2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-6644 | — | — | 3.1% | Apr 8, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web scr... |
| CVE-2012-6643 | — | — | 1.7% | Apr 8, 2014 | Multiple SQL injection vulnerabilities in the update_counter function in includes/functions.php in ClipBucket 2.6 allow ... |
| CVE-2012-6642 | — | — | 0.9% | Apr 8, 2014 | Cross-site scripting (XSS) vulnerability in ClipBucket 2.6 allows remote attackers to inject arbitrary web script or HTM... |
| CVE-2012-1561 | — | — | 3.0% | Apr 8, 2014 | Cross-site scripting (XSS) vulnerability in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2... |
| CVE-2012-0033 | — | — | 2.4% | Apr 8, 2014 | The CBounceDCCMod::OnPrivCTCP function in bouncedcc.cpp in the bouncedcc module in ZNC 0.200 and 0.202 allows remote att... |
| CVE-2012-6641 | — | — | 1.8% | Apr 7, 2014 | Cross-site scripting (XSS) vulnerability in redirect.php in the Socolissimo module (modules/socolissimo/) in PrestaShop ... |
| CVE-2012-2095 | — | — | 0.8% | Apr 7, 2014 | The SetWiredProperty function in the D-Bus interface in WICD before 1.7.2 allows local users to write arbitrary configur... |
| CVE-2012-1834 | — | — | 2.4% | Apr 7, 2014 | Cross-site scripting (XSS) vulnerability in the cms_tpv_admin_head function in functions.php in the CMS Tree Page View p... |
| CVE-2012-6640 | — | — | 1.8% | Apr 5, 2014 | Cross-site scripting (XSS) vulnerability in Horde Internet Mail Program (IMP) before 5.0.22, as used in Horde Groupware ... |
| CVE-2012-5567 | — | — | 2.4% | Apr 5, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith Calendar Application H4 before 3.0.18, as used in... |
| CVE-2012-5566 | — | — | 2.4% | Apr 5, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith Calendar Application H4 before 3.0.17, as used in... |
| CVE-2012-5565 | — | — | 1.8% | Apr 5, 2014 | Cross-site scripting (XSS) vulnerability in js/compose-dimp.js in Horde Internet Mail Program (IMP) before 5.0.24, as us... |
| CVE-2012-6429 | — | — | 15.3% | Apr 4, 2014 | Buffer overflow in the PrepareSync method in the SyncService.dll ActiveX control in Samsung Kies before 2.5.1.12123_2_7 ... |
| CVE-2012-5648 | — | — | 2.1% | Apr 4, 2014 | Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands ... |
| CVE-2012-4920 | — | — | 3.2% | Apr 4, 2014 | Directory traversal vulnerability in the zing_forum_output function in forum.php in the Zingiri Forum (aka Forums) plugi... |
| CVE-2012-0032 | — | — | 0.3% | Apr 1, 2014 | Red Hat JBoss Operations Network (JON) before 3.0.1 uses 0777 permissions for the root directory when installing a remot... |
| CVE-2012-3359 | — | — | 0.3% | Mar 31, 2014 | Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac session cookie, whi... |
| CVE-2012-6430 | — | — | 3.9% | Mar 24, 2014 | Cross-site scripting (XSS) vulnerability in Open Solution Quick.Cms 5.0 and Quick.Cart 6.0, possibly as downloaded befor... |
| CVE-2012-4886 | — | — | 15.3% | Mar 24, 2014 | Stack-based buffer overflow in wpsio.dll in Kingsoft WPS Office 2012 possibly 8.1.0.3238 allows remote attackers to exec... |
| CVE-2012-5650 | — | — | 3.8% | Mar 18, 2014 | Cross-site scripting (XSS) vulnerability in the Futon UI in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x b... |
| CVE-2012-5641 | — | — | 8.9% | Mar 18, 2014 | Directory traversal vulnerability in the partition2 function in mochiweb_util.erl in MochiWeb before 2.4.0, as used in A... |
| CVE-2012-5158 | — | — | 0.8% | Mar 14, 2014 | Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which all... |
| CVE-2012-0891 | — | — | 0.9% | Mar 14, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Puppet Dashboard 1.0 before 1.2.5 and Enterprise 1.0 before 1.2.5... |
| CVE-2012-6290 | — | — | 4.2% | Mar 11, 2014 | SQL injection vulnerability in ImageCMS before 4.2 allows remote authenticated administrators to execute arbitrary SQL c... |
| CVE-2012-6619 | — | — | 3.9% | Mar 6, 2014 | The default configuration for MongoDB before 2.3.2 does not validate objects, which allows remote authenticated users to... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now