2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2012-10064CRITICAL9.3Omni Secure Files plugin versions prior to 0.1.14 contain an arbitrary file upload vulnerability in the bundled plupload...
CVE-2012-10060CRITICAL9.3Sysax Multi Server versions prior to 5.55 contain a stack-based buffer overflow in its SSH service. When a remote attack...
CVE-2012-10059CRITICAL9.4Dolibarr ERP/CRM versions <= 3.1.1 and <= 3.2.0 contain a post-authenticated OS command injection vulnerability in its d...
CVE-2012-10058CRITICAL10RabidHamster R4 v1.25 contains a stack-based buffer overflow vulnerability due to unsafe use of sprintf() when logging m...
CVE-2012-10055CRITICAL9.3ComSndFTP FTP Server version 1.3.7 Beta contains a format string vulnerability in its handling of the USER command. By s...
CVE-2012-10054CRITICAL9.3Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx ...
CVE-2012-10040CRITICAL9.4Openfiler v2.x contains a command injection vulnerability in the system.html page. The device parameter is used to insta...
CVE-2012-10039CRITICAL9.4ZEN Load Balancer versions 2.0 and 3.0-rc1 contain a command injection vulnerability in content2-2.cgi. The filelog para...
CVE-2012-10038CRITICAL9.3Auxilium RateMyPet contains an unauthenticated arbitrary file upload vulnerability in upload_banners.php. The banner upl...
CVE-2012-10037CRITICAL9.3PhpTax version 0.8 contains a remote code execution vulnerability in drawimage.php. The pfilez GET parameter is unsafely...
CVE-2012-10053CRITICAL9.3Simple Web Server 2.2 rc2 contains a stack-based buffer overflow vulnerability in its handling of the Connection HTTP he...
CVE-2012-10052CRITICAL9.3EGallery version 1.2 contains an unauthenticated arbitrary file upload vulnerability in the uploadify.php script. The ap...
CVE-2012-10050CRITICAL9.3CuteFlow version 2.11.2 and earlier contains an arbitrary file upload vulnerability in the restart_circulation_values_wr...
CVE-2012-10049CRITICAL9.3WebPageTest version 2.6 and earlier contains an arbitrary file upload vulnerability in the resultimage.php script. The a...
CVE-2012-10047CRITICAL10Cyclope Employee Surveillance Solution versions 6.x are vulnerable to a SQL injection flaw in its login mechanism. The u...
CVE-2012-10046CRITICAL9.3The E-Mail Security Virtual Appliance (ESVA) (tested on version ESVA_2057) contains an unauthenticated command injection...
CVE-2012-10045CRITICAL9.3XODA version 0.4.5 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitra...
CVE-2012-10044CRITICAL10MobileCartly version 1.0 contains an arbitrary file creation vulnerability in the savepage.php script. The application f...
CVE-2012-10043CRITICAL9.3A stack-based buffer overflow vulnerability exists in ActFax Server version 4.32, specifically in the "Import Users from...
CVE-2012-10041CRITICAL9.3WAN Emulator v2.3 contains two unauthenticated command execution vulnerabilities. The result.php script calls shell_exec...
CVE-2012-10036CRITICAL9.3Project Pier 0.8.8 and earlier contains an unauthenticated arbitrary file upload vulnerability in tools/upload_file.php....
CVE-2012-10035CRITICAL10Turbo FTP Server versions 1.30.823 and 1.30.826 contain a buffer overflow vulnerability in the handling of the PORT comm...
CVE-2012-10033CRITICAL9.3Narcissus is vulnerable to remote code execution via improper input handling in its image configuration workflow. Specif...
CVE-2012-10030CRITICAL9.3FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbit...
CVE-2012-10027CRITICAL9.3WP-Property plugin for WordPress up to and including version 1.35.0 contains an unauthenticated file upload vulnerabilit...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now