2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-1667 | — | — | 13.4% | Jun 5, 2012 | ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1... |
| CVE-2012-1173 | — | — | 6.9% | Jun 4, 2012 | Multiple integer overflows in tiff_getimage.c in LibTIFF 3.9.4 allow remote attackers to execute arbitrary code via a cr... |
| CVE-2012-0944 | — | — | 1.2% | Jun 4, 2012 | Aptdaemon 0.43 and earlier in Ubuntu 11.04, 11.10, and 12.04 LTS does not authenticate packages when the transaction is ... |
| CVE-2012-0862 | — | — | 2.8% | Jun 4, 2012 | builtins.c in Xinetd before 2.3.15 does not check the service type when the tcpmux-server service is enabled, which expo... |
| CVE-2012-0815 | — | — | 4.3% | Jun 4, 2012 | The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service... |
| CVE-2012-0061 | — | — | 4.4% | Jun 4, 2012 | The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly validate region tags, which allows user-... |
| CVE-2012-0060 | — | — | 4.8% | Jun 4, 2012 | RPM before 4.9.1.3 does not properly validate region tags, which allows remote attackers to cause a denial of service (c... |
| CVE-2012-1255 | — | — | 2.3% | Jun 4, 2012 | SQL injection vulnerability in Segue 2.2.10.2 and earlier allows remote attackers to execute arbitrary SQL commands via ... |
| CVE-2012-1254 | — | — | 1.4% | Jun 4, 2012 | Cross-site scripting (XSS) vulnerability in Segue 2.2.10.2 and earlier allows remote attackers to inject arbitrary web s... |
| CVE-2012-1251 | — | — | 0.6% | Jun 4, 2012 | Opera before 9.63 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers... |
| CVE-2012-1250 | — | — | 5.9% | Jun 4, 2012 | Logitec LAN-W300N/R routers with firmware before 2.27 do not properly restrict login access, which allows remote attacke... |
| CVE-2012-2630 | — | — | 1.1% | Jun 4, 2012 | The Puella Magi Madoka Magica iP application 1.05 and earlier for Android places cleartext Twitter credentials in a log ... |
| CVE-2012-1253 | — | — | 1.8% | Jun 4, 2012 | Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.7, when Internet Explorer is used, allows remote ... |
| CVE-2012-1252 | — | — | 0.9% | Jun 4, 2012 | Cross-site scripting (XSS) vulnerability in RSSOwl before 2.1.1 allows remote attackers to inject arbitrary web script o... |
| CVE-2012-2948 | — | — | 2.1% | Jun 2, 2012 | chan_skinny.c in the Skinny (aka SCCP) channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Asterisk... |
| CVE-2012-2947 | — | — | 2.3% | Jun 2, 2012 | chan_iax2.c in the IAX2 channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Asterisk Open Source 1.... |
| CVE-2012-2944 | — | — | 6.2% | Jun 1, 2012 | Buffer overflow in the addchar function in common/parseconf.c in upsd in Network UPS Tools (NUT) before 2.6.4 allows rem... |
| CVE-2012-2752 | — | — | 0.4% | Jun 1, 2012 | Untrusted search path vulnerability in VMware vMA 4.x and 5.x before 5.0.0.2 allows local users to gain privileges via a... |
| CVE-2012-0409 | — | — | 4.8% | Jun 1, 2012 | Multiple buffer overflows in EMC AutoStart 5.3.x and 5.4.x before 5.4.3 allow remote attackers to cause a denial of serv... |
| CVE-2012-2352 | — | — | 3.2% | May 31, 2012 | The archive management (arc_manage) page in wwsympa/wwsympa.fcgi.in in Sympa before 6.1.11 does not check permissions, w... |
| CVE-2012-0949 | — | — | 2.1% | May 31, 2012 | The Apport hook in Update Manager as used by Ubuntu 12.04 LTS, 11.10, and 11.04 uploads certain system state archive fil... |
| CVE-2012-2488 | — | — | 2.2% | May 31, 2012 | Cisco IOS XR before 4.2.1 on ASR 9000 series devices and CRS series devices allows remote attackers to cause a denial of... |
| CVE-2012-2952 | — | — | 2.4% | May 29, 2012 | SQL injection vulnerability in add_ons.php in Jaow 2.4.5 and earlier allows remote attackers to execute arbitrary SQL co... |
| CVE-2012-2951 | — | — | — | May 29, 2012 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-6587. Reason: This candidate is a duplicate of... |
| CVE-2012-1988 | — | — | 2.6% | May 29, 2012 | Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x b... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now