2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-0189 | — | — | 4.5% | Jan 18, 2012 | Multiple unspecified vulnerabilities in the (1) PrintFile and (2) SaveDoc methods in the VsVIEW6 ActiveX control in VsVI... |
| CVE-2012-0188 | — | — | 3.6% | Jan 18, 2012 | Unspecified vulnerability in the SetLicenseInfoEx method in an ActiveX control in mraboutb.dll in IBM SPSS Dimensions 5.... |
| CVE-2012-0031 | — | — | 2.9% | Jan 18, 2012 | scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon c... |
| CVE-2012-0267 | — | — | 39.0% | Jan 15, 2012 | The StopModule method in the NTR ActiveX control before 2.0.4.8 allows remote attackers to execute arbitrary code via a ... |
| CVE-2012-0266 | — | — | 42.1% | Jan 15, 2012 | Multiple stack-based buffer overflows in the NTR ActiveX control before 2.0.4.8 allow remote attackers to execute arbitr... |
| CVE-2012-0693 | — | — | 1.0% | Jan 14, 2012 | submitticket.php in WHMCompleteSolution (WHMCS) 5.03 allows remote attackers to inject arbitrary code into a subject fie... |
| CVE-2012-0030 | — | — | 1.8% | Jan 13, 2012 | Nova 2011.3 and Essex, when using the OpenStack API, allows remote authenticated users to bypass access restrictions for... |
| CVE-2012-0697 | — | — | 7.6% | Jan 13, 2012 | HP StorageWorks P2000 G3 MSA array systems have a default account, which makes it easier for remote attackers to perform... |
| CVE-2012-0696 | — | — | 1.3% | Jan 13, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in the Executive Viewer (EV) in IBM Cognos TM1 before 9.5 FP1 allow ... |
| CVE-2012-0310 | — | — | 1.5% | Jan 13, 2012 | CRLF injection vulnerability in Cogent DataHub 7.1.2 and earlier, Cascade DataHub 6.4.20 and earlier, and OPC DataHub 6.... |
| CVE-2012-0309 | — | — | 1.3% | Jan 13, 2012 | Cross-site scripting (XSS) vulnerability in Cogent DataHub 7.1.2 and earlier, Cascade DataHub 6.4.20 and earlier, and OP... |
| CVE-2012-0695 | — | — | 0.7% | Jan 12, 2012 | Multiple unspecified vulnerabilities in Google Chrome before 17.0.963.27 on the Acer AC700, Samsung Series 5, and Cr-48 ... |
| CVE-2012-0013 | — | — | 73.8% | Jan 10, 2012 | Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Se... |
| CVE-2012-0009 | — | — | 20.6% | Jan 10, 2012 | Untrusted search path vulnerability in the Windows Object Packager configuration in Microsoft Windows XP SP2 and SP3 and... |
| CVE-2012-0007 | — | — | 19.3% | Jan 10, 2012 | The Microsoft Anti-Cross Site Scripting (AntiXSS) Library 3.x and 4.0 does not properly evaluate characters after the de... |
| CVE-2012-0005 | — | — | 1.8% | Jan 10, 2012 | The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Server 2003... |
| CVE-2012-0004 | — | — | 22.5% | Jan 10, 2012 | Unspecified vulnerability in DirectShow in DirectX in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows... |
| CVE-2012-0001 | — | — | 9.6% | Jan 10, 2012 | The kernel in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 ... |
| CVE-2012-0394 | — | — | 74.4% | Jan 8, 2012 | The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers... |
| CVE-2012-0393 | — | — | 38.3% | Jan 8, 2012 | The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which... |
| CVE-2012-0392 | — | — | 96.8% | Jan 8, 2012 | The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows ... |
| CVE-2012-0024 | — | — | 2.9% | Jan 8, 2012 | MaraDNS before 1.3.07.12 and 1.4.x before 1.4.08 computes hash values for DNS data without restricting the ability to tr... |
| CVE-2012-0287 | — | — | 2.6% | Jan 6, 2012 | Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer... |
| CVE-2012-0390 | — | — | 1.2% | Jan 6, 2012 | The DTLS implementation in GnuTLS 3.0.10 and earlier executes certain error-handling code only if there is a specific re... |
| CVE-2012-0027 | — | — | 5.0% | Jan 6, 2012 | The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher, which al... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now