2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-2428Integer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via a crafted pa...
CVE-2012-2427Heap-based buffer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via pa...
CVE-2012-2426The server in xArrow before 3.4.1 does not properly allocate memory, which allows remote attackers to cause a denial of ...
CVE-2012-1824Untrusted search path vulnerability in Measuresoft ScadaPro Client before 4.0.0 and ScadaPro Server before 4.0.0 allows ...
CVE-2012-2042Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption)...
CVE-2012-1821The Network Threat Protection module in the Manager component in Symantec Endpoint Protection (SEP) 11.0.600x through 11...
CVE-2012-1172The file-upload implementation in rfc1867.c in PHP before 5.4.0 does not properly handle invalid [ (open square bracket)...
CVE-2012-0295The Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remo...
CVE-2012-0294Directory traversal vulnerability in the Manager service in the management console in Symantec Endpoint Protection (SEP)...
CVE-2012-0289Buffer overflow in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.710x and Symantec Network Access Control (S...
CVE-2012-2374CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote...
CVE-2012-2369Format string vulnerability in the log_message_cb function in otr-plugin.c in the Off-the-Record Messaging (OTR) pidgin-...
CVE-2012-2759Cross-site scripting (XSS) vulnerability in login-with-ajax.php in the Login With Ajax (aka login-with-ajax) plugin befo...
CVE-2012-1990Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric Kerweb before 3.0.1 and Kerwin before 6.0.1 al...
CVE-2012-2928The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict t...
CVE-2012-2927The TM Software Tempo plugin before 6.4.3.1, 6.5.x before 6.5.0.2, and 7.x before 7.0.3 for Atlassian JIRA does not prop...
CVE-2012-2926CRITICAL9.1Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible bef...
CVE-2012-2567The Xelex MobileTrack application 2.3.7 and earlier for Android uses hardcoded credentials, which allows remote attacker...
CVE-2012-2562The Xelex MobileTrack application 2.3.7 and earlier for Android does not verify the origin of SMS commands, which allows...
CVE-2012-2925SQL injection vulnerability in engine.php in Simple PHP Agenda 2.2.8 allows remote attackers to execute arbitrary SQL co...
CVE-2012-2924PHP remote file inclusion vulnerability in admin/setup.inc.php in Hypermethod eLearning Server 4G allows remote attacker...
CVE-2012-2923SQL injection vulnerability in news.php4 in Hypermethod eLearning Server 4G allows remote attackers to execute arbitrary...
CVE-2012-2922The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensiti...
CVE-2012-2921Universal Feed Parser (aka feedparser or python-feedparser) before 5.1.2 allows remote attackers to cause a denial of se...
CVE-2012-2920Cross-site scripting (XSS) vulnerability in the userphoto_options_page function in user-photo.php in the User Photo plug...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now