2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2012-5648——Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands ...
CVE-2012-4920——Directory traversal vulnerability in the zing_forum_output function in forum.php in the Zingiri Forum (aka Forums) plugi...
CVE-2012-0032——Red Hat JBoss Operations Network (JON) before 3.0.1 uses 0777 permissions for the root directory when installing a remot...
CVE-2012-3359——Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac session cookie, whi...
CVE-2012-6430——Cross-site scripting (XSS) vulnerability in Open Solution Quick.Cms 5.0 and Quick.Cart 6.0, possibly as downloaded befor...
CVE-2012-4886——Stack-based buffer overflow in wpsio.dll in Kingsoft WPS Office 2012 possibly 8.1.0.3238 allows remote attackers to exec...
CVE-2012-5650——Cross-site scripting (XSS) vulnerability in the Futon UI in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x b...
CVE-2012-5641——Directory traversal vulnerability in the partition2 function in mochiweb_util.erl in MochiWeb before 2.4.0, as used in A...
CVE-2012-5158——Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which all...
CVE-2012-0891——Multiple cross-site scripting (XSS) vulnerabilities in Puppet Dashboard 1.0 before 1.2.5 and Enterprise 1.0 before 1.2.5...
CVE-2012-6290——SQL injection vulnerability in ImageCMS before 4.2 allows remote authenticated administrators to execute arbitrary SQL c...
CVE-2012-6619——The default configuration for MongoDB before 2.3.2 does not validate objects, which allows remote authenticated users to...
CVE-2012-6637——Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expre...
CVE-2012-6636——The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote atta...
CVE-2012-2134——The handle_connection_error function in ldap_helper.c in bind-dyndb-ldap before 1.1.0rc1 does not properly handle LDAP q...
CVE-2012-0270——Multiple stack-based buffer overflows in Csound before 5.16.6 allow remote attackers to execute arbitrary code via a cra...
CVE-2012-6638——The tcp_rcv_state_process function in net/ipv4/tcp_input.c in the Linux kernel before 3.2.24 allows remote attackers to ...
CVE-2012-6108——HP Linux Imaging and Printing (HPLIP) before 3.13.2 uses world-writable permissions for /var/log/hp and /var/log/hp/tmp,...
CVE-2012-2663——extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow r...
CVE-2012-1171——The libxml RSHUTDOWN function in PHP 5.x allows remote attackers to bypass the open_basedir protection mechanism and rea...
CVE-2012-1088——iproute2 before 3.3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file used by (...
CVE-2012-6149——Multiple cross-site scripting (XSS) vulnerabilities in systems/sdc/notes.jsp in Spacewalk and Red Hat Network (RHN) Sate...
CVE-2012-1100——Red Hat JBoss Operations Network (JON) 3.0.x before 3.0.1, 2.4.2, and earlier, when LDAP authentication is enabled and t...
CVE-2012-0062——Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 allows remote attackers to hijack agent sessi...
CVE-2012-0052——Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 does not check the JON agent key, which allow...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now