2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-2179 | — | — | 1.7% | Jun 22, 2012 | libodm.a in IBM AIX 5.3, 6.1, and 7.1 allows local users to overwrite arbitrary files via a symlink attack on a temporar... |
| CVE-2012-2172 | — | — | 1.6% | Jun 22, 2012 | Cross-site scripting (XSS) vulnerability in SoftwareRegistration.do in the Storage Manager Profiler in IBM System Storag... |
| CVE-2012-2171 | — | — | 5.1% | Jun 22, 2012 | SQL injection vulnerability in ModuleServlet.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager... |
| CVE-2012-0304 | — | — | 0.3% | Jun 22, 2012 | Symantec LiveUpdate Administrator before 2.3.1 uses weak permissions (Everyone: Full Control) for the installation direc... |
| CVE-2012-0191 | — | — | 1.0% | Jun 22, 2012 | The web container in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack does not properly perform access c... |
| CVE-2012-0187 | — | — | 1.6% | Jun 22, 2012 | Untrusted search path vulnerability in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack allows local use... |
| CVE-2012-0186 | — | — | 1.6% | Jun 22, 2012 | Directory traversal vulnerability in the Eclipse Help component in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Se... |
| CVE-2012-2127 | — | — | 4.3% | Jun 21, 2012 | fs/proc/root.c in the procfs implementation in the Linux kernel before 3.2 does not properly interact with CLONE_NEWPID ... |
| CVE-2012-0028 | — | — | 0.5% | Jun 21, 2012 | The robust futex implementation in the Linux kernel before 2.6.28 does not properly handle processes that make exec syst... |
| CVE-2012-3791 | — | — | 1.3% | Jun 21, 2012 | Multiple SQL injection vulnerabilities in Simple Web Content Management System 1.1 allow remote attackers to execute arb... |
| CVE-2012-2718 | — | — | 1.9% | Jun 21, 2012 | SQL injection vulnerability in the Counter module for Drupal allows remote attackers to execute arbitrary SQL commands v... |
| CVE-2012-2716 | — | — | 0.8% | Jun 21, 2012 | Cross-site request forgery (CSRF) vulnerability in the Comment Moderation module 6.x-1.x before 6.x-1.1 for Drupal allow... |
| CVE-2012-2654 | — | — | 2.6% | Jun 21, 2012 | The (1) EC2 and (2) OS APIs in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) do not prop... |
| CVE-2012-2389 | — | — | 0.4% | Jun 21, 2012 | hostapd 0.7.3, and possibly other versions before 1.0, uses 0644 permissions for /etc/hostapd/hostapd.conf, which might ... |
| CVE-2012-2149 | — | — | 13.4% | Jun 21, 2012 | The WPXContentListener::_closeTableRow function in WPXContentListener.cpp in libwpd 0.8.8, as used by OpenOffice.org (OO... |
| CVE-2012-1616 | — | — | 4.8% | Jun 21, 2012 | Use-after-free vulnerability in icclib before 2.13, as used by Argyll CMS before 1.4 and possibly other programs, allows... |
| CVE-2012-1149 | — | — | 13.7% | Jun 21, 2012 | Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice be... |
| CVE-2012-0219 | — | — | 0.5% | Jun 21, 2012 | Heap-based buffer overflow in the xioscan_readline function in xio-readline.c in socat 1.4.0.0 through 1.7.2.0 and 2.0.0... |
| CVE-2012-3063 | — | — | 1.0% | Jun 20, 2012 | Cisco Application Control Engine (ACE) before A4(2.3) and A5 before A5(1.1), when multicontext mode is enabled, does not... |
| CVE-2012-3058 | — | — | 1.9% | Jun 20, 2012 | Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500... |
| CVE-2012-2496 | — | — | 2.0% | Jun 20, 2012 | A certain Java applet in the VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility ... |
| CVE-2012-2495 | — | — | 1.4% | Jun 20, 2012 | The HostScan downloader implementation in Cisco AnyConnect Secure Mobility Client 3.x before 3.0 MR8 and Cisco Secure De... |
| CVE-2012-2494 | — | — | 1.4% | Jun 20, 2012 | The VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2.x before 2.5 MR6... |
| CVE-2012-2493 | — | — | 3.9% | Jun 20, 2012 | The VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2.x before 2.5 MR6... |
| CVE-2012-3790 | — | — | 1.2% | Jun 20, 2012 | Cross-site scripting (XSS) vulnerability in index.php in Adiscon LogAnalyzer before 3.4.4 and 3.5.x before 3.5.5 allows ... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now