2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-4247 | — | — | 2.1% | Aug 12, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote atta... |
| CVE-2012-4246 | — | — | 1.9% | Aug 12, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote atta... |
| CVE-2012-4035 | — | — | 3.1% | Aug 12, 2012 | The new_password page in PBBoard 2.1.4 allows remote attackers to change the password of arbitrary user accounts via the... |
| CVE-2012-4034 | — | — | 2.5% | Aug 12, 2012 | Multiple SQL injection vulnerabilities in PBBoard 2.1.4 allow remote attackers to execute arbitrary SQL commands via the... |
| CVE-2012-3953 | — | — | 1.1% | Aug 12, 2012 | SQL injection vulnerability in admin/index.php in phpList before 2.10.19 allows remote administrators to execute arbitra... |
| CVE-2012-3952 | — | — | 1.9% | Aug 12, 2012 | Cross-site scripting (XSS) vulnerability in admin/index.php in phpList before 2.10.19 allows remote attackers to inject ... |
| CVE-2012-3457 | — | — | 0.3% | Aug 12, 2012 | PNP4Nagios 0.6 through 0.6.16 uses world-readable permissions for process_perfdata.cfg, which allows local users to obta... |
| CVE-2012-3132 | — | — | 1.8% | Aug 10, 2012 | SQL injection vulnerability in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 all... |
| CVE-2012-4235 | — | — | 1.4% | Aug 10, 2012 | The RSGallery2 (com_rsgallery2) component before 3.2.0 for Joomla! 2.5.x does not place index.html files in image direct... |
| CVE-2012-4071 | — | — | 1.2% | Aug 10, 2012 | Cross-site scripting (XSS) vulnerability in the comments module in the RSGallery2 (com_rsgallery2) component before 2.3.... |
| CVE-2012-3554 | — | — | 1.2% | Aug 10, 2012 | SQL injection vulnerability in the RSGallery2 (com_rsgallery2) component before 2.3.0 for Joomla! 1.5.x, and before 3.2.... |
| CVE-2012-3465 | — | — | 2.0% | Aug 10, 2012 | Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/sanitize_helper.rb in the strip_tags help... |
| CVE-2012-3464 | — | — | 2.6% | Aug 10, 2012 | Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on... |
| CVE-2012-3463 | — | — | 1.3% | Aug 10, 2012 | Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_tag_helper.rb in Ruby on Rails 3.x b... |
| CVE-2012-2863 | — | — | 1.1% | Aug 9, 2012 | The PDF functionality in Google Chrome before 21.0.1180.75 allows remote attackers to cause a denial of service or possi... |
| CVE-2012-2862 | — | — | 1.1% | Aug 9, 2012 | Use-after-free vulnerability in the PDF functionality in Google Chrome before 21.0.1180.75 allows remote attackers to ca... |
| CVE-2012-2745 | — | — | 0.4% | Aug 9, 2012 | The copy_creds function in kernel/cred.c in the Linux kernel before 3.3.2 provides an invalid replacement session keyrin... |
| CVE-2012-2744 | — | — | 4.4% | Aug 9, 2012 | net/ipv6/netfilter/nf_conntrack_reasm.c in the Linux kernel before 2.6.34, when the nf_conntrack_ipv6 module is enabled,... |
| CVE-2012-2373 | — | — | 0.3% | Aug 9, 2012 | The Linux kernel before 3.4.5 on the x86 platform, when Physical Address Extension (PAE) is enabled, does not properly u... |
| CVE-2012-2136 | — | — | 0.6% | Aug 9, 2012 | The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before 3.4.5 does not properly validate a certa... |
| CVE-2012-4004 | — | — | 1.2% | Aug 8, 2012 | Cross-site scripting (XSS) vulnerability in the Sleipnir Mobile application 2.2.0 and earlier and Sleipnir Mobile Black ... |
| CVE-2012-2649 | — | — | 2.0% | Aug 8, 2012 | The Sleipnir Mobile application 2.2.0 and earlier and Sleipnir Mobile Black Edition application 2.2.0 and earlier for An... |
| CVE-2012-3440 | — | — | 0.4% | Aug 8, 2012 | A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary f... |
| CVE-2012-3424 | — | — | 1.9% | Aug 8, 2012 | The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x befo... |
| CVE-2012-2960 | — | — | 2.6% | Aug 8, 2012 | Cross-site scripting (XSS) vulnerability in the import functionality in HP ArcSight Connector appliance 6.2.0.6244.0 and... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now