CVE-2012-2022
published 2012-08-07CVE-2012-2022: Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node Manager i (NNMi) 8.x, 9.0x, 9.1x, and 9.20 allow remote attackers to inject arbitrary…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.31%
81.6th percentile
Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node Manager i (NNMi) 8.x, 9.0x, 9.1x, and 9.20 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | network_node_manager_i | — | — |
| hp | network_node_manager_i | — | — |
| hp | network_node_manager_i | — | — |
| hp | network_node_manager_i | — | — |
| hp | network_node_manager_i | — | — |
| hp | network_node_manager_i | — | — |
| hp | network_node_manager_i | — | — |
| hp | network_node_manager_i | — | — |
| hp | network_node_manager_i | — | — |
| hp | network_node_manager_i | — | — |
| hp | network_node_manager_i | — | — |
| hp | network_node_manager_i | — | — |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_1909 | — | — |
| msrc | windows_10_version_20h2 | — | — |
| msrc | windows_10_version_21h1 | — | — |
| msrc | windows_10_version_21h2 | — | — |
| msrc | windows_11_version_21h2 | — | — |
| msrc | windows_7 | — | — |
| msrc | windows_8.1 | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2008 | — | — |
| msrc | windows_server_2008_r2 | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
cisa9.8CRITICAL
vendor_msrc4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rpv7-pxwh-9c3x: Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node Manager i (NNMi) 8
ghsa_unreviewed·2022-05-13
CVE-2012-2022 [MEDIUM] CWE-79 GHSA-rpv7-pxwh-9c3x: Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node Manager i (NNMi) 8
Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node Manager i (NNMi) 8.x, 9.0x, 9.1x, and 9.20 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CISA
Oracle Java SE Sandbox Bypass Vulnerability
cisa·2022-03-28·CVSS 9.8
CVE-2012-5076 [CRITICAL] Oracle Java SE Sandbox Bypass Vulnerability
Vulnerability: Oracle Java SE Sandbox Bypass Vulnerability
Affected: Oracle Java SE
The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2012-5076
Remediation Due Date: 2022-04-18
CISA
Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability
cisa·2022-03-03·CVSS 8.8
CVE-2012-1856 [HIGH] CWE-94 Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability
Vulnerability: Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability
Affected: Microsoft Office
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2012-1856
Remediation Due Date: 2022-03-24
CISA
Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability
cisa·2022-03-03·CVSS 7.8
CVE-2017-0001 [HIGH] Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability
Vulnerability: Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability
Affected: Microsoft Graphics Device Interface (GDI)
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-0001
Remediation Due Date: 2022-03-24
CISA
Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability
cisa·2021-11-03·CVSS 8.8
CVE-2012-0158 [HIGH] CWE-94 Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability
Vulnerability: Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability
Affected: Microsoft MSCOMCTL.OCX
Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2012-0158
Remediation Due Date: 2022-05-03
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Microsoft fixes Linux boot issues on dual-boot Windows systems
blogs_bleepingcomputer·2025-05-14·CVSS 8.6
[HIGH] Microsoft fixes Linux boot issues on dual-boot Windows systems
## Microsoft fixes Linux boot issues on dual-boot Windows systems
## Sergiu Gatlan
Microsoft has fixed a known issue preventing Linux from booting on dual-boot systems with Secure Boot enabled after installing the August 2024 Windows security updates.
The list of affected systems includes those running client (Windows 10 and Windows 11) and server (Windows Server 2012 and later) OS versions.
This issue is triggered by a Secure Boot Advanced Targeting (SBAT) update that blocks UEFI shim bootloaders vulnerable to exploits targeting the CVE-2022-2601 GRUB2 Secure Boot bypass.
While Microsoft said in the CVE-2022-2601 advisory that this SBAT update would not be delivered to devices where dual booting is detected, it also acknowledged that the dual-boot detection failed to detect some cust
Bugzilla
CVE-2012-0477 Mozilla: Potential XSS through ISO-2022-KR/ISO-2022-CN decoding issues (MFSA 2012-29)
bugzilla·2012-04-22·CVSS 4.3
CVE-2012-0477 [MEDIUM] CVE-2012-0477 Mozilla: Potential XSS through ISO-2022-KR/ISO-2022-CN decoding issues (MFSA 2012-29)
CVE-2012-0477 Mozilla: Potential XSS through ISO-2022-KR/ISO-2022-CN decoding issues (MFSA 2012-29)
Security researcher Masato Kinugawa found that during the decoding of ISO-2022-KR and ISO-2022-CN character sets, characters near 1024 bytes are treated incorrectly, either doubling or deleting bytes. On certain pages it might be possible for an attacker to pad the output of the page such that these errors fall in the right place to affect the structure of the page, allowing for cross-site script (XSS) injection.
Reference:
http://www.mozilla.org/security/announce/2012/mfsa2012-29.html
Discussion:
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Masato Kinugawa as the original reporter.
---
This issue has been addressed
2012-08-07
Published