2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-5505 | — | — | 1.4% | Sep 30, 2014 | atat.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read private data structures via a reques... |
| CVE-2012-5504 | — | — | 1.2% | Sep 30, 2014 | Cross-site scripting (XSS) vulnerability in widget_traversal.py in Plone before 4.2.3 and 4.3 before beta 1 allows remot... |
| CVE-2012-5503 | — | — | 1.4% | Sep 30, 2014 | ftp.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read hidden folder contents via unspecifie... |
| CVE-2012-5502 | — | — | 1.0% | Sep 30, 2014 | Cross-site scripting (XSS) vulnerability in safe_html.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authe... |
| CVE-2012-5501 | — | — | 1.4% | Sep 30, 2014 | at_download.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read arbitrary BLOBs (Files and Im... |
| CVE-2012-5499 | — | — | 2.4% | Sep 30, 2014 | python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to cause a denial of service (memo... |
| CVE-2012-5498 | — | — | 2.6% | Sep 30, 2014 | queryCatalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to bypass caching and cause a denial... |
| CVE-2012-5497 | — | — | 2.1% | Sep 30, 2014 | membership_tool.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to enumerate user account names v... |
| CVE-2012-5496 | — | — | 1.6% | Sep 30, 2014 | kupu_spellcheck.py in Kupu in Plone before 4.0 allows remote attackers to cause a denial of service (ZServer thread lock... |
| CVE-2012-5495 | — | — | 1.7% | Sep 30, 2014 | python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a craft... |
| CVE-2012-5494 | — | — | 1.2% | Sep 30, 2014 | Cross-site scripting (XSS) vulnerability in python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote ... |
| CVE-2012-5493 | — | — | 1.7% | Sep 30, 2014 | gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain permissions to bypass... |
| CVE-2012-5492 | — | — | 1.4% | Sep 30, 2014 | uid_catalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to obtain metadata about hidden objec... |
| CVE-2012-5491 | — | — | 1.2% | Sep 30, 2014 | z3c.form, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain the default form field ... |
| CVE-2012-5490 | — | — | 1.2% | Sep 30, 2014 | Cross-site scripting (XSS) vulnerability in kssdevel.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attack... |
| CVE-2012-5489 | — | — | 1.3% | Sep 30, 2014 | The App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21 and 3.13.x before 2.13.11, as used in P... |
| CVE-2012-5488 | — | — | 2.5% | Sep 30, 2014 | python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a craft... |
| CVE-2012-5487 | — | — | 1.7% | Sep 30, 2014 | The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticat... |
| CVE-2012-5486 | — | — | 2.4% | Sep 30, 2014 | ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attacker... |
| CVE-2012-5485 | — | — | 2.1% | Sep 30, 2014 | registerConfiglet.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via unsp... |
| CVE-2012-6110 | — | — | 0.4% | Sep 29, 2014 | bcron-exec in bcron before 0.10 does not close file descriptors associated with temporary files when running a cron job,... |
| CVE-2012-6107 | — | — | 2.2% | Sep 29, 2014 | Apache Axis2/C does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subje... |
| CVE-2012-5621 | — | — | 2.8% | Sep 29, 2014 | lib/engine/components/opal/opal-call.cpp in ekiga before 4.0.0 allows remote attackers to cause a denial of service (cra... |
| CVE-2012-5619 | — | — | 0.4% | Sep 29, 2014 | The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system entries in FAT file systems and other file... |
| CVE-2012-6657 | — | — | 0.5% | Sep 28, 2014 | The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now