2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-4413OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote aut...
CVE-2012-4405Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (iccl...
CVE-2012-3547Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2.1.10 through 2.1.12, when using TLS-based EAP m...
CVE-2012-3524libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows...
CVE-2012-3034WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers t...
CVE-2012-3032SQL injection vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other prod...
CVE-2012-3031Multiple cross-site scripting (XSS) vulnerabilities in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIM...
CVE-2012-3030WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, stores sensitive informat...
CVE-2012-3028Cross-site request forgery (CSRF) vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC...
CVE-2012-4969HIGH8.1Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 al...
CVE-2012-2994The CoSoSys Endpoint Protector 4 appliance establishes an EPProot password based entirely on the appliance serial number...
CVE-2012-2993MEDIUM5.9Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificat...
CVE-2012-2062Open redirect vulnerability in the Redirecting click bouncer module for Drupal allows remote attackers to redirect users...
CVE-2012-2061Cross-site request forgery (CSRF) vulnerability in the Admin tools module for Drupal allows remote attackers to hijack t...
CVE-2012-2060Cross-site scripting (XSS) vulnerability in the Admin tools module for Drupal allows remote attackers to inject arbitrar...
CVE-2012-2059Cross-site scripting (XSS) vulnerability in the ticketyboo News Ticker module for Drupal allows remote attackers to inje...
CVE-2012-2058The Ubercart Payflow module for Drupal does not use a secure token, which allows remote attackers to forge payments via ...
CVE-2012-2057Cross-site request forgery (CSRF) vulnerability in the Ubercart Bulk Stock Updater module for Drupal allows remote attac...
CVE-2012-2056Cross-site request forgery (CSRF) vulnerability in the Content Lock module for Drupal allows remote attackers to hijack ...
CVE-2012-1899Multiple cross-site scripting (XSS) vulnerabilities in webfolio/admin/users/edit in Webfolio CMS 1.1.4 and earlier allow...
CVE-2012-4968Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe 2.3.x before 2.3.13 and 2.4.x before 2.4.7 allow rem...
CVE-2012-2996Cross-site request forgery (CSRF) vulnerability in saveAccountSubTab.imss in Trend Micro InterScan Messaging Security Su...
CVE-2012-2995Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_13...
CVE-2012-2575Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 6.0a4 allows remote attackers to inject arbitrary web scrip...
CVE-2012-3924The SSLVPN implementation in Cisco IOS 15.1 and 15.2, when DTLS is enabled, does not properly handle certain outbound AC...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now