Upstream Drupal has reported SA-CORE-2012-004  which corrects multiple vulnerabilities:
1) Access bypass (User module search - Drupal 6 and 7) 2) Access bypass (Upload module - Drupal 6) 3) Arbitrary PHP code execution (File upload modules - Drupal 6 and 7)
CVEs have been requested and are not yet assigned.
These flaws have been fixed in Drupal 6.27 and 7.18.
Please login to add feedback.