2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-0414Cross-site scripting (XSS) vulnerability in the Spacewalk service in SUSE Manager 1.2 for SUSE Linux Enterprise (SLE) 11...
CVE-2012-6608Cross-site scripting (XSS) vulnerability in xmlservices/E_book.php in Elastix 2.3.0 allows remote attackers to inject ar...
CVE-2012-6607The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and ob...
CVE-2012-0787The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and EXDEV or EBUSY is ret...
CVE-2012-0786The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and ob...
CVE-2012-4503cmdmon.c in Chrony before 1.29 allows remote attackers to obtain potentially sensitive information from stack memory via...
CVE-2012-4502Multiple integer overflows in pktlength.c in Chrony before 1.29 allow remote attackers to cause a denial of service (cra...
CVE-2012-6303Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in ...
CVE-2012-0827The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated user...
CVE-2012-0826Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 a...
CVE-2012-0825Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which all...
CVE-2012-4572Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the impleme...
CVE-2012-4529The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mo...
CVE-2012-4115The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM virtual-media data, which...
CVE-2012-4117The fabric-interconnect component in Cisco Unified Computing System (UCS) does not properly verify X.509 certificates, w...
CVE-2012-4116The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM media traffic, which allo...
CVE-2012-4114The fabric-interconnect KVM module in Cisco Unified Computing System (UCS) does not encrypt video data, which allows man...
CVE-2012-4113The fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges and read...
CVE-2012-4112The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) allows local users to gain privileges ...
CVE-2012-4121Cisco NX-OS allows local users to gain privileges, and read or modify arbitrary files, via the sed (1) r and (2) w comma...
CVE-2012-4099The BGP implementation in Cisco NX-OS does not properly filter AS paths, which allows remote attackers to cause a denial...
CVE-2012-4097The BGP implementation in Cisco NX-OS does not properly filter segment types in AS paths, which allows remote attackers ...
CVE-2012-4077Cisco NX-OS allows local users to gain privileges and execute arbitrary commands via the sed e option, aka Bug IDs CSCtf...
CVE-2012-4076Cisco NX-OS allows local users to gain privileges and execute arbitrary commands via shell metacharacters in a command t...
CVE-2012-4709Invensys Wonderware InTouch HMI 2012 R2 and earlier allows remote attackers to read arbitrary files, send HTTP requests ...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now