2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-3410 | — | — | 0.4% | Aug 27, 2012 | Stack-based buffer overflow in lib/sh/eaccess.c in GNU Bash before 4.2 patch 33 might allow local users to bypass intend... |
| CVE-2012-1587 | — | — | — | Aug 27, 2012 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-4944. Reason: This candidate is a duplicate of... |
| CVE-2012-1586 | — | — | 0.7% | Aug 27, 2012 | mount.cifs in cifs-utils 2.6 allows local users to determine the existence of arbitrary files or directories via the fil... |
| CVE-2012-0855 | — | — | 1.8% | Aug 27, 2012 | Heap-based buffer overflow in the get_sot function in the J2K decoder (j2k.c) in libavcodec in FFmpeg before 0.9.1 allow... |
| CVE-2012-0849 | — | — | 1.5% | Aug 27, 2012 | Integer overflow in the ff_j2k_dwt_init function in libavcodec/j2k_dwt.c in FFmpeg before 0.9.1 allows remote attackers ... |
| CVE-2012-4679 | — | — | 2.4% | Aug 27, 2012 | Cross-site scripting (XSS) vulnerability in admin/login.php in Newscoop before 3.5.5 allows remote attackers to inject a... |
| CVE-2012-2129 | — | — | 2.6% | Aug 27, 2012 | Cross-site scripting (XSS) vulnerability in doku.php in DokuWiki 2012-01-25 Angua allows remote attackers to inject arbi... |
| CVE-2012-2128 | — | — | 1.2% | Aug 27, 2012 | Cross-site request forgery (CSRF) vulnerability in doku.php in DokuWiki 2012-01-25 Angua allows remote attackers to hija... |
| CVE-2012-2112 | — | — | 1.4% | Aug 27, 2012 | Cross-site scripting (XSS) vulnerability in the Exception Handler in TYPO3 4.4.x before 4.4.15, 4.5.x before 4.5.15, 4.6... |
| CVE-2012-1935 | — | — | 2.9% | Aug 27, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4.x before 4 RC4 allow remote att... |
| CVE-2012-1934 | — | — | 2.5% | Aug 27, 2012 | SQL injection vulnerability in admin/country/edit.php in Newscoop before 3.5.5 and 4.x before 4 RC4 allows remote attack... |
| CVE-2012-1933 | — | — | 5.6% | Aug 27, 2012 | Multiple PHP remote file inclusion vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4 before RC4, when register_global... |
| CVE-2012-4678 | — | — | 2.2% | Aug 26, 2012 | munin-cgi-graph for Munin 2.0 rc4 does not delete temporary files, which allows remote attackers to cause a denial of se... |
| CVE-2012-2297 | — | — | 1.1% | Aug 26, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in the Creative Commons module 6.x-1.x before 6.x-1.1 for Drupal all... |
| CVE-2012-2147 | — | — | 1.9% | Aug 26, 2012 | munin-cgi-graph in Munin 2.0 rc4 allows remote attackers to cause a denial of service (disk or memory consumption) via m... |
| CVE-2012-2146 | — | — | 1.7% | Aug 26, 2012 | Elixir 0.8.0 uses Blowfish in CFB mode without constructing a unique initialization vector (IV), which makes it easier f... |
| CVE-2012-2104 | — | — | 5.1% | Aug 26, 2012 | cgi-bin/munin-cgi-graph in Munin 2.x writes data to a log file without sanitizing non-printable characters, which might ... |
| CVE-2012-2103 | — | — | 0.3% | Aug 26, 2012 | The qmailscan plugin for Munin 1.4.5 allows local users to overwrite arbitrary files via a symlink attack on temporary f... |
| CVE-2012-1921 | — | — | 1.0% | Aug 26, 2012 | Cross-site request forgery (CSRF) vulnerability in goform/admin/formWlEncrypt in Sitecom WLM-2501 allows remote attacker... |
| CVE-2012-1296 | — | — | 1.3% | Aug 26, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in apps/admin/handlers/preview.php in Elefant CMS 1.0.x before 1.0.2... |
| CVE-2012-1177 | — | — | 1.9% | Aug 26, 2012 | libgdata before 0.10.2 and 0.11.x before 0.11.1 does not validate SSL certificates, which allows remote attackers to obt... |
| CVE-2012-1176 | — | — | 2.7% | Aug 26, 2012 | Buffer overflow in the fribidi_utf8_to_unicode function in PyFriBidi before 0.11.0 allows remote attackers to cause a de... |
| CVE-2012-1175 | — | — | 4.3% | Aug 26, 2012 | Integer overflow in the GnashImage::size method in libbase/GnashImage.h in GNU Gnash 0.8.10 allows remote attackers to c... |
| CVE-2012-4677 | — | — | 0.2% | Aug 26, 2012 | Tunnelblick 3.3beta20 and earlier allows local users to gain privileges by using a crafted Info.plist file to control th... |
| CVE-2012-4676 | — | — | 0.2% | Aug 26, 2012 | The errorExitIfAttackViaString function in Tunnelblick 3.3beta20 and earlier allows local users to delete arbitrary file... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now