2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-6649CRITICAL9.8WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload.
CVE-2012-5389HIGH7.5NULL Pointer Dereference in PowerTCP WebServer for ActiveX 1.9.2 and earlier allows remote attackers to cause a denial o...
CVE-2012-5340HIGH7.8SumatraPDF 2.1.1/MuPDF 1.0 allows remote attackers to cause an Integer Overflow in the lex_number() function via a corru...
CVE-2012-4606HIGH7.8Citrix XenServer 4.1, 6.0, 5.6 SP2, 5.6 Feature Pack 1, 5.6 Common Criteria, 5.6, 5.5, 5.0, and 5.0 Update 3 contains a ...
CVE-2012-5626HIGH7.5EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3....
CVE-2012-6083HIGH7.5Freeciv before 2.3.3 allows remote attackers to cause a denial of service via a crafted packet.
CVE-2012-5867CRITICAL9.8HT Editor 2.0.20 has a Remote Stack Buffer Overflow Vulnerability
CVE-2012-5699CRITICAL9.8BabyGekko before 1.2.4 allows PHP file inclusion.
CVE-2012-5698HIGH8.8BabyGekko before 1.2.4 has SQL injection.
CVE-2012-4981HIGH8.8Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability
CVE-2012-4900MEDIUM5.5Corel WordPerfect Office X6 16.0.0.388 has a DoS Vulnerability via untrusted pointer dereference
CVE-2012-4863MEDIUM6.5IBM WebSphere MQ 7.1 and 7.5: Queue manager has a DoS vulnerability
CVE-2012-2087CRITICAL9.8ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.
CVE-2012-4919CRITICAL9.8Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability
CVE-2012-5190CRITICAL9.8Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability
CVE-2012-1326HIGH7.4Cisco IronPort Web Security Appliance up to and including 7.5 does not validate the basic constraints of the certificate...
CVE-2012-1316MEDIUM5.9Cisco IronPort Web Security Appliance does not check for certificate revocation which could lead to MITM attacks
CVE-2012-0070HIGH7.5spamdyke prior to 4.2.1: STARTTLS reveals plaintext
CVE-2012-1563HIGH7.5Joomla! before 2.5.3 allows Admin Account Creation.
CVE-2012-1562HIGH7.5Joomla! core before 2.5.3 allows unauthorized password change.
CVE-2012-0945MEDIUM4.9whoopsie-daisy before 0.1.26: Root user can remove arbitrary files
CVE-2012-0334MEDIUM6.4Cisco IronPort Web Security Appliance AsyncOS software prior to 7.5 has a SSL Certificate Caching vulnerability which co...
CVE-2012-4761HIGH7.8A Privilege Escalation vulnerability exists in the unquoted Service Binary in SDPAgent or SDBAgent in Safend Data Protec...
CVE-2012-4760HIGH7.8A Privilege Escalation vulnerability exists in the SDBagent service in Safend Data Protector Agent 3.4.5586.9772, which ...
CVE-2012-4750CRITICAL9.8A Code Execution vulnerability exists in the memcpy function when processing AMF requests in Ezhometech EzServer 7.0, wh...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now