2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-10064CRITICAL9.3Omni Secure Files plugin versions prior to 0.1.14 contain an arbitrary file upload vulnerability in the bundled plupload...
CVE-2012-10063CRITICAL9.8Nagios XI versions prior to 2012R1.3 contain a SQL injection vulnerability in the legacy Core Configuration Manager (CCM...
CVE-2012-10062HIGH8.7A vulnerability in XAMPP, developed by Apache Friends, version 1.7.3's default WebDAV configuration allows remote authen...
CVE-2012-10061HIGH8.7Sockso Music Host Server versions <= 1.5 are vulnerable to a path traversal flaw that allows unauthenticated remote atta...
CVE-2012-10060CRITICAL9.8Sysax Multi Server versions prior to 5.55 contain a stack-based buffer overflow in its SSH service. When a remote attack...
CVE-2012-10059CRITICAL9.4Dolibarr ERP/CRM versions <= 3.1.1 and <= 3.2.0 contain a post-authenticated OS command injection vulnerability in its d...
CVE-2012-10058CRITICAL10RabidHamster R4 v1.25 contains a stack-based buffer overflow vulnerability due to unsafe use of sprintf() when logging m...
CVE-2012-10057HIGH8.4Lattice Semiconductor ispVM System v18.0.2 contains a buffer overflow vulnerability in its handling of .xcf project file...
CVE-2012-10056HIGH8.7PHP Volunteer Management System v1.0.2 contains an arbitrary file upload vulnerability in its document upload functional...
CVE-2012-10055CRITICAL9.3ComSndFTP FTP Server version 1.3.7 Beta contains a format string vulnerability in its handling of the USER command. By s...
CVE-2012-10054CRITICAL9.8Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx ...
CVE-2012-10040CRITICAL9.4Openfiler v2.x contains a command injection vulnerability in the system.html page. The device parameter is used to insta...
CVE-2012-10039CRITICAL9.4ZEN Load Balancer versions 2.0 and 3.0-rc1 contain a command injection vulnerability in content2-2.cgi. The filelog para...
CVE-2012-10038CRITICAL9.3Auxilium RateMyPet contains an unauthenticated arbitrary file upload vulnerability in upload_banners.php. The banner upl...
CVE-2012-10037CRITICAL9.3PhpTax version 0.8 contains a remote code execution vulnerability in drawimage.php. The pfilez GET parameter is unsafely...
CVE-2012-10053CRITICAL9.3Simple Web Server 2.2 rc2 contains a stack-based buffer overflow vulnerability in its handling of the Connection HTTP he...
CVE-2012-10052CRITICAL9.3EGallery version 1.2 contains an unauthenticated arbitrary file upload vulnerability in the uploadify.php script. The ap...
CVE-2012-10051HIGH8.4Photodex ProShow Producer version 5.0.3256 contains a stack-based buffer overflow vulnerability in the handling of plugi...
CVE-2012-10050CRITICAL9.3CuteFlow version 2.11.2 and earlier contains an arbitrary file upload vulnerability in the restart_circulation_values_wr...
CVE-2012-10049CRITICAL9.3WebPageTest version 2.6 and earlier contains an arbitrary file upload vulnerability in the resultimage.php script. The a...
CVE-2012-10048HIGH8.7Zenoss Core 3.x contains a command injection vulnerability in the showDaemonXMLConfig endpoint. The daemon parameter is ...
CVE-2012-10047CRITICAL10Cyclope Employee Surveillance Solution versions 6.x are vulnerable to a SQL injection flaw in its login mechanism. The u...
CVE-2012-10046CRITICAL9.3The E-Mail Security Virtual Appliance (ESVA) (tested on version ESVA_2057) contains an unauthenticated command injection...
CVE-2012-10045CRITICAL9.3XODA version 0.4.5 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitra...
CVE-2012-10044CRITICAL10MobileCartly version 1.0 contains an arbitrary file creation vulnerability in the savepage.php script. The application f...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now