2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-2428 | — | — | 4.6% | May 25, 2012 | Integer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via a crafted pa... |
| CVE-2012-2427 | — | — | 4.0% | May 25, 2012 | Heap-based buffer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via pa... |
| CVE-2012-2426 | — | — | 2.2% | May 25, 2012 | The server in xArrow before 3.4.1 does not properly allocate memory, which allows remote attackers to cause a denial of ... |
| CVE-2012-1824 | — | — | 0.5% | May 25, 2012 | Untrusted search path vulnerability in Measuresoft ScadaPro Client before 4.0.0 and ScadaPro Server before 4.0.0 allows ... |
| CVE-2012-2042 | — | — | 3.8% | May 24, 2012 | Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption)... |
| CVE-2012-1821 | — | — | 2.9% | May 24, 2012 | The Network Threat Protection module in the Manager component in Symantec Endpoint Protection (SEP) 11.0.600x through 11... |
| CVE-2012-1172 | — | — | 6.4% | May 24, 2012 | The file-upload implementation in rfc1867.c in PHP before 5.4.0 does not properly handle invalid [ (open square bracket)... |
| CVE-2012-0295 | — | — | 4.0% | May 23, 2012 | The Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remo... |
| CVE-2012-0294 | — | — | 1.6% | May 23, 2012 | Directory traversal vulnerability in the Manager service in the management console in Symantec Endpoint Protection (SEP)... |
| CVE-2012-0289 | — | — | 1.5% | May 23, 2012 | Buffer overflow in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.710x and Symantec Network Access Control (S... |
| CVE-2012-2374 | — | — | 1.4% | May 23, 2012 | CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote... |
| CVE-2012-2369 | — | — | 3.6% | May 23, 2012 | Format string vulnerability in the log_message_cb function in otr-plugin.c in the Off-the-Record Messaging (OTR) pidgin-... |
| CVE-2012-2759 | — | — | 2.2% | May 22, 2012 | Cross-site scripting (XSS) vulnerability in login-with-ajax.php in the Login With Ajax (aka login-with-ajax) plugin befo... |
| CVE-2012-1990 | — | — | 1.6% | May 22, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric Kerweb before 3.0.1 and Kerwin before 6.0.1 al... |
| CVE-2012-2928 | — | — | 3.1% | May 22, 2012 | The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict t... |
| CVE-2012-2927 | — | — | 1.3% | May 22, 2012 | The TM Software Tempo plugin before 6.4.3.1, 6.5.x before 6.5.0.2, and 7.x before 7.0.3 for Atlassian JIRA does not prop... |
| CVE-2012-2926 | CRITICAL | 9.1 | 66.6% | May 22, 2012 | Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible bef... |
| CVE-2012-2567 | — | — | 1.4% | May 22, 2012 | The Xelex MobileTrack application 2.3.7 and earlier for Android uses hardcoded credentials, which allows remote attacker... |
| CVE-2012-2562 | — | — | 2.2% | May 22, 2012 | The Xelex MobileTrack application 2.3.7 and earlier for Android does not verify the origin of SMS commands, which allows... |
| CVE-2012-2925 | — | — | 1.1% | May 21, 2012 | SQL injection vulnerability in engine.php in Simple PHP Agenda 2.2.8 allows remote attackers to execute arbitrary SQL co... |
| CVE-2012-2924 | — | — | 2.6% | May 21, 2012 | PHP remote file inclusion vulnerability in admin/setup.inc.php in Hypermethod eLearning Server 4G allows remote attacker... |
| CVE-2012-2923 | — | — | 1.1% | May 21, 2012 | SQL injection vulnerability in news.php4 in Hypermethod eLearning Server 4G allows remote attackers to execute arbitrary... |
| CVE-2012-2922 | — | — | 3.0% | May 21, 2012 | The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensiti... |
| CVE-2012-2921 | — | — | 1.9% | May 21, 2012 | Universal Feed Parser (aka feedparser or python-feedparser) before 5.1.2 allows remote attackers to cause a denial of se... |
| CVE-2012-2920 | — | — | 2.2% | May 21, 2012 | Cross-site scripting (XSS) vulnerability in the userphoto_options_page function in user-photo.php in the User Photo plug... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now