2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-5578MEDIUM6.2Python keyring has insecure permissions on new databases allowing world-readable files to be created
CVE-2012-6079HIGH7.5W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download th...
CVE-2012-6078HIGH7.5W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the ...
CVE-2012-6077HIGH7.5W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of d...
CVE-2012-0877HIGH7.5PyXML: Hash table collisions CPU usage Denial of Service
CVE-2012-0812MEDIUM6.1PostfixAdmin 2.3.4 has multiple XSS vulnerabilities
CVE-2012-3407HIGH7.8plow has local buffer overflow vulnerability
CVE-2012-2079HIGH8.8A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal.
CVE-2012-2078MEDIUM4.8Cross-site scripting (XSS) vulnerability in the Activity module 6.x-1.x for Drupal.
CVE-2012-1637MEDIUM4.8Cross-site scripting vulnerability (XSS) in the Quick Tabs module 6.x-2.x before 6.x-2.1, 6.x-3.x before 6.x-3.1, and 7....
CVE-2012-1001MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Chyrp before 2.1.2 and before 2.5 Beta 2 allow remote attackers t...
CVE-2012-4524HIGH7.5xlockmore before 5.43 'dclock' security bypass vulnerability
CVE-2012-3460CRITICAL9.8cumin: At installation postgresql database user created without password
CVE-2012-3543HIGH7.5mono 2.10.x ASP.NET Web Form Hash collision DoS
CVE-2012-2350HIGH7.5pam_shield before 0.9.4: Default configuration does not perform protective action
CVE-2012-2238HIGH7.5trytond 2.4: ModelView.button fails to validate authorization
CVE-2012-1257MEDIUM5.5Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information vi...
CVE-2012-6136MEDIUM5.5tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.
CVE-2012-6135HIGH7.5RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.
CVE-2012-6071HIGH7.5nuSOAP before 0.7.3-5 does not properly check the hostname of a cert.
CVE-2012-6070HIGH7.5Falconpl before 0.9.6.9-git20120606 misuses the libcurl API which may allow remote attackers to interfere with security ...
CVE-2012-0843MEDIUM5.5uzbl: Information disclosure via world-readable cookies storage file
CVE-2012-0824CRITICAL9.8gnusound 0.7.5 has format string issue
CVE-2012-0842MEDIUM5.5surf: cookie jar has read access from other local user
CVE-2012-4441MEDIUM6.1Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitra...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now