2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-5056 | — | — | 1.0% | Jun 4, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in ownCloud Server before 4.0.8 allow remote attackers to inject arb... |
| CVE-2012-5395 | — | — | 1.2% | Jun 2, 2014 | Session fixation vulnerability in the CentralAuth extension for MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.... |
| CVE-2012-5391 | — | — | 2.3% | Jun 2, 2014 | Session fixation vulnerability in Special:UserLogin in MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before ... |
| CVE-2012-5877 | — | — | 7.7% | May 30, 2014 | Nero MediaHome 4.5.8.0 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and cr... |
| CVE-2012-5876 | — | — | 4.3% | May 30, 2014 | Multiple off-by-one errors in NMMediaServerService.dll in Nero MediaHome 4.5.8.0 and earlier allow remote attackers to c... |
| CVE-2012-5572 | — | — | 1.5% | May 30, 2014 | CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie.pm) in Dancer before 1.3114 allows remote attackers... |
| CVE-2012-5560 | — | — | 0.4% | May 30, 2014 | The default configuration in mate-settings-daemon 1.5.3 allows local users to change the timezone for the system via a c... |
| CVE-2012-4915 | — | — | 50.0% | May 29, 2014 | Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers t... |
| CVE-2012-6452 | — | — | 1.5% | May 27, 2014 | Axway Secure Messenger before 6.5 Updated Release 7, as used in Axway Email Firewall, provides different responses to au... |
| CVE-2012-5662 | — | — | 0.6% | May 27, 2014 | x3270 before 3.3.12ga12 does not verify that the server hostname matches a domain name in the subject's Common Name (CN)... |
| CVE-2012-6647 | — | — | 0.4% | May 26, 2014 | The futex_wait_requeue_pi function in kernel/futex.c in the Linux kernel before 3.5.1 does not ensure that calls have tw... |
| CVE-2012-3333 | — | — | 1.8% | May 26, 2014 | CRLF injection vulnerability in IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.... |
| CVE-2012-5649 | — | — | 6.6% | May 23, 2014 | Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to execute arbitrary cod... |
| CVE-2012-6648 | — | — | 0.4% | May 22, 2014 | gdm/guest-session-cleanup.sh in gdm-guest-session 0.24 and earlier, as used in Ubuntu Linux 10.04 LTS, 10.10, and 11.04,... |
| CVE-2012-0943 | — | — | 0.8% | May 22, 2014 | debian/guest-account in Light Display Manager (lightdm) 1.0.x before 1.0.6 and 1.1.x before 1.1.7, as used in Ubuntu Lin... |
| CVE-2012-1166 | — | — | 4.8% | May 21, 2014 | The default keybindings for wwm in LTSP Display Manager (ldm) 2.2.x before 2.2.7 allow remote attackers to execute arbit... |
| CVE-2012-6146 | — | — | 1.0% | May 20, 2014 | The Backend History Module in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 does not properly r... |
| CVE-2012-1600 | — | — | 2.7% | May 14, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in functions.php in phpPgAdmin before 5.0.4 allow remote attackers t... |
| CVE-2012-6342 | — | — | 1.7% | May 13, 2014 | Cross-site request forgery (CSRF) vulnerability in logout.action in Atlassian Confluence 3.4.6 allows remote attackers t... |
| CVE-2012-5477 | — | — | 0.3% | May 8, 2014 | The smart proxy in Foreman before 1.1 uses a umask set to 0, which allows local users to modify files created by the dae... |
| CVE-2012-3415 | — | — | — | Apr 27, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-2401. Reason: This candidate is a duplicate of... |
| CVE-2012-4410 | — | — | — | Apr 27, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2012-4230 | — | — | 1.2% | Apr 25, 2014 | The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive ... |
| CVE-2012-5723 | — | — | 0.7% | Apr 24, 2014 | Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial ... |
| CVE-2012-3946 | — | — | 1.9% | Apr 24, 2014 | Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now