2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-2932 | — | — | 1.2% | Apr 24, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to injec... |
| CVE-2012-2930 | — | — | 0.7% | Apr 24, 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers t... |
| CVE-2012-2808 | — | — | 1.3% | Apr 1, 2015 | The PRNG implementation in the DNS resolver in Bionic in Android before 4.1.1 incorrectly uses time and PID information ... |
| CVE-2012-3541 | — | — | — | Feb 24, 2015 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2012-6687 | — | — | 6.1% | Feb 19, 2015 | FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial of service (segmentation fault and crash)... |
| CVE-2012-6684 | — | — | 2.3% | Jan 8, 2015 | Cross-site scripting (XSS) vulnerability in the RedCloth library 4.2.9 for Ruby and earlier allows remote attackers to i... |
| CVE-2012-5853 | — | — | 2.2% | Jan 8, 2015 | SQL injection vulnerability in the "the_search_function" function in cardoza_ajax_search.php in the AJAX Post Search (ca... |
| CVE-2012-1415 | — | — | 1.1% | Dec 28, 2014 | Cross-site request forgery (CSRF) vulnerability in lib/logout.php in DFLabs PTK 1.0.5 and earlier allows remote attacker... |
| CVE-2012-1303 | — | — | 1.0% | Dec 28, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in amCharts Flash 1 allow remote attackers to inject arbitrary web s... |
| CVE-2012-1302 | — | — | 1.8% | Dec 28, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in amMap 2.6.3 allow remote attackers to inject arbitrary web script... |
| CVE-2012-1203 | — | — | 1.1% | Dec 28, 2014 | Cross-site request forgery (CSRF) vulnerability in starnet/index.php in SyndeoCMS 3.0 and earlier allows remote attacker... |
| CVE-2012-6656 | — | — | 3.4% | Dec 5, 2014 | iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to cause a denial of serv... |
| CVE-2012-6662 | — | — | 6.5% | Nov 24, 2014 | Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in ... |
| CVE-2012-6665 | — | — | 3.1% | Nov 17, 2014 | Directory traversal vulnerability in index.php in phpMoneyBooks 1.0.4 allows remote attackers to read arbitrary files vi... |
| CVE-2012-1669 | — | — | 3.5% | Nov 17, 2014 | Directory traversal vulnerability in index.php in phpMoneyBooks before 1.0.3 allows remote attackers to include and exec... |
| CVE-2012-2301 | — | — | 1.2% | Nov 16, 2014 | The Ubercart module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer product cla... |
| CVE-2012-6661 | — | — | 2.3% | Nov 3, 2014 | Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number gener... |
| CVE-2012-5508 | — | — | 1.5% | Nov 3, 2014 | The error pages in Plone before 4.2.3 and 4.3 before beta 1 allow remote attackers to obtain random numbers and derive t... |
| CVE-2012-5500 | — | — | 1.1% | Nov 3, 2014 | The batch id change script (renameObjectsByPaths.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers... |
| CVE-2012-5580 | — | — | 3.1% | Oct 27, 2014 | Format string vulnerability in the print_proxies function in bin/proxy.c in libproxy 0.3.1 might allow context-dependent... |
| CVE-2012-1111 | — | — | 0.5% | Oct 27, 2014 | lightdm before 1.0.9 does not properly close file descriptors before opening a child process, which allows local users t... |
| CVE-2012-5702 | — | — | 2.1% | Oct 21, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrar... |
| CVE-2012-5243 | — | — | 2.8% | Oct 21, 2014 | functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information v... |
| CVE-2012-5242 | — | — | 2.5% | Oct 21, 2014 | Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to ... |
| CVE-2012-5697 | — | — | 0.4% | Oct 20, 2014 | The btinstall installation script in Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 uses weak permissions... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now