2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-3729 | — | — | 0.3% | Sep 20, 2012 | The Berkeley Packet Filter (BPF) interpreter implementation in the kernel in Apple iOS before 6 accesses uninitialized m... |
| CVE-2012-3728 | — | — | 0.3% | Sep 20, 2012 | The kernel in Apple iOS before 6 dereferences invalid pointers during the handling of packet-filter data structures, whi... |
| CVE-2012-3727 | — | — | 3.3% | Sep 20, 2012 | Buffer overflow in the IPsec component in Apple iOS before 6 allows remote attackers to execute arbitrary code via a cra... |
| CVE-2012-3726 | — | — | 2.2% | Sep 20, 2012 | Double free vulnerability in ImageIO in Apple iOS before 6 allows remote attackers to execute arbitrary code or cause a ... |
| CVE-2012-3725 | — | — | 0.7% | Sep 20, 2012 | The DNAv4 protocol implementation in the DHCP component in Apple iOS before 6 sends Wi-Fi packets containing a MAC addre... |
| CVE-2012-3724 | — | — | 1.3% | Sep 20, 2012 | CFNetwork in Apple iOS before 6 does not properly identify the host portion of a URL, which allows remote attackers to o... |
| CVE-2012-3723 | — | — | 0.4% | Sep 20, 2012 | Apple Mac OS X before 10.7.5 does not properly handle the bNbrPorts field of a USB hub descriptor, which allows physical... |
| CVE-2012-3722 | — | — | 2.9% | Sep 20, 2012 | The Sorenson codec in QuickTime in Apple Mac OS X before 10.7.5, and in CoreMedia in iOS before 6, accesses uninitialize... |
| CVE-2012-3721 | — | — | 1.5% | Sep 20, 2012 | Profile Manager in Apple Mac OS X before 10.7.5 does not properly perform authentication for the Device Management priva... |
| CVE-2012-3720 | — | — | 1.4% | Sep 20, 2012 | Mobile Accounts in Apple Mac OS X before 10.7.5 and 10.8.x before 10.8.2 saves password hashes for external-account use ... |
| CVE-2012-3719 | — | — | 1.9% | Sep 20, 2012 | Mail in Apple Mac OS X before 10.7.5 does not properly handle embedded web plugins, which allows remote attackers to exe... |
| CVE-2012-3718 | — | — | 0.3% | Sep 20, 2012 | Apple Mac OS X before 10.7.5 and 10.8.x before 10.8.2 allows local users to read passwords entered into Login Window (ak... |
| CVE-2012-3716 | — | — | 6.6% | Sep 20, 2012 | CoreText in Apple Mac OS X 10.7.x before 10.7.5 allows remote attackers to execute arbitrary code or cause a denial of s... |
| CVE-2012-3715 | — | — | 1.7% | Sep 20, 2012 | Apple Safari before 6.0.1 makes http requests for https URIs in certain circumstances involving a paste into the address... |
| CVE-2012-3714 | — | — | 0.9% | Sep 20, 2012 | The Form Autofill feature in Apple Safari before 6.0.1 does not restrict the filled fields to the set of fields containe... |
| CVE-2012-3713 | — | — | 1.7% | Sep 20, 2012 | Apple Safari before 6.0.1 does not properly handle the Quarantine attribute of HTML documents, which allows user-assiste... |
| CVE-2012-0650 | — | — | 3.0% | Sep 20, 2012 | Buffer overflow in the DirectoryService Proxy in DirectoryService in Apple Mac OS X through 10.6.8 allows remote attacke... |
| CVE-2012-5007 | — | — | 1.3% | Sep 20, 2012 | The Fill PDF module 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to write to arbitrary PDF files via unspec... |
| CVE-2012-1631 | — | — | 0.6% | Sep 20, 2012 | Cross-site request forgery (CSRF) vulnerability in the Admin:hover module for Drupal allows remote attackers to hijack t... |
| CVE-2012-1630 | — | — | 0.9% | Sep 20, 2012 | Cross-site scripting (XSS) vulnerability in the Taxonomy Navigator module for Drupal allows remote authenticated users w... |
| CVE-2012-1629 | — | — | 0.9% | Sep 20, 2012 | Cross-site scripting (XSS) vulnerability in the Taxotouch module for Drupal allows remote authenticated users with certa... |
| CVE-2012-1628 | — | — | 0.9% | Sep 20, 2012 | Cross-site scripting (XSS) vulnerability in the SuperCron module for Drupal allows remote authenticated users to inject ... |
| CVE-2012-1626 | — | — | 1.1% | Sep 20, 2012 | SQL injection vulnerability in the conversion form for Events in the Date module 6.x-2.x before 6.x-2.8 for Drupal allow... |
| CVE-2012-1625 | — | — | 1.1% | Sep 20, 2012 | Eval injection vulnerability in the fillpdf_form_export_decode function in fillpdf.admin.inc in the Fill PDF module 6.x-... |
| CVE-2012-1633 | — | — | 0.7% | Sep 20, 2012 | Cross-site request forgery (CSRF) vulnerability in the Password Policy module before 6.x-1.4 and 7.x-1.0 beta3 for Drupa... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now