2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-0215model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict a...
CVE-2012-3996TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (...
CVE-2012-3881Multiple SQL injection vulnerabilities in RTG 0.7.4 and RTG2 0.9.2 allow remote attackers to execute arbitrary SQL comma...
CVE-2012-3805Multiple cross-site scripting (XSS) vulnerabilities in the getAllPassedParams function in system/functions.php in Kajona...
CVE-2012-3399Config/diff.php in Basilic 1.5.14 allows remote attackers to execute arbitrary commands via shell metacharacters in the ...
CVE-2012-3376DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNo...
CVE-2012-2763Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and p...
CVE-2012-1620slock 0.9 does not properly handle the XRaiseWindow event when the screen is locked, which might allow physically proxim...
CVE-2012-0911CRITICAL9.8TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted...
CVE-2012-3076The administrative web interface on Cisco TelePresence Recording Server before 1.8.0 allows remote authenticated users t...
CVE-2012-3075The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1.7.4 allows remote authenticat...
CVE-2012-3074An unspecified API on Cisco TelePresence Immersive Endpoint Devices before 1.9.1 allows remote attackers to execute arbi...
CVE-2012-3073The IP implementation on Cisco TelePresence Multipoint Switch before 1.8.1, Cisco TelePresence Manager before 1.9.0, and...
CVE-2012-2486The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1.9.0, Cisco TelePresen...
CVE-2012-3890The in_mod plugin in Winamp before 5.63 allows remote attackers to cause a denial of service (heap memory corruption) or...
CVE-2012-3889The in_mod plugin in Winamp before 5.63 allows remote attackers to cause a denial of service (memory corruption) or poss...
CVE-2012-2020Unspecified vulnerability in HP Operations Agent before 11.03.12 allows remote attackers to execute arbitrary code via u...
CVE-2012-2019Unspecified vulnerability in HP Operations Agent before 11.03.12 allows remote attackers to execute arbitrary code via u...
CVE-2012-1894Microsoft Office for Mac 2011 uses world-writable permissions for the "Applications/Microsoft Office 2011/" directory an...
CVE-2012-1893win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, W...
CVE-2012-1891CRITICAL9.8Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components...
CVE-2012-1890win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, W...
CVE-2012-1870The CBC mode in the TLS protocol, as used in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP...
CVE-2012-1863Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 Windows SharePoint Servi...
CVE-2012-1862Open redirect vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 allows remote attackers to redirect u...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now