2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-4667 | — | — | 1.8% | Aug 25, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in SquidClamav 5.x before 5.8 allow remote attackers to inject arbit... |
| CVE-2012-3514 | — | — | 1.5% | Aug 25, 2012 | OCaml Xml-Light Library before r234 computes hash values without restricting the ability to trigger hash collisions pred... |
| CVE-2012-3508 | — | — | 4.2% | Aug 25, 2012 | Cross-site scripting (XSS) vulnerability in program/lib/washtml.php in Roundcube Webmail 0.8.0 allows remote attackers t... |
| CVE-2012-3507 | — | — | 2.1% | Aug 25, 2012 | Cross-site scripting (XSS) vulnerability in program/steps/mail/func.inc in RoundCube Webmail before 0.8.0, when using th... |
| CVE-2012-3503 | CRITICAL | 9.8 | 3.0% | Aug 25, 2012 | The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value,... |
| CVE-2012-3501 | — | — | 3.3% | Aug 25, 2012 | The squidclamav_check_preview_handler function in squidclamav.c in SquidClamav 5.x before 5.8 and 6.x before 6.7 passes ... |
| CVE-2012-3481 | — | — | 5.1% | Aug 25, 2012 | Integer overflow in the ReadImage function in plug-ins/common/file-gif-load.c in the GIF image format plug-in in GIMP 2.... |
| CVE-2012-3480 | — | — | 1.0% | Aug 25, 2012 | Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strtod_l, and other unspecified "related func... |
| CVE-2012-3479 | — | — | 3.8% | Aug 25, 2012 | lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the ... |
| CVE-2012-3441 | — | — | 2.4% | Aug 25, 2012 | The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in Icinga 1.7.1 grants access to all databas... |
| CVE-2012-3416 | — | — | 5.1% | Aug 25, 2012 | Condor before 7.8.2 allows remote attackers to bypass host-based authentication and execute actions such as ALLOW_ADMINI... |
| CVE-2012-3403 | — | — | 5.0% | Aug 25, 2012 | Heap-based buffer overflow in the KiSS CEL file format plug-in in GIMP 2.8.x and earlier allows remote attackers to caus... |
| CVE-2012-3402 | — | — | 4.3% | Aug 25, 2012 | Integer overflow in plug-ins/common/psd.c in the Adobe Photoshop PSD plugin in GIMP 2.2.13 and earlier allows remote att... |
| CVE-2012-0048 | — | — | 2.5% | Aug 25, 2012 | OpenTTD 0.3.5 through 1.1.4 allows remote attackers to cause a denial of service (game pause) by connecting to the serve... |
| CVE-2012-2990 | — | — | 3.7% | Aug 24, 2012 | The MASetupCaller ActiveX control before 1.4.2012.508 in MASetupCaller.dll in MarkAny ContentSAFER, as distributed in Sa... |
| CVE-2012-2984 | — | — | 1.7% | Aug 24, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in monitor/m_overview.ink in Websense Content Gateway before 7.7.3 a... |
| CVE-2012-0713 | — | — | 1.2% | Aug 24, 2012 | Unspecified vulnerability in the XML feature in IBM DB2 9.7 before FP6 on Linux, UNIX, and Windows allows remote authent... |
| CVE-2012-4337 | — | — | 5.0% | Aug 23, 2012 | Foxit Reader before 5.3 on Windows XP and Windows 7 allows remote attackers to execute arbitrary code via a PDF document... |
| CVE-2012-4605 | — | — | 1.4% | Aug 23, 2012 | The default configuration of the SMTP component in Websense Email Security 6.1 through 7.3 enables weak SSL ciphers in t... |
| CVE-2012-4604 | — | — | 1.3% | Aug 23, 2012 | The TRITON management console in Websense Web Security before 7.6 Hotfix 24 allows remote attackers to bypass authentica... |
| CVE-2012-2582 | — | — | 4.2% | Aug 23, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.13, ... |
| CVE-2012-3502 | — | — | 9.9% | Aug 22, 2012 | The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c in the mod_proxy_htt... |
| CVE-2012-2687 | — | — | 22.5% | Aug 22, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_ne... |
| CVE-2012-4599 | — | — | 3.9% | Aug 22, 2012 | McAfee SmartFilter Administration, and SmartFilter Administration Bess Edition, before 4.2.1.01 does not require authent... |
| CVE-2012-4598 | — | — | 29.4% | Aug 22, 2012 | An unspecified ActiveX control in McAfee Virtual Technician (MVT) before 6.4, and ePO-MVT, allows remote attackers to ex... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now