2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-4413——OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote aut...
CVE-2012-4405——Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (iccl...
CVE-2012-3547——Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2.1.10 through 2.1.12, when using TLS-based EAP m...
CVE-2012-3524——libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows...
CVE-2012-3034——WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers t...
CVE-2012-3032——SQL injection vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other prod...
CVE-2012-3031——Multiple cross-site scripting (XSS) vulnerabilities in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIM...
CVE-2012-3030——WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, stores sensitive informat...
CVE-2012-3028——Cross-site request forgery (CSRF) vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC...
CVE-2012-4969HIGH8.1Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 al...
CVE-2012-2994——The CoSoSys Endpoint Protector 4 appliance establishes an EPProot password based entirely on the appliance serial number...
CVE-2012-2993MEDIUM5.9Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificat...
CVE-2012-2062——Open redirect vulnerability in the Redirecting click bouncer module for Drupal allows remote attackers to redirect users...
CVE-2012-2061——Cross-site request forgery (CSRF) vulnerability in the Admin tools module for Drupal allows remote attackers to hijack t...
CVE-2012-2060——Cross-site scripting (XSS) vulnerability in the Admin tools module for Drupal allows remote attackers to inject arbitrar...
CVE-2012-2059——Cross-site scripting (XSS) vulnerability in the ticketyboo News Ticker module for Drupal allows remote attackers to inje...
CVE-2012-2058——The Ubercart Payflow module for Drupal does not use a secure token, which allows remote attackers to forge payments via ...
CVE-2012-2057——Cross-site request forgery (CSRF) vulnerability in the Ubercart Bulk Stock Updater module for Drupal allows remote attac...
CVE-2012-2056——Cross-site request forgery (CSRF) vulnerability in the Content Lock module for Drupal allows remote attackers to hijack ...
CVE-2012-1899——Multiple cross-site scripting (XSS) vulnerabilities in webfolio/admin/users/edit in Webfolio CMS 1.1.4 and earlier allow...
CVE-2012-4968——Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe 2.3.x before 2.3.13 and 2.4.x before 2.4.7 allow rem...
CVE-2012-2996——Cross-site request forgery (CSRF) vulnerability in saveAccountSubTab.imss in Trend Micro InterScan Messaging Security Su...
CVE-2012-2995——Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_13...
CVE-2012-2575——Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 6.0a4 allows remote attackers to inject arbitrary web scrip...
CVE-2012-3924——The SSLVPN implementation in Cisco IOS 15.1 and 15.2, when DTLS is enabled, does not properly handle certain outbound AC...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now