2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2012-6609HIGH7.5Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J...
CVE-2012-1496HIGH8.8Local file inclusion in WebCalendar before 1.2.5.
CVE-2012-6613HIGH7.2D-Link DSR-250N devices with firmware 1.05B73_WW allow Persistent Root Access because of the admin password for the admi...
CVE-2012-6345HIGH7.5Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information.
CVE-2012-6302HIGH7.8Soapbox through 0.3.1: Sandbox bypass - runs a second instance of Soapbox within a sandboxed Soapbox.
CVE-2012-6663HIGH7.5General Electric D20ME devices are not properly configured and reveal plaintext passwords.
CVE-2012-5389HIGH7.5NULL Pointer Dereference in PowerTCP WebServer for ActiveX 1.9.2 and earlier allows remote attackers to cause a denial o...
CVE-2012-5340HIGH7.8SumatraPDF 2.1.1/MuPDF 1.0 allows remote attackers to cause an Integer Overflow in the lex_number() function via a corru...
CVE-2012-4606HIGH7.8Citrix XenServer 4.1, 6.0, 5.6 SP2, 5.6 Feature Pack 1, 5.6 Common Criteria, 5.6, 5.5, 5.0, and 5.0 Update 3 contains a ...
CVE-2012-5626HIGH7.5EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3....
CVE-2012-6083HIGH7.5Freeciv before 2.3.3 allows remote attackers to cause a denial of service via a crafted packet.
CVE-2012-5698HIGH8.8BabyGekko before 1.2.4 has SQL injection.
CVE-2012-4981HIGH8.8Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability
CVE-2012-1326HIGH7.4Cisco IronPort Web Security Appliance up to and including 7.5 does not validate the basic constraints of the certificate...
CVE-2012-0070HIGH7.5spamdyke prior to 4.2.1: STARTTLS reveals plaintext
CVE-2012-1563HIGH7.5Joomla! before 2.5.3 allows Admin Account Creation.
CVE-2012-1562HIGH7.5Joomla! core before 2.5.3 allows unauthorized password change.
CVE-2012-4761HIGH7.8A Privilege Escalation vulnerability exists in the unquoted Service Binary in SDPAgent or SDBAgent in Safend Data Protec...
CVE-2012-4760HIGH7.8A Privilege Escalation vulnerability exists in the SDBagent service in Safend Data Protector Agent 3.4.5586.9772, which ...
CVE-2012-4603HIGH7.8Citrix XenApp Online Plug-in for Windows 12.1 and earlier, and Citrix Receiver for Windows 3.2 and earlier could allow r...
CVE-2012-4030HIGH7.5Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote ...
CVE-2012-3824HIGH7.5In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.
CVE-2012-3823HIGH7.5Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved.
CVE-2012-3822HIGH7.5Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attacke...
CVE-2012-3810HIGH7.5Samsung Kies before 2.5.0.12094_27_11 has registry modification.

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now