2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-3838Gekko before 1.2.0 allows remote attackers to obtain the installation path via a direct request to (1) admin/templates/b...
CVE-2012-3837Multiple cross-site scripting (XSS) vulnerabilities in apps/users/registration.template.php in Baby Gekko 1.2.0 and earl...
CVE-2012-3836Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko before 1.2.0 allow remote attackers to inject arbitrar...
CVE-2012-3835Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 3....
CVE-2012-3834SQL injection vulnerability in forensics/base_qry_main.php in AlienVault Open Source Security Information Management (OS...
CVE-2012-3833Cross-site scripting (XSS) vulnerability in the default index page in admin/ in Quick.CMS 4.0 allows remote attackers to...
CVE-2012-3832Cross-site scripting (XSS) vulnerability in decoda/Decoda.php in Decoda before 3.2 allows remote attackers to inject arb...
CVE-2012-3831Cross-site scripting (XSS) vulnerability in decoda/templates/video.php in Decoda before 3.3.1 allows remote attackers to...
CVE-2012-3830Cross-site scripting (XSS) vulnerability in decoda/templates/video.php in Decoda before 3.3.3 allows remote attackers to...
CVE-2012-3829Joomla! 2.5.3 allows remote attackers to obtain the installation path via the Host HTTP Header.
CVE-2012-3828Cross-site scripting (XSS) vulnerability in Joomla! 2.5.3 allows remote attackers to inject arbitrary web script or HTML...
CVE-2012-2314The bootloader configuration module (pyanaconda/bootloader.py) in Anaconda uses 755 permissions for /etc/grub.d, which a...
CVE-2012-3368Integer signedness error in attach.c in dtach 0.8 allows remote attackers to obtain sensitive information from daemon st...
CVE-2012-2181Directory traversal vulnerability in the Dojo module in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF14, and 8.0, a...
CVE-2012-3811Unrestricted file upload vulnerability in ImageUpload.ashx in the Wallboard application in Avaya IP Office Customer Call...
CVE-2012-2748Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allows remote attackers to obtain sensitive information via vect...
CVE-2012-2747Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allows remote attackers to gain privileges via unknown attack ve...
CVE-2012-2318msg.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.4 does not properly handle crafted characters, which...
CVE-2012-2214proxy.c in libpurple in Pidgin before 2.10.4 does not properly handle canceled SOCKS5 connection attempts, which allows ...
CVE-2012-1148Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to...
CVE-2012-1147readfilemap.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (file descriptor con...
CVE-2012-0876The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash c...
CVE-2012-3366The Trigger plugin in bcfg2 1.2.x before 1.2.3 allows remote attackers with root access to the client to execute arbitra...
CVE-2012-2746389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), when the password of a LDAP user ha...
CVE-2012-2678389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user ...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now