2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-6637——Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expre...
CVE-2012-6636——The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote atta...
CVE-2012-2134——The handle_connection_error function in ldap_helper.c in bind-dyndb-ldap before 1.1.0rc1 does not properly handle LDAP q...
CVE-2012-0270——Multiple stack-based buffer overflows in Csound before 5.16.6 allow remote attackers to execute arbitrary code via a cra...
CVE-2012-6638——The tcp_rcv_state_process function in net/ipv4/tcp_input.c in the Linux kernel before 3.2.24 allows remote attackers to ...
CVE-2012-6108——HP Linux Imaging and Printing (HPLIP) before 3.13.2 uses world-writable permissions for /var/log/hp and /var/log/hp/tmp,...
CVE-2012-2663——extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow r...
CVE-2012-1171——The libxml RSHUTDOWN function in PHP 5.x allows remote attackers to bypass the open_basedir protection mechanism and rea...
CVE-2012-1088——iproute2 before 3.3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file used by (...
CVE-2012-6149——Multiple cross-site scripting (XSS) vulnerabilities in systems/sdc/notes.jsp in Spacewalk and Red Hat Network (RHN) Sate...
CVE-2012-1100——Red Hat JBoss Operations Network (JON) 3.0.x before 3.0.1, 2.4.2, and earlier, when LDAP authentication is enabled and t...
CVE-2012-0062——Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 allows remote attackers to hijack agent sessi...
CVE-2012-0052——Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 does not check the JON agent key, which allow...
CVE-2012-5546——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This identifier was publicly assigned by ...
CVE-2012-0064——xkeyboard-config before 2.5 in X.Org before 7.6 enables certain XKB debugging functions by default, which allows physica...
CVE-2012-3406——The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions doe...
CVE-2012-3405——The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not p...
CVE-2012-3404——The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other versions does not p...
CVE-2012-2328——internal/cimxml/sax/NodeFactory.java in Standards-Based Linux Instrumentation for Manageability (SBLIM) Common Informati...
CVE-2012-5524——The _ssl_verify_callback function in tls_nb.py in Gajim before 0.15.3 does not properly verify SSL certificates, which a...
CVE-2012-1095——osc before 0.134 might allow remote OBS repository servers or package maintainers to execute arbitrary commands via a cr...
CVE-2012-6152——The Yahoo! protocol plugin in libpurple in Pidgin before 2.10.8 does not properly validate UTF-8 data, which allows remo...
CVE-2012-0059MEDIUM4.9A flaw was found in Spacewalk-backend. This information disclosure vulnerability occurs when a system registration XML-R...
CVE-2012-0875——SystemTap 1.7, 1.6.7, and probably other versions, when unprivileged mode is enabled, allows local users to obtain sensi...
CVE-2012-6493——Cross-site request forgery (CSRF) vulnerability in Rapid7 Nexpose Security Console before 5.5.4 allows remote attackers ...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now