2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-4767MEDIUM6.1An issue exists in Safend Data Protector Agent 3.4.5586.9772 in the securitylayer.log file in the logs.9972 directory, w...
CVE-2012-4603HIGH7.8Citrix XenApp Online Plug-in for Windows 12.1 and earlier, and Citrix Receiver for Windows 3.2 and earlier could allow r...
CVE-2012-4284CRITICAL9.8A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the se...
CVE-2012-3821MEDIUM4.3A Security Bypass vulnerability exists in the activate.asp page in Arial Software Campaign Enterprise 11.0.551, which co...
CVE-2012-4030HIGH7.5Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote ...
CVE-2012-3824HIGH7.5In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.
CVE-2012-3823HIGH7.5Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved.
CVE-2012-3822HIGH7.5Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attacke...
CVE-2012-3810HIGH7.5Samsung Kies before 2.5.0.12094_27_11 has registry modification.
CVE-2012-3809HIGH7.5Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification.
CVE-2012-3808HIGH7.5Samsung Kies before 2.5.0.12094_27_11 has arbitrary file modification.
CVE-2012-3807CRITICAL9.8Samsung Kies before 2.5.0.12094_27_11 has arbitrary file execution.
CVE-2012-3806HIGH7.5Samsung Kies before 2.5.0.12094_27_11 contains a NULL pointer dereference vulnerability which could allow remote attacke...
CVE-2012-2950HIGH8.1Gateway Geomatics MapServer for Windows before 3.0.6 contains a Local File Include Vulnerability which allows remote att...
CVE-2012-5558MEDIUM4.8Cross-site scripting (XSS) vulnerability in the Smiley module 6.x-1.x versions prior to 6.x-1.1 and Smileys module 6.x-1...
CVE-2012-4434HIGH8.8fwknop before 2.0.3 allow remote authenticated users to cause a denial of service (server crash) or possibly execute arb...
CVE-2012-3490HIGH8.8The (1) my_popenv_impl and (2) my_spawnv functions in src/condor_utils/my_popen.cpp and the (3) systemCommand function i...
CVE-2012-2931HIGH7.2PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbi...
CVE-2012-2226CRITICAL9.8Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sen...
CVE-2012-2142HIGH7.8The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF ...
CVE-2012-1915MEDIUM6.1EllisLab CodeIgniter 2.1.2 allows remote attackers to bypass the xss_clean() Filter and perform XSS attacks.
CVE-2012-2724MEDIUM5.3The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal r...
CVE-2012-2714CRITICAL9.8The BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentic...
CVE-2012-1261MEDIUM6.1Cross-site scripting (XSS) vulnerability in cgi-bin/scrut_fa_exclusions.cgi in Plixer International Scrutinizer NetFlow ...
CVE-2012-1260MEDIUM6.1Cross-site scripting (XSS) vulnerability in cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow An...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now