2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-4752 | — | — | 2.2% | Sep 5, 2012 | appconfig.php in ownCloud before 4.0.6 does not properly restrict access, which allows remote authenticated users to edi... |
| CVE-2012-4397 | — | — | 1.9% | Sep 5, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.1 allow remote attackers to inject arbitrary ... |
| CVE-2012-4396 | — | — | 2.5% | Sep 5, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.2 allow remote attackers to inject arbitrary ... |
| CVE-2012-4395 | — | — | 1.9% | Sep 5, 2012 | Cross-site scripting (XSS) vulnerability in index.php in ownCloud before 4.0.3 allows remote attackers to inject arbitra... |
| CVE-2012-4394 | — | — | 1.9% | Sep 5, 2012 | Cross-site scripting (XSS) vulnerability in apps/files/js/filelist.js in ownCloud before 4.0.5 allows remote attackers t... |
| CVE-2012-4393 | — | — | 1.1% | Sep 5, 2012 | Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud before 4.0.6 allow remote attackers to hijack the... |
| CVE-2012-4392 | — | — | 2.8% | Sep 5, 2012 | index.php in ownCloud 4.0.7 does not properly validate the oc_token cookie, which allows remote attackers to bypass auth... |
| CVE-2012-4391 | — | — | 1.0% | Sep 5, 2012 | Cross-site request forgery (CSRF) vulnerability in core/ajax/appconfig.php in ownCloud before 4.0.7 allows remote attack... |
| CVE-2012-4390 | — | — | 1.8% | Sep 5, 2012 | (1) apps/calendar/appinfo/remote.php and (2) apps/contacts/appinfo/remote.php in ownCloud before 4.0.7 allows remote aut... |
| CVE-2012-4389 | — | — | 3.3% | Sep 5, 2012 | Incomplete blacklist vulnerability in lib/migrate.php in ownCloud before 4.0.7 allows remote attackers to execute arbitr... |
| CVE-2012-4387 | — | — | 8.4% | Sep 5, 2012 | Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long para... |
| CVE-2012-4386 | — | — | 3.5% | Sep 5, 2012 | The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration p... |
| CVE-2012-3551 | — | — | 3.3% | Sep 5, 2012 | Cross-site scripting (XSS) vulnerability in crowbar_framework/app/views/support/index.html.haml in the Crowbar barclamp ... |
| CVE-2012-3542 | — | — | 2.5% | Sep 5, 2012 | OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers ... |
| CVE-2012-3540 | — | — | 2.9% | Sep 5, 2012 | Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attacke... |
| CVE-2012-3537 | — | — | 0.6% | Sep 5, 2012 | The Crowbar Ohai plugin (chef/cookbooks/ohai/files/default/plugins/crowbar.rb) in the Deployer Barclamp in Crowbar, poss... |
| CVE-2012-3535 | — | — | 6.2% | Sep 5, 2012 | Heap-based buffer overflow in OpenJPEG 1.5.0 and earlier allows remote attackers to cause a denial of service (applicati... |
| CVE-2012-3531 | — | — | 1.5% | Sep 5, 2012 | Cross-site scripting (XSS) vulnerability in the Install Tool in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x... |
| CVE-2012-3530 | — | — | 1.6% | Sep 5, 2012 | Incomplete blacklist vulnerability in the t3lib_div::quoteJSvalue API function in TYPO3 4.5.x before 4.5.19, 4.6.x befor... |
| CVE-2012-3529 | — | — | 0.8% | Sep 5, 2012 | The configuration module in the backend in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows ... |
| CVE-2012-3528 | — | — | 2.0% | Sep 5, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in the backend in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and... |
| CVE-2012-3527 | — | — | 2.1% | Sep 5, 2012 | view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows... |
| CVE-2012-3526 | — | — | 7.0% | Sep 5, 2012 | The reverse proxy add forward module (mod_rpaf) 0.5 and 0.6 for the Apache HTTP Server allows remote attackers to cause ... |
| CVE-2012-3509 | — | — | 3.6% | Sep 5, 2012 | Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/obj... |
| CVE-2012-3012 | — | — | 1.5% | Sep 5, 2012 | The Arbiter Power Sentinel 1133A device with firmware before 11Jun2012 Rev 421 allows remote attackers to cause a denial... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now