2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-0717 | — | — | 1.1% | Jun 20, 2012 | IBM WebSphere Application Server 7.0 before 7.0.0.23, when a certain SSLv2 configuration with client authentication is u... |
| CVE-2012-0716 | — | — | 1.8% | Jun 20, 2012 | Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server 7.0 before 7.... |
| CVE-2012-3588 | — | — | 10.7% | Jun 19, 2012 | Directory traversal vulnerability in preview.php in the Plugin Newsletter plugin 1.5 for WordPress allows remote attacke... |
| CVE-2012-3587 | — | — | 1.7% | Jun 19, 2012 | APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG a... |
| CVE-2012-3553 | — | — | 1.7% | Jun 19, 2012 | chan_skinny.c in the Skinny (aka SCCP) channel driver in Asterisk Open Source 10.x before 10.5.1 allows remote authentic... |
| CVE-2012-2753 | — | — | 0.4% | Jun 19, 2012 | Untrusted search path vulnerability in TrGUI.exe in the Endpoint Connect (aka EPC) GUI in Check Point Endpoint Security ... |
| CVE-2012-2334 | — | — | 13.0% | Jun 19, 2012 | Integer overflow in filter/source/msfilter/msdffimp.cxx in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and... |
| CVE-2012-0954 | — | — | 2.2% | Jun 19, 2012 | APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG a... |
| CVE-2012-0950 | — | — | 1.8% | Jun 19, 2012 | The Apport hook (DistUpgradeApport.py) in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uploads the /va... |
| CVE-2012-0802 | — | — | 4.6% | Jun 19, 2012 | Multiple buffer overflows in Spamdyke before 4.3.0 might allow remote attackers to execute arbitrary code via vectors re... |
| CVE-2012-3006 | — | — | 1.2% | Jun 19, 2012 | The Innominate mGuard Smart HW before HW-101130 and BD before BD-101030, mGuard industrial RS, mGuard delta HW before HW... |
| CVE-2012-2638 | — | — | 1.1% | Jun 19, 2012 | Cross-site scripting (XSS) vulnerability in SmallPICT.cgi in SmallPICT before 2.7 allows remote attackers to inject arbi... |
| CVE-2012-2637 | — | — | 1.1% | Jun 19, 2012 | Cross-site scripting (XSS) vulnerability in KENT-WEB WEB PATIO 4.04 and earlier might allow remote attackers to inject a... |
| CVE-2012-2636 | — | — | 1.1% | Jun 19, 2012 | Cross-site scripting (XSS) vulnerability in KENT-WEB WEB PATIO 4.04 and earlier allows remote attackers to inject arbitr... |
| CVE-2012-3578 | — | — | 7.7% | Jun 17, 2012 | Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.1 and earlier for WordPress... |
| CVE-2012-3577 | — | — | 13.0% | Jun 17, 2012 | Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress... |
| CVE-2012-2693 | — | — | 0.3% | Jun 17, 2012 | libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the... |
| CVE-2012-2692 | — | — | 1.5% | Jun 17, 2012 | MantisBT before 1.2.11 does not check the delete_attachments_threshold permission when form_security_validation is set t... |
| CVE-2012-2691 | — | — | 3.8% | Jun 17, 2012 | The mc_issue_note_update function in the SOAP API in MantisBT before 1.2.11 does not properly check privileges, which al... |
| CVE-2012-2672 | — | — | 0.5% | Jun 17, 2012 | Oracle Mojarra 2.1.7 does not properly "clean up" the FacesContext reference during startup, which allows local users to... |
| CVE-2012-2671 | — | — | 2.4% | Jun 17, 2012 | The Rack::Cache rubygem 0.3.0 through 1.1 caches Set-Cookie and other sensitive headers, which allows attackers to obtai... |
| CVE-2012-2670 | — | — | 1.5% | Jun 17, 2012 | manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to ... |
| CVE-2012-2668 | — | — | 4.1% | Jun 17, 2012 | libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the ... |
| CVE-2012-2417 | — | — | 2.7% | Jun 17, 2012 | PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which red... |
| CVE-2012-2091 | — | — | 6.5% | Jun 17, 2012 | Multiple buffer overflows in FlightGear 2.6 and earlier and SimGear 2.6 and earlier allow user-assisted remote attackers... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now