2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-4740 | — | — | 1.2% | Aug 31, 2012 | Cross-site scripting (XSS) vulnerability in the captive portal in PacketFence before 3.3.0 allows remote attackers to in... |
| CVE-2012-2117 | — | — | 1.3% | Aug 31, 2012 | Cross-site scripting (XSS) vulnerability in the Gigya - Social optimization module 6.x before 6.x-3.2 for Drupal allows ... |
| CVE-2012-2116 | — | — | 1.0% | Aug 31, 2012 | Cross-site request forgery (CSRF) vulnerability in the Commerce Reorder module before 7.x-1.1 for Drupal allows remote a... |
| CVE-2012-2114 | — | — | 2.4% | Aug 31, 2012 | Stack-based buffer overflow in fprintf in musl before 0.8.8 and earlier allows context-dependent attackers to cause a de... |
| CVE-2012-2083 | — | — | 1.3% | Aug 31, 2012 | Cross-site scripting (XSS) vulnerability in the fusion_core_preprocess_page function in fusion_core/template.php in the ... |
| CVE-2012-4739 | — | — | 3.3% | Aug 31, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in Barracuda SSL VPN before 2.2.2.203 (2012-07-05) allow remote atta... |
| CVE-2012-3534 | — | — | 3.8% | Aug 31, 2012 | GNU Gatekeeper before 3.1 does not limit the number of connections to the status port, which allows remote attackers to ... |
| CVE-2012-3533 | — | — | 1.1% | Aug 31, 2012 | The python SDK before 3.1.0.6 and CLI before 3.1.0.8 for oVirt 3.1 does not check the server SSL certificate against the... |
| CVE-2012-2704 | — | — | 1.5% | Aug 31, 2012 | The Advertisement module 6.x-2.x before 6.x-2.3 for Drupal does not properly restrict access to debug information, which... |
| CVE-2012-4171 | — | — | 4.8% | Aug 31, 2012 | Adobe Flash Player before 10.3.183.23 and 11.x before 11.4.402.265 on Windows and Mac OS X, before 10.3.183.23 and 11.x ... |
| CVE-2012-2872 | — | — | 1.1% | Aug 31, 2012 | Cross-site scripting (XSS) vulnerability in an SSL interstitial page in Google Chrome before 21.0.1180.89 allows remote ... |
| CVE-2012-2871 | — | — | 2.4% | Aug 31, 2012 | libxml2 2.9.0-rc1 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly support a cast of an unsp... |
| CVE-2012-2870 | — | — | 2.4% | Aug 31, 2012 | libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage memory, which might a... |
| CVE-2012-2869 | — | — | 1.9% | Aug 31, 2012 | Google Chrome before 21.0.1180.89 does not properly load URLs, which allows remote attackers to cause a denial of servic... |
| CVE-2012-2868 | — | — | 0.9% | Aug 31, 2012 | Race condition in Google Chrome before 21.0.1180.89 allows remote attackers to cause a denial of service or possibly hav... |
| CVE-2012-2867 | — | — | 1.4% | Aug 31, 2012 | The SPDY implementation in Google Chrome before 21.0.1180.89 allows remote attackers to cause a denial of service (appli... |
| CVE-2012-2866 | — | — | 1.4% | Aug 31, 2012 | Google Chrome before 21.0.1180.89 does not properly perform a cast of an unspecified variable during handling of run-in ... |
| CVE-2012-2865 | — | — | 1.1% | Aug 31, 2012 | Google Chrome before 21.0.1180.89 does not properly perform line breaking, which allows remote attackers to cause a deni... |
| CVE-2012-4245 | — | — | 4.5% | Aug 31, 2012 | The scriptfu network server in GIMP 2.6 does not require authentication, which allows remote attackers to execute arbitr... |
| CVE-2012-3478 | — | — | 0.4% | Aug 31, 2012 | rssh 2.3.3 and earlier allows local users to bypass intended restricted shell access via crafted environment variables i... |
| CVE-2012-3380 | — | — | 1.2% | Aug 31, 2012 | Directory traversal vulnerability in naxsi-ui/nx_extract.py in the Naxsi module before 0.46-1 for Nginx allows local use... |
| CVE-2012-3379 | — | — | — | Aug 31, 2012 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-0808. Reason: This candidate is a duplicate of... |
| CVE-2012-3378 | — | — | 0.3% | Aug 31, 2012 | The register_application function in atk-adaptor/bridge.c in GNOME at-spi2-atk 2.5.2 does not seed the random number gen... |
| CVE-2012-2658 | — | — | 0.5% | Aug 31, 2012 | Buffer overflow in the SQLDriverConnect function in unixODBC 2.3.1 allows local users to cause a denial of service (cras... |
| CVE-2012-2657 | — | — | 0.4% | Aug 31, 2012 | Buffer overflow in the SQLDriverConnect function in unixODBC 2.0.10, 2.3.1, and earlier allows local users to cause a de... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now