2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2012-0810MEDIUM5.5The int3 handler in the Linux kernel before 3.3 relies on a per-CPU debug stack, which allows local users to cause a den...
CVE-2012-6721MEDIUM6.3Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Forum, (2) Event, and (3) Classifieds plugins in S...
CVE-2012-6720MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in SocialEngine before 4.2.4 allow remote attackers to inject arbitr...
CVE-2012-2517MEDIUM6.1Cross-site scripting (XSS) vulnerability in PrestaShop before 1.4.9 allows remote attackers to inject arbitrary web scri...
CVE-2012-2452MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in pragmaMx 1.x before 1.12.2 allow remote attackers to inject arbit...
CVE-2012-4519MEDIUM6.1Zenphoto before 1.4.3.4 admin-news-articles.php date parameter XSS.
CVE-2012-5828MEDIUM6.5BlackBerry PlayBook before 2.1 has an Information Disclosure Vulnerability via a Web browser component error
CVE-2012-2204MEDIUM5.5InfoSphere Guardium aix_ktap module: DoS
CVE-2012-1994MEDIUM5.7HP Systems Insight Manager before 7.0 allows a remote user on adjacent network to access information
CVE-2012-6449MEDIUM5.4The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability.
CVE-2012-6666MEDIUM6.1vBSeo before 3.6.0PL2 allows XSS via the member.php u parameter.
CVE-2012-5570MEDIUM4.3The Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allows remote authenticated users with the "access basic_webm...
CVE-2012-4029MEDIUM6.1Cross-site scripting (XSS) vulnerability in main/dropbox/index.php in Chamilo LMS before 1.8.8.6 allows remote attackers...
CVE-2012-6341MEDIUM6.5An Information Disclosure vulnerability exists in the my config file in NEtGEAR WGR614 v7 and v9, which could let a mali...
CVE-2012-6340MEDIUM4.6An Authentication vulnerability exists in NETGEAR WGR614 v7 and v9 due to a hardcoded credential used for serial program...
CVE-2012-2593MEDIUM6.1Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote atta...
CVE-2012-6133MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary ...
CVE-2012-5776MEDIUM5.4Dokeos 2.1.1 has multiple XSS issues involving "extra_" parameters in main/auth/profile.php.
CVE-2012-6114MEDIUM5.5The git-changelog utility in git-extras 1.7.0 allows local users to overwrite arbitrary files via a symlink attack on (1...
CVE-2012-6448MEDIUM6.1Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web scrip...
CVE-2012-6494MEDIUM6.1Rapid7 Nexpose before 5.5.4 contains a session hijacking vulnerability which allows remote attackers to capture a user's...
CVE-2012-6344MEDIUM6.1Novell ZENworks Configuration Management before 11.2.4 allows XSS.
CVE-2012-4900MEDIUM5.5Corel WordPerfect Office X6 16.0.0.388 has a DoS Vulnerability via untrusted pointer dereference
CVE-2012-4863MEDIUM6.5IBM WebSphere MQ 7.1 and 7.5: Queue manager has a DoS vulnerability
CVE-2012-1316MEDIUM5.9Cisco IronPort Web Security Appliance does not check for certificate revocation which could lead to MITM attacks

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now