2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-1121MantisBT before 1.2.9 does not properly check permissions, which allows remote authenticated users with manager privileg...
CVE-2012-1120The SOAP API in MantisBT before 1.2.9 does not properly enforce the bugnote_allow_user_edit_delete and delete_bug_thresh...
CVE-2012-1119MantisBT before 1.2.9 does not audit when users copy or clone a bug report, which makes it easier for remote attackers t...
CVE-2012-1118The access_has_bug_level function in core/access_api.php in MantisBT before 1.2.9 does not properly restrict access when...
CVE-2012-0813Wicd before 1.7.1 saves sensitive information in log files in /var/log/wicd, which allows context-dependent attackers to...
CVE-2012-3818The fpm exporter in Revelation 0.4.13-2 and earlier encrypts the version number but not the password when exporting a fi...
CVE-2012-3232Cross-site scripting (XSS) vulnerability in search.php in web@all 2.0, as downloaded before May 30, 2012, allows remote ...
CVE-2012-3057Heap-based buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 L through SP11 EP26, T27 LB through SP21...
CVE-2012-3056Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 ...
CVE-2012-3055Stack-based buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 L through SP11 EP26, T27 LB through SP2...
CVE-2012-3054Heap-based buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 L through SP11 EP26, T27 LB through SP21...
CVE-2012-3053Buffer overflow in the Cisco WebEx Advanced Recording Format (ARF) player T27 L through SP11 EP26, T27 LB through SP21 E...
CVE-2012-3231Multiple cross-site request forgery (CSRF) vulnerabilities in web@all 2.0, as downloaded before May 30, 2012, allow remo...
CVE-2012-2743Revelation 0.4.13-2 and earlier does not iterate through SHA hashing algorithms for AES encryption, which makes it easie...
CVE-2012-2742Revelation 0.4.13-2 and earlier uses only the first 32 characters of a password followed by a sequence of zeros, which r...
CVE-2012-3816WinRadius Server 2009 allows remote attackers to cause a denial of service (crash) via a long password in an Access-Requ...
CVE-2012-3815Buffer overflow in RunTime.exe in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 al...
CVE-2012-3814Unrestricted file upload vulnerability in font-upload.php in the Font Uploader plugin 1.2.4 for WordPress allows remote ...
CVE-2012-2717Multiple cross-site scripting (XSS) vulnerabilities in the Mobile Tools module 6.x-2.x before 6.x-2.3 for Drupal allow r...
CVE-2012-2451The Config::IniFiles module before 2.71 for Perl creates temporary files with predictable names, which allows local user...
CVE-2012-2388The GMP Plugin in strongSwan 4.2.0 through 4.6.3 allows remote attackers to bypass authentication via a (1) empty or (2)...
CVE-2012-3802Unspecified vulnerability in the Post Affiliate Pro (PAP) module for Drupal allows remote authenticated users to read th...
CVE-2012-1989telnet.rb in Puppet 2.7.x before 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows local use...
CVE-2012-2834Integer overflow in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service or possibly h...
CVE-2012-2833Buffer overflow in the JS API in the PDF functionality in Google Chrome before 20.0.1132.43 allows remote attackers to c...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now