2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2012-4740Cross-site scripting (XSS) vulnerability in the captive portal in PacketFence before 3.3.0 allows remote attackers to in...
CVE-2012-2117Cross-site scripting (XSS) vulnerability in the Gigya - Social optimization module 6.x before 6.x-3.2 for Drupal allows ...
CVE-2012-2116Cross-site request forgery (CSRF) vulnerability in the Commerce Reorder module before 7.x-1.1 for Drupal allows remote a...
CVE-2012-2114Stack-based buffer overflow in fprintf in musl before 0.8.8 and earlier allows context-dependent attackers to cause a de...
CVE-2012-2083Cross-site scripting (XSS) vulnerability in the fusion_core_preprocess_page function in fusion_core/template.php in the ...
CVE-2012-4739Multiple cross-site scripting (XSS) vulnerabilities in Barracuda SSL VPN before 2.2.2.203 (2012-07-05) allow remote atta...
CVE-2012-3534GNU Gatekeeper before 3.1 does not limit the number of connections to the status port, which allows remote attackers to ...
CVE-2012-3533The python SDK before 3.1.0.6 and CLI before 3.1.0.8 for oVirt 3.1 does not check the server SSL certificate against the...
CVE-2012-2704The Advertisement module 6.x-2.x before 6.x-2.3 for Drupal does not properly restrict access to debug information, which...
CVE-2012-4171Adobe Flash Player before 10.3.183.23 and 11.x before 11.4.402.265 on Windows and Mac OS X, before 10.3.183.23 and 11.x ...
CVE-2012-2872Cross-site scripting (XSS) vulnerability in an SSL interstitial page in Google Chrome before 21.0.1180.89 allows remote ...
CVE-2012-2871libxml2 2.9.0-rc1 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly support a cast of an unsp...
CVE-2012-2870libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage memory, which might a...
CVE-2012-2869Google Chrome before 21.0.1180.89 does not properly load URLs, which allows remote attackers to cause a denial of servic...
CVE-2012-2868Race condition in Google Chrome before 21.0.1180.89 allows remote attackers to cause a denial of service or possibly hav...
CVE-2012-2867The SPDY implementation in Google Chrome before 21.0.1180.89 allows remote attackers to cause a denial of service (appli...
CVE-2012-2866Google Chrome before 21.0.1180.89 does not properly perform a cast of an unspecified variable during handling of run-in ...
CVE-2012-2865Google Chrome before 21.0.1180.89 does not properly perform line breaking, which allows remote attackers to cause a deni...
CVE-2012-4245The scriptfu network server in GIMP 2.6 does not require authentication, which allows remote attackers to execute arbitr...
CVE-2012-3478rssh 2.3.3 and earlier allows local users to bypass intended restricted shell access via crafted environment variables i...
CVE-2012-3380Directory traversal vulnerability in naxsi-ui/nx_extract.py in the Naxsi module before 0.46-1 for Nginx allows local use...
CVE-2012-3379Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-0808. Reason: This candidate is a duplicate of...
CVE-2012-3378The register_application function in atk-adaptor/bridge.c in GNOME at-spi2-atk 2.5.2 does not seed the random number gen...
CVE-2012-2658Buffer overflow in the SQLDriverConnect function in unixODBC 2.3.1 allows local users to cause a denial of service (cras...
CVE-2012-2657Buffer overflow in the SQLDriverConnect function in unixODBC 2.0.10, 2.3.1, and earlier allows local users to cause a de...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now