2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2012-3350SQL injection vulnerability in index.php in Webmatic 3.1.1 allows remote attackers to execute arbitrary SQL commands via...
CVE-2012-3236fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and applic...
CVE-2012-2844The PDF functionality in Google Chrome before 20.0.1132.57 does not properly handle JavaScript code, which allows remote...
CVE-2012-2843Use-after-free vulnerability in Google Chrome before 20.0.1132.57 allows remote attackers to cause a denial of service o...
CVE-2012-2842Use-after-free vulnerability in Google Chrome before 20.0.1132.57 allows remote attackers to cause a denial of service o...
CVE-2012-2614Buffer overflow in programmer.exe in Lattice Diamond Programmer 1.4.2 allows user-assisted remote attackers to cause a d...
CVE-2012-1661ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, wh...
CVE-2012-3362Cross-site request forgery (CSRF) vulnerability in eXtplorer 2.1 RC3 and earlier allows remote attackers to hijack the a...
CVE-2012-2653arpwatch 2.1a15, as used by Red Hat, Debian, Fedora, and possibly others, does not properly drop supplementary groups, w...
CVE-2012-2351The default configuration of the auth/saml plugin in Mahara before 1.4.2 sets the "Match username attribute to Remote us...
CVE-2012-1174The rm_rf_children function in util.c in the systemd-logind login manager in systemd before 44, when logging out, allows...
CVE-2012-1163Integer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to execute arbitrary...
CVE-2012-1162Heap-based buffer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to cause a...
CVE-2012-1037PHP remote file inclusion vulnerability in front/popup.php in GLPI 0.78 through 0.80.61 allows remote authenticated user...
CVE-2012-0215model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict a...
CVE-2012-3996TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (...
CVE-2012-3881Multiple SQL injection vulnerabilities in RTG 0.7.4 and RTG2 0.9.2 allow remote attackers to execute arbitrary SQL comma...
CVE-2012-3805Multiple cross-site scripting (XSS) vulnerabilities in the getAllPassedParams function in system/functions.php in Kajona...
CVE-2012-3399Config/diff.php in Basilic 1.5.14 allows remote attackers to execute arbitrary commands via shell metacharacters in the ...
CVE-2012-3376DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNo...
CVE-2012-2763Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and p...
CVE-2012-1620slock 0.9 does not properly handle the XRaiseWindow event when the screen is locked, which might allow physically proxim...
CVE-2012-3076The administrative web interface on Cisco TelePresence Recording Server before 1.8.0 allows remote authenticated users t...
CVE-2012-3075The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1.7.4 allows remote authenticat...
CVE-2012-3074An unspecified API on Cisco TelePresence Immersive Endpoint Devices before 1.9.1 allows remote attackers to execute arbi...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now