2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-0333Cisco Small Business IP phones with SPA 500 series firmware 7.4.9 and earlier do not require authentication for Push XML...
CVE-2012-0279Quest Toad for Data Analysts 3.0.1 uses weak permissions (Everyone: Full Control) for the %COMMONPROGRAMFILES%\Quest Sha...
CVE-2012-2162The Web Server Plug-in in IBM WebSphere Application Server (WAS) 8.0 and earlier uses unencrypted HTTP communication aft...
CVE-2012-0878Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which migh...
CVE-2012-2217The HTC IQRD service for Android on the HTC EVO 4G before 4.67.651.3, EVO Design 4G before 2.12.651.5, Shift 4G before 2...
CVE-2012-1521Use-after-free vulnerability in the XML parser in Google Chrome before 18.0.1025.168 allows remote attackers to cause a ...
CVE-2012-2416chan_sip.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.11.1 and 10.x before 10.3.1 and Asterisk B...
CVE-2012-2415Heap-based buffer overflow in chan_skinny.c in the Skinny channel driver in Asterisk Open Source 1.6.2.x before 1.6.2.24...
CVE-2012-2414main/manager.c in the Manager Interface in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x...
CVE-2012-2111The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in ...
CVE-2012-0863Mumble 1.2.3 and earlier uses world-readable permissions for .local/share/data/Mumble/.mumble.sqlite files in home direc...
CVE-2012-2213Squid 3.1.9 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary ...
CVE-2012-2212McAfee Web Gateway 7.0 allows remote attackers to bypass the access configuration for the CONNECT method by providing an...
CVE-2012-2441RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address fi...
CVE-2012-2440The default configuration of the TP-Link 8840T router enables web-based administration on the WAN interface, which allow...
CVE-2012-2439The default configuration of the NETGEAR ProSafe FVS318N firewall enables web-based administration on the WAN interface,...
CVE-2012-1803RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Ad...
CVE-2012-0466template/en/default/list/list.js.tmpl in Bugzilla 2.x and 3.x before 3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and ...
CVE-2012-0465Bugzilla 3.5.x and 3.6.x before 3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and 4.2.x before 4.2.1, when the inbound_...
CVE-2012-1244The NTT DOCOMO sp mode mail application 5400 and earlier for Android does not properly verify X.509 certificates from SS...
CVE-2012-1242Untrusted search path vulnerability in JustSystems Ichitaro 2011 Sou, Ichitaro 2006 through 2011, Ichitaro Government 20...
CVE-2012-0269Buffer overflow in JustSystems Ichitaro 2011 Sou, Ichitaro 2006 through 2011, Ichitaro Government 2006 through 2010, Ich...
CVE-2012-1245Cross-site scripting (XSS) vulnerability in the cleanup_urls function in forum/utils/html.py in OSQA before 1234, and 0....
CVE-2012-2425The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit ...
CVE-2012-2424The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit ...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now