2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-1667ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1...
CVE-2012-1173Multiple integer overflows in tiff_getimage.c in LibTIFF 3.9.4 allow remote attackers to execute arbitrary code via a cr...
CVE-2012-0944Aptdaemon 0.43 and earlier in Ubuntu 11.04, 11.10, and 12.04 LTS does not authenticate packages when the transaction is ...
CVE-2012-0862builtins.c in Xinetd before 2.3.15 does not check the service type when the tcpmux-server service is enabled, which expo...
CVE-2012-0815The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service...
CVE-2012-0061The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly validate region tags, which allows user-...
CVE-2012-0060RPM before 4.9.1.3 does not properly validate region tags, which allows remote attackers to cause a denial of service (c...
CVE-2012-1255SQL injection vulnerability in Segue 2.2.10.2 and earlier allows remote attackers to execute arbitrary SQL commands via ...
CVE-2012-1254Cross-site scripting (XSS) vulnerability in Segue 2.2.10.2 and earlier allows remote attackers to inject arbitrary web s...
CVE-2012-1251Opera before 9.63 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers...
CVE-2012-1250Logitec LAN-W300N/R routers with firmware before 2.27 do not properly restrict login access, which allows remote attacke...
CVE-2012-2630The Puella Magi Madoka Magica iP application 1.05 and earlier for Android places cleartext Twitter credentials in a log ...
CVE-2012-1253Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.7, when Internet Explorer is used, allows remote ...
CVE-2012-1252Cross-site scripting (XSS) vulnerability in RSSOwl before 2.1.1 allows remote attackers to inject arbitrary web script o...
CVE-2012-2948chan_skinny.c in the Skinny (aka SCCP) channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Asterisk...
CVE-2012-2947chan_iax2.c in the IAX2 channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Asterisk Open Source 1....
CVE-2012-2944Buffer overflow in the addchar function in common/parseconf.c in upsd in Network UPS Tools (NUT) before 2.6.4 allows rem...
CVE-2012-2752Untrusted search path vulnerability in VMware vMA 4.x and 5.x before 5.0.0.2 allows local users to gain privileges via a...
CVE-2012-0409Multiple buffer overflows in EMC AutoStart 5.3.x and 5.4.x before 5.4.3 allow remote attackers to cause a denial of serv...
CVE-2012-2352The archive management (arc_manage) page in wwsympa/wwsympa.fcgi.in in Sympa before 6.1.11 does not check permissions, w...
CVE-2012-0949The Apport hook in Update Manager as used by Ubuntu 12.04 LTS, 11.10, and 11.04 uploads certain system state archive fil...
CVE-2012-2488Cisco IOS XR before 4.2.1 on ASR 9000 series devices and CRS series devices allows remote attackers to cause a denial of...
CVE-2012-2952SQL injection vulnerability in add_ons.php in Jaow 2.4.5 and earlier allows remote attackers to execute arbitrary SQL co...
CVE-2012-2951Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-6587. Reason: This candidate is a duplicate of...
CVE-2012-1988Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x b...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now