2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2012-4919CRITICAL9.8Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability
CVE-2012-5190CRITICAL9.8Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability
CVE-2012-4750CRITICAL9.8A Code Execution vulnerability exists in the memcpy function when processing AMF requests in Ezhometech EzServer 7.0, wh...
CVE-2012-4284CRITICAL9.8A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the se...
CVE-2012-3807CRITICAL9.8Samsung Kies before 2.5.0.12094_27_11 has arbitrary file execution.
CVE-2012-2226CRITICAL9.8Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sen...
CVE-2012-2714CRITICAL9.8The BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentic...
CVE-2012-1259CRITICAL9.8Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and pos...
CVE-2012-5878CRITICAL9.8Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary comman...
CVE-2012-6094CRITICAL9.8cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized ...
CVE-2012-1577CRITICAL9.8lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0.
CVE-2012-5582CRITICAL9.8opendnssec misuses libcurl API
CVE-2012-3460CRITICAL9.8cumin: At installation postgresql database user created without password
CVE-2012-0824CRITICAL9.8gnusound 0.7.5 has format string issue
CVE-2012-6125CRITICAL9.8Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.
CVE-2012-0694CRITICAL9.8SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers ...
CVE-2012-1187CRITICAL9.8Bitlbee does not drop extra group privileges correctly in unix.c
CVE-2012-6712CRITICAL9.8In the Linux kernel before 3.4, a buffer overflow occurs in drivers/net/wireless/iwlwifi/iwl-agn-sta.c, which will cause...
CVE-2012-1301CRITICAL9.8The FeedProxy.aspx script in Umbraco 4.7.0 allows remote attackers to proxy requests on their behalf via the "url" param...
CVE-2012-3363CRITICAL9.1Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement clas...
CVE-2012-6437CRITICAL9.8The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware imag...
CVE-2012-6069CRITICAL10The CoDeSys Runtime Toolkit’s file transfer functionality does not perform input validation, which allows an attacker t...
CVE-2012-6068CRITICAL9.8The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attac...
CVE-2012-4787CRITICAL9Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code v...
CVE-2012-2239CRITICAL9.1Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connectio...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now