2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2012-1621Multiple cross-site scripting (XSS) vulnerabilities in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04...
CVE-2012-2592Cross-site scripting (XSS) vulnerability in Axigen Mail Server 8.0.1 allows remote attackers to inject arbitrary web scr...
CVE-2012-3522Cross-site scripting (XSS) vulnerability in contrib/langwiz.php in GeSHi before 1.0.8.11 allows remote attackers to inje...
CVE-2012-3521Multiple directory traversal vulnerabilities in the cssgen contrib module in GeSHi before 1.0.8.11 allow remote attacker...
CVE-2012-5583phpCAS before 1.3.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or ...
CVE-2012-5390The standard universe shadow (condor_shadow.std) component in Condor 7.7.3 through 7.7.6, 7.8.0 before 7.8.5, and 7.9.0 ...
CVE-2012-4728The (1) QProGetNotebookWindowHandle and (2) Ordinal132 functions in QPW160.dll in Corel Quattro Pro X6 Standard Edition ...
CVE-2012-6143Spoon::Cookie in the Spoon module 0.24 for Perl does not properly use the Storable::thaw function, which allows remote a...
CVE-2012-6142Session::Cookie in the HTML::EP module 0.2011 for Perl does not properly use the Storable::thaw function, which allows r...
CVE-2012-6141The App::Context module 0.01 through 0.968 for Perl does not properly use the Storable::thaw function, which allows remo...
CVE-2012-5336lib/base.php in ownCloud before 4.0.8 does not properly validate the user_id session variable, which allows remote authe...
CVE-2012-5057CRLF injection vulnerability in ownCloud Server before 4.0.8 allows remote attackers to inject arbitrary HTTP headers an...
CVE-2012-5056Multiple cross-site scripting (XSS) vulnerabilities in ownCloud Server before 4.0.8 allow remote attackers to inject arb...
CVE-2012-5395Session fixation vulnerability in the CentralAuth extension for MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20....
CVE-2012-5391Session fixation vulnerability in Special:UserLogin in MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before ...
CVE-2012-5877Nero MediaHome 4.5.8.0 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and cr...
CVE-2012-5876Multiple off-by-one errors in NMMediaServerService.dll in Nero MediaHome 4.5.8.0 and earlier allow remote attackers to c...
CVE-2012-5572CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie.pm) in Dancer before 1.3114 allows remote attackers...
CVE-2012-5560The default configuration in mate-settings-daemon 1.5.3 allows local users to change the timezone for the system via a c...
CVE-2012-4915Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers t...
CVE-2012-6452Axway Secure Messenger before 6.5 Updated Release 7, as used in Axway Email Firewall, provides different responses to au...
CVE-2012-5662x3270 before 3.3.12ga12 does not verify that the server hostname matches a domain name in the subject's Common Name (CN)...
CVE-2012-6647The futex_wait_requeue_pi function in kernel/futex.c in the Linux kernel before 3.5.1 does not ensure that calls have tw...
CVE-2012-3333CRLF injection vulnerability in IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7....
CVE-2012-5649Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to execute arbitrary cod...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now