2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-2203 | — | — | 1.6% | Aug 8, 2012 | IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Ser... |
| CVE-2012-2191 | — | — | 3.9% | Aug 8, 2012 | IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Ser... |
| CVE-2012-0421 | — | — | 0.3% | Aug 8, 2012 | The SUSE Audit Log Keeper daemon before 0.2.1-0.4.6.1 for SUSE Manager and Spacewalk uses world-readable permissions for... |
| CVE-2012-4178 | — | — | 1.2% | Aug 7, 2012 | SQL injection vulnerability in spywall/includes/deptUploads_data.php in Symantec Web Gateway 5.0.3.18 allows remote atta... |
| CVE-2012-3445 | — | — | 2.2% | Aug 7, 2012 | The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed para... |
| CVE-2012-3438 | — | — | 2.5% | Aug 7, 2012 | The Magick_png_malloc function in coders/png.c in GraphicsMagick 6.7.8-6 does not use the proper variable type for the a... |
| CVE-2012-3437 | — | — | 2.8% | Aug 7, 2012 | The Magick_png_malloc function in coders/png.c in ImageMagick 6.7.8 and earlier does not use the proper variable type fo... |
| CVE-2012-3429 | — | — | 3.1% | Aug 7, 2012 | The dns_to_ldap_dn_escape function in src/ldap_convert.c in bind-dyndb-ldap 1.1.0rc1 and earlier does not properly escap... |
| CVE-2012-3423 | — | — | 6.2% | Aug 7, 2012 | The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows r... |
| CVE-2012-3422 | — | — | 3.1% | Aug 7, 2012 | The getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 returns an uninitialized pointer when the in... |
| CVE-2012-3386 | — | — | 0.5% | Aug 7, 2012 | The "make distcheck" rule in GNU Automake before 1.11.6 and 1.12.x before 1.12.2 grants world-writable permissions to th... |
| CVE-2012-0213 | — | — | 7.5% | Aug 7, 2012 | The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remot... |
| CVE-2012-4177 | — | — | 58.0% | Aug 7, 2012 | The web browser plugin for Ubisoft Uplay PC before 2.0.4 allows remote attackers to execute arbitrary programs via the -... |
| CVE-2012-3454 | — | — | 0.3% | Aug 7, 2012 | eXtplorer 2.1.0b6 uses world writable permissions for the /var/lib/extplorer/ftp_tmp directory, which allows local users... |
| CVE-2012-3453 | — | — | 0.3% | Aug 7, 2012 | logol 1.5.0 uses world writable permissions for the /var/lib/logol/results directory, which allows local users to delete... |
| CVE-2012-3452 | — | — | 0.3% | Aug 7, 2012 | gnome-screensaver 3.4.x before 3.4.4 and 3.5.x before 3.5.4, when multiple screens are used, only locks the screen with ... |
| CVE-2012-3449 | — | — | 0.3% | Aug 7, 2012 | Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/... |
| CVE-2012-3413 | — | — | 2.5% | Aug 7, 2012 | The HTMLQuoteColorer::process function in messageviewer/htmlquotecolorer.cpp in KDE PIM 4.6 through 4.8 does not disable... |
| CVE-2012-2652 | — | — | 0.3% | Aug 7, 2012 | The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, ... |
| CVE-2012-4005 | — | — | 1.4% | Aug 7, 2012 | The NHN Japan NAVER LINE application before 2.5.5 for Android does not properly handle implicit intents, which allows re... |
| CVE-2012-2648 | — | — | 1.4% | Aug 7, 2012 | Cross-site scripting (XSS) vulnerability in the GoodReader app 3.16 and earlier for iOS on the iPad, and 3.15.1 and earl... |
| CVE-2012-2317 | — | — | 2.5% | Aug 7, 2012 | The Debian php_crypt_revamped.patch patch for PHP 5.3.x, as used in the php5 package before 5.3.3-7+squeeze4 in Debian G... |
| CVE-2012-2022 | — | — | 2.3% | Aug 7, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node Manager i (NNMi) 8.x, 9.0x, 9.1x, and 9.20 allow ... |
| CVE-2012-3448 | — | — | 9.9% | Aug 6, 2012 | Unspecified vulnerability in Ganglia Web before 3.5.1 allows remote attackers to execute arbitrary PHP code via unknown ... |
| CVE-2012-2665 | — | — | 7.0% | Aug 6, 2012 | Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and Libr... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now