2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-2949 | — | — | 3.6% | May 29, 2012 | The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control acce... |
| CVE-2012-2943 | — | — | 2.0% | May 27, 2012 | CRLF injection vulnerability in cryptographp.inc.php in Cryptographp allows remote attackers to inject arbitrary HTTP he... |
| CVE-2012-2942 | — | — | 5.4% | May 27, 2012 | Buffer overflow in the trash buffer in the header capture functionality in HAProxy before 1.4.21, when global.tune.bufsi... |
| CVE-2012-2941 | — | — | 1.6% | May 27, 2012 | Cross-site scripting (XSS) vulnerability in search/ in Yandex.Server 2010 9.0 Enterprise allows remote attackers to inje... |
| CVE-2012-2940 | — | — | 2.5% | May 27, 2012 | MediaChance Real-DRAW PRO 5.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted (... |
| CVE-2012-2939 | — | — | 3.9% | May 27, 2012 | Multiple unrestricted file upload vulnerabilities in Travelon Express 6.2.2 allow remote authenticated users to execute ... |
| CVE-2012-2938 | — | — | 1.8% | May 27, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in Travelon Express 6.2.2 allow remote attackers to inject arbitrary... |
| CVE-2012-2937 | — | — | 2.5% | May 27, 2012 | Multiple SQL injection vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to execute arbitrary SQL command... |
| CVE-2012-2936 | — | — | 1.4% | May 27, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to inject arbitrary... |
| CVE-2012-2436 | — | — | 2.5% | May 27, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to inject arbitrary... |
| CVE-2012-2435 | — | — | 1.6% | May 27, 2012 | Directory traversal vulnerability in the captcha module in Pligg CMS before 1.2.2 allows remote authenticated users to i... |
| CVE-2012-2935 | — | — | 0.9% | May 27, 2012 | Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Checkout/pages/main.php in OSCommer... |
| CVE-2012-2235 | — | — | 1.0% | May 27, 2012 | Cross-site scripting (XSS) vulnerability in Support Incident Tracker (SiT!) 3.65 and earlier allows remote attackers to ... |
| CVE-2012-1792 | — | — | 0.9% | May 27, 2012 | Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Setup/Application/Install/RPC/DBCheck.php in OSComme... |
| CVE-2012-1413 | — | — | 0.9% | May 27, 2012 | Cross-site scripting (XSS) vulnerability in zc_install/includes/modules/pages/database_setup/header_php.php in Zen Cart ... |
| CVE-2012-2568 | — | — | 4.4% | May 25, 2012 | d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attacke... |
| CVE-2012-2176 | — | — | 31.2% | May 25, 2012 | Multiple stack-based buffer overflows in a certain ActiveX control in qp2.cab in IBM Lotus Quickr 8.2 before 8.2.0.27-00... |
| CVE-2012-2429 | — | — | 3.8% | May 25, 2012 | The server in xArrow before 3.4.1 performs an invalid read operation, which allows remote attackers to execute arbitrary... |
| CVE-2012-2428 | — | — | 4.6% | May 25, 2012 | Integer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via a crafted pa... |
| CVE-2012-2427 | — | — | 4.0% | May 25, 2012 | Heap-based buffer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via pa... |
| CVE-2012-2426 | — | — | 2.2% | May 25, 2012 | The server in xArrow before 3.4.1 does not properly allocate memory, which allows remote attackers to cause a denial of ... |
| CVE-2012-1824 | — | — | 0.5% | May 25, 2012 | Untrusted search path vulnerability in Measuresoft ScadaPro Client before 4.0.0 and ScadaPro Server before 4.0.0 allows ... |
| CVE-2012-2042 | — | — | 3.8% | May 24, 2012 | Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption)... |
| CVE-2012-1821 | — | — | 2.9% | May 24, 2012 | The Network Threat Protection module in the Manager component in Symantec Endpoint Protection (SEP) 11.0.600x through 11... |
| CVE-2012-1172 | — | — | 6.4% | May 24, 2012 | The file-upload implementation in rfc1867.c in PHP before 5.4.0 does not properly handle invalid [ (open square bracket)... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now