2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-5578 | MEDIUM | 6.2 | 0.4% | Nov 25, 2019 | Python keyring has insecure permissions on new databases allowing world-readable files to be created |
| CVE-2012-6079 | HIGH | 7.5 | 2.1% | Nov 22, 2019 | W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download th... |
| CVE-2012-6078 | HIGH | 7.5 | 2.3% | Nov 22, 2019 | W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the ... |
| CVE-2012-6077 | HIGH | 7.5 | 5.4% | Nov 22, 2019 | W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of d... |
| CVE-2012-0877 | HIGH | 7.5 | 1.9% | Nov 22, 2019 | PyXML: Hash table collisions CPU usage Denial of Service |
| CVE-2012-0812 | MEDIUM | 6.1 | 1.2% | Nov 22, 2019 | PostfixAdmin 2.3.4 has multiple XSS vulnerabilities |
| CVE-2012-3407 | HIGH | 7.8 | 0.4% | Nov 22, 2019 | plow has local buffer overflow vulnerability |
| CVE-2012-2079 | HIGH | 8.8 | 0.5% | Nov 22, 2019 | A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal. |
| CVE-2012-2078 | MEDIUM | 4.8 | 0.5% | Nov 21, 2019 | Cross-site scripting (XSS) vulnerability in the Activity module 6.x-1.x for Drupal. |
| CVE-2012-1637 | MEDIUM | 4.8 | 0.5% | Nov 21, 2019 | Cross-site scripting vulnerability (XSS) in the Quick Tabs module 6.x-2.x before 6.x-2.1, 6.x-3.x before 6.x-3.1, and 7.... |
| CVE-2012-1001 | MEDIUM | 6.1 | 3.6% | Nov 21, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in Chyrp before 2.1.2 and before 2.5 Beta 2 allow remote attackers t... |
| CVE-2012-4524 | HIGH | 7.5 | 2.9% | Nov 21, 2019 | xlockmore before 5.43 'dclock' security bypass vulnerability |
| CVE-2012-3460 | CRITICAL | 9.8 | 1.3% | Nov 21, 2019 | cumin: At installation postgresql database user created without password |
| CVE-2012-3543 | HIGH | 7.5 | 2.6% | Nov 21, 2019 | mono 2.10.x ASP.NET Web Form Hash collision DoS |
| CVE-2012-2350 | HIGH | 7.5 | 1.3% | Nov 21, 2019 | pam_shield before 0.9.4: Default configuration does not perform protective action |
| CVE-2012-2238 | HIGH | 7.5 | 1.8% | Nov 21, 2019 | trytond 2.4: ModelView.button fails to validate authorization |
| CVE-2012-1257 | MEDIUM | 5.5 | 0.7% | Nov 20, 2019 | Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information vi... |
| CVE-2012-6136 | MEDIUM | 5.5 | 0.3% | Nov 20, 2019 | tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes. |
| CVE-2012-6135 | HIGH | 7.5 | 2.3% | Nov 19, 2019 | RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process. |
| CVE-2012-6071 | HIGH | 7.5 | 1.3% | Nov 19, 2019 | nuSOAP before 0.7.3-5 does not properly check the hostname of a cert. |
| CVE-2012-6070 | HIGH | 7.5 | 1.6% | Nov 19, 2019 | Falconpl before 0.9.6.9-git20120606 misuses the libcurl API which may allow remote attackers to interfere with security ... |
| CVE-2012-0843 | MEDIUM | 5.5 | 0.4% | Nov 19, 2019 | uzbl: Information disclosure via world-readable cookies storage file |
| CVE-2012-0824 | CRITICAL | 9.8 | 1.8% | Nov 19, 2019 | gnusound 0.7.5 has format string issue |
| CVE-2012-0842 | MEDIUM | 5.5 | 0.4% | Nov 19, 2019 | surf: cookie jar has read access from other local user |
| CVE-2012-4441 | MEDIUM | 6.1 | 1.9% | Nov 18, 2019 | Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitra... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now