2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-3394 | — | — | 2.1% | Jul 23, 2012 | auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.... |
| CVE-2012-3393 | — | — | 1.0% | Jul 23, 2012 | Cross-site scripting (XSS) vulnerability in repository/lib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 allow... |
| CVE-2012-3392 | — | — | 1.9% | Jul 23, 2012 | mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is op... |
| CVE-2012-3391 | — | — | 1.1% | Jul 23, 2012 | mod/forum/rsslib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly implement the requirement for... |
| CVE-2012-3390 | — | — | 1.0% | Jul 23, 2012 | lib/filelib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly restrict file access after a block... |
| CVE-2012-3389 | — | — | 1.8% | Jul 23, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typessettings.php in Moodle 2.2.x before 2.2.4 and 2.3.x ... |
| CVE-2012-3388 | — | — | 1.1% | Jul 23, 2012 | The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly inte... |
| CVE-2012-3387 | — | — | 1.1% | Jul 23, 2012 | Moodle 2.3.x before 2.3.1 uses only a client-side check for whether references are permitted in a file upload, which all... |
| CVE-2012-2977 | — | — | 2.8% | Jul 23, 2012 | The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to change arbitrary passwor... |
| CVE-2012-2976 | — | — | 5.4% | Jul 23, 2012 | The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary shell ... |
| CVE-2012-2961 | — | — | 2.5% | Jul 23, 2012 | SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attack... |
| CVE-2012-2957 | — | — | 59.3% | Jul 23, 2012 | The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows local users to gain privileges by modifying ... |
| CVE-2012-2953 | — | — | 67.4% | Jul 23, 2012 | The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary comman... |
| CVE-2012-2574 | — | — | 1.2% | Jul 23, 2012 | SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attack... |
| CVE-2012-0305 | — | — | 0.4% | Jul 23, 2012 | Untrusted search path vulnerability in Symantec System Recovery 2011 before SP2 and Backup Exec System Recovery 2010 bef... |
| CVE-2012-4045 | — | — | 3.1% | Jul 22, 2012 | Multiple heap-based buffer overflows in bmp.w5s in Winamp before 5.63 build 3235 allow remote attackers to execute arbit... |
| CVE-2012-3385 | — | — | 1.9% | Jul 22, 2012 | WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows r... |
| CVE-2012-3384 | — | — | 1.2% | Jul 22, 2012 | Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to h... |
| CVE-2012-3383 | — | — | 3.1% | Jul 22, 2012 | The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is... |
| CVE-2012-2737 | — | — | 0.4% | Jul 22, 2012 | The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does n... |
| CVE-2012-2113 | — | — | 5.5% | Jul 22, 2012 | Multiple integer overflows in tiff2pdf in libtiff before 4.0.2 allow remote attackers to cause a denial of service (appl... |
| CVE-2012-2088 | — | — | 6.5% | Jul 22, 2012 | Integer signedness error in the TIFFReadDirectory function in tif_dirread.c in libtiff 3.9.4 and earlier allows remote a... |
| CVE-2012-3361 | — | — | 2.6% | Jul 22, 2012 | virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenti... |
| CVE-2012-3360 | — | — | 3.0% | Jul 22, 2012 | Directory traversal vulnerability in virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), wh... |
| CVE-2012-3357 | — | — | 1.9% | Jul 22, 2012 | The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC before 1.1.15 does not properly handle log messages when a ... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now