2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-0007The Microsoft Anti-Cross Site Scripting (AntiXSS) Library 3.x and 4.0 does not properly evaluate characters after the de...
CVE-2012-0005The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Server 2003...
CVE-2012-0004Unspecified vulnerability in DirectShow in DirectX in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows...
CVE-2012-0003HIGH8.1Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows ...
CVE-2012-0001The kernel in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 ...
CVE-2012-0394The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers...
CVE-2012-0393The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which...
CVE-2012-0392The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows ...
CVE-2012-0391CRITICAL9.8The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during ...
CVE-2012-0024MaraDNS before 1.3.07.12 and 1.4.x before 1.4.08 computes hash values for DNS data without restricting the ability to tr...
CVE-2012-0287Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer...
CVE-2012-0390The DTLS implementation in GnuTLS 3.0.10 and earlier executes certain error-handling code only if there is a specific re...
CVE-2012-0027The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher, which al...
CVE-2012-0026Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-0287. Reason: This candidate is a duplicate of...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now