executable (PE) file with a kernel ImageBase value.</td>
<td>2012-04-20</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2273&amp;vector=(AV:L/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">4.9</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2273" target="_blank">CVE-2012-2273</a></td>
</tr>
<tr>
<td width="20%">demandmedia &#8212; pluck_sitelife</td>
<td>Multiple cross-site scripting (XSS) vulnerabilities in Demand Media Pluck SiteLife before 5.0.13 allow remote attackers to inject arbitrary web script or HTML via (1) the jsonRequest parameter to Direct/Process, the (2) r or (3) cb parameter to Direct/jsonp.htm, or (4) the cb parameter to sys/jsonp.app/.htm.</td>
<td>2012-04-18</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0253&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0253" target="_blank">CVE-2012-0253</a></td>
</tr>
<tr>
<td width="20%">emc &#8212; data_protection_advisor</td>
<td>Integer overflow in the DPA_Utilities library in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a denial of service (infinite loop) via a negative 64-bit value in a certain size field.</td>
<td>2012-04-20</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0407&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0407" target="_blank">CVE-2012-0407</a></td>
</tr>
<tr>
<td width="20%">freebsd &#8212; libarchive</td>
<td>Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functions in archive_read_support_format_iso9660.c in libarchive through 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ISO9660 image.</td>
<td>2012-04-13</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-1777&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1777" target="_blank">CVE-2011-1777</a></td>
</tr>
<tr>
<td width="20%">freebsd &#8212; libarchive</td>
<td>Buffer overflow in libarchive through 2.8.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TAR archive.</td>
<td>2012-04-13</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-1778&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1778" target="_blank">CVE-2011-1778</a></td>
</tr>
<tr>
<td width="20%">hp &#8212; openvms</td>
<td>Unspecified vulnerability in HP OpenVMS 7.3-2 on the Alpha platform, 8.3 and 8.4 on the Alpha and IA64 platforms, and 8.3-1h1 on the IA64 platform allows local users to cause a denial of service via unknown vectors.</td>
<td>2012-04-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0134&amp;vector=(AV:L/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">4.9</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0134" target="_blank">CVE-2012-0134</a></td>
</tr>
<tr>
<td width="20%">igor_sysoev &#8212; nginx</td>
<td>Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.</td>
<td>2012-04-17</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1180&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1180" target="_blank">CVE-2012-1180</a></td>
</tr>
<tr>
<td width="20%">igor_sysoev &#8212; nginx</td>
<td>Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (memory overwrite) or possibly execute arbitrary code via a crafted MP4 file.</td>
<td>2012-04-17</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2089&amp;vector=(AV:N/AC:H/Au:N/C:P/I:P/A:P)" target="_blank">5.1</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2089" target="_blank">CVE-2012-2089</a></td>
</tr>
<tr>
<td width="20%">koyo &#8212; h0-ecom</td>
<td>Cross-site scripting (XSS) vulnerability in the web server in the ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</td>
<td>2012-04-13</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1807&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1807" target="_blank">CVE-2012-1807</a></td>
</tr>
<tr>
<td width="20%">koyo &#8212; h0-ecom</td>
<td>The web server in the ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 allows remote attackers to cause a denial of service (resource consumption) via unspecified vectors.</td>
<td>2012-04-13</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1809&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1809" target="_blank">CVE-2012-1809</a></td>
</tr>
<tr>
<td width="20%">nsoftware &#8212; unitronics_uniopc</td>
<td>https50.ocx in IP*Works! SSL in the server in Unitronics UniOPC before 2.0.0 does not properly implement an unspecified function, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site.</td>
<td>2012-04-18</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-5086&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-5086" target="_blank">CVE-2011-5086</a></td>
</tr>
<tr>
<td width="20%">opcsystems &#8212; opcsystems.net</td>
<td>Open Automation Software OPC Systems.NET before 5.0 allows remote attackers to cause a denial of service via a malformed .NET RPC packet on TCP port 58723.</td>
<td>2012-04-18</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-4871&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4871" target="_blank">CVE-2011-4871</a></td>
</tr>
<tr>
<td width="20%">owncloud &#8212; owncloud</td>
<td>Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 3.0.0 allow remote attackers to inject arbitrary web script or HTML via (1) an arbitrary field to apps/contacts/ajax/addcard.php, (2) the parameter parameter to apps/contacts/ajax/addproperty.php, (3) the name parameter to apps/contacts/ajax/createaddressbook, (4) the file parameter to files/download.php, or the (5) name, (6) user, or (7) redirect_url parameter to files/index.php.</td>
<td>2012-04-20</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2269&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2269" target="_blank">CVE-2012-2269</a></td>
</tr>
<tr>
<td width="20%">owncloud &#8212; owncloud</td>
<td>Open redirect vulnerability in index.php (aka the Login Page) in ownCloud 3.0.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter.</td>
<td>2012-04-20</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2270&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:N)" target="_blank">5.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2270" target="_blank">CVE-2012-2270</a></td>
</tr>
<tr>
<td width="20%">owncloud &#8212; owncloud</td>
<td>Cross-site request forgery (CSRF) vulnerability in ownCloud 3.0.2 allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) sequences via vectors involving contacts. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</td>
<td>2012-04-20</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2397&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2397" target="_blank">CVE-2012-2397</a></td>
</tr>
<tr>
<td width="20%">owncloud &#8212; owncloud</td>
<td>Cross-site scripting (XSS) vulnerability in files/ajax/download.php in ownCloud 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the files parameter, a different vulnerability than CVE-2012-2269.4. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</td>
<td>2012-04-20</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2398&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2398" target="_blank">CVE-2012-2398</a></td>
</tr>
<tr>
<td width="20%">realnetworks &#8212; helix_mobile_server</td>
<td>Multiple cross-site scripting (XSS) vulnerabilities in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</td>
<td>2012-04-17</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1984&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1984" target="_blank">CVE-2012-1984</a></td>
</tr>
<tr>
<td width="20%">realnetworks &#8212; helix_mobile_server</td>
<td>Cross-site request forgery (CSRF) vulnerability in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to hijack the authentication of administrators for requests that cause a denial of service (stack consumption and daemon crash) via a malformed URL.</td>
<td>2012-04-17</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1985&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1985" target="_blank">CVE-2012-1985</a></td>
</tr>
<tr>
<td width="20%">realnetworks &#8212; helix_mobile_server</td>
<td>master.exe in the SNMP Master Agent in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to cause a denial of service (daemon crash) by establishing and closing a port-705 TCP connection, a different vulnerability than CVE-2012-1923.</td>
<td>2012-04-17</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2267&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2267" target="_blank">CVE-2012-2267</a></td>
</tr>
<tr>
<td width="20%">realnetworks &#8212; helix_mobile_server</td>
<td>master.exe in the SNMP Master Agent in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to cause a denial of service (unhandled exception and daemon crash) via a crafted Open-PDU request that triggers incorrect DisplayString processing, a different vulnerability than CVE-2012-1923.</td>
<td>2012-04-17</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2268&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2268" target="_blank">CVE-2012-2268</a></td>
</tr>
<tr>
<td width="20%">recruit &#8212; dokodemo_rikunabi_2013</td>
<td>Cross-site scripting (XSS) vulnerability in the RECRUIT Dokodemo Rikunabi 2013 extension before 1.0.1 for Google Chrome allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</td>
<td>2012-04-16</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1240&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1240" target="_blank">CVE-2012-1240</a></td>
</tr>
<tr>
<td width="20%">ryan_walberg &#8212; php_gift_registry</td>
<td>SQL injection vulnerability in users.php in PHP Gift Registry 1.5.5 allows remote authenticated users to execute arbitrary SQL commands via the userid parameter in an edit action.</td>
<td>2012-04-20</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2236&amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:P)" target="_blank">6.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2236" target="_blank">CVE-2012-2236</a></td>
</tr>
<tr>
<td width="20%">siemens &#8212; scalance_s_firmware</td>
<td>Stack-based buffer overflow in the Profinet DCP protocol implementation on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with firmware before 2.3.0.3 allows remote attackers to cause a denial of service (device outage) or possibly execute arbitrary code via a crafted DCP frame.</td>
<td>2012-04-18</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1800&amp;vector=(AV:A/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">6.1</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1800" target="_blank">CVE-2012-1800</a></td>
</tr>
<tr>
<td width="20%">videolan &#8212; vlc_media_player</td>
<td>VideoLAN VLC media player 2.0.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted MP4 file.</td>
<td>2012-04-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2396&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:P)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2396" target="_blank">CVE-2012-2396</a></td>
</tr>
</tbody>
</table>
<p>
</div>
<p><a name="low"></a></p>
<div>
<table align="center" border="1" summary="Low Vulnerabilities">
<thead>
<tr>
<th colspan="5">Low Vulnerabilities</th>
</tr>
<tr>
<th>Primary<br />
Vendor &#8212; Product</th>
<th>Description</th>
<th>Published</th>
<th>CVSS Score</th>
<th>Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td width="20%">hp &#8212; system_management_homepage</td>
<td>Unspecified vulnerability in HP System Management Homepage (SMH) before 7.0 allows remote authenticated users to cause a denial of service via unknown vectors.</td>
<td>2012-04-18</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0135&amp;vector=(AV:N/AC:M/Au:S/C:N/I:N/A:P)" target="_blank">3.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0135" target="_blank">CVE-2012-0135</a></td>
</tr>
<tr>
<td width="20%">hp &#8212; system_management_homepage</td>
<td>Unspecified vulnerability in HP System Management Homepage (SMH) before 7.0 allows local users to modify data or obtain sensitive information via unknown vectors.</td>
<td>2012-04-18</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1993&amp;vector=(AV:L/AC:L/Au:S/C:P/I:P/A:N)" target="_blank">3.2</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1993" target="_blank">CVE-2012-1993</a></td>
</tr>
<tr>
<td width="20%">realnetworks &#8212; helix_mobile_server</td>
<td>RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x store passwords in cleartext under adm_b_db\users\, which allows local users to obtain sensitive information by reading a database.</td>
<td>2012-04-17</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1923&amp;vector=(AV:L/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">2.1</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1923" target="_blank">CVE-2012-1923</a></td>
</tr>
<tr>
<td width="20%">syndeocms &#8212; syndeocms</td>
<td>Cross-site scripting (XSS) vulnerability in starnet/index.php in SyndeoCMS 3.0.01 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the email parameter (aka Email address field) in an edit_user configuration action.</td>
<td>2012-04-17</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1979&amp;vector=(AV:N/AC:M/Au:S/C:N/I:P/A:N)" target="_blank">3.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1979" target="_blank">CVE-2012-1979</a></td>
</tr>
</tbody>
</table>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.freednslookup.net/2012/04/23/sb12-114-vulnerability-summary-for-the-week-of-april-16-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SB12-107: Vulnerability Summary for the Week of April 9, 2012</title>
		<link>http://www.freednslookup.net/2012/04/17/sb12-107-vulnerability-summary-for-the-week-of-april-9-2012/</link>
		<comments>http://www.freednslookup.net/2012/04/17/sb12-107-vulnerability-summary-for-the-week-of-april-9-2012/#comments</comments>
		<pubDate>Tue, 17 Apr 2012 19:00:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[US-Cert]]></category>

		<guid isPermaLink="false">http://www.freednslookup.net/2012/04/17/sb12-107-vulnerability-summary-for-the-week-of-april-9-2012/</guid>
		<description><![CDATA[The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cyber Security Division (NCSD) / United States Computer Emergency Readiness Team [...]]]></description>
			<content:encoded><![CDATA[<p><a name="top"></a></p>
<table align="center">
<tr>
<td>
<p>The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cyber Security Division (NCSD) / United States Computer Emergency Readiness Team (US-CERT). For updated or updated entries, please visit the <a href="http://nvd.nist.gov" target="_blank">NVD</a>, which contains historical vulnerability information.</p>
<p>The vulnerabilities are based on the <a href="http://cve.mitre.org/" target="_blank">CVE</a> vulnerability naming standard and are organized according to severity, determined by the <a href="http://nvd.nist.gov/cvss.cfm" target="_blank">Common Vulnerability Scoring System</a> (CVSS) standard. The division of high, medium, and low severities correspond to the following scores:</p>
<ul>
<li>
<p><strong>High</strong> &#8211; Vulnerabilities will be labeled High severity if they have a CVSS base score of 7.0 &#8211; 10.0</p>
</li>
<li>
<p><strong>Medium</strong> &#8211; Vulnerabilities will be labeled Medium severity if they have a CVSS base score of 4.0 &#8211; 6.9</p>
</li>
<li>
<p><strong>Low</strong> &#8211; Vulnerabilities will be labeled Low severity if they have a CVSS base score of 0.0 &#8211; 3.9</p>
</li>
</ul>
<p>Entries may include additional information provided by organizations and efforts sponsored by US-CERT. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletins is compiled from external, open source reports and is not a direct result of US-CERT analysis.</p>
</td>
</tr>
</table>
<p>
<a name="high"></a></p>
<div>
<table align="center" border="1" summary="High Vulnerabilities">
<thead>
<tr>
<th colspan="5">High Vulnerabilities</th>
</tr>
<tr>
<th>Primary<br />
Vendor &#8212; Product</th>
<th>Description</th>
<th>Published</th>
<th>CVSS Score</th>
<th>Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td>360zip &#8212; 360zip</td>
<td>360zip 1.93beta allows remote attackers to execute arbitrary code via vectors related to file browsing and file extraction.</td>
<td>2012-04-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2225&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2225" target="_blank">CVE-2012-2225</a></td>
</tr>
<tr>
<td>adobe &#8212; acrobat</td>
<td>Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 allows attackers to execute arbitrary code via a crafted TrueType font.</td>
<td>2012-04-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0774&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0774" target="_blank">CVE-2012-0774</a></td>
</tr>
<tr>
<td>adobe &#8212; acrobat</td>
<td>The JavaScript implementation in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.</td>
<td>2012-04-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0775&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0775" target="_blank">CVE-2012-0775</a></td>
</tr>
<tr>
<td>adobe &#8212; acrobat</td>
<td>The installer in Adobe Reader 9.x before 9.5.1 and 10.x before 10.1.3 allows attackers to bypass intended access restrictions and execute arbitrary code via unspecified vectors.</td>
<td>2012-04-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0776&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0776" target="_blank">CVE-2012-0776</a></td>
</tr>
<tr>
<td>adobe &#8212; acrobat</td>
<td>The JavaScript API in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 on Mac OS X and Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.</td>
<td>2012-04-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0777&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0777" target="_blank">CVE-2012-0777</a></td>
</tr>
<tr>
<td>antonin_descampe &#8212; openjpeg</td>
<td>The JPEG 2000 codec in OpenJPEG before 1.5 does not properly allocate memory during file parsing, which allows remote attackers to execute arbitrary code via a crafted file.</td>
<td>2012-04-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1499&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1499" target="_blank">CVE-2012-1499</a></td>
</tr>
<tr>
<td>google &#8212; chrome</td>
<td>Adobe Flash Player before 11.2.202.229 in Google Chrome before 18.0.1025.151 allow attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2012-0725.</td>
<td>2012-04-06</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0724&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0724" target="_blank">CVE-2012-0724</a></td>
</tr>
<tr>
<td>google &#8212; chrome</td>
<td>Adobe Flash Player before 11.2.202.229 in Google Chrome before 18.0.1025.151 allow attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2012-0724.</td>
<td>2012-04-06</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0725&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0725" target="_blank">CVE-2012-0725</a></td>
</tr>
<tr>
<td>microsoft &#8212; windows_7</td>
<td>The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute arbitrary code via a updated file with additional content, aka &quot;WinVerifyTrust Signature Validation Vulnerability.&quot;</td>
<td>2012-04-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0151&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0151" target="_blank">CVE-2012-0151</a></td>
</tr>
<tr>
<td>microsoft &#8212; biztalk_server</td>
<td>The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2, and 2009 Gold and R2; Visual FoxPro 8.0 SP1 and 9.0 SP2; and Visual Basic 6.0 Runtime allow remote attackers to execute arbitrary code via a crafted (a) web site, (b) Office document, or (c) .rtf file that triggers &quot;system state&quot; corruption, as exploited in the wild in April 2012, aka &quot;MSCOMCTL.OCX RCE Vulnerability.&quot;</td>
<td>2012-04-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0158&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0158" target="_blank">CVE-2012-0158</a></td>
</tr>
<tr>
<td>microsoft &#8212; .net_framework</td>
<td>Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate function parameters, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka &quot;.NET Framework Parameter Validation Vulnerability.&quot;</td>
<td>2012-04-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0163&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0163" target="_blank">CVE-2012-0163</a></td>
</tr>
<tr>
<td>microsoft &#8212; ie</td>
<td>Microsoft Internet Explorer 6 through 9 allows user-assisted remote attackers to execute arbitrary code via a crafted HTML document that is not properly handled during a &quot;Print table of links&quot; print operation, aka &quot;Print Feature Remote Code Execution Vulnerability.&quot;</td>
<td>2012-04-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0168&amp;vector=(AV:N/AC:H/Au:N/C:C/I:C/A:C)" target="_blank">7.6</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0168" target="_blank">CVE-2012-0168</a></td>
</tr>
<tr>
<td>microsoft &#8212; ie</td>
<td>Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka &quot;JScript9 Remote Code Execution Vulnerability.&quot;</td>
<td>2012-04-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0169&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0169" target="_blank">CVE-2012-0169</a></td>
</tr>
<tr>
<td>microsoft &#8212; ie</td>
<td>Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka &quot;OnReadyStateChange Remote Code Execution Vulnerability.&quot;</td>
<td>2012-04-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0170&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0170" target="_blank">CVE-2012-0170</a></td>
</tr>
<tr>
<td>microsoft &#8212; ie</td>
<td>Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka &quot;SelectAll Remote Code Execution Vulnerability.&quot;</td>
<td>2012-04-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0171&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0171" target="_blank">CVE-2012-0171</a></td>
</tr>
<tr>
<td>microsoft &#8212; ie</td>
<td>Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka &quot;VML Style Remote Code Execution Vulnerability.&quot;</td>
<td>2012-04-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0172&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0172" target="_blank">CVE-2012-0172</a></td>
</tr>
<tr>
<td>microsoft &#8212; office</td>
<td>Heap-based buffer overflow in the Office Works File Converter in Microsoft Office 2007 SP2, Works 9, and Works 6-9 File Converter allows remote attackers to execute arbitrary code via a crafted Works (aka .wps) file, aka &quot;Office WPS Converter Heap Overflow Vulnerability.&quot;</td>
<td>2012-04-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0177&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0177" target="_blank">CVE-2012-0177</a></td>
</tr>
<tr>
<td>microsys &#8212; promotic</td>
<td>Use-after-free vulnerability in MICROSYS PROMOTIC before 8.1.7 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (data corruption and application crash) via a crafted project (aka .pra) file.</td>
<td>2012-04-13</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-4874&amp;vector=(AV:A/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">7.9</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4874" target="_blank">CVE-2011-4874</a></td>
</tr>
<tr>
<td>novell &#8212; zenworks_configuration_management</td>
<td>Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to execute arbitrary code via an opcode 0x6c request.</td>
<td>2012-04-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3175&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3175" target="_blank">CVE-2011-3175</a></td>
</tr>
<tr>
<td>novell &#8212; zenworks_configuration_management</td>
<td>Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to execute arbitrary code via an opcode 0x4c request.</td>
<td>2012-04-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3176&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3176" target="_blank">CVE-2011-3176</a></td>
</tr>
<tr>
<td>ola_lasisi &#8212; e-ticketing</td>
<td>SQL injection vulnerability in loginscript.php in e-ticketing allows remote attackers to execute arbitrary SQL commands via the password parameter.</td>
<td>2012-04-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1673&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1673" target="_blank">CVE-2012-1673</a></td>
</tr>
<tr>
<td>samba &#8212; samba</td>
<td>The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.</td>
<td>2012-04-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1182&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1182" target="_blank">CVE-2012-1182</a></td>
</tr>
<tr>
<td>sony &#8212; bravia_tv</td>
<td>The Sony Bravia TV KDL-32CX525 allows remote attackers to cause a denial of service (configuration outage or device crash) via a flood of TCP SYN packets, as demonstrated by hping, a related issue to CVE-1999-0116.</td>
<td>2012-04-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2210&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">7.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2210" target="_blank">CVE-2012-2210</a></td>
</tr>
<tr>
<td>toshiba_tec &#8212; e-studio</td>
<td>The TopAccess web-based management interface on TOSHIBA TEC e-Studio multi-function peripheral (MFP) devices with firmware 30x through 302, 35x through 354, and 4xx through 421 allows remote attackers to bypass authentication and obtain administrative privileges via unspecified vectors.</td>
<td>2012-04-06</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1239&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1239" target="_blank">CVE-2012-1239</a></td>
</tr>
<tr>
<td>useasdf_4444 &#8212; hotel_booking_portal</td>
<td>SQL injection vulnerability in getcity.php in Hotel Booking Portal 0.1 allows remote attackers to execute arbitrary SQL commands via the country parameter.</td>
<td>2012-04-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1672&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1672" target="_blank">CVE-2012-1672</a></td>
</tr>
<tr>
<td>xunlei &#8212; thunder</td>
<td>Xunlei Thunder before 7.2.6 allows remote attackers to execute arbitrary code via a crafted file, related to a &quot;DLL injection vulnerability.&quot;</td>
<td>2012-04-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2224&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2224" target="_blank">CVE-2012-2224</a></td>
</tr>
</tbody>
</table>
<p>
</div>
<p><a name="medium"></a></p>
<div>
<table align="center" border="1" summary="Medium Vulnerabilities">
<thead>
<tr>
<th colspan="5">Medium Vulnerabilities</th>
</tr>
<tr>
<th>Primary<br />
Vendor &#8212; Product</th>
<th>Description</th>
<th>Published</th>
<th>CVSS Score</th>
<th>Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td width="20%">apache &#8212; hadoop</td>
<td>The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used in Cloudera CDH CDH3u0 through CDH3u2, Cloudera hadoop-0.20-sbin before 0.20.2+923.197, and other products, allows remote authenticated users to impersonate arbitrary cluster user accounts via unspecified vectors.</td>
<td>2012-04-12</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1574&amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:P)" target="_blank">6.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1574" target="_blank">CVE-2012-1574</a></td>
</tr>
<tr>
<td width="20%">atvise &#8212; webmi2ads</td>
<td>Directory traversal vulnerability in the web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 allows remote attackers to read arbitrary files via a crafted HTTP request.</td>
<td>2012-04-13</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-4880&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4880" target="_blank">CVE-2011-4880</a></td>
</tr>
<tr>
<td width="20%">atvise &#8212; webmi2ads</td>
<td>The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 does not properly check return values from functions, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted HTTP request.</td>
<td>2012-04-13</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-4881&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4881" target="_blank">CVE-2011-4881</a></td>
</tr>
<tr>
<td width="20%">atvise &#8212; webmi2ads</td>
<td>The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 allows remote attackers to cause a denial of service (application exit) via an unspecified command in an HTTP request.</td>
<td>2012-04-13</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-4882&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4882" target="_blank">CVE-2011-4882</a></td>
</tr>
<tr>
<td width="20%">atvise &#8212; webmi2ads</td>
<td>The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 does not properly validate values in HTTP requests, which allows remote attackers to cause a denial of service (resource consumption) via a crafted request.</td>
<td>2012-04-13</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-4883&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4883" target="_blank">CVE-2011-4883</a></td>
</tr>
<tr>
<td width="20%">cloudera &#8212; cloudera_manager</td>
<td>Cloudera Manager 3.7.x before 3.7.5 and Service and Configuration Manager 3.5, when Kerberos is not enabled, does not properly install taskcontroller.cfg, which allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors, a different vulnerability than CVE-2012-1574.</td>
<td>2012-04-12</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2230&amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:P)" target="_blank">6.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2230" target="_blank">CVE-2012-2230</a></td>
</tr>
<tr>
<td width="20%">cmsmadesimple &#8212; cms_made_simple</td>
<td>Cross-site scripting (XSS) vulnerability in admin/edituser.php in CMS Made Simple 1.10.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the email parameter (aka the Email Address field in the Edit User template).</td>
<td>2012-04-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1992&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1992" target="_blank">CVE-2012-1992</a></td>
</tr>
<tr>
<td width="20%">dotnetnuke &#8212; dotnetnuke</td>
<td>Cross-site scripting (XSS) vulnerability in DotNetNuke 6.x through 6.0.2 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted URL containing text that is used within a modal popup.</td>
<td>2012-04-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1030&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1030" target="_blank">CVE-2012-1030</a></td>
</tr>
<tr>
<td width="20%">dotnetnuke &#8212; dotnetnuke</td>
<td>Cross-site scripting (XSS) vulnerability in the telerik HTML editor in DotNetNuke before 5.6.4 and 6.x before 6.1.0 allows remote attackers to inject arbitrary web script or HTML via a message.</td>
<td>2012-04-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1036&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1036" target="_blank">CVE-2012-1036</a></td>
</tr>
<tr>
<td width="20%">hp &#8212; system_management_homepage</td>
<td>Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) 6.2.2.7 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts.</td>
<td>2012-04-12</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3846&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3846" target="_blank">CVE-2011-3846</a></td>
</tr>
<tr>
<td width="20%">icz &#8212; sencha_sns</td>
<td>Cross-site request forgery (CSRF) vulnerability in SENCHA SNS before 1.0.2 allows remote attackers to hijack the authentication of arbitrary users.</td>
<td>2012-04-06</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1237&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1237" target="_blank">CVE-2012-1237</a></td>
</tr>
<tr>
<td width="20%">icz &#8212; sencha_sns</td>
<td>Session fixation vulnerability in SENCHA SNS before 1.0.2 allows remote attackers to hijack web sessions via unspecified vectors.</td>
<td>2012-04-06</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1238&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1238" target="_blank">CVE-2012-1238</a></td>
</tr>
<tr>
<td width="20%">microsoft &#8212; forefront_unified_access_gateway</td>
<td>Open redirect vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka &quot;UAG Blind HTTP Redirect Vulnerability.&quot;</td>
<td>2012-04-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0146&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:N)" target="_blank">5.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0146" target="_blank">CVE-2012-0146</a></td>
</tr>
<tr>
<td width="20%">microsoft &#8212; forefront_unified_access_gateway</td>
<td>Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 does not properly configure the default web site, which allows remote attackers to obtain sensitive information via a crafted HTTPS request, aka &quot;Unfiltered Access to UAG Default Website Vulnerability.&quot;</td>
<td>2012-04-10</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0147&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0147" target="_blank">CVE-2012-0147</a></td>
</tr>
<tr>
<td width="20%">novell &#8212; imanager</td>
<td>Buffer overflow in the Create Attribute function in jclient in Novell iManager 2.7.4 before patch 4 allows remote authenticated users to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted EnteredAttrName parameter, a related issue to CVE-2010-1929.</td>
<td>2012-04-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-4188&amp;vector=(AV:N/AC:L/Au:S/C:N/I:N/A:P)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4188" target="_blank">CVE-2011-4188</a></td>
</tr>
<tr>
<td width="20%">novell &#8212; zenworks_configuration_management</td>
<td>Directory traversal vulnerability in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to read arbitrary files via an opcode 0&#215;21 request.</td>
<td>2012-04-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2215&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2215" target="_blank">CVE-2012-2215</a></td>
</tr>
<tr>
<td width="20%">novell &#8212; zenworks_configuration_management</td>
<td>The xplat agent in Novell ZENworks Configuration Management (ZCM) 10.3.x before 10.3.4 and 11.x before 11.2 enables the HTTP TRACE method, which might make it easier for remote attackers to conduct cross-site tracing (XST) attacks via unspecified vectors.</td>
<td>2012-04-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2223&amp;vector=(AV:N/AC:M/Au:N/C:P/I:N/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2223" target="_blank">CVE-2012-2223</a></td>
</tr>
<tr>
<td width="20%">phpmyadmin &#8212; phpmyadmin</td>
<td>show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a configuration file does not exist, allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message about this missing file.</td>
<td>2012-04-06</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1902&amp;vector=(AV:N/AC:M/Au:N/C:P/I:N/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1902" target="_blank">CVE-2012-1902</a></td>
</tr>
<tr>
<td width="20%">plume-cms &#8212; plume_cms</td>
<td>Multiple cross-site scripting (XSS) vulnerabilities in Plume CMS 1.2.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the u_email parameter (aka Authors Email field) to manager/users.php, (2) the u_realname parameter (aka Authors Name field) to manager/users.php, or (3) the c_author parameter (aka Author field) in an ADD A COMMENT section.</td>
<td>2012-04-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-2156&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2156" target="_blank">CVE-2012-2156</a></td>
</tr>
<tr>
<td width="20%">wireshark &#8212; wireshark</td>
<td>The dissect_packet function in epan/packet.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in a capture file, as demonstrated by an airopeek file.</td>
<td>2012-04-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0041&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:P)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0041" target="_blank">CVE-2012-0041</a></td>
</tr>
<tr>
<td width="20%">wireshark &#8212; wireshark</td>
<td>Buffer overflow in the reassemble_message function in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a series of fragmented RLC packets.</td>
<td>2012-04-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0043&amp;vector=(AV:A/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">5.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0043" target="_blank">CVE-2012-0043</a></td>
</tr>
<tr>
<td width="20%">wireshark &#8212; wireshark</td>
<td>Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in a (1) Accellent 5Views (aka .5vw) file, (2) I4B trace file, or (3) NETMON 2 capture file.</td>
<td>2012-04-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0066&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:P)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0066" target="_blank">CVE-2012-0066</a></td>
</tr>
<tr>
<td width="20%">wireshark &#8212; wireshark</td>
<td>wiretap/iptrace.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in an AIX iptrace file.</td>
<td>2012-04-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0067&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:P)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0067" target="_blank">CVE-2012-0067</a></td>
</tr>
<tr>
<td width="20%">wireshark &#8212; wireshark</td>
<td>The lanalyzer_read function in wiretap/lanalyzer.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a Novell catpure file containing a record that is too small.</td>
<td>2012-04-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0068&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:P)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0068" target="_blank">CVE-2012-0068</a></td>
</tr>
<tr>
<td width="20%">wireshark &#8212; wireshark</td>
<td>The pcap_process_pseudo_header function in wiretap/pcap-common.c in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (application crash) via a WTAP_ENCAP_ERF file containing an Extension or Multi-Channel header with an invalid pseudoheader size, related to the pcap and pcap-ng file parsers.</td>
<td>2012-04-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1595&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:P)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1595" target="_blank">CVE-2012-1595</a></td>
</tr>
<tr>
<td width="20%">wireshark &#8212; wireshark</td>
<td>The mp2t_process_fragmented_payload function in epan/dissectors/packet-mp2t.c in the MP2T dissector in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (application crash) via a packet containing an invalid pointer value that triggers an incorrect memory-allocation attempt.</td>
<td>2012-04-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1596&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1596" target="_blank">CVE-2012-1596</a></td>
</tr>
</tbody>
</table>
<p>
</div>
<p><a name="low"></a></p>
<div>
<table align="center" border="1" summary="Low Vulnerabilities">
<thead>
<tr>
<th colspan="5">Low Vulnerabilities</th>
</tr>
<tr>
<th>Primary<br />
Vendor &#8212; Product</th>
<th>Description</th>
<th>Published</th>
<th>CVSS Score</th>
<th>Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td width="20%">hp &#8212; procurve_switch_5400zl</td>
<td>HP ProCurve 5400 zl switches with certain serial numbers include a compact flash card that contains an unspecified virus, which might allow user-assisted remote attackers to execute arbitrary code on a PC by leveraging manual transfer of this card.</td>
<td>2012-04-12</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0133&amp;vector=(AV:L/AC:H/Au:N/C:P/I:P/A:P)" target="_blank">3.7</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0133" target="_blank">CVE-2012-0133</a></td>
</tr>
<tr>
<td width="20%">ibm &#8212; tivoli_event_pump</td>
<td>IBM Tivoli Event Pump 4.2.2, when the LOG_REQUESTS and VALIDATE_SOAP_USERS options are enabled, places credentials into the AOPSCLOG (aka AOPLOG) data set, which allows local users to obtain sensitive information by reading the data.</td>
<td>2012-04-09</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0742&amp;vector=(AV:L/AC:M/Au:N/C:P/I:N/A:N)" target="_blank">1.9</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0742" target="_blank">CVE-2012-0742</a></td>
</tr>
<tr>
<td width="20%">wireshark &#8212; wireshark</td>
<td>Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 does not properly perform certain string conversions, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet, related to epan/to_str.c.</td>
<td>2012-04-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0042&amp;vector=(AV:A/AC:M/Au:N/C:N/I:N/A:P)" target="_blank">2.9</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0042" target="_blank">CVE-2012-0042</a></td>
</tr>
<tr>
<td width="20%">wireshark &#8212; wireshark</td>
<td>epan/dissectors/packet-ansi_a.c in the ANSI A dissector in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed packet.</td>
<td>2012-04-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1593&amp;vector=(AV:A/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">3.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1593" target="_blank">CVE-2012-1593</a></td>
</tr>
<tr>
<td width="20%">wireshark &#8212; wireshark</td>
<td>epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.</td>
<td>2012-04-11</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1594&amp;vector=(AV:A/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">3.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1594" target="_blank">CVE-2012-1594</a></td>
</tr>
</tbody>
</table>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.freednslookup.net/2012/04/17/sb12-107-vulnerability-summary-for-the-week-of-april-9-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TA12-101B: Adobe Reader and Acrobat Security Updates and Architectural Improvements</title>
		<link>http://www.freednslookup.net/2012/04/11/ta12-101b-adobe-reader-and-acrobat-security-updates-and-architectural-improvements/</link>
		<comments>http://www.freednslookup.net/2012/04/11/ta12-101b-adobe-reader-and-acrobat-security-updates-and-architectural-improvements/#comments</comments>
		<pubDate>Wed, 11 Apr 2012 14:00:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[US-Cert]]></category>

		<guid isPermaLink="false">http://www.freednslookup.net/2012/04/11/ta12-101b-adobe-reader-and-acrobat-security-updates-and-architectural-improvements/</guid>
		<description><![CDATA[Original release date: April 10, 2012 &#124; Last revised: &#8211; Systems Affected Adobe Reader X (10.1.2) and earlier 10.x versions for Windows and Macintosh Adobe Reader 9.5 and earlier 9.x versions for Windows, Macintosh, and UNIX Adobe Acrobat X (10.1.2) and earlier 10.x versions for Windows and Macintosh Adobe Acrobat 9.5 and earlier 9.x versions [...]]]></description>
			<content:encoded><![CDATA[<p>Original release date: April 10, 2012 | Last revised: &#8211;</p>
<p><a name="affected"></a></p>
<h3>Systems Affected</h3>
<ul>
<li>Adobe Reader X (10.1.2) and earlier 10.x versions for Windows and Macintosh</li>
<li>Adobe Reader 9.5 and earlier 9.x versions for Windows, Macintosh, and UNIX</li>
<li>Adobe Acrobat X (10.1.2) and earlier 10.x versions for Windows and Macintosh</li>
<li>Adobe Acrobat 9.5 and earlier 9.x versions for Windows and Macintosh</li>
</ul>
<p><a name="overview"></a></p>
<h3>Overview</h3>
<p>Adobe has released Security Bulletin <a href="http://www.adobe.com/support/security/bulletins/apsb12-08.html">APSB12-08</a>, which describes multiple vulnerabilities affecting Adobe Reader and Acrobat. As part of this update, Adobe Reader and Acrobat 9.x will use the system-wide Flash Player browser plug-in instead of the Authplay component. In addition, Reader and Acrobat now disable the rendering of 3D content by default.</p>
<p><a name="description"></a></p>
<h3>Description</h3>
<p>Adobe Security Bulletin <a href="http://www.adobe.com/support/security/bulletins/apsb12-08.html">APSB12-08</a> describes a number of vulnerabilities affecting Adobe Reader and Acrobat. These vulnerabilities affect Adobe Reader and Acrobat versions 9.x through 9.5, and Reader X and Acrobat X versions prior to 10.1.3.</p>
<p>The <a href="http://blogs.adobe.com/asset/2012/04/background-on-security-bulletin-apsb12-08.html">Adobe ASSET blog</a> provides additional details on new security architecture changes to Adobe Reader and Acrobat. Adobe Reader and Acrobat 9.5.1 will use the Adobe Flash Player plug-in version installed on the user’s system rather than the Authplay component that ships with Adobe Reader and Acrobat. This change helps limit the number of <a href="http://www.kb.cert.org/vuls/id/259425">out-of-date, vulnerable Flash runtimes</a> available to an attacker. Adobe Reader and Acrobat 9.5.1 also now disable rendering of 3D content by default because the 3D rendering components have a <a href="http://www.kb.cert.org/vuls/bypublished?searchview&amp;query=rt3d.dll">history of vulnerabilities</a>.</p>
<p>US-CERT recommends that Flash users upgrade to the latest version of <a href="http://get.adobe.com/flashplayer/">Adobe Flash Player</a> and turn on automatic updates.</p>
<p>An attacker could exploit these vulnerabilities by convincing a user to open a specially crafted PDF file. This can happen automatically as the result of viewing a webpage.</p>
<p><a name="impact"></a></p>
<h3>Impact</h3>
<p>These vulnerabilities could allow a remote attacker to execute arbitrary code, write arbitrary files or folders to the file system, escalate local privileges, or cause a denial of service on an affected system as the result of a user opening a malicious PDF file.</p>
<p><a name="solution"></a></p>
<h3>Solution</h3>
<p><strong>Update Reader</strong></p>
<p>Adobe has released updates to address this issue. Users are encouraged to read Adobe Security Bulletin <a href="http://www.adobe.com/support/security/bulletins/apsb12-08.html">APSB12-08</a> and update vulnerable versions of Adobe Reader and Acrobat.</p>
<p><strong><em>In addition to updating, please consider the following mitigations.</em></strong></p>
<p><b>Disable JavaScript in Adobe Reader and Acrobat</b></p>
<p>Disabling JavaScript may prevent some exploits from resulting in code execution. You can disable Acrobat JavaScript using the Preferences menu (<tt>Edit</tt> -&gt; <tt>Preferences</tt> -&gt; <tt>JavaScript;</tt> uncheck <tt>Enable Acrobat JavaScript</tt>).</p>
<p>Adobe provides a framework to <a href="http://kb2.adobe.com/cps/504/cpsid_50431.html">blacklist specific JavaScipt APIs</a>. If JavaScript must be enabled, this framework may be useful when specific APIs are known to be vulnerable or used in attacks.</p>
<p><b>Prevent Internet Explorer from automatically opening PDF files</b></p>
<p>The installer for Adobe Reader and Acrobat configures Internet Explorer to automatically open PDF files without any user interaction. This behavior can be reverted to a safer option that prompts the user by importing the following as a .REG file:</p>
<p><tt>Windows Registry Editor Version 5.00</p>
<p>[HKEY_CLASSES_ROOT\AcroExch.Document.7]<br />
&quot;EditFlags&quot;=hex:00,00,00,00</tt></p>
<p><b>Disable the display of PDF files in the web browser</b></p>
<p>Preventing PDF files from opening inside a web browser will partially mitigate this vulnerability. Applying this workaround may also mitigate future vulnerabilities.</p>
<p>To prevent PDF files from automatically being opened in a web browser, do the following:</p>
<p>1. Open Adobe Acrobat Reader.<br />
2. Open the <tt>Edit</tt> menu.<br />
3. Choose the <tt>Preferences</tt> option.<br />
4. Choose the <tt>Internet</tt> section.<br />
5. Uncheck the &quot;<tt>Display PDF in browser</tt>&quot; checkbox.</p>
<p><b>Do not access PDF files from untrusted sources</b></p>
<p>Do not open unfamiliar or unexpected PDF files, particularly those hosted on websites or delivered as email attachments. Please see Cyber Security Tip <a href="http://www.us-cert.gov/cas/tips/ST04-010.html">ST04-010</a>.</p>
<p><a name="references"></a></p>
<h3>References</h3>
<ul>
<li>Security update available for Adobe Reader and Acrobat &#8211; &lt;<a href="https://www.adobe.com/support/security/bulletins/apsb11-30.html">https://www.adobe.com/support/security/bulletins/apsb11-30.html</a>&gt;</li>
<li>Adobe Reader and Acrobat JavaScript Blacklist Framework &#8211; &lt;<a href="http://kb2.adobe.com/cps/504/cpsid_50431.html">http://kb2.adobe.com/cps/504/cpsid_50431.html</a>&gt;</li>
<li>Background on Security Bulletin APSB12-08 &#8211; &lt;<a href="http://blogs.adobe.com/asset/2012/04/background-on-security-bulletin-apsb12-08.html">http://blogs.adobe.com/asset/2012/04/background-on-security-bulletin-apsb12-08.html</a>&gt;</li>
<li>Adobe Flash Player &#8211; &lt;<a href="http://get.adobe.com/flashplayer/">http://get.adobe.com/flashplayer/</a>&gt;</li>
<li>Adobe Flash vulnerability affects Flash Player and other Adobe products &#8211; &lt;<a href="http://www.kb.cert.org/vuls/id/259425">http://www.kb.cert.org/vuls/id/259425</a>&gt;</li>
<li>Vulnerability Notes with advice to disable 3D rendering &#8211; &lt;<a href="http://www.kb.cert.org/vuls/bypublished?searchview&amp;query=rt3d.dll">http://www.kb.cert.org/vuls/bypublished?searchview&amp;query=rt3d.dll</a>&gt;</li>
</ul>
<p><a name="revisions"></a></p>
<h3>Revision History</h3>
<ul>
<li>April 10, 2012: Initial release</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.freednslookup.net/2012/04/11/ta12-101b-adobe-reader-and-acrobat-security-updates-and-architectural-improvements/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TA12-101A: Microsoft Updates for Multiple Vulnerabilities</title>
		<link>http://www.freednslookup.net/2012/04/11/ta12-101a-microsoft-updates-for-multiple-vulnerabilities/</link>
		<comments>http://www.freednslookup.net/2012/04/11/ta12-101a-microsoft-updates-for-multiple-vulnerabilities/#comments</comments>
		<pubDate>Wed, 11 Apr 2012 14:00:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[US-Cert]]></category>

		<guid isPermaLink="false">http://www.freednslookup.net/2012/04/11/ta12-101a-microsoft-updates-for-multiple-vulnerabilities/</guid>
		<description><![CDATA[Original release date: April 10, 2012 &#124; Last revised: &#8211; Systems Affected Microsoft Windows Microsoft Internet Explorer Microsoft .NET Framework Microsoft Office Microsoft Server Software Microsoft SQL Server Microsoft Developer Tools Microsoft Forefront United Access Gateway Overview There are multiple vulnerabilities in Microsoft Windows, Internet Explorer, Microsoft .NET Framework, Microsoft Office, Microsoft Server Software, Microsoft [...]]]></description>
			<content:encoded><![CDATA[<p>Original release date: April 10, 2012 | Last revised: &#8211;</p>
<p><a name="affected"></a></p>
<h3>Systems Affected</h3>
<ul>
<li>Microsoft Windows</li>
<li>Microsoft Internet Explorer</li>
<li>Microsoft .NET Framework</li>
<li>Microsoft Office</li>
<li>Microsoft Server Software</li>
<li>Microsoft SQL Server</li>
<li>Microsoft Developer Tools</li>
<li>Microsoft Forefront United Access Gateway</li>
</ul>
<p><a name="overview"></a></p>
<h3>Overview</h3>
<p>There are multiple vulnerabilities in Microsoft Windows, Internet Explorer, Microsoft .NET Framework, Microsoft Office, Microsoft Server Software, Microsoft SQL Server, Microsoft Developer Tools, and Microsoft Forefront United Access Gateway.  Microsoft has released updates to address these vulnerabilities.</p>
<p><a name="description"></a></p>
<h3>Description</h3>
<p>The <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-apr">Microsoft Security Bulletin Summary for April 2012</a> describes multiple vulnerabilities in Microsoft software. Microsoft has released updates to address the vulnerabilities.</p>
<p><a name="impact"></a></p>
<h3>Impact</h3>
<p>A remote, unauthenticated attacker could execute arbitrary code, cause a denial of service, or gain unauthorized access to your files or system.</p>
<p><a name="solution"></a></p>
<h3>Solution</h3>
<p><strong>Apply updates</strong></p>
<p>Microsoft has provided updates for these vulnerabilities in the <a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-apr">Microsoft Security Bulletin Summary for April 2012</a>, which describes any known issues related to the updates. Administrators are encouraged to note these issues and test for any potentially adverse effects. In addition, administrators should consider using an automated update distribution system such as <a href="http://technet.microsoft.com/en-us/wsus/default.aspx">Windows Server Update Services</a> (WSUS). Home users are encouraged to enable <a href="http://windows.microsoft.com/en-us/windows-vista/Turn-automatic-updating-on-or-off">automatic updates</a>.</p>
<p><a name="references"></a></p>
<h3>References</h3>
<ul>
<li>Microsoft Security Bulletin Summary for April 2012 &#8211; &lt;<a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-apr">http://technet.microsoft.com/en-us/security/bulletin/ms12-apr</a>&gt;</li>
<li>Microsoft Windows Server Update Services &#8211; &lt;<a href="http://technet.microsoft.com/en-us/wsus/default.aspx">http://technet.microsoft.com/en-us/wsus/default.aspx</a>&gt;</li>
<li>Microsoft Update &#8211; &lt;<a href="https://www.update.microsoft.com/">https://www.update.microsoft.com/</a>&gt;</li>
<li>Microsoft Update Overview &#8211; &lt;<a href="http://www.microsoft.com/security/updates/mu.aspx">http://www.microsoft.com/security/updates/mu.aspx</a>&gt;</li>
<li>Turn Automatic Updating On or Off &#8211; &lt;<a href="http://windows.microsoft.com/en-us/windows-vista/Turn-automatic-updating-on-or-off">http://windows.microsoft.com/en-us/windows-vista/Turn-automatic-updating-on-or-off</a>&gt;</li>
</ul>
<p><a name="revisions"></a></p>
<h3>Revision History</h3>
<ul>
<li>April 10, 2012: Initial release</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.freednslookup.net/2012/04/11/ta12-101a-microsoft-updates-for-multiple-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SB12-093: Vulnerability Summary for the Week of March 26, 2012</title>
		<link>http://www.freednslookup.net/2012/04/02/sb12-093-vulnerability-summary-for-the-week-of-march-26-2012/</link>
		<comments>http://www.freednslookup.net/2012/04/02/sb12-093-vulnerability-summary-for-the-week-of-march-26-2012/#comments</comments>
		<pubDate>Mon, 02 Apr 2012 22:00:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[US-Cert]]></category>

		<guid isPermaLink="false">http://www.freednslookup.net/2012/04/02/sb12-093-vulnerability-summary-for-the-week-of-march-26-2012/</guid>
		<description><![CDATA[The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cyber Security Division (NCSD) / United States Computer Emergency Readiness Team [...]]]></description>
			<content:encoded><![CDATA[<p><a name="top"></a></p>
<table align="center">
<tr>
<td>
<p>The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cyber Security Division (NCSD) / United States Computer Emergency Readiness Team (US-CERT). For updated or updated entries, please visit the <a href="http://nvd.nist.gov" target="_blank">NVD</a>, which contains historical vulnerability information.</p>
<p>The vulnerabilities are based on the <a href="http://cve.mitre.org/" target="_blank">CVE</a> vulnerability naming standard and are organized according to severity, determined by the <a href="http://nvd.nist.gov/cvss.cfm" target="_blank">Common Vulnerability Scoring System</a> (CVSS) standard. The division of high, medium, and low severities correspond to the following scores:</p>
<ul>
<li>
<p><strong>High</strong> &#8211; Vulnerabilities will be labeled High severity if they have a CVSS base score of 7.0 &#8211; 10.0</p>
</li>
<li>
<p><strong>Medium</strong> &#8211; Vulnerabilities will be labeled Medium severity if they have a CVSS base score of 4.0 &#8211; 6.9</p>
</li>
<li>
<p><strong>Low</strong> &#8211; Vulnerabilities will be labeled Low severity if they have a CVSS base score of 0.0 &#8211; 3.9</p>
</li>
</ul>
<p>Entries may include additional information provided by organizations and efforts sponsored by US-CERT. This information may include identifying informaton, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletins is compiled from external, open source reports and is not a direct result of US-CERT analysis.</p>
</td>
</tr>
</table>
<p>
<a name="high"></a></p>
<div>
<table align="center" border="1" summary="High Vulnerabilities">
<thead>
<tr>
<th colspan="5">High Vulnerabilities</th>
</tr>
<tr>
<th>Primary<br />
Vendor &#8212; Product</th>
<th>Description</th>
<th>Published</th>
<th>CVSS Score</th>
<th>Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td>adobe &#8212; adobe_air</td>
<td>An unspecified ActiveX control in Adobe Flash Player before 10.3.183.18 and 11.x before 11.2.202.228, and AIR before 3.2.0.2070, on Windows does not properly perform URL security domain checking, which allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors.</td>
<td>2012-03-28</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0772&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0772" target="_blank">CVE-2012-0772</a></td>
</tr>
<tr>
<td>adobe &#8212; adobe_air</td>
<td>The NetStream class in Adobe Flash Player before 10.3.183.18 and 11.x before 11.2.202.228 on Windows, Mac OS X, and Linux; Flash Player before 10.3.183.18 and 11.x before 11.2.202.223 on Solaris; Flash Player before 11.1.111.8 on Android 2.x and 3.x; and AIR before 3.2.0.2070 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.</td>
<td>2012-03-28</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0773&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0773" target="_blank">CVE-2012-0773</a></td>
</tr>
<tr>
<td>atmail &#8212; atmail_open</td>
<td>@Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to execute arbitrary code via an e-mail attachment with an executable extension, leading to the creation of an executable file under tmp/.</td>
<td>2012-03-27</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1916&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1916" target="_blank">CVE-2012-1916</a></td>
</tr>
<tr>
<td>cisco &#8212; ios</td>
<td>The IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.2.xSG before 3.2.2SG allows remote attackers to cause a denial of service (device reload) by sending IKE UDP packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCts38429.</td>
<td>2012-03-29</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0381&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">7.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0381" target="_blank">CVE-2012-0381</a></td>
</tr>
<tr>
<td>cisco &#8212; ios</td>
<td>The Multicast Source Discovery Protocol (MSDP) implementation in Cisco IOS 12.0, 12.2 through 12.4, and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.1S and 3.1.xSG and 3.2.xSG before 3.2.2SG allows remote attackers to cause a denial of service (device reload) via encapsulated IGMP data in an MSDP packet, aka Bug ID CSCtr28857.</td>
<td>2012-03-29</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0382&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:C)" target="_blank">7.1</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0382" target="_blank">CVE-2012-0382</a></td>
</tr>
<tr>
<td>cisco &#8212; ios</td>
<td>Memory leak in the NAT feature in Cisco IOS 12.4, 15.0, and 15.1 allows remote attackers to cause a denial of service (memory consumption, and device hang or reload) via SIP packets that require translation, related to a &quot;memory starvation vulnerability,&quot; aka Bug ID CSCti35326.</td>
<td>2012-03-29</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0383&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">7.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0383" target="_blank">CVE-2012-0383</a></td>
</tr>
<tr>
<td>cisco &#8212; ios</td>
<td>Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS before 3.1.2S, 3.2.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.1.xSG and 3.2.xSG before 3.2.2SG, when AAA authorization is enabled, allow remote authenticated users to bypass intended access restrictions and execute commands via a (1) HTTP or (2) HTTPS session, aka Bug ID CSCtr91106.</td>
<td>2012-03-29</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0384&amp;vector=(AV:N/AC:M/Au:S/C:C/I:C/A:C)" target="_blank">8.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0384" target="_blank">CVE-2012-0384</a></td>
</tr>
<tr>
<td>cisco &#8212; ios</td>
<td>The Smart Install feature in Cisco IOS 12.2, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (device reload) by sending a malformed Smart Install message over TCP, aka Bug ID CSCtt16051.</td>
<td>2012-03-29</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0385&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">7.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0385" target="_blank">CVE-2012-0385</a></td>
</tr>
<tr>
<td>cisco &#8212; ios</td>
<td>The SSHv2 implementation in Cisco IOS 12.2, 12.4, 15.0, 15.1, and 15.2 and IOS XE 2.3.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S allows remote attackers to cause a denial of service (device reload) via a crafted username in a reverse SSH login attempt, aka Bug ID CSCtr49064.</td>
<td>2012-03-29</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0386&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">7.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0386" target="_blank">CVE-2012-0386</a></td>
</tr>
<tr>
<td>cisco &#8212; ios</td>
<td>Memory leak in the HTTP Inspection Engine feature in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted transit HTTP traffic, aka Bug ID CSCtq36153.</td>
<td>2012-03-29</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0387&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">7.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0387" target="_blank">CVE-2012-0387</a></td>
</tr>
<tr>
<td>cisco &#8212; ios</td>
<td>Memory leak in the H.323 inspection feature in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via malformed transit H.323 traffic, aka Bug ID CSCtq45553.</td>
<td>2012-03-29</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0388&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">7.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0388" target="_blank">CVE-2012-0388</a></td>
</tr>
<tr>
<td>cisco &#8212; ios</td>
<td>Memory leak in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted IP packets, aka Bug ID CSCto89536.</td>
<td>2012-03-29</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1310&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">7.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1310" target="_blank">CVE-2012-1310</a></td>
</tr>
<tr>
<td>cisco &#8212; ios</td>
<td>The RSVP feature in Cisco IOS 15.0 and 15.1 and IOS XE 3.2.xS through 3.4.xS before 3.4.2S, when a VRF interface is configured, allows remote attackers to cause a denial of service (interface queue wedge and service outage) via crafted RSVP packets, aka Bug ID CSCts80643.</td>
<td>2012-03-29</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1311&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">7.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1311" target="_blank">CVE-2012-1311</a></td>
</tr>
<tr>
<td>cisco &#8212; ios</td>
<td>The MACE feature in Cisco IOS 15.1 and 15.2 allows remote attackers to cause a denial of service (device reload) via crafted transit traffic, aka Bug IDs CSCtq64987 and CSCtu57226.</td>
<td>2012-03-29</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1312&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:C)" target="_blank">7.1</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1312" target="_blank">CVE-2012-1312</a></td>
</tr>
<tr>
<td>cisco &#8212; ios</td>
<td>The WAAS Express feature in Cisco IOS 15.1 and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted transit traffic, aka Bug ID CSCtt45381.</td>
<td>2012-03-29</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1314&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">7.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1314" target="_blank">CVE-2012-1314</a></td>
</tr>
<tr>
<td>cisco &#8212; ios</td>
<td>Memory leak in the SIP inspection feature in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted transit SIP traffic, aka Bug ID CSCti46171.</td>
<td>2012-03-29</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1315&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">7.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1315" target="_blank">CVE-2012-1315</a></td>
</tr>
</tbody>
</table>
<p>
</div>
<p><a name="medium"></a></p>
<div>
<table align="center" border="1" summary="Medium Vulnerabilities">
<thead>
<tr>
<th colspan="5">Medium Vulnerabilities</th>
</tr>
<tr>
<th>Primary<br />
Vendor &#8212; Product</th>
<th>Description</th>
<th>Published</th>
<th>CVSS Score</th>
<th>Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td width="20%">apache &#8212; wicket</td>
<td>Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the wicket:pageMapName parameter.</td>
<td>2012-03-23</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0047&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0047" target="_blank">CVE-2012-0047</a></td>
</tr>
<tr>
<td width="20%">apache &#8212; traffic_server</td>
<td>Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate heap memory, which allows remote attackers to cause a denial of service (daemon crash) via a long HTTP Host header.</td>
<td>2012-03-26</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0256&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0256" target="_blank">CVE-2012-0256</a></td>
</tr>
<tr>
<td width="20%">apache &#8212; wicket</td>
<td>Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-application files via a relative pathname in a URL for a Wicket resource that corresponds to a null package.</td>
<td>2012-03-23</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1089&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1089" target="_blank">CVE-2012-1089</a></td>
</tr>
<tr>
<td width="20%">atmail &#8212; atmail_open</td>
<td>compose.php in @Mail WebMail Client in AtMail Open-Source before 1.05 does not properly handle ../ (dot dot slash) sequences in the unique parameter, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a &#8230;/./ (dot dot dot slash dot slash) sequence.</td>
<td>2012-03-27</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1917&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1917" target="_blank">CVE-2012-1917</a></td>
</tr>
<tr>
<td width="20%">atmail &#8212; atmail_open</td>
<td>Multiple directory traversal vulnerabilities in (1) compose.php and (2) libs/Atmail/SendMsg.php in @Mail WebMail Client in AtMail Open-Source before 1.05 allow remote attackers to read arbitrary files via a .. (dot dot) in the Attachment[] parameter.</td>
<td>2012-03-27</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1918&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1918" target="_blank">CVE-2012-1918</a></td>
</tr>
<tr>
<td width="20%">atmail &#8212; atmail_open</td>
<td>CRLF injection vulnerability in mime.php in @Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to conduct directory traversal attacks and read arbitrary files via a %0A sequence followed by a .. (dot dot) in the file parameter.</td>
<td>2012-03-27</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1919&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:N)" target="_blank">6.4</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1919" target="_blank">CVE-2012-1919</a></td>
</tr>
<tr>
<td width="20%">atmail &#8212; atmail_open</td>
<td>@Mail WebMail Client in AtMail Open-Source 1.04 and earlier allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function.</td>
<td>2012-03-27</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1920&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1920" target="_blank">CVE-2012-1920</a></td>
</tr>
<tr>
<td width="20%">drupal &#8212; drupal</td>
<td>** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that end a session via the user/logout URI. NOTE: the vendor disputes the significance of this issue, by considering the &quot;security benefit against platform complexity and performance impact&quot; and concluding that a change to the logout behavior is not planned because &quot;for most sites it is not worth the trade-off.&quot;</td>
<td>2012-03-28</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2007-6752&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6752" target="_blank">CVE-2007-6752</a></td>
</tr>
<tr>
<td width="20%">gnu &#8212; gnutls</td>
<td>The asn1_get_length_der function in decoding.c in GNU Libtasn1 before 2.12, as used in GnuTLS before 3.0.16 and other products, does not properly handle certain large length values, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly have unspecified other impact via a crafted ASN.1 structure.</td>
<td>2012-03-26</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1569&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1569" target="_blank">CVE-2012-1569</a></td>
</tr>
<tr>
<td width="20%">gnu &#8212; gnutls</td>
<td>gnutls_cipher.c in libgnutls in GnuTLS before 2.12.17 and 3.x before 3.0.15 does not properly handle data encrypted with a block cipher, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) via a crafted record, as demonstrated by a crafted GenericBlockCipher structure.</td>
<td>2012-03-26</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1573&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1573" target="_blank">CVE-2012-1573</a></td>
</tr>
<tr>
<td width="20%">google &#8212; chrome</td>
<td>Google Chrome before 17.0.963.83 does not properly restrict the extension web request API, which allows remote attackers to cause a denial of service (disrupted system requests) via a crafted extension.</td>
<td>2012-03-23</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3049&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3049" target="_blank">CVE-2011-3049</a></td>
</tr>
<tr>
<td width="20%">hp &#8212; hp-ux</td>
<td>Unspecified vulnerability in the WBEM implementation in HP HP-UX 11.11 and 11.23 allows remote attackers to obtain access to diagnostic information via unknown vectors, a related issue to CVE-2012-0125.</td>
<td>2012-03-28</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0126&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:N)" target="_blank">5.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0126" target="_blank">CVE-2012-0126</a></td>
</tr>
<tr>
<td width="20%">maradns &#8212; maradns</td>
<td>The resolver in MaraDNS before 1.3.0.7.15 and 1.4.x before 1.4.12 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a &quot;ghost domain names&quot; attack.</td>
<td>2012-03-28</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1570&amp;vector=(AV:N/AC:L/Au:N/C:N/I:P/A:P)" target="_blank">6.4</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1570" target="_blank">CVE-2012-1570</a></td>
</tr>
<tr>
<td width="20%">microsoft &#8212; windows_2000</td>
<td>Untrusted search path vulnerability in Shell32.dll in Microsoft Windows 2000, Windows XP, Windows Vista, Windows Server 2008, and Windows 7, when using an environment configured with a string such as %APPDATA% or %PROGRAMFILES% in a certain way, allows local users to gain privileges via a Trojan horse DLL under the current working directory, as demonstrated by iTunes and Safari.</td>
<td>2012-03-28</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2007-6753&amp;vector=(AV:L/AC:H/Au:N/C:C/I:C/A:C)" target="_blank">6.2</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6753" target="_blank">CVE-2007-6753</a></td>
</tr>
<tr>
<td width="20%">opera &#8212; opera</td>
<td>Opera before 11.62 allows user-assisted remote attackers to trick users into downloading and executing arbitrary files via a small window for the download dialog.</td>
<td>2012-03-27</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1924&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1924" target="_blank">CVE-2012-1924</a></td>
</tr>
<tr>
<td width="20%">opera &#8212; opera</td>
<td>Opera before 11.62 does not ensure that a dialog window is placed on top of content windows, which makes it easier for user-assisted remote attackers to trick users into downloading and executing arbitrary files via a download dialog located under other windows.</td>
<td>2012-03-27</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1925&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1925" target="_blank">CVE-2012-1925</a></td>
</tr>
<tr>
<td width="20%">opera &#8212; opera</td>
<td>Opera before 11.62 allows remote attackers to bypass the Same Origin Policy via the (1) history.pushState and (2) history.replaceState functions in conjunction with cross-domain frames, leading to unintended read access to history.state information.</td>
<td>2012-03-27</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1926&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1926" target="_blank">CVE-2012-1926</a></td>
</tr>
<tr>
<td width="20%">opera &#8212; opera</td>
<td>Opera before 11.62 allows remote attackers to spoof the address field by triggering the launch of a dialog window associated with a different domain.</td>
<td>2012-03-27</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1927&amp;vector=(AV:N/AC:L/Au:N/C:N/I:P/A:P)" target="_blank">6.4</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1927" target="_blank">CVE-2012-1927</a></td>
</tr>
<tr>
<td width="20%">opera &#8212; opera</td>
<td>Opera before 11.62 allows remote attackers to spoof the address field by triggering a page reload followed by a redirect to a different domain.</td>
<td>2012-03-27</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1928&amp;vector=(AV:N/AC:L/Au:N/C:N/I:P/A:P)" target="_blank">6.4</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1928" target="_blank">CVE-2012-1928</a></td>
</tr>
<tr>
<td width="20%">opera &#8212; opera</td>
<td>Opera before 11.62 on Mac OS X allows remote attackers to spoof the address field and security dialogs via crafted styling that causes page content to be displayed outside of the intended content area.</td>
<td>2012-03-27</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1929&amp;vector=(AV:N/AC:L/Au:N/C:N/I:P/A:P)" target="_blank">6.4</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1929" target="_blank">CVE-2012-1929</a></td>
</tr>
<tr>
<td width="20%">opera &#8212; opera</td>
<td>Opera before 11.62 on UNIX uses world-readable permissions for temporary files during printing, which allows local users to obtain sensitive information by reading these files.</td>
<td>2012-03-27</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1930&amp;vector=(AV:L/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">4.6</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1930" target="_blank">CVE-2012-1930</a></td>
</tr>
<tr>
<td width="20%">opera &#8212; opera</td>
<td>Opera before 11.62 on UNIX, when used in conjunction with an unspecified printing application, allows local users to overwrite arbitrary files via a symlink attack on a temporary file during printing.</td>
<td>2012-03-27</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1931&amp;vector=(AV:L/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">4.6</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1931" target="_blank">CVE-2012-1931</a></td>
</tr>
<tr>
<td width="20%">privawall &#8212; privawall_antivirus</td>
<td>The scanner engine in PrivaWall Antivirus 5.6 and earlier does not recognize the Office XML (aka Open Document XML) file format, which allows remote attackers to bypass malware detection via a crafted file embedded in a WordML document.</td>
<td>2012-03-28</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1907&amp;vector=(AV:N/AC:L/Au:N/C:N/I:P/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1907" target="_blank">CVE-2012-1907</a></td>
</tr>
<tr>
<td width="20%">realnetworks &#8212; realplayer</td>
<td>mp4fformat.dll in the QuickTime File Format plugin in RealNetworks RealPlayer 15 and earlier, and RealPlayer SP 1.1.4 Build 12.0.0.756 and earlier, allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted MP4 file.</td>
<td>2012-03-28</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1904&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1904" target="_blank">CVE-2012-1904</a></td>
</tr>
</tbody>
</table>
<p>
</div>
<p><a name="low"></a></p>
<div>
<table align="center" border="1" summary="Low Vulnerabilities">
<thead>
<tr>
<th colspan="5">Low Vulnerabilities</th>
</tr>
<tr>
<th>Primary<br />
Vendor &#8212; Product</th>
<th>Description</th>
<th>Published</th>
<th>CVSS Score</th>
<th>Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td width="20%">hp &#8212; hp-ux</td>
<td>Unspecified vulnerability in the WBEM implementation in HP HP-UX 11.31 allows local users to obtain access to diagnostic information via unknown vectors, a related issue to CVE-2012-0126.</td>
<td>2012-03-28</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0125&amp;vector=(AV:L/AC:M/Au:N/C:P/I:P/A:N)" target="_blank">3.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0125" target="_blank">CVE-2012-0125</a></td>
</tr>
</tbody>
</table>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.freednslookup.net/2012/04/02/sb12-093-vulnerability-summary-for-the-week-of-march-26-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SB12-086: Vulnerability Summary for the Week of March 19, 2012</title>
		<link>http://www.freednslookup.net/2012/03/27/sb12-086-vulnerability-summary-for-the-week-of-march-19-2012/</link>
		<comments>http://www.freednslookup.net/2012/03/27/sb12-086-vulnerability-summary-for-the-week-of-march-19-2012/#comments</comments>
		<pubDate>Tue, 27 Mar 2012 17:00:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[US-Cert]]></category>

		<guid isPermaLink="false">http://www.freednslookup.net/2012/03/27/sb12-086-vulnerability-summary-for-the-week-of-march-19-2012/</guid>
		<description><![CDATA[The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cyber Security Division (NCSD) / United States Computer Emergency Readiness Team [...]]]></description>
			<content:encoded><![CDATA[<p><a name="top"></a></p>
<table align="center">
<tr>
<td>
<p>The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cyber Security Division (NCSD) / United States Computer Emergency Readiness Team (US-CERT). For updated or updated entries, please visit the <a href="http://nvd.nist.gov" target="_blank">NVD</a>, which contains historical vulnerability information.</p>
<p>The vulnerabilities are based on the <a href="http://cve.mitre.org/" target="_blank">CVE</a> vulnerability naming standard and are organized according to severity, determined by the <a href="http://nvd.nist.gov/cvss.cfm" target="_blank">Common Vulnerability Scoring System</a> (CVSS) standard. The division of high, medium, and low severities correspond to the following scores:</p>
<ul>
<li>
<p><strong>High</strong> &#8211; Vulnerabilities will be labeled High severity if they have a CVSS base score of 7.0 &#8211; 10.0</p>
</li>
<li>
<p><strong>Medium</strong> &#8211; Vulnerabilities will be labeled Medium severity if they have a CVSS base score of 4.0 &#8211; 6.9</p>
</li>
<li>
<p><strong>Low</strong> &#8211; Vulnerabilities will be labeled Low severity if they have a CVSS base score of 0.0 &#8211; 3.9</p>
</li>
</ul>
<p>Entries may include additional information provided by organizations and efforts sponsored by US-CERT. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletins is compiled from external, open source reports and is not a direct result of US-CERT analysis.</p>
</td>
</tr>
</table>
<p>
<a name="high"></a></p>
<div>
<table align="center" border="1" summary="High Vulnerabilities">
<thead>
<tr>
<th colspan="5">High Vulnerabilities</th>
</tr>
<tr>
<th>Primary<br />
Vendor &#8212; Product</th>
<th>Description</th>
<th>Published</th>
<th>CVSS Score</th>
<th>Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td>ajaxplorer &#8212; ajaxplorer</td>
<td>Multiple directory traversal vulnerabilities in the Get Template feature in plugins/gui.ajax/class.AJXP_ClientDriver.php in AjaXplorer 3.2.x before 3.2.5 and 4.0.x before 4.0.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) pluginName or (2) pluginPath parameter in a get_template action. NOTE: some of these details are obtained from third party information.</td>
<td>2012-03-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1839&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1839" target="_blank">CVE-2012-1839</a></td>
</tr>
<tr>
<td>ajaxplorer &#8212; ajaxplorer</td>
<td>AjaXplorer 3.2.x before 3.2.5 and 4.0.x before 4.0.4 does not properly perform cookie authentication, which allows remote attackers to obtain login access by leveraging knowledge of a password hash.</td>
<td>2012-03-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1840&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1840" target="_blank">CVE-2012-1840</a></td>
</tr>
<tr>
<td>createvision &#8212; createvision_cms</td>
<td>SQL injection vulnerability in artykul_print.php in CreateVision CMS allows remote attackers to execute arbitrary SQL commands via the id parameter.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1778&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1778" target="_blank">CVE-2012-1778</a></td>
</tr>
<tr>
<td>dell &#8212; powervault_ml6000_firmware</td>
<td>The Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100) and the IBM TS3310 tape library with firmware before R6C (606G.GS001), uses default passwords for unspecified user accounts, which makes it easier for remote attackers to obtain access via unknown vectors.</td>
<td>2012-03-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1844&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1844" target="_blank">CVE-2012-1844</a></td>
</tr>
<tr>
<td>dotclear &#8212; dotclear</td>
<td>Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary code by uploading a file with an executable PHP extension, then accessing it via a direct request to the file in an unspecified directory.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-5083&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-5083" target="_blank">CVE-2011-5083</a></td>
</tr>
<tr>
<td>gomlab &#8212; gom_media_player</td>
<td>Unspecified vulnerability in Gretech GOM Media Player before 2.1.37.5091 allows remote attackers to execute arbitrary code via a crafted AVI file.</td>
<td>2012-03-17</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1264&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1264" target="_blank">CVE-2012-1264</a></td>
</tr>
<tr>
<td>gomlab &#8212; gom_media_player</td>
<td>Unspecified vulnerability in the Open URL feature in Gretech GOM Media Player before 2.1.39.5101 has unknown impact and attack vectors, a different vulnerability than CVE-2007-5779 and CVE-2012-1264.</td>
<td>2012-03-17</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1774&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1774" target="_blank">CVE-2012-1774</a></td>
</tr>
<tr>
<td>google &#8212; chrome</td>
<td>Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 17.0.963.83 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the :first-letter pseudo-element.</td>
<td>2012-03-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3050&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3050" target="_blank">CVE-2011-3050</a></td>
</tr>
<tr>
<td>google &#8212; chrome</td>
<td>Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 17.0.963.83 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the cross-fade function.</td>
<td>2012-03-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3051&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3051" target="_blank">CVE-2011-3051</a></td>
</tr>
<tr>
<td>google &#8212; chrome</td>
<td>The WebGL implementation in Google Chrome before 17.0.963.83 does not properly handle CANVAS elements, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.</td>
<td>2012-03-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3052&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3052" target="_blank">CVE-2011-3052</a></td>
</tr>
<tr>
<td>google &#8212; chrome</td>
<td>Use-after-free vulnerability in Google Chrome before 17.0.963.83 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to block splitting.</td>
<td>2012-03-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3053&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3053" target="_blank">CVE-2011-3053</a></td>
</tr>
<tr>
<td>google &#8212; chrome</td>
<td>Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vectors involving a &quot;magic iframe.&quot;</td>
<td>2012-03-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3056&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3056" target="_blank">CVE-2011-3056</a></td>
</tr>
<tr>
<td>google &#8212; chrome</td>
<td>Use-after-free vulnerability in Google Chrome 17.0.963.66 and earlier allows remote attackers to bypass the DEP and ASLR protection mechanisms, and execute arbitrary code, via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012. NOTE: the primary affected product may be clarified later; it was not identified by the researcher, who reportedly stated &quot;it really doesn&#039;t matter if it&#039;s third-party code.&quot;</td>
<td>2012-03-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1845&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1845" target="_blank">CVE-2012-1845</a></td>
</tr>
<tr>
<td>google &#8212; chrome</td>
<td>Google Chrome 17.0.963.66 and earlier allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a sandboxed process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012. NOTE: the primary affected product may be clarified later; it was not identified by the researcher, who reportedly stated &quot;it really doesn&#039;t matter if it&#039;s third-party code.&quot;</td>
<td>2012-03-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1846&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1846" target="_blank">CVE-2012-1846</a></td>
</tr>
<tr>
<td>ibm &#8212; db2</td>
<td>Integer signedness error in the db2dasrrm process in the DB2 Administration Server (DAS) in IBM DB2 9.1 through FP11, 9.5 before FP9, and 9.7 through FP5 on UNIX platforms allows remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow.</td>
<td>2012-03-20</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0711&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0711" target="_blank">CVE-2012-0711</a></td>
</tr>
<tr>
<td>ibm &#8212; db2</td>
<td>Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM DB2 9.5 before FP9 on UNIX, allows local users to gain privileges via unknown vectors.</td>
<td>2012-03-20</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1796&amp;vector=(AV:L/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">7.2</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1796" target="_blank">CVE-2012-1796</a></td>
</tr>
<tr>
<td>ibm &#8212; db2</td>
<td>IBM DB2 9.5 uses world-writable permissions for nodes.reg, which has unspecified impact and attack vectors.</td>
<td>2012-03-20</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1797&amp;vector=(AV:N/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">10.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1797" target="_blank">CVE-2012-1797</a></td>
</tr>
<tr>
<td>inspire_ircd &#8212; inspircd</td>
<td>Heap-based buffer overflow in dns.cpp in InspIRCd 2.0.5 might allow remote attackers to execute arbitrary code via a crafted DNS query that uses compression.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1836&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1836" target="_blank">CVE-2012-1836</a></td>
</tr>
<tr>
<td>kylegilman &#8212; video_embed_&amp;_thumbnail_generator</td>
<td>kg_callffmpeg.php in the Video Embed &amp; Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to execute arbitrary commands via unspecified vectors.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1785&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1785" target="_blank">CVE-2012-1785</a></td>
</tr>
<tr>
<td>myjoblist &#8212; myjoblist</td>
<td>SQL injection vulnerability in MyJobList 0.1.3 allows remote attackers to execute arbitrary SQL commands via the eid parameter in a profile action to index.php.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1784&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1784" target="_blank">CVE-2012-1784</a></td>
</tr>
<tr>
<td>netmechanica &#8212; netdecision</td>
<td>The Traffic Grapher Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the source code of NtDecision script files with a .nd extension via an invalid version number in an HTTP request, as demonstrated using default.nd. NOTE: some of these details are obtained from third party information.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1466&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">7.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1466" target="_blank">CVE-2012-1466</a></td>
</tr>
<tr>
<td>rsa &#8212; envision</td>
<td>EMC RSA enVision 4.x before 4.1 Patch 4 does not properly restrict the number of failed authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.</td>
<td>2012-03-20</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0400&amp;vector=(AV:A/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">7.9</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0400" target="_blank">CVE-2012-0400</a></td>
</tr>
<tr>
<td>rsa &#8212; envision</td>
<td>EMC RSA enVision 4.x before 4.1 Patch 4 uses unspecified hardcoded credentials, which makes it easier for remote attackers to obtain access via unknown vectors.</td>
<td>2012-03-20</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0402&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0402" target="_blank">CVE-2012-0402</a></td>
</tr>
<tr>
<td>saurabh_gupta &#8212; tiny_server</td>
<td>Tiny Server 1.1.9 and earlier allows remote attackers to cause a denial of service (crash) via a long string in a GET request without an HTTP version number.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1783&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:C)" target="_blank">7.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1783" target="_blank">CVE-2012-1783</a></td>
</tr>
<tr>
<td>socialcms &#8212; socialcms</td>
<td>SQL injection vulnerability in search.php in SocialCMS 1.0.5 allows remote attackers to execute arbitrary SQL commands via the category parameter.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1780&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1780" target="_blank">CVE-2012-1780</a></td>
</tr>
<tr>
<td>videolan &#8212; vlc_media_player</td>
<td>Stack-based buffer overflow in VideoLAN VLC media player before 2.0.1 allows remote attackers to execute arbitrary code via a crafted MMS:// stream.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1775&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1775" target="_blank">CVE-2012-1775</a></td>
</tr>
<tr>
<td>videolan &#8212; vlc_media_player</td>
<td>Multiple heap-based buffer overflows in VideoLAN VLC media player before 2.0.1 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Real RTSP stream.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1776&amp;vector=(AV:N/AC:M/Au:N/C:C/I:C/A:C)" target="_blank">9.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1776" target="_blank">CVE-2012-1776</a></td>
</tr>
<tr>
<td>vmware &#8212; esx</td>
<td>The XPDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.</td>
<td>2012-03-16</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1508&amp;vector=(AV:L/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">7.2</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1508" target="_blank">CVE-2012-1508</a></td>
</tr>
<tr>
<td>vmware &#8212; view</td>
<td>Buffer overflow in the XPDM display driver in VMware View before 4.6.1 allows guest OS users to gain guest OS privileges via unspecified vectors.</td>
<td>2012-03-16</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1509&amp;vector=(AV:L/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">7.2</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1509" target="_blank">CVE-2012-1509</a></td>
</tr>
<tr>
<td>vmware &#8212; esx</td>
<td>Buffer overflow in the WDDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS privileges via unspecified vectors.</td>
<td>2012-03-16</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1510&amp;vector=(AV:L/AC:L/Au:N/C:C/I:C/A:C)" target="_blank">7.2</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1510" target="_blank">CVE-2012-1510</a></td>
</tr>
<tr>
<td>webglimpse &#8212; webglimpse</td>
<td>webglimpse.cgi in Webglimpse before 2.20.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter, as exploited in the wild in March 2012.</td>
<td>2012-03-20</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1795&amp;vector=(AV:N/AC:L/Au:N/C:P/I:P/A:P)" target="_blank">7.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1795" target="_blank">CVE-2012-1795</a></td>
</tr>
</tbody>
</table>
<p>
</div>
<p><a name="medium"></a></p>
<div>
<table align="center" border="1" summary="Medium Vulnerabilities">
<thead>
<tr>
<th colspan="5">Medium Vulnerabilities</th>
</tr>
<tr>
<th>Primary<br />
Vendor &#8212; Product</th>
<th>Description</th>
<th>Published</th>
<th>CVSS Score</th>
<th>Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td width="20%">ahnlab &#8212; v3_internet_security</td>
<td>The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \4a\46\49\46 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1433&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1433" target="_blank">CVE-2012-1433</a></td>
</tr>
<tr>
<td width="20%">ahnlab &#8212; v3_internet_security</td>
<td>The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \1940\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1434&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1434" target="_blank">CVE-2012-1434</a></td>
</tr>
<tr>
<td width="20%">ahnlab &#8212; v3_internet_security</td>
<td>The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \50\4B\4C\49\54\45 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1435&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1435" target="_blank">CVE-2012-1435</a></td>
</tr>
<tr>
<td width="20%">ahnlab &#8212; v3_internet_security</td>
<td>The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \2D\6C\68 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1436&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1436" target="_blank">CVE-2012-1436</a></td>
</tr>
<tr>
<td width="20%">ahnlab &#8212; v3_internet_security</td>
<td>The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools AntiVirus 7.0.3.5, F-Prot Antivirus 4.6.2.117, VirusBuster 13.6.151.0, Fortinet Antivirus 4.2.254.0, Antiy Labs AVL SDK 2.0.3.7, K7 AntiVirus 9.77.3565, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Jiangmin Antivirus 13.0.900, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Sophos Anti-Virus 4.61.0, NOD32 Antivirus 5795, Avira AntiVir 7.11.1.163, Norman Antivirus 6.06.12, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Panda Antivirus 10.0.2.7, McAfee Gateway (formerly Webwasher) 2010.1C, Trend Micro AntiVirus 9.120.0.1004, Comodo Antivirus 7424, Bitdefender 7.2, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, nProtect Anti-Virus 2011-01-17.01, AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, avast! Antivirus 4.8.1351.0 and 5.0.677.0, and VBA32 3.12.14.2 allows user-assisted remote attackers to bypass malware detection via a RAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different RAR parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1443&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1443" target="_blank">CVE-2012-1443</a></td>
</tr>
<tr>
<td width="20%">ahnlab &#8212; v3_internet_security</td>
<td>The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, Panda Antivirus 10.0.2.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field corresponding to that entire entry, plus part of the header of the next entry. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1459&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1459" target="_blank">CVE-2012-1459</a></td>
</tr>
<tr>
<td width="20%">ahnlab &#8212; v3_internet_security</td>
<td>The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, Norman Antivirus 6.06.12, Sophos Anti-Virus 4.61.0, and AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11 allows remote attackers to bypass malware detection via a ZIP file containing an invalid block of data at the beginning. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ZIP parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1462&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1462" target="_blank">CVE-2012-1462</a></td>
</tr>
<tr>
<td width="20%">ahnlab &#8212; v3_internet_security</td>
<td>The ELF file parser in AhnLab V3 Internet Security 2011.01.18.00, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a updated endianness field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1463&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1463" target="_blank">CVE-2012-1463</a></td>
</tr>
<tr>
<td width="20%">aladdin &#8212; esafe</td>
<td>The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, and nProtect Anti-Virus 2011-01-17.01 allows remote attackers to bypass malware detection via an ELF file with a ustar character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1429&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1429" target="_blank">CVE-2012-1429</a></td>
</tr>
<tr>
<td width="20%">aladdin &#8212; esafe</td>
<td>The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, nProtect Anti-Virus 2011-01-17.01, Sophos Anti-Virus 4.61.0, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via an ELF file with a \1940\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1430&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1430" target="_blank">CVE-2012-1430</a></td>
</tr>
<tr>
<td width="20%">aladdin &#8212; esafe</td>
<td>The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, McAfee Gateway (formerly Webwasher) 2010.1C, nProtect Anti-Virus 2011-01-17.01, Sophos Anti-Virus 4.61.0, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via an ELF file with a \4a\46\49\46 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1431&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1431" target="_blank">CVE-2012-1431</a></td>
</tr>
<tr>
<td width="20%">aladdin &#8212; esafe</td>
<td>The Microsoft EXE file parser in Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \57\69\6E\5A\69\70 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1432&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1432" target="_blank">CVE-2012-1432</a></td>
</tr>
<tr>
<td width="20%">aladdin &#8212; esafe</td>
<td>The ELF file parser in eSafe 7.0.17.0, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a updated padding field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1439&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1439" target="_blank">CVE-2012-1439</a></td>
</tr>
<tr>
<td width="20%">aladdin &#8212; esafe</td>
<td>The ELF file parser in Norman Antivirus 6.06.12, eSafe 7.0.17.0, CA eTrust Vet Antivirus 36.1.8511, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a updated identsize field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1440&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1440" target="_blank">CVE-2012-1440</a></td>
</tr>
<tr>
<td width="20%">aladdin &#8212; esafe</td>
<td>The Microsoft EXE file parser in eSafe 7.0.17.0 and Prevx 3.0 allows remote attackers to bypass malware detection via an EXE file with a updated value in any of several e_ fields. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1441&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1441" target="_blank">CVE-2012-1441</a></td>
</tr>
<tr>
<td width="20%">aladdin &#8212; esafe</td>
<td>The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, F-Secure Anti-Virus 9.0.16160.0, Sophos Anti-Virus 4.61.0, Antiy Labs AVL SDK 2.0.3.7, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a updated class field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1442&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1442" target="_blank">CVE-2012-1442</a></td>
</tr>
<tr>
<td width="20%">aladdin &#8212; esafe</td>
<td>The ELF file parser in eSafe 7.0.17.0, Prevx 3.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a updated abiversion field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1444&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1444" target="_blank">CVE-2012-1444</a></td>
</tr>
<tr>
<td width="20%">aladdin &#8212; esafe</td>
<td>The ELF file parser in eSafe 7.0.17.0, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a updated abi field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1445&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1445" target="_blank">CVE-2012-1445</a></td>
</tr>
<tr>
<td width="20%">aladdin &#8212; esafe</td>
<td>The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Norman Antivirus 6.06.12, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, McAfee Gateway (formerly Webwasher) 2010.1C, Sophos Anti-Virus 4.61.0, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a updated encoding field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1446&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1446" target="_blank">CVE-2012-1446</a></td>
</tr>
<tr>
<td width="20%">aladdin &#8212; esafe</td>
<td>The ELF file parser in Fortinet Antivirus 4.2.254.0, eSafe 7.0.17.0, Dr.Web 5.0.2.03300, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a updated e_version field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1447&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1447" target="_blank">CVE-2012-1447</a></td>
</tr>
<tr>
<td width="20%">aladdin &#8212; esafe</td>
<td>The ELF file parser in Dr.Web 5.0.2.03300, eSafe 7.0.17.0, McAfee Gateway (formerly Webwasher) 2010.1C, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a updated ei_version field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1454&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1454" target="_blank">CVE-2012-1454</a></td>
</tr>
<tr>
<td width="20%">aladdin &#8212; esafe</td>
<td>The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, and Trend Micro HouseCall 9.120.0.1004 allows remote attackers to bypass malware detection via a TAR file with an appended ZIP file. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1456&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1456" target="_blank">CVE-2012-1456</a></td>
</tr>
<tr>
<td width="20%">aladdin &#8212; esafe</td>
<td>The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field that exceeds the total TAR file size. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1457&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1457" target="_blank">CVE-2012-1457</a></td>
</tr>
<tr>
<td width="20%">aladdin &#8212; esafe</td>
<td>The Gzip file parser in Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, and VBA32 3.12.14.2 allows remote attackers to bypass malware detection via a .tar.gz file with stray bytes at the end. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different Gzip parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1460&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1460" target="_blank">CVE-2012-1460</a></td>
</tr>
<tr>
<td width="20%">alokin87 &#8212; webfoliocms1.0.2</td>
<td>Multiple cross-site request forgery (CSRF) vulnerabilities in Webfolio CMS 1.1.4 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator via an add action to admin/users/add or (2) modify a web page via a save action to admin/pages/edit/web_page_name.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1498&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1498" target="_blank">CVE-2012-1498</a></td>
</tr>
<tr>
<td width="20%">anti-virus &#8212; vba32</td>
<td>The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, and VBA32 3.12.14.2 allows remote attackers to bypass malware detection via a .tar.gz file with multiple compressed streams. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different Gzip parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1461&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1461" target="_blank">CVE-2012-1461</a></td>
</tr>
<tr>
<td width="20%">antiy &#8212; avl_sdk</td>
<td>The TAR file parser in Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Jiangmin Antivirus 13.0.900, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a POSIX TAR file with a \1940\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1424&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1424" target="_blank">CVE-2012-1424</a></td>
</tr>
<tr>
<td width="20%">antiy &#8212; avl_sdk</td>
<td>The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, and Trend Micro HouseCall 9.120.0.1004 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \50\4B34 character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1425&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1425" target="_blank">CVE-2012-1425</a></td>
</tr>
<tr>
<td width="20%">antiy &#8212; avl_sdk</td>
<td>The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Rising Antivirus 22.83.00.03, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via a CAB file with a updated coffFiles field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1453&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1453" target="_blank">CVE-2012-1453</a></td>
</tr>
<tr>
<td width="20%">apache &#8212; http_server</td>
<td>fcgid_spawn_ctl.c in the mod_fcgid module 2.3.6 for the Apache HTTP Server does not recognize the FcgidMaxProcessesPerClass directive for a virtual host, which makes it easier for remote attackers to cause a denial of service (memory consumption) via a series of HTTP requests that triggers a process count higher than the intended limit.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1181&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1181" target="_blank">CVE-2012-1181</a></td>
</tr>
<tr>
<td width="20%">authentium &#8212; command_antivirus</td>
<td>The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \7fELF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1420&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1420" target="_blank">CVE-2012-1420</a></td>
</tr>
<tr>
<td width="20%">authentium &#8212; command_antivirus</td>
<td>The TAR file parser in Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, K7 AntiVirus 9.77.3565, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1423&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1423" target="_blank">CVE-2012-1423</a></td>
</tr>
<tr>
<td width="20%">authentium &#8212; command_antivirus</td>
<td>The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, K7 AntiVirus 9.77.3565, Norman Antivirus 6.06.12, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \42\5A\68 character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1426&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1426" target="_blank">CVE-2012-1426</a></td>
</tr>
<tr>
<td width="20%">bitweaver &#8212; bitweaver</td>
<td>Directory traversal vulnerability in wiki/rankings.php in Bitweaver 2.7 and 2.8.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the style parameter.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2010-5086&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-5086" target="_blank">CVE-2010-5086</a></td>
</tr>
<tr>
<td width="20%">ca &#8212; arcserve_backup</td>
<td>CA ARCserve Backup r12.0 through SP2, r12.5 before SP2, r15 through SP1, and r16 before SP1 on Windows allows remote attackers to cause a denial of service (service shutdown) via a crafted network request.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1662&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1662" target="_blank">CVE-2012-1662</a></td>
</tr>
<tr>
<td width="20%">cat &#8212; quick_heal</td>
<td>The TAR file parser in ClamAV 0.96.4 and Quick Heal (aka Cat QuickHeal) 11.00 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial [aliases] character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1419&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1419" target="_blank">CVE-2012-1419</a></td>
</tr>
<tr>
<td width="20%">cat &#8212; quick_heal</td>
<td>The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Norman Antivirus 6.06.12, Rising Antivirus 22.83.00.03, and AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial MSCF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1421&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1421" target="_blank">CVE-2012-1421</a></td>
</tr>
<tr>
<td width="20%">cat &#8212; quick_heal</td>
<td>The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial ITSF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1422&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1422" target="_blank">CVE-2012-1422</a></td>
</tr>
<tr>
<td width="20%">cat &#8212; quick_heal</td>
<td>The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Norman Antivirus 6.06.12, and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a POSIX TAR file with a \57\69\6E\5A\69\70 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1427&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1427" target="_blank">CVE-2012-1427</a></td>
</tr>
<tr>
<td width="20%">cat &#8212; quick_heal</td>
<td>The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Norman Antivirus 6.06.12, and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a POSIX TAR file with a \4a\46\49\46 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1428&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1428" target="_blank">CVE-2012-1428</a></td>
</tr>
<tr>
<td width="20%">cat &#8212; quick_heal</td>
<td>The CAB file parser in Quick Heal (aka Cat QuickHeal) 11.00, Trend Micro AntiVirus 9.120.0.1004, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Trend Micro HouseCall 9.120.0.1004, and Emsisoft Anti-Malware 5.1.0.1 allows remote attackers to bypass malware detection via a CAB file with a updated cbCabinet field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1448&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1448" target="_blank">CVE-2012-1448</a></td>
</tr>
<tr>
<td width="20%">cat &#8212; quick_heal</td>
<td>The CAB file parser in Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Quick Heal (aka Cat QuickHeal) 11.00 allows remote attackers to bypass malware detection via a CAB file with a updated reserved1 field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1452&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1452" target="_blank">CVE-2012-1452</a></td>
</tr>
<tr>
<td width="20%">clamav &#8212; clamav</td>
<td>The Microsoft CHM file parser in ClamAV 0.96.4 and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a crafted reset interval in the LZXC header of a CHM file. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CHM parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1458&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1458" target="_blank">CVE-2012-1458</a></td>
</tr>
<tr>
<td width="20%">comodo &#8212; comodo_antivirus</td>
<td>The Microsoft Office file parser in Comodo Antivirus 7425 allows remote attackers to bypass malware detection via an Office file with a \50\4B\53\70\58 character sequence at a certain location.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1437&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1437" target="_blank">CVE-2012-1437</a></td>
</tr>
<tr>
<td width="20%">comodo &#8212; comodo_antivirus</td>
<td>The Microsoft Office file parser in Comodo Antivirus 7425 and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via an Office file with a ustar character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different Office parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1438&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1438" target="_blank">CVE-2012-1438</a></td>
</tr>
<tr>
<td width="20%">contao &#8212; contao_cms</td>
<td>Multiple cross-site request forgery (CSRF) vulnerabilities in main.php in Contao (formerly TYPOlight) 2.11.0 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) delete users via a delete action in the user module, (2) delete news via a delete action in the news module, or (3) delete newsletters via a delete action in the newsletters module.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1297&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1297" target="_blank">CVE-2012-1297</a></td>
</tr>
<tr>
<td width="20%">dell &#8212; powervault_ml6000_firmware</td>
<td>Absolute path traversal vulnerability in logShow.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100), allows remote attackers to read arbitrary files via a full pathname in the file parameter.</td>
<td>2012-03-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1841&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1841" target="_blank">CVE-2012-1841</a></td>
</tr>
<tr>
<td width="20%">dell &#8212; powervault_ml6000_firmware</td>
<td>Cross-site scripting (XSS) vulnerability in checkQKMProg.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</td>
<td>2012-03-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1842&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1842" target="_blank">CVE-2012-1842</a></td>
</tr>
<tr>
<td width="20%">dell &#8212; powervault_ml6000_firmware</td>
<td>Cross-site request forgery (CSRF) vulnerability in saveRestore.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100), allows remote attackers to hijack the authentication of users for requests that execute Linux commands via the fileName parameter, related to a &quot;command-injection vulnerability.&quot;</td>
<td>2012-03-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1843&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1843" target="_blank">CVE-2012-1843</a></td>
</tr>
<tr>
<td width="20%">dotclear &#8212; dotclear</td>
<td>Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) login_data parameter to admin/auth.php; (2) nb parameter to admin/blogs.php; (3) type, (4) sortby, (5) order, or (6) status parameters to admin/comments.php; or (7) page parameter to admin/plugin.php.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1039&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1039" target="_blank">CVE-2012-1039</a></td>
</tr>
<tr>
<td width="20%">emsisoft &#8212; anti-malware</td>
<td>The CAB file parser in Emsisoft Anti-Malware 5.1.0.1, Sophos Anti-Virus 4.61.0, and Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0 allows remote attackers to bypass malware detection via a CAB file with a updated reserved3 field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1450&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1450" target="_blank">CVE-2012-1450</a></td>
</tr>
<tr>
<td width="20%">emsisoft &#8212; anti-malware</td>
<td>The CAB file parser in Emsisoft Anti-Malware 5.1.0.1 and Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0 allows remote attackers to bypass malware detection via a CAB file with a updated reserved2 field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1451&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1451" target="_blank">CVE-2012-1451</a></td>
</tr>
<tr>
<td width="20%">eset &#8212; nod32_antivirus</td>
<td>The CAB file parser in NOD32 Antivirus 5795 and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a CAB file with a updated vMajor field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1449&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1449" target="_blank">CVE-2012-1449</a></td>
</tr>
<tr>
<td width="20%">eset &#8212; nod32_antivirus</td>
<td>The CAB file parser in NOD32 Antivirus 5795 and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a CAB file with a updated vMinor version field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1455&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1455" target="_blank">CVE-2012-1455</a></td>
</tr>
<tr>
<td width="20%">google &#8212; chrome</td>
<td>Integer signedness error in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.</td>
<td>2012-03-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3045&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3045" target="_blank">CVE-2011-3045</a></td>
</tr>
<tr>
<td width="20%">google &#8212; chrome</td>
<td>Google Chrome before 17.0.963.83 does not properly restrict the extension web request API, which allows remote attackers to cause a denial of service (disrupted system requests) via a crafted extension.</td>
<td>2012-03-23</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3049&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3049" target="_blank">CVE-2011-3049</a></td>
</tr>
<tr>
<td width="20%">google &#8212; chrome</td>
<td>The WebUI privilege implementation in Google Chrome before 17.0.963.83 does not properly perform isolation, which allows remote attackers to bypass intended access restrictions via unspecified vectors.</td>
<td>2012-03-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3054&amp;vector=(AV:N/AC:L/Au:N/C:N/I:P/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3054" target="_blank">CVE-2011-3054</a></td>
</tr>
<tr>
<td width="20%">google &#8212; chrome</td>
<td>The browser native UI in Google Chrome before 17.0.963.83 does not require user confirmation before an unpacked extension installation, which allows user-assisted remote attackers to have an unspecified impact via a crafted extension.</td>
<td>2012-03-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3055&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3055" target="_blank">CVE-2011-3055</a></td>
</tr>
<tr>
<td width="20%">google &#8212; chrome</td>
<td>Google V8, as used in Google Chrome before 17.0.963.83, allows remote attackers to cause a denial of service via vectors that trigger an invalid read operation.</td>
<td>2012-03-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-3057&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3057" target="_blank">CVE-2011-3057</a></td>
</tr>
<tr>
<td width="20%">ibm &#8212; db2</td>
<td>IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 does not properly check variables, which allows remote authenticated users to bypass intended restrictions on viewing table data by leveraging the CREATEIN privilege to execute crafted SQL CREATE VARIABLE statements.</td>
<td>2012-03-20</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0709&amp;vector=(AV:N/AC:L/Au:S/C:P/I:N/A:N)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0709" target="_blank">CVE-2012-0709</a></td>
</tr>
<tr>
<td width="20%">ibm &#8212; db2</td>
<td>IBM DB2 9.1 before FP11, 9.5 before FP9, 9.7 before FP5, and 9.8 before FP4 allows remote attackers to cause a denial of service (daemon crash) via a crafted Distributed Relational Database Architecture (DRDA) request.</td>
<td>2012-03-20</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0710&amp;vector=(AV:N/AC:L/Au:N/C:N/I:N/A:P)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0710" target="_blank">CVE-2012-0710</a></td>
</tr>
<tr>
<td width="20%">ibm &#8212; db2</td>
<td>The XML feature in IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 allows remote authenticated users to cause a denial of service (infinite loop) by calling the XMLPARSE function with a crafted string expression.</td>
<td>2012-03-20</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0712&amp;vector=(AV:N/AC:L/Au:S/C:N/I:N/A:P)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0712" target="_blank">CVE-2012-0712</a></td>
</tr>
<tr>
<td width="20%">ibm &#8212; tivoli_endpoint_manager</td>
<td>Cross-site scripting (XSS) vulnerability in IBM Tivoli Endpoint Manager (TEM) 8 before 8.2 patch 3 allows remote attackers to inject arbitrary web script or HTML via the ScheduleParam parameter to the webreports program.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0719&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0719" target="_blank">CVE-2012-0719</a></td>
</tr>
<tr>
<td width="20%">ibm &#8212; tivoli_endpoint_manager</td>
<td>The (1) webreports, (2) post/create-role, and (3) post/update-role programs in IBM Tivoli Endpoint Manager (TEM) before 8.2 do not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.</td>
<td>2012-03-21</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1837&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1837" target="_blank">CVE-2012-1837</a></td>
</tr>
<tr>
<td width="20%">idevspot &#8212; idev-businessdirectory</td>
<td>Cross-site scripting (XSS) vulnerability in IDevSpot idev-BusinessDirectory 3.0 allows remote attackers to inject arbitrary web script or HTML via the SEARCH parameter to index.php.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1779&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1779" target="_blank">CVE-2012-1779</a></td>
</tr>
<tr>
<td width="20%">iwork &#8212; webglimpse</td>
<td>wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to obtain the installation path via a crafted request.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-5112&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-5112" target="_blank">CVE-2009-5112</a></td>
</tr>
<tr>
<td width="20%">iwork &#8212; webglimpse</td>
<td>Cross-site scripting (XSS) vulnerability in wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the DOC parameter.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-5113&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-5113" target="_blank">CVE-2009-5113</a></td>
</tr>
<tr>
<td width="20%">iwork &#8212; webglimpse</td>
<td>Directory traversal vulnerability in wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the DOC parameter.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2009-5114&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-5114" target="_blank">CVE-2009-5114</a></td>
</tr>
<tr>
<td width="20%">janetter &#8212; janetter</td>
<td>Janetter before 3.3.0.0 (aka 3.3.0) allows remote attackers to obtain session information for twitter.com web sites via unspecified vectors.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0328&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0328" target="_blank">CVE-2012-0328</a></td>
</tr>
<tr>
<td width="20%">janetter &#8212; janetter</td>
<td>Multiple cross-site request forgery (CSRF) vulnerabilities in Janetter before 3.3.0.0 (aka 3.3.0) allow remote attackers to hijack the authentication of arbitrary users for requests that (1) tweet, (2) upload an image file, or (3) execute arbitrary commands.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1236&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1236" target="_blank">CVE-2012-1236</a></td>
</tr>
<tr>
<td width="20%">joakim_nygard &#8212; webgrind</td>
<td>Absolute path traversal vulnerability in Webgrind 1.0 and 1.0.2 allows remote attackers to read arbitrary files via a full pathname in the file parameter to index.php.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1790&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1790" target="_blank">CVE-2012-1790</a></td>
</tr>
<tr>
<td width="20%">kylegilman &#8212; video_embed_&amp;_thumbnail_generator</td>
<td>The Media Upload form in the Video Embed &amp; Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to obtain the installation path via unknown vectors.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1786&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1786" target="_blank">CVE-2012-1786</a></td>
</tr>
<tr>
<td width="20%">lg-nortel &#8212; elo_gs24m_switch</td>
<td>The web management interface on the LG-Nortel ELO GS24M switch allows remote attackers to bypass authentication, and consequently obtain cleartext credential and configuration information, via a direct request to a configuration web page.</td>
<td>2012-03-22</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1838&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1838" target="_blank">CVE-2012-1838</a></td>
</tr>
<tr>
<td width="20%">netmechanica &#8212; netdecision</td>
<td>Dashboard Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the installation path via a request with a trailing &quot;?&quot; character, which causes Dashboard to attempt to access a non-existent resource. NOTE: some of these details are obtained from third party information.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1464&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1464" target="_blank">CVE-2012-1464</a></td>
</tr>
<tr>
<td width="20%">netmechanica &#8212; netdecision</td>
<td>Stack-based buffer overflow in the HTTP Server in NetMechanica NetDecision before 4.6.1 allows remote attackers to cause a denial of service (application crash) via a long URL in an HTTP request. NOTE: some of these details are obtained from third party information.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1465&amp;vector=(AV:N/AC:M/Au:N/C:N/I:N/A:P)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1465" target="_blank">CVE-2012-1465</a></td>
</tr>
<tr>
<td width="20%">osqa &#8212; osqa</td>
<td>Multiple cross-site scripting (XSS) vulnerabilities in questions/ask in OSQA 3b allow remote attackers to inject arbitrary web script or HTML via the (1) url bar or (2) picture bar.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1782&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1782" target="_blank">CVE-2012-1782</a></td>
</tr>
<tr>
<td width="20%">oxwall &#8212; oxwall</td>
<td>Multiple cross-site scripting (XSS) vulnerabilities in OxWall 1.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) captchaField, (2) email, (3) form_name, (4) password, (5) realname, (6) repeatPassword, or (7) username parameters to Oxwall/join; (8) captcha, (9) email, (10) form_name, (11) from, or (12) subject parameters to Oxwall/contact; (13) tag parameter to Oxwall/blogs/browse-by-tag; or (14) PATH_INFO to Oxwall/photo/viewlist/tagged, (15) Oxwall/photo/viewlist, or (16) Oxwall/video/viewlist.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0872&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0872" target="_blank">CVE-2012-0872</a></td>
</tr>
<tr>
<td width="20%">rsa &#8212; envision</td>
<td>Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA enVision 4.x before 4.1 Patch 4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</td>
<td>2012-03-20</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0399&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0399" target="_blank">CVE-2012-0399</a></td>
</tr>
<tr>
<td width="20%">rsa &#8212; envision</td>
<td>Multiple SQL injection vulnerabilities in EMC RSA enVision 4.x before 4.1 Patch 4 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.</td>
<td>2012-03-20</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0401&amp;vector=(AV:N/AC:L/Au:S/C:P/I:P/A:P)" target="_blank">6.5</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0401" target="_blank">CVE-2012-0401</a></td>
</tr>
<tr>
<td width="20%">rsa &#8212; envision</td>
<td>Directory traversal vulnerability in EMC RSA enVision 4.x before 4.1 Patch 4 allows remote authenticated users to have an unspecified impact via unknown vectors.</td>
<td>2012-03-20</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0403&amp;vector=(AV:N/AC:M/Au:S/C:C/I:N/A:N)" target="_blank">6.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0403" target="_blank">CVE-2012-0403</a></td>
</tr>
<tr>
<td width="20%">s2member &#8212; s2member</td>
<td>Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code field).</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2011-5082&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-5082" target="_blank">CVE-2011-5082</a></td>
</tr>
<tr>
<td width="20%">socialcms &#8212; socialcms</td>
<td>Multiple cross-site scripting (XSS) vulnerabilities in ajax/commentajax.php in SocialCMS 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) TREF_email_address or (2) TR_name parameters.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1781&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1781" target="_blank">CVE-2012-1781</a></td>
</tr>
<tr>
<td width="20%">symantec &#8212; altiris_wise_package_studio</td>
<td>Multiple SQL injection vulnerabilities in Symantec Altiris WISE Package Studio before 8.0MR1 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.</td>
<td>2012-03-17</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0293&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0293" target="_blank">CVE-2012-0293</a></td>
</tr>
<tr>
<td width="20%">tetsuya_aoyama &#8212; twicca</td>
<td>The twicca application 0.7.0 through 0.9.30 for Android does not properly restrict the use of network privileges, which allows remote attackers to read media files on an SD card via a crafted application.</td>
<td>2012-03-17</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0326&amp;vector=(AV:N/AC:L/Au:N/C:P/I:N/A:N)" target="_blank">5.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0326" target="_blank">CVE-2012-0326</a></td>
</tr>
<tr>
<td width="20%">tskynet &#8212; kongreg8</td>
<td>Multiple cross-site scripting (XSS) vulnerabilities in Kongreg8 1.7.3 allow remote attackers to inject arbitrary web script or HTML via the (1) surname or (2) firstname parameters to modules/members/addmember.php; or (3) groupdescription or (4) groupname parameters to modules/groups/addgroupform.php.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1789&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1789" target="_blank">CVE-2012-1789</a></td>
</tr>
<tr>
<td width="20%">vmware &#8212; view</td>
<td>Cross-site scripting (XSS) vulnerability in View Manager Portal in VMware View before 4.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.</td>
<td>2012-03-16</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1511&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1511" target="_blank">CVE-2012-1511</a></td>
</tr>
<tr>
<td width="20%">vmware &#8212; vsphere</td>
<td>Cross-site scripting (XSS) vulnerability in the internal browser in vSphere Client in VMware vSphere 4.1 before Update 2 and 5.0 before Update 1 allows remote attackers to inject arbitrary web script or HTML via a crafted log-file entry.</td>
<td>2012-03-16</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1512&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1512" target="_blank">CVE-2012-1512</a></td>
</tr>
<tr>
<td width="20%">vmware &#8212; vcenter_orchestrator</td>
<td>The Web Configuration tool in VMware vCenter Orchestrator (vCO) 4.0 before Update 4, 4.1 before Update 2, and 4.2 before Update 1 places the vCenter Server password in an HTML document, which allows remote authenticated administrators to obtain sensitive information by reading this document.</td>
<td>2012-03-16</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1513&amp;vector=(AV:N/AC:L/Au:S/C:P/I:N/A:N)" target="_blank">4.0</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1513" target="_blank">CVE-2012-1513</a></td>
</tr>
<tr>
<td width="20%">vmware &#8212; vshield_manager</td>
<td>Cross-site request forgery (CSRF) vulnerability in VMware vShield Manager (vSM) 1.0.1 before Update 2 and 4.1.0 before Update 2 allows remote attackers to hijack the authentication of arbitrary users.</td>
<td>2012-03-16</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1514&amp;vector=(AV:N/AC:M/Au:N/C:P/I:P/A:P)" target="_blank">6.8</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1514" target="_blank">CVE-2012-1514</a></td>
</tr>
<tr>
<td width="20%">webglimpse &#8212; webglimpse</td>
<td>Multiple cross-site scripting (XSS) vulnerabilities in wgarcmin.cgi in Webglimpse 2.20.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) URL, (2) FILE, or (3) DOMAIN parameters.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1787&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1787" target="_blank">CVE-2012-1787</a></td>
</tr>
<tr>
<td width="20%">wonderdesk &#8212; wonderdesk_sql</td>
<td>Multiple cross-site scripting (XSS) vulnerabilities in wonderdesk.cgi in WonderDesk SQL 4.14 allow remote attackers to inject arbitrary web script or HTML via the (1) cus_email parameter in a cust_lostpw action; or (2) help_name, (3) help_email, (4) help_website, or (5) help_example_url parameters in an hd_modify_record action.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-1788&amp;vector=(AV:N/AC:M/Au:N/C:N/I:P/A:N)" target="_blank">4.3</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1788" target="_blank">CVE-2012-1788</a></td>
</tr>
</tbody>
</table>
<p>
</div>
<p><a name="low"></a></p>
<div>
<table align="center" border="1" summary="Low Vulnerabilities">
<thead>
<tr>
<th colspan="5">Low Vulnerabilities</th>
</tr>
<tr>
<th>Primary<br />
Vendor &#8212; Product</th>
<th>Description</th>
<th>Published</th>
<th>CVSS Score</th>
<th>Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td width="20%">bdale_garbee &#8212; as31</td>
<td>as31 2.3.1-4 does not seed the random number generator and generates predictable temporary file names, which makes it easier for local users to create or truncate files via a symlink attack.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0808&amp;vector=(AV:L/AC:L/Au:N/C:N/I:P/A:P)" target="_blank">3.6</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0808" target="_blank">CVE-2012-0808</a></td>
</tr>
<tr>
<td width="20%">golismero &#8212; golismero</td>
<td>libs/updater.py in GoLismero 0.6.3, and other versions before Git revision 2b3bb43d6867, as used in backtrack and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on GoLismero-controlled files, as demonstrated using Admin/changes.dat.</td>
<td>2012-03-19</td>
<td><a href="http://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2012-0054&amp;vector=(AV:L/AC:L/Au:N/C:N/I:P/A:P)" target="_blank">3.6</a></td>
<td><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0054" target="_blank">CVE-2012-0054</a></td>
</tr>
</tbody>
</table>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.freednslookup.net/2012/03/27/sb12-086-vulnerability-summary-for-the-week-of-march-19-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

