2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-2969Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to bypass intended restrictions on filena...
CVE-2012-2968Directory traversal vulnerability in Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to c...
CVE-2012-2967Caucho Quercus, as distributed in Resin before 4.0.29, does not properly implement the == (equals sign equals sign) oper...
CVE-2012-2966Caucho Quercus, as distributed in Resin before 4.0.29, overwrites entries in the SERVER superglobal array on the basis o...
CVE-2012-2965Caucho Quercus, as distributed in Resin before 4.0.29, does not properly handle unspecified characters in the names of v...
CVE-2012-2964The BreakingPoint Storm appliance before 3.0 requires cleartext credentials for establishing a session from a GUI admini...
CVE-2012-2963The administrative interface in the embedded web server on the BreakingPoint Storm appliance before 3.0 does not require...
CVE-2012-2602Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before ...
CVE-2012-2577Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 ...
CVE-2012-4247Multiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote atta...
CVE-2012-4246Multiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote atta...
CVE-2012-4035The new_password page in PBBoard 2.1.4 allows remote attackers to change the password of arbitrary user accounts via the...
CVE-2012-4034Multiple SQL injection vulnerabilities in PBBoard 2.1.4 allow remote attackers to execute arbitrary SQL commands via the...
CVE-2012-3953SQL injection vulnerability in admin/index.php in phpList before 2.10.19 allows remote administrators to execute arbitra...
CVE-2012-3952Cross-site scripting (XSS) vulnerability in admin/index.php in phpList before 2.10.19 allows remote attackers to inject ...
CVE-2012-3457PNP4Nagios 0.6 through 0.6.16 uses world-readable permissions for process_perfdata.cfg, which allows local users to obta...
CVE-2012-3132SQL injection vulnerability in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 all...
CVE-2012-4235The RSGallery2 (com_rsgallery2) component before 3.2.0 for Joomla! 2.5.x does not place index.html files in image direct...
CVE-2012-4071Cross-site scripting (XSS) vulnerability in the comments module in the RSGallery2 (com_rsgallery2) component before 2.3....
CVE-2012-3554SQL injection vulnerability in the RSGallery2 (com_rsgallery2) component before 2.3.0 for Joomla! 1.5.x, and before 3.2....
CVE-2012-3465Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/sanitize_helper.rb in the strip_tags help...
CVE-2012-3464Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on...
CVE-2012-3463Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_tag_helper.rb in Ruby on Rails 3.x b...
CVE-2012-2863The PDF functionality in Google Chrome before 21.0.1180.75 allows remote attackers to cause a denial of service or possi...
CVE-2012-2862Use-after-free vulnerability in the PDF functionality in Google Chrome before 21.0.1180.75 allows remote attackers to ca...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now