2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-5491 | — | — | 1.2% | Sep 30, 2014 | z3c.form, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain the default form field ... |
| CVE-2012-5490 | — | — | 1.2% | Sep 30, 2014 | Cross-site scripting (XSS) vulnerability in kssdevel.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attack... |
| CVE-2012-5489 | — | — | 1.3% | Sep 30, 2014 | The App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21 and 3.13.x before 2.13.11, as used in P... |
| CVE-2012-5488 | — | — | 2.5% | Sep 30, 2014 | python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a craft... |
| CVE-2012-5487 | — | — | 1.7% | Sep 30, 2014 | The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticat... |
| CVE-2012-5486 | — | — | 2.4% | Sep 30, 2014 | ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attacker... |
| CVE-2012-5485 | — | — | 2.1% | Sep 30, 2014 | registerConfiglet.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via unsp... |
| CVE-2012-6110 | — | — | 0.4% | Sep 29, 2014 | bcron-exec in bcron before 0.10 does not close file descriptors associated with temporary files when running a cron job,... |
| CVE-2012-6107 | — | — | 2.2% | Sep 29, 2014 | Apache Axis2/C does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subje... |
| CVE-2012-5621 | — | — | 2.8% | Sep 29, 2014 | lib/engine/components/opal/opal-call.cpp in ekiga before 4.0.0 allows remote attackers to cause a denial of service (cra... |
| CVE-2012-5619 | — | — | 0.4% | Sep 29, 2014 | The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system entries in FAT file systems and other file... |
| CVE-2012-6657 | — | — | 0.5% | Sep 28, 2014 | The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action... |
| CVE-2012-5700 | — | — | 1.8% | Sep 22, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko before 1.2.2f allow remote attackers to inject arbitra... |
| CVE-2012-6659 | — | — | 0.9% | Sep 19, 2014 | Cross-site scripting (XSS) vulnerability in the admin interface in Phorum before 5.2.19 allows remote attackers to injec... |
| CVE-2012-2588 | — | — | 2.4% | Sep 19, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Enterprise 6.5 allow remote attackers to inject arbitr... |
| CVE-2012-6658 | — | — | 1.8% | Sep 17, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in SpiceWorks 5.3.75941 allow remote attackers to inject arbitrary w... |
| CVE-2012-2956 | — | — | 1.1% | Sep 17, 2014 | SQL injection vulnerability in SpiceWorks 5.3.75941 allows remote authenticated users to execute arbitrary SQL commands ... |
| CVE-2012-2583 | — | — | 3.7% | Sep 17, 2014 | Cross-site scripting (XSS) vulnerability in Mini Mail Dashboard Widget plugin 1.42 for WordPress allows remote attackers... |
| CVE-2012-1507 | — | — | 2.4% | Sep 17, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.7 allow remote attackers to inject arbitrary w... |
| CVE-2012-1506 | — | — | 1.3% | Sep 17, 2014 | SQL injection vulnerability in the updateStatus function in lib/models/benefits/Hsp.php in OrangeHRM before 2.7 allows r... |
| CVE-2012-1417 | — | — | 1.7% | Sep 17, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow ... |
| CVE-2012-1032 | — | — | 1.2% | Sep 17, 2014 | Cross-site scripting (XSS) vulnerability in the Euroling SiteSeeker module 3.x before 3.4.5 for EPiServer allows remote ... |
| CVE-2012-1556 | — | — | 3.3% | Sep 12, 2014 | Cross-site scripting (XSS) vulnerability in Synology Photo Station 5 for DiskStation Manager (DSM) 3.2-1955 allows remot... |
| CVE-2012-4240 | — | — | 1.2% | Sep 11, 2014 | SQL injection vulnerability in modules/calendar/json.php in Group-Office community before 4.0.90 allows remote authentic... |
| CVE-2012-0984 | — | — | 4.2% | Sep 11, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in XOOPS before 2.5.5 allow remote attackers to inject arbitrary web... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now