2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-0414——Cross-site scripting (XSS) vulnerability in the Spacewalk service in SUSE Manager 1.2 for SUSE Linux Enterprise (SLE) 11...
CVE-2012-6608——Cross-site scripting (XSS) vulnerability in xmlservices/E_book.php in Elastix 2.3.0 allows remote attackers to inject ar...
CVE-2012-6607——The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and ob...
CVE-2012-0787——The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and EXDEV or EBUSY is ret...
CVE-2012-0786——The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and ob...
CVE-2012-4503——cmdmon.c in Chrony before 1.29 allows remote attackers to obtain potentially sensitive information from stack memory via...
CVE-2012-4502——Multiple integer overflows in pktlength.c in Chrony before 1.29 allow remote attackers to cause a denial of service (cra...
CVE-2012-6303——Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in ...
CVE-2012-0827——The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated user...
CVE-2012-0826——Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 a...
CVE-2012-0825——Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which all...
CVE-2012-4572——Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the impleme...
CVE-2012-4529——The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mo...
CVE-2012-4115——The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM virtual-media data, which...
CVE-2012-4117——The fabric-interconnect component in Cisco Unified Computing System (UCS) does not properly verify X.509 certificates, w...
CVE-2012-4116——The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM media traffic, which allo...
CVE-2012-4114——The fabric-interconnect KVM module in Cisco Unified Computing System (UCS) does not encrypt video data, which allows man...
CVE-2012-4113——The fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges and read...
CVE-2012-4112——The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) allows local users to gain privileges ...
CVE-2012-4121——Cisco NX-OS allows local users to gain privileges, and read or modify arbitrary files, via the sed (1) r and (2) w comma...
CVE-2012-4099——The BGP implementation in Cisco NX-OS does not properly filter AS paths, which allows remote attackers to cause a denial...
CVE-2012-4097——The BGP implementation in Cisco NX-OS does not properly filter segment types in AS paths, which allows remote attackers ...
CVE-2012-4077——Cisco NX-OS allows local users to gain privileges and execute arbitrary commands via the sed e option, aka Bug IDs CSCtf...
CVE-2012-4076——Cisco NX-OS allows local users to gain privileges and execute arbitrary commands via shell metacharacters in a command t...
CVE-2012-4709——Invensys Wonderware InTouch HMI 2012 R2 and earlier allows remote attackers to read arbitrary files, send HTTP requests ...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now