2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-1177libgdata before 0.10.2 and 0.11.x before 0.11.1 does not validate SSL certificates, which allows remote attackers to obt...
CVE-2012-1176Buffer overflow in the fribidi_utf8_to_unicode function in PyFriBidi before 0.11.0 allows remote attackers to cause a de...
CVE-2012-1175Integer overflow in the GnashImage::size method in libbase/GnashImage.h in GNU Gnash 0.8.10 allows remote attackers to c...
CVE-2012-4677Tunnelblick 3.3beta20 and earlier allows local users to gain privileges by using a crafted Info.plist file to control th...
CVE-2012-4676The errorExitIfAttackViaString function in Tunnelblick 3.3beta20 and earlier allows local users to delete arbitrary file...
CVE-2012-3487Race condition in Tunnelblick 3.3beta20 and earlier allows local users to kill unintended processes by waiting for a spe...
CVE-2012-3486Tunnelblick 3.3beta20 and earlier allows local users to gain privileges via an OpenVPN configuration file that specifies...
CVE-2012-3485Tunnelblick 3.3beta20 and earlier relies on argv[0] to determine the name of an appropriate (1) kernel module pathname o...
CVE-2012-3484Tunnelblick 3.3beta20 and earlier relies on a test for specific ownership and permissions to determine whether a program...
CVE-2012-3483Race condition in the runScript function in Tunnelblick 3.3beta20 and earlier allows local users to gain privileges by r...
CVE-2012-4675Cross-site scripting (XSS) vulnerability in PluXml 5.1.6 allows remote attackers to inject arbitrary web script or HTML ...
CVE-2012-4674PluXml before 5.1.6 allows remote attackers to obtain the installation path via the PHPSESSID.
CVE-2012-2227Directory traversal vulnerability in update/index.php in PluXml before 5.1.6 allows remote attackers to include and exec...
CVE-2012-4673SQL injection vulnerability in application/controllers/invoice.php in NeoInvoice might allow remote attackers to execute...
CVE-2012-3519routerlist.c in Tor before 0.2.2.38 uses a different amount of time for relay-list iteration depending on which relay is...
CVE-2012-3518The networkstatus_parse_vote_from_string function in routerparse.c in Tor before 0.2.2.38 does not properly handle an in...
CVE-2012-3517Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote attackers to cause a denial of service (...
CVE-2012-3477SQL injection vulnerability in signup_check.php in NeoInvoice allows remote attackers to execute arbitrary SQL commands ...
CVE-2012-2289EMC ApplicationXtender Desktop before 6.5 SP2 and ApplicationXtender Web Access .NET before 6.5 SP2 allow remote attacke...
CVE-2012-4672Apple iChat Server does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMP...
CVE-2012-4671psyced before 20120821 does not verify that a request was made for an XMPP Server Dialback response, which allows remote...
CVE-2012-4670Tigase XMPP Server before 5.1.0 does not verify that a request was made for an XMPP Server Dialback response, which allo...
CVE-2012-4669M-Link R14.6 before R14.6v14 and R15.1 before R15.1v10 does not verify that a request was made for an XMPP Server Dialba...
CVE-2012-3525s2s/out.c in jabberd2 2.2.16 and earlier does not verify that a request was made for an XMPP Server Dialback response, w...
CVE-2012-4668Cross-site scripting (XSS) vulnerability in Roundcube Webmail 0.8.1 and earlier allows remote attackers to inject arbitr...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now