2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2012-5648Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands ...
CVE-2012-4920Directory traversal vulnerability in the zing_forum_output function in forum.php in the Zingiri Forum (aka Forums) plugi...
CVE-2012-0032Red Hat JBoss Operations Network (JON) before 3.0.1 uses 0777 permissions for the root directory when installing a remot...
CVE-2012-3359Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac session cookie, whi...
CVE-2012-6430Cross-site scripting (XSS) vulnerability in Open Solution Quick.Cms 5.0 and Quick.Cart 6.0, possibly as downloaded befor...
CVE-2012-4886Stack-based buffer overflow in wpsio.dll in Kingsoft WPS Office 2012 possibly 8.1.0.3238 allows remote attackers to exec...
CVE-2012-5650Cross-site scripting (XSS) vulnerability in the Futon UI in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x b...
CVE-2012-5641Directory traversal vulnerability in the partition2 function in mochiweb_util.erl in MochiWeb before 2.4.0, as used in A...
CVE-2012-5158Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which all...
CVE-2012-0891Multiple cross-site scripting (XSS) vulnerabilities in Puppet Dashboard 1.0 before 1.2.5 and Enterprise 1.0 before 1.2.5...
CVE-2012-6290SQL injection vulnerability in ImageCMS before 4.2 allows remote authenticated administrators to execute arbitrary SQL c...
CVE-2012-6619The default configuration for MongoDB before 2.3.2 does not validate objects, which allows remote authenticated users to...
CVE-2012-6637Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expre...
CVE-2012-6636The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote atta...
CVE-2012-2134The handle_connection_error function in ldap_helper.c in bind-dyndb-ldap before 1.1.0rc1 does not properly handle LDAP q...
CVE-2012-0270Multiple stack-based buffer overflows in Csound before 5.16.6 allow remote attackers to execute arbitrary code via a cra...
CVE-2012-6638The tcp_rcv_state_process function in net/ipv4/tcp_input.c in the Linux kernel before 3.2.24 allows remote attackers to ...
CVE-2012-6108HP Linux Imaging and Printing (HPLIP) before 3.13.2 uses world-writable permissions for /var/log/hp and /var/log/hp/tmp,...
CVE-2012-2663extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow r...
CVE-2012-1171The libxml RSHUTDOWN function in PHP 5.x allows remote attackers to bypass the open_basedir protection mechanism and rea...
CVE-2012-1088iproute2 before 3.3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file used by (...
CVE-2012-6149Multiple cross-site scripting (XSS) vulnerabilities in systems/sdc/notes.jsp in Spacewalk and Red Hat Network (RHN) Sate...
CVE-2012-1100Red Hat JBoss Operations Network (JON) 3.0.x before 3.0.1, 2.4.2, and earlier, when LDAP authentication is enabled and t...
CVE-2012-0062Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 allows remote attackers to hijack agent sessi...
CVE-2012-0052Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 does not check the JON agent key, which allow...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now