2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-0007 | — | — | 19.3% | Jan 10, 2012 | The Microsoft Anti-Cross Site Scripting (AntiXSS) Library 3.x and 4.0 does not properly evaluate characters after the de... |
| CVE-2012-0005 | — | — | 1.8% | Jan 10, 2012 | The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Server 2003... |
| CVE-2012-0004 | — | — | 22.5% | Jan 10, 2012 | Unspecified vulnerability in DirectShow in DirectX in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows... |
| CVE-2012-0003 | HIGH | 8.1 | 69.5% | Jan 10, 2012 | Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows ... |
| CVE-2012-0001 | — | — | 9.6% | Jan 10, 2012 | The kernel in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 ... |
| CVE-2012-0394 | — | — | 74.4% | Jan 8, 2012 | The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers... |
| CVE-2012-0393 | — | — | 38.3% | Jan 8, 2012 | The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which... |
| CVE-2012-0392 | — | — | 96.8% | Jan 8, 2012 | The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows ... |
| CVE-2012-0391 | CRITICAL | 9.8 | 75.1% | Jan 8, 2012 | The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during ... |
| CVE-2012-0024 | — | — | 2.9% | Jan 8, 2012 | MaraDNS before 1.3.07.12 and 1.4.x before 1.4.08 computes hash values for DNS data without restricting the ability to tr... |
| CVE-2012-0287 | — | — | 2.6% | Jan 6, 2012 | Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer... |
| CVE-2012-0390 | — | — | 1.2% | Jan 6, 2012 | The DTLS implementation in GnuTLS 3.0.10 and earlier executes certain error-handling code only if there is a specific re... |
| CVE-2012-0027 | — | — | 5.0% | Jan 6, 2012 | The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher, which al... |
| CVE-2012-0026 | — | — | — | Jan 4, 2012 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-0287. Reason: This candidate is a duplicate of... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now