2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-3886 | — | — | 1.3% | Jul 26, 2012 | AirDroid 1.0.4 beta uses the MD5 algorithm for values in the checklogin key parameter and 7bb cookie, which makes it eas... |
| CVE-2012-3885 | — | — | 1.3% | Jul 26, 2012 | The default configuration of AirDroid 1.0.4 beta uses a four-character alphanumeric password, which makes it easier for ... |
| CVE-2012-3884 | — | — | 1.4% | Jul 26, 2012 | AirDroid 1.0.4 beta implements authentication through direct transmission of a password hash over HTTP, which makes it e... |
| CVE-2012-4068 | — | — | 4.5% | Jul 26, 2012 | Heap-based buffer overflow in the SoapServer service in Citrix Provisioning Services 5.0, 5.1, 5.6, 5.6 SP1, 6.0, and 6.... |
| CVE-2012-4043 | — | — | 1.4% | Jul 26, 2012 | Cross-site scripting (XSS) vulnerability in global-protect/login.esp in Palo Alto Networks Global Protect Portal, Global... |
| CVE-2012-3698 | — | — | 1.1% | Jul 26, 2012 | Apple Xcode before 4.4 does not properly compose a designated requirement (DR) during signing of programs that lack bund... |
| CVE-2012-3015 | — | — | 0.5% | Jul 26, 2012 | Untrusted search path vulnerability in Siemens SIMATIC STEP7 before 5.5 SP1, as used in SIMATIC PCS7 7.1 SP3 and earlier... |
| CVE-2012-3005 | — | — | 0.4% | Jul 26, 2012 | Untrusted search path vulnerability in Invensys Wonderware InTouch 2012 and earlier, as used in Wonderware Application S... |
| CVE-2012-4061 | — | — | 1.2% | Jul 25, 2012 | Multiple SQL injection vulnerabilities in ASP-DEv XM Diary allow remote attackers to execute arbitrary SQL commands via ... |
| CVE-2012-4060 | — | — | 1.1% | Jul 25, 2012 | Multiple SQL injection vulnerabilities in ASP-DEv XM Forums RC3 allow remote attackers to execute arbitrary SQL commands... |
| CVE-2012-4059 | — | — | 0.7% | Jul 25, 2012 | Cross-site request forgery (CSRF) vulnerability in home/secretqtn.php in SocketMail Pro 2.2.9 allows remote attackers to... |
| CVE-2012-4058 | — | — | 1.2% | Jul 25, 2012 | Cross-site scripting (XSS) vulnerability in SocketMail Pro 2.2.9 allows remote attackers to inject arbitrary web script ... |
| CVE-2012-4057 | — | — | 6.3% | Jul 25, 2012 | Buffer overflow in the Player in Remote-Anything 5.60.15 allows remote attackers to execute arbitrary code via a crafted... |
| CVE-2012-4056 | — | — | 1.3% | Jul 25, 2012 | SQL injection vulnerability in index2.php in Uiga Personal Portal allows remote attackers to execute arbitrary SQL comma... |
| CVE-2012-4055 | — | — | 1.1% | Jul 25, 2012 | SQL injection vulnerability in index2.php in Uiga Fan Club allows remote attackers to execute arbitrary SQL commands via... |
| CVE-2012-4054 | — | — | 1.2% | Jul 25, 2012 | Buffer overflow in the readfile function in CPE17 Autorun Killer 1.7.1 and earlier allows physically proximate attackers... |
| CVE-2012-2442 | — | — | 2.7% | Jul 25, 2012 | Buffer overflow in the Video Manager in Nokia PC Suite 7.1.180.64 and earlier allows remote attackers to cause a denial ... |
| CVE-2012-2310 | — | — | 1.0% | Jul 25, 2012 | Cross-site scripting (XSS) vulnerability in the cctags module for Drupal 6.x-1.x before 6.x-1.10 and 7.x-1.x before 7.x-... |
| CVE-2012-2309 | — | — | 0.9% | Jul 25, 2012 | Cross-site scripting (XSS) vulnerability in the Glossify Internal Links Auto SEO module for Drupal 6.x-2.5 and earlier a... |
| CVE-2012-2308 | — | — | 0.9% | Jul 25, 2012 | Cross-site scripting (XSS) vulnerability in the Taxonomy Grid : Catalog module for Drupal 6.x-1.6 and earlier allows rem... |
| CVE-2012-2307 | — | — | 0.6% | Jul 25, 2012 | Cross-site request forgery (CSRF) vulnerability in the Addressbook module for Drupal 6.x-4.2 and earlier allows remote a... |
| CVE-2012-2306 | — | — | 1.2% | Jul 25, 2012 | SQL injection vulnerability in the Addressbook module for Drupal 6.x-4.2 and earlier allows remote attackers to execute ... |
| CVE-2012-2305 | — | — | 0.6% | Jul 25, 2012 | Cross-site request forgery (CSRF) vulnerability in the Node Gallery module for Drupal 6.x-3.1 and earlier allows remote ... |
| CVE-2012-2302 | — | — | 1.7% | Jul 25, 2012 | Site Documentation (Sitedoc) module for Drupal 6.x-1.x before 6.x-1.4 does not properly check the save location when arc... |
| CVE-2012-2296 | — | — | 1.6% | Jul 25, 2012 | The Janrain Engage (formerly RPX) module for Drupal 6.x-1.x. 6.x-2.x before 6.x-2.2, and 7.x-2.x before 7.x-2.2 stores u... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now