2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-0694CRITICAL9.8SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers ...
CVE-2012-2945HIGH7.5Hadoop 1.0.3 contains a symlink vulnerability.
CVE-2012-1187CRITICAL9.8Bitlbee does not drop extra group privileges correctly in unix.c
CVE-2012-0046HIGH7.5mediawiki allows deleted text to be exposed
CVE-2012-5577HIGH7.5Python keyring lib before 0.10 created keyring files with world-readable permissions.
CVE-2012-6719The sharebar plugin before 1.2.2 for WordPress has SQL injection.
CVE-2012-6718The sharebar plugin before 1.2.2 for WordPress has XSS, a different issue than CVE-2013-3491.
CVE-2012-6717The redirection plugin before 2.2.12 for WordPress has XSS, a different issue than CVE-2011-4562.
CVE-2012-6716The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links.
CVE-2012-6714The count-per-day plugin before 3.2.3 for WordPress has XSS via search words.
CVE-2012-6715The formbuilder plugin before 0.9.1 for WordPress has XSS via a Referer header.
CVE-2012-6713The job-manager plugin before 0.7.19 for WordPress has multiple XSS issues.
CVE-2012-6712CRITICAL9.8In the Linux kernel before 3.4, a buffer overflow occurs in drivers/net/wireless/iwlwifi/iwl-agn-sta.c, which will cause...
CVE-2012-6711HIGH7A heap-based buffer overflow exists in GNU Bash before 4.3 when wide characters, not supported by the current locale set...
CVE-2012-6652Directory traversal vulnerability in pageflipbook.php script from index.php in Page Flip Book plugin for WordPress (wppa...
CVE-2012-6710ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empt...
CVE-2012-0721Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2012-0433LOW3.3The install-chef-suse.sh script shipped with crowbar before 2012-10-02 is creating files containing confidential data wi...
CVE-2012-5628gofer before 0.68 uses world-writable permissions for /var/lib/gofer/journal/watchdog, which allows local users to cause...
CVE-2012-3536Two XSS vulnerabilities were fixed in message list and view in the Hupa Webmail application from the Apache James projec...
CVE-2012-6709ELinks 0.12 and Twibright Links 2.3 have Missing SSL Certificate Validation.
CVE-2012-0771Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory...
CVE-2012-6347Multiple cross-site scripting (XSS) vulnerabilities in Java number format exception handling in FortiGate FortiDB before...
CVE-2012-6346Multiple cross-site scripting (XSS) vulnerabilities in FortiWeb before 4.4.4 allow remote attackers to inject arbitrary ...
CVE-2012-5360Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted QT file.

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now