2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-0884The implementation of Cryptographic Message Syntax (CMS) and PKCS #7 in OpenSSL before 0.9.8u and 1.x before 1.0.0h does...
CVE-2012-0195Cross-site scripting (XSS) vulnerability in the Start Center Layout and Configuration component in IBM Maximo Asset Mana...
CVE-2012-0647WebKit in Apple Safari before 5.1.4 does not properly handle redirects in conjunction with HTTP authentication, which mi...
CVE-2012-0640WebKit in Apple Safari before 5.1.4 does not properly implement "From third parties and advertisers" cookie blocking, wh...
CVE-2012-0584The Internationalized Domain Name (IDN) feature in Apple Safari before 5.1.4 on Windows does not properly restrict the c...
CVE-2012-1558yaSSL CyaSSL before 2.0.8 allows remote attackers to cause a denial of service (NULL pointer dereference and application...
CVE-2012-1557SQL injection vulnerability in admin/plib/api-rpc/Agent.php in Parallels Plesk Panel 7.x and 8.x before 8.6 MU#2, 9.x be...
CVE-2012-1545Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, allows remote attackers to bypass Protected Mode or ca...
CVE-2012-1544Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-1876. Reason: This candidate is a duplicate of...
CVE-2012-0325Cross-site scripting (XSS) vulnerability in Jenkins before 1.454, Jenkins LTS before 1.424.5, and Jenkins Enterprise 1.4...
CVE-2012-0324Cross-site scripting (XSS) vulnerability in Jenkins before 1.454, Jenkins LTS before 1.424.5, and Jenkins Enterprise 1.4...
CVE-2012-0323Cross-site scripting (XSS) vulnerability in the Autocomplete plugin before 3.0 for SquirrelMail allows remote attackers ...
CVE-2012-0245Multiple stack-based buffer overflows in RobNetScanHost.exe in ABB Robot Communications Runtime before 5.14.02, as used ...
CVE-2012-0648WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary code or cause a den...
CVE-2012-0646Format string vulnerability in VPN in Apple iOS before 5.1 allows remote attackers to execute arbitrary code via a craft...
CVE-2012-0645Siri in Apple iOS before 5.1 does not properly restrict the ability of Mail.app to handle voice commands, which allows p...
CVE-2012-0644Race condition in the Passcode Lock feature in Apple iOS before 5.1 allows physically proximate attackers to bypass inte...
CVE-2012-0643The kernel in Apple iOS before 5.1 does not properly handle debug system calls, which allows remote attackers to bypass ...
CVE-2012-0642Integer underflow in Apple iOS before 5.1 allows remote attackers to execute arbitrary code or cause a denial of service...
CVE-2012-0641CFNetwork in Apple iOS before 5.1 does not properly construct request headers during parsing of URLs, which allows remot...
CVE-2012-0639WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary code or cause a den...
CVE-2012-0638WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary code or cause a den...
CVE-2012-0637WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary code or cause a den...
CVE-2012-0636WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary code or cause a den...
CVE-2012-0635WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cau...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now