2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2012-6151Net-SNMP 5.7.1 and earlier, when AgentX is registering to handle a MIB and processing GETNEXT requests, allows remote at...
CVE-2012-5394Cross-site request forgery (CSRF) vulnerability in the CentralAuth extension for MediaWiki before 1.19.9, 1.20.x before ...
CVE-2012-3047Cross-site scripting (XSS) vulnerability in the web-wizard setup page on Cisco Scientific Atlanta D20 and D30 cable mode...
CVE-2012-6612The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers to h...
CVE-2012-6150The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid requi...
CVE-2012-6535DjVuLibre before 3.5.25.3, as used in Evince, Sumatra PDF Reader, VuDroid, and other products, allows remote attackers t...
CVE-2012-0434The server in Crowbar, as used in SUSE Cloud 1.0, uses weak permissions for the production.log file, which has unspecifi...
CVE-2012-0427yast2-add-on-creator in SUSE inst-source-utils 2008.11.26 before 2008.11.26-0.9.1 and 2012.9.13 before 2012.9.13-0.8.1 a...
CVE-2012-0426Race condition in sap_suse_cluster_connector before 1.0.0-0.8.1 in SUSE Linux Enterprise for SAP Applications 11 SP2 all...
CVE-2012-0425LanItems.ycp in save_y2logs in yast2-network before 2.24.4 in SUSE YaST writes cleartext Wi-Fi credentials to the y2log ...
CVE-2012-0420zypp-refresh-wrapper in SUSE Zypper before 1.3.20 and 1.6.x before 1.6.166 allows local users to create files in arbitra...
CVE-2012-0414Cross-site scripting (XSS) vulnerability in the Spacewalk service in SUSE Manager 1.2 for SUSE Linux Enterprise (SLE) 11...
CVE-2012-6608Cross-site scripting (XSS) vulnerability in xmlservices/E_book.php in Elastix 2.3.0 allows remote attackers to inject ar...
CVE-2012-6607The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and ob...
CVE-2012-0787The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and EXDEV or EBUSY is ret...
CVE-2012-0786The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and ob...
CVE-2012-4503cmdmon.c in Chrony before 1.29 allows remote attackers to obtain potentially sensitive information from stack memory via...
CVE-2012-4502Multiple integer overflows in pktlength.c in Chrony before 1.29 allow remote attackers to cause a denial of service (cra...
CVE-2012-6303Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in ...
CVE-2012-0827The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated user...
CVE-2012-0826Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 a...
CVE-2012-0825Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which all...
CVE-2012-4572Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the impleme...
CVE-2012-4529The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mo...
CVE-2012-4115The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM virtual-media data, which...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now