2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-3350 | — | — | 2.9% | Jul 12, 2012 | SQL injection vulnerability in index.php in Webmatic 3.1.1 allows remote attackers to execute arbitrary SQL commands via... |
| CVE-2012-3236 | — | — | 10.7% | Jul 12, 2012 | fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and applic... |
| CVE-2012-2844 | — | — | 2.0% | Jul 12, 2012 | The PDF functionality in Google Chrome before 20.0.1132.57 does not properly handle JavaScript code, which allows remote... |
| CVE-2012-2843 | — | — | 1.7% | Jul 12, 2012 | Use-after-free vulnerability in Google Chrome before 20.0.1132.57 allows remote attackers to cause a denial of service o... |
| CVE-2012-2842 | — | — | 1.5% | Jul 12, 2012 | Use-after-free vulnerability in Google Chrome before 20.0.1132.57 allows remote attackers to cause a denial of service o... |
| CVE-2012-2614 | — | — | 4.1% | Jul 12, 2012 | Buffer overflow in programmer.exe in Lattice Diamond Programmer 1.4.2 allows user-assisted remote attackers to cause a d... |
| CVE-2012-1661 | — | — | 23.8% | Jul 12, 2012 | ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, wh... |
| CVE-2012-3362 | — | — | 0.9% | Jul 12, 2012 | Cross-site request forgery (CSRF) vulnerability in eXtplorer 2.1 RC3 and earlier allows remote attackers to hijack the a... |
| CVE-2012-2653 | — | — | 3.2% | Jul 12, 2012 | arpwatch 2.1a15, as used by Red Hat, Debian, Fedora, and possibly others, does not properly drop supplementary groups, w... |
| CVE-2012-2351 | — | — | 2.1% | Jul 12, 2012 | The default configuration of the auth/saml plugin in Mahara before 1.4.2 sets the "Match username attribute to Remote us... |
| CVE-2012-1174 | — | — | 0.3% | Jul 12, 2012 | The rm_rf_children function in util.c in the systemd-logind login manager in systemd before 44, when logging out, allows... |
| CVE-2012-1163 | — | — | 2.6% | Jul 12, 2012 | Integer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to execute arbitrary... |
| CVE-2012-1162 | — | — | 4.0% | Jul 12, 2012 | Heap-based buffer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to cause a... |
| CVE-2012-1037 | — | — | 1.3% | Jul 12, 2012 | PHP remote file inclusion vulnerability in front/popup.php in GLPI 0.78 through 0.80.61 allows remote authenticated user... |
| CVE-2012-0215 | — | — | 2.0% | Jul 12, 2012 | model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict a... |
| CVE-2012-3996 | — | — | 4.6% | Jul 12, 2012 | TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (... |
| CVE-2012-3881 | — | — | 1.1% | Jul 12, 2012 | Multiple SQL injection vulnerabilities in RTG 0.7.4 and RTG2 0.9.2 allow remote attackers to execute arbitrary SQL comma... |
| CVE-2012-3805 | — | — | 1.6% | Jul 12, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in the getAllPassedParams function in system/functions.php in Kajona... |
| CVE-2012-3399 | — | — | 65.3% | Jul 12, 2012 | Config/diff.php in Basilic 1.5.14 allows remote attackers to execute arbitrary commands via shell metacharacters in the ... |
| CVE-2012-3376 | — | — | 2.7% | Jul 12, 2012 | DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNo... |
| CVE-2012-2763 | — | — | 81.7% | Jul 12, 2012 | Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and p... |
| CVE-2012-1620 | — | — | 0.5% | Jul 12, 2012 | slock 0.9 does not properly handle the XRaiseWindow event when the screen is locked, which might allow physically proxim... |
| CVE-2012-3076 | — | — | 2.2% | Jul 12, 2012 | The administrative web interface on Cisco TelePresence Recording Server before 1.8.0 allows remote authenticated users t... |
| CVE-2012-3075 | — | — | 2.2% | Jul 12, 2012 | The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1.7.4 allows remote authenticat... |
| CVE-2012-3074 | — | — | 1.2% | Jul 12, 2012 | An unspecified API on Cisco TelePresence Immersive Endpoint Devices before 1.9.1 allows remote attackers to execute arbi... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now