2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-1615HIGH7.8A Privilege Escalation vulnerability exits in Fedoraproject Sectool due to an incorrect DBus file.
CVE-2012-1592HIGH8.8A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious ...
CVE-2012-1115MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, a...
CVE-2012-1114MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.p...
CVE-2012-1105MEDIUM5.5An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. Th...
CVE-2012-1104MEDIUM5.3A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of ser...
CVE-2012-5562HIGH8.6A flaw was found in rhn-proxy. This vulnerability may allow the rhn-proxy to transmit user credentials in clear-text whe...
CVE-2012-4576HIGH7.8FreeBSD: Input Validation Flaw allows local users to gain elevated privileges
CVE-2012-4526MEDIUM6.1piwigo has XSS in password.php (incomplete fix for CVE-2012-4525)
CVE-2012-4525MEDIUM6.1piwigo has XSS in password.php
CVE-2012-4480HIGH7.8mom creates world-writable pid files in /var/run
CVE-2012-4428HIGH7.5openslp: SLPIntersectStringList()' Function has a DoS vulnerability
CVE-2012-6655LOW3.3An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a l...
CVE-2012-2248HIGH8.1An issue was discovered in dhclient 4.3.1-6 due to an embedded path variable.
CVE-2012-6639HIGH8.8An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitte...
CVE-2012-5644MEDIUM5.5libuser has information disclosure when moving user's home directory
CVE-2012-5640MEDIUM5.5thttpd has a local DoS vulnerability via specially-crafted .htpasswd files
CVE-2012-5631HIGH8.8ipa 3.0 does not properly check server identity before sending credential containing cookies
CVE-2012-5630MEDIUM6.3libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.
CVE-2012-5617HIGH7.8gksu-polkit: permissive PolicyKit policy configuration file allows privilege escalation
CVE-2012-5582CRITICAL9.8opendnssec misuses libcurl API
CVE-2012-5535HIGH7.5gnome-system-log polkit policy allows arbitrary files on the system to be read
CVE-2012-5527MEDIUM5.5Claws Mail vCalendar plugin: credentials exposed on interface
CVE-2012-5521MEDIUM6.5quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal
CVE-2012-5518HIGH7.5vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now