2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-1897——Multiple cross-site request forgery (CSRF) vulnerabilities in Wolf CMS 0.75 and earlier allow remote attackers to hijack...
CVE-2012-1639——Multiple cross-site scripting (XSS) vulnerabilities in product/commerce_product.module in the Drupal Commerce module for...
CVE-2012-1576——The myuser_delete function in libathemecore/account.c in Atheme 5.x before 5.2.7, 6.x before 6.0.10, and 7.x before 7.0....
CVE-2012-4833——fuser in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly restrict the -k option, which allows local...
CVE-2012-4830——Unspecified vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11 and 7.0 through 7.0.0.6 allows remote attackers...
CVE-2012-3319——IBM Rational Business Developer 8.x before 8.0.1.4 allows remote attackers to obtain potentially sensitive information v...
CVE-2012-3035——Buffer overflow in Emerson DeltaV 9.3.1 and 10.3 through 11.3.1 allows remote attackers to cause a denial of service (da...
CVE-2012-0748——Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified services in IBM Rational Team Concert (RTC) 4....
CVE-2012-4450——389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allow...
CVE-2012-4437——Cross-site scripting (XSS) vulnerability in the SmartyException class in Smarty (aka smarty-php) before 3.1.12 allows re...
CVE-2012-4432——Use-after-free vulnerability in opngreduc.c in OptiPNG Hg and 0.7.x before 0.7.3 might allow remote attackers to execute...
CVE-2012-4427——The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extens...
CVE-2012-4415——Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote a...
CVE-2012-4429——Vino 2.28, 2.32, 3.4.2, and earlier allows remote attackers to read clipboard activity by listening on TCP port 5900.
CVE-2012-3500——scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools before 8.3, allows local users to modify ...
CVE-2012-2242——scripts/dget.pl in devscripts before 2.10.73 allows remote attackers to execute arbitrary commands via a crafted (1) .ds...
CVE-2012-2241——scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete arbitrary files via a crafted (1) .dsc or ...
CVE-2012-2240——scripts/dscverify.pl in devscripts before 2.12.3 allows remote attackers to execute arbitrary commands via unspecified v...
CVE-2012-2153——Drupal 7.x before 7.14 does not properly restrict access to nodes in a list when using a "contributed node access module...
CVE-2012-1591——The image module in Drupal 7.x before 7.14 does not properly check permissions when caching derivative image styles of p...
CVE-2012-1590——The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which all...
CVE-2012-1588——Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.mod...
CVE-2012-4448——Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hija...
CVE-2012-1833——VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allo...
CVE-2012-5197——Multiple unspecified vulnerabilities in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 have unknown impact and attack...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now