2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-2745 | — | — | 0.4% | Aug 9, 2012 | The copy_creds function in kernel/cred.c in the Linux kernel before 3.3.2 provides an invalid replacement session keyrin... |
| CVE-2012-2744 | — | — | 4.4% | Aug 9, 2012 | net/ipv6/netfilter/nf_conntrack_reasm.c in the Linux kernel before 2.6.34, when the nf_conntrack_ipv6 module is enabled,... |
| CVE-2012-2373 | — | — | 0.3% | Aug 9, 2012 | The Linux kernel before 3.4.5 on the x86 platform, when Physical Address Extension (PAE) is enabled, does not properly u... |
| CVE-2012-2136 | — | — | 0.6% | Aug 9, 2012 | The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before 3.4.5 does not properly validate a certa... |
| CVE-2012-4004 | — | — | 1.2% | Aug 8, 2012 | Cross-site scripting (XSS) vulnerability in the Sleipnir Mobile application 2.2.0 and earlier and Sleipnir Mobile Black ... |
| CVE-2012-2649 | — | — | 2.0% | Aug 8, 2012 | The Sleipnir Mobile application 2.2.0 and earlier and Sleipnir Mobile Black Edition application 2.2.0 and earlier for An... |
| CVE-2012-3440 | — | — | 0.4% | Aug 8, 2012 | A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary f... |
| CVE-2012-3424 | — | — | 1.9% | Aug 8, 2012 | The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x befo... |
| CVE-2012-2960 | — | — | 2.6% | Aug 8, 2012 | Cross-site scripting (XSS) vulnerability in the import functionality in HP ArcSight Connector appliance 6.2.0.6244.0 and... |
| CVE-2012-2203 | — | — | 1.6% | Aug 8, 2012 | IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Ser... |
| CVE-2012-2191 | — | — | 3.9% | Aug 8, 2012 | IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Ser... |
| CVE-2012-0421 | — | — | 0.3% | Aug 8, 2012 | The SUSE Audit Log Keeper daemon before 0.2.1-0.4.6.1 for SUSE Manager and Spacewalk uses world-readable permissions for... |
| CVE-2012-4178 | — | — | 1.2% | Aug 7, 2012 | SQL injection vulnerability in spywall/includes/deptUploads_data.php in Symantec Web Gateway 5.0.3.18 allows remote atta... |
| CVE-2012-3445 | — | — | 2.2% | Aug 7, 2012 | The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed para... |
| CVE-2012-3438 | — | — | 2.5% | Aug 7, 2012 | The Magick_png_malloc function in coders/png.c in GraphicsMagick 6.7.8-6 does not use the proper variable type for the a... |
| CVE-2012-3437 | — | — | 2.8% | Aug 7, 2012 | The Magick_png_malloc function in coders/png.c in ImageMagick 6.7.8 and earlier does not use the proper variable type fo... |
| CVE-2012-3429 | — | — | 3.1% | Aug 7, 2012 | The dns_to_ldap_dn_escape function in src/ldap_convert.c in bind-dyndb-ldap 1.1.0rc1 and earlier does not properly escap... |
| CVE-2012-3423 | — | — | 6.2% | Aug 7, 2012 | The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows r... |
| CVE-2012-3422 | — | — | 3.1% | Aug 7, 2012 | The getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 returns an uninitialized pointer when the in... |
| CVE-2012-3386 | — | — | 0.5% | Aug 7, 2012 | The "make distcheck" rule in GNU Automake before 1.11.6 and 1.12.x before 1.12.2 grants world-writable permissions to th... |
| CVE-2012-0213 | — | — | 7.5% | Aug 7, 2012 | The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remot... |
| CVE-2012-4177 | — | — | 58.0% | Aug 7, 2012 | The web browser plugin for Ubisoft Uplay PC before 2.0.4 allows remote attackers to execute arbitrary programs via the -... |
| CVE-2012-3454 | — | — | 0.3% | Aug 7, 2012 | eXtplorer 2.1.0b6 uses world writable permissions for the /var/lib/extplorer/ftp_tmp directory, which allows local users... |
| CVE-2012-3453 | — | — | 0.3% | Aug 7, 2012 | logol 1.5.0 uses world writable permissions for the /var/lib/logol/results directory, which allows local users to delete... |
| CVE-2012-3452 | — | — | 0.3% | Aug 7, 2012 | gnome-screensaver 3.4.x before 3.4.4 and 3.5.x before 3.5.4, when multiple screens are used, only locks the screen with ... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now