2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-6637Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expre...
CVE-2012-6636The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote atta...
CVE-2012-2134The handle_connection_error function in ldap_helper.c in bind-dyndb-ldap before 1.1.0rc1 does not properly handle LDAP q...
CVE-2012-0270Multiple stack-based buffer overflows in Csound before 5.16.6 allow remote attackers to execute arbitrary code via a cra...
CVE-2012-6638The tcp_rcv_state_process function in net/ipv4/tcp_input.c in the Linux kernel before 3.2.24 allows remote attackers to ...
CVE-2012-6108HP Linux Imaging and Printing (HPLIP) before 3.13.2 uses world-writable permissions for /var/log/hp and /var/log/hp/tmp,...
CVE-2012-2663extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow r...
CVE-2012-1171The libxml RSHUTDOWN function in PHP 5.x allows remote attackers to bypass the open_basedir protection mechanism and rea...
CVE-2012-1088iproute2 before 3.3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file used by (...
CVE-2012-6149Multiple cross-site scripting (XSS) vulnerabilities in systems/sdc/notes.jsp in Spacewalk and Red Hat Network (RHN) Sate...
CVE-2012-1100Red Hat JBoss Operations Network (JON) 3.0.x before 3.0.1, 2.4.2, and earlier, when LDAP authentication is enabled and t...
CVE-2012-0062Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 allows remote attackers to hijack agent sessi...
CVE-2012-0052Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 does not check the JON agent key, which allow...
CVE-2012-5546Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This identifier was publicly assigned by ...
CVE-2012-0064xkeyboard-config before 2.5 in X.Org before 7.6 enables certain XKB debugging functions by default, which allows physica...
CVE-2012-3406The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions doe...
CVE-2012-3405The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not p...
CVE-2012-3404The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other versions does not p...
CVE-2012-2328internal/cimxml/sax/NodeFactory.java in Standards-Based Linux Instrumentation for Manageability (SBLIM) Common Informati...
CVE-2012-5524The _ssl_verify_callback function in tls_nb.py in Gajim before 0.15.3 does not properly verify SSL certificates, which a...
CVE-2012-1095osc before 0.134 might allow remote OBS repository servers or package maintainers to execute arbitrary commands via a cr...
CVE-2012-6152The Yahoo! protocol plugin in libpurple in Pidgin before 2.10.8 does not properly validate UTF-8 data, which allows remo...
CVE-2012-0059MEDIUM4.9A flaw was found in Spacewalk-backend. This information disclosure vulnerability occurs when a system registration XML-R...
CVE-2012-0875SystemTap 1.7, 1.6.7, and probably other versions, when unprivileged mode is enabled, allows local users to obtain sensi...
CVE-2012-6493Cross-site request forgery (CSRF) vulnerability in Rapid7 Nexpose Security Console before 5.5.4 allows remote attackers ...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now