2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-6151 | — | — | 9.5% | Dec 13, 2013 | Net-SNMP 5.7.1 and earlier, when AgentX is registering to handle a MIB and processing GETNEXT requests, allows remote at... |
| CVE-2012-5394 | — | — | 0.7% | Dec 13, 2013 | Cross-site request forgery (CSRF) vulnerability in the CentralAuth extension for MediaWiki before 1.19.9, 1.20.x before ... |
| CVE-2012-3047 | — | — | 0.9% | Dec 10, 2013 | Cross-site scripting (XSS) vulnerability in the web-wizard setup page on Cisco Scientific Atlanta D20 and D30 cable mode... |
| CVE-2012-6612 | — | — | 10.1% | Dec 7, 2013 | The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers to h... |
| CVE-2012-6150 | — | — | 3.8% | Dec 3, 2013 | The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid requi... |
| CVE-2012-6535 | — | — | 4.6% | Dec 2, 2013 | DjVuLibre before 3.5.25.3, as used in Evince, Sumatra PDF Reader, VuDroid, and other products, allows remote attackers t... |
| CVE-2012-0434 | — | — | 1.7% | Dec 2, 2013 | The server in Crowbar, as used in SUSE Cloud 1.0, uses weak permissions for the production.log file, which has unspecifi... |
| CVE-2012-0427 | — | — | 0.5% | Dec 2, 2013 | yast2-add-on-creator in SUSE inst-source-utils 2008.11.26 before 2008.11.26-0.9.1 and 2012.9.13 before 2012.9.13-0.8.1 a... |
| CVE-2012-0426 | — | — | 0.3% | Dec 2, 2013 | Race condition in sap_suse_cluster_connector before 1.0.0-0.8.1 in SUSE Linux Enterprise for SAP Applications 11 SP2 all... |
| CVE-2012-0425 | — | — | 1.1% | Dec 2, 2013 | LanItems.ycp in save_y2logs in yast2-network before 2.24.4 in SUSE YaST writes cleartext Wi-Fi credentials to the y2log ... |
| CVE-2012-0420 | — | — | 0.3% | Dec 2, 2013 | zypp-refresh-wrapper in SUSE Zypper before 1.3.20 and 1.6.x before 1.6.166 allows local users to create files in arbitra... |
| CVE-2012-0414 | — | — | 2.0% | Dec 2, 2013 | Cross-site scripting (XSS) vulnerability in the Spacewalk service in SUSE Manager 1.2 for SUSE Linux Enterprise (SLE) 11... |
| CVE-2012-6608 | — | — | 2.6% | Nov 25, 2013 | Cross-site scripting (XSS) vulnerability in xmlservices/E_book.php in Elastix 2.3.0 allows remote attackers to inject ar... |
| CVE-2012-6607 | — | — | 0.4% | Nov 23, 2013 | The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and ob... |
| CVE-2012-0787 | — | — | 0.4% | Nov 23, 2013 | The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and EXDEV or EBUSY is ret... |
| CVE-2012-0786 | — | — | 0.4% | Nov 23, 2013 | The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and ob... |
| CVE-2012-4503 | — | — | 3.1% | Nov 5, 2013 | cmdmon.c in Chrony before 1.29 allows remote attackers to obtain potentially sensitive information from stack memory via... |
| CVE-2012-4502 | — | — | 3.3% | Nov 5, 2013 | Multiple integer overflows in pktlength.c in Chrony before 1.29 allow remote attackers to cause a denial of service (cra... |
| CVE-2012-6303 | — | — | 10.2% | Oct 28, 2013 | Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in ... |
| CVE-2012-0827 | — | — | 1.3% | Oct 28, 2013 | The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated user... |
| CVE-2012-0826 | — | — | 0.9% | Oct 28, 2013 | Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 a... |
| CVE-2012-0825 | — | — | 2.0% | Oct 28, 2013 | Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which all... |
| CVE-2012-4572 | — | — | 0.3% | Oct 28, 2013 | Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the impleme... |
| CVE-2012-4529 | — | — | 2.0% | Oct 28, 2013 | The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mo... |
| CVE-2012-4115 | — | — | 0.8% | Oct 21, 2013 | The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM virtual-media data, which... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now