2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-5359 | — | — | 3.3% | Feb 8, 2018 | Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted ASF file. |
| CVE-2012-3331 | — | — | 1.7% | Feb 8, 2018 | IBM Sametime allows remote attackers to obtain sensitive information from the Sametime Log database via a direct request... |
| CVE-2012-2166 | — | — | 2.8% | Feb 8, 2018 | IBM XIV Storage System 2810-A14 and 2812-A14 devices before level 10.2.4.e-2 and 2810-114 and 2812-114 devices before le... |
| CVE-2012-0941 | — | — | 1.4% | Feb 8, 2018 | Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiGate UTM WAF appliances with FortiOS 4.3.x before 4... |
| CVE-2012-3878 | — | — | — | Jan 30, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2012-6708 | — | — | 8.8% | Jan 18, 2018 | jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differen... |
| CVE-2012-6682 | — | — | 1.7% | Jan 11, 2018 | Cross-site scripting (XSS) vulnerability in downloads/actions/editdownload.php in the DragonByte Technologies vBDownload... |
| CVE-2012-6671 | — | — | 1.6% | Jan 11, 2018 | Multiple cross-site scripting (XSS) vulnerabilities in actions/main.php in the DragonByte Technologies Forumon RPG modul... |
| CVE-2012-6670 | — | — | 1.7% | Jan 11, 2018 | Multiple cross-site scripting (XSS) vulnerabilities in the DragonByte Technologies vbActivity module before 3.0.1 for vB... |
| CVE-2012-6668 | — | — | 1.7% | Jan 11, 2018 | Multiple cross-site scripting (XSS) vulnerabilities in the Shout Reports in the DragonByte Technologies vBShout module b... |
| CVE-2012-0699 | — | — | 3.6% | Jan 11, 2018 | Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow re... |
| CVE-2012-6667 | — | — | 4.2% | Jan 11, 2018 | Cross-site scripting (XSS) vulnerability in vbshout.php in DragonByte Technologies vBShout module for vBulletin allows r... |
| CVE-2012-3353 | — | — | 3.1% | Jan 9, 2018 | The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to impo... |
| CVE-2012-2576 | — | — | 59.1% | Dec 20, 2017 | SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Prof... |
| CVE-2012-2456 | — | — | — | Nov 13, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-5174. Reason: This candidate is a reservation ... |
| CVE-2012-5636 | — | — | 3.1% | Oct 30, 2017 | Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.22, 1.5.x before 1.5.10, and 6.x before 6.4.0... |
| CVE-2012-4449 | — | — | 1.2% | Oct 30, 2017 | Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when ... |
| CVE-2012-0881 | — | — | 17.1% | Oct 30, 2017 | Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a cr... |
| CVE-2012-5358 | — | — | 1.9% | Oct 30, 2017 | The XSLTCompiledTransform function in Ektron Content Management System (CMS) before 8.02 SP5 configures the XSL with ena... |
| CVE-2012-5357 | — | — | 67.8% | Oct 30, 2017 | Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true... |
| CVE-2012-4378 | — | — | 1.5% | Oct 26, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.18.5 and 1.19.x before 1.19.2, when unspecifie... |
| CVE-2012-4377 | — | — | 1.6% | Oct 26, 2017 | Cross-site scripting (XSS) vulnerability in MediaWiki before 1.18.5 and 1.19.x before 1.19.2 allows remote attackers to ... |
| CVE-2012-1622 | — | — | 5.0% | Oct 26, 2017 | Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors. |
| CVE-2012-4570 | — | — | 1.9% | Oct 23, 2017 | SQL injection vulnerability in LetoDMS_Core/Core/inc.ClassDMS.php in LetoDMS (formerly MyDMS) before 3.3.8 allows remote... |
| CVE-2012-4569 | — | — | 1.3% | Oct 23, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in out/out.UsrMgr.php in LetoDMS (formerly MyDMS) before 3.3.9 allow... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now