2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-1259CRITICAL9.8Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and pos...
CVE-2012-1258MEDIUM6.5cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer before 9.0.1.19899 does not validate ...
CVE-2012-5878CRITICAL9.8Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary comman...
CVE-2012-5693HIGH8.8Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allows remote attackers to execute arbitrary commands via ...
CVE-2012-4451MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to injec...
CVE-2012-5663HIGH7.5The isearch package (textproc/isearch) before 1.47.01nb1 uses the tempnam() function to create insecure temporary files ...
CVE-2012-5645HIGH7.5A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A ...
CVE-2012-5476MEDIUM5.5Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world r...
CVE-2012-5474MEDIUM5.5The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-dj...
CVE-2012-4980HIGH7.8Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attacker...
CVE-2012-4420HIGH7.5An information disclosure flaw was found in the way the Java Virtual Machine (JVM) implementation of Java SE 7 as provid...
CVE-2012-3462HIGH8.8A flaw was found in SSSD version 1.9.0. The SSSD's access-provider logic causes the result of the HBAC rule processing t...
CVE-2012-2736MEDIUM4.4In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an o...
CVE-2012-6111HIGH7.5gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function
CVE-2012-6094CRITICAL9.8cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized ...
CVE-2012-5639MEDIUM6.5LibreOffice and OpenOffice automatically open embedded content
CVE-2012-3409HIGH7.8ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege ...
CVE-2012-2656HIGH7.5An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote atta...
CVE-2012-2312HIGH7.8An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security c...
CVE-2012-2237MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote att...
CVE-2012-5620Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2012-1577CRITICAL9.8lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0.
CVE-2012-2148LOW3.3An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies
CVE-2012-2130HIGH7.4A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption error when generating...
CVE-2012-2092MEDIUM5.9A Security Bypass vulnerability exists in Ubuntu Cobbler before 2,2,2 in the cobbler-ubuntu-import script due to an erro...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now