2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2012-10062HIGH8.7A vulnerability in XAMPP, developed by Apache Friends, version 1.7.3's default WebDAV configuration allows remote authen...
CVE-2012-10061HIGH8.7Sockso Music Host Server versions <= 1.5 are vulnerable to a path traversal flaw that allows unauthenticated remote atta...
CVE-2012-10057HIGH8.4Lattice Semiconductor ispVM System v18.0.2 contains a buffer overflow vulnerability in its handling of .xcf project file...
CVE-2012-10056HIGH8.7PHP Volunteer Management System v1.0.2 contains an arbitrary file upload vulnerability in its document upload functional...
CVE-2012-10051HIGH8.4Photodex ProShow Producer version 5.0.3256 contains a stack-based buffer overflow vulnerability in the handling of plugi...
CVE-2012-10048HIGH8.7Zenoss Core 3.x contains a command injection vulnerability in the showDaemonXMLConfig endpoint. The daemon parameter is ...
CVE-2012-10042HIGH8.7Sflog! CMS 1.0 contains an authenticated arbitrary file upload vulnerability in the blog management interface. The appli...
CVE-2012-10034HIGH7.5ClanSphere 2011.3 is vulnerable to a local file inclusion (LFI) flaw due to improper handling of the cs_lang cookie para...
CVE-2012-10032HIGH8.7Maxthon3 version 3.2.2 build 1000 and prior are vulnerable to cross context scripting (XCS) via the about:history page. ...
CVE-2012-10031HIGH8.6BlazeVideo HDTV Player Pro v6.6.0.3 is vulnerable to a stack-based buffer overflow due to improper handling of user-supp...
CVE-2012-10029HIGH8.6Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in `v...
CVE-2012-10028HIGH8.6Netwin SurgeFTP version 23c8 and prior contains a vulnerability in its web-based administrative console that allows auth...
CVE-2012-10024HIGH7.1XBMC version 11.0 contains a path traversal vulnerability in its embedded HTTP server. When accessed via HTTP Basic Auth...
CVE-2012-10022HIGH8.5Kloxo versions 6.1.12 and earlier contain two setuid root binaries—lxsuexec and lxrestart—that allow local privilege esc...
CVE-2012-10018HIGH8.3The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and ...
CVE-2012-10017HIGH8.8A vulnerability was found in BestWebSoft Portfolio Plugin up to 2.04 on WordPress. It has been classified as problematic...
CVE-2012-10016HIGH7.5A vulnerability classified as problematic has been found in Halulu simple-download-button-shortcode Plugin 1.0 on WordPr...
CVE-2012-10015HIGH8.8A vulnerability was found in BestWebSoft Twitter Plugin up to 2.14 on WordPress. It has been classified as problematic. ...
CVE-2012-10012HIGH8.8A vulnerability has been found in BestWebSoft Facebook Like Button up to 2.13 and classified as problematic. Affected by...
CVE-2012-10010HIGH8.8A vulnerability was found in BestWebSoft Contact Form 3.21. It has been classified as problematic. This affects the func...
CVE-2012-2201HIGH7.5IBM WebSphere MQ 7.1 is vulnerable to a denial of service, caused by an error when handling user ids. A remote attacker ...
CVE-2012-1102HIGH7.5It was discovered that the XML::Atom Perl module before version 0.39 did not disable external entities when parsing XML ...
CVE-2012-0955HIGH7.4software-properties was vulnerable to a person-in-the-middle attack due to incorrect TLS certificate validation in softw...
CVE-2012-3336HIGH8.8IBM InfoSphere Guardium 8.0, 8.01, and 8.2 is vulnerable to SQL injection. A remote authenticated attacker could send sp...
CVE-2012-1094HIGH7.5JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-c...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now