2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-6565 | — | — | 0.9% | Jun 17, 2013 | Cross-site scripting (XSS) vulnerability in REDCap before 4.14.3 allows remote authenticated users to inject arbitrary w... |
| CVE-2012-6564 | — | — | 1.4% | Jun 17, 2013 | Cross-site scripting (XSS) vulnerability in REDCap before 4.14.5 allows remote attackers to inject arbitrary web script ... |
| CVE-2012-3544 | — | — | 10.8% | Jun 1, 2013 | Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer codi... |
| CVE-2012-6399 | — | — | 0.5% | May 27, 2013 | Cisco WebEx 4.1 on iOS does not verify that the server hostname matches a domain name in the subject's Common Name (CN) ... |
| CVE-2012-4697 | — | — | 2.3% | May 23, 2013 | TURCK BL20 Programmable Gateway and BL67 Programmable Gateway have hardcoded accounts, which allows remote attackers to ... |
| CVE-2012-6563 | — | — | 1.2% | May 23, 2013 | engine/lib/access.php in Elgg before 1.8.5 does not properly clear cached access lists during plugin boot, which allows ... |
| CVE-2012-6562 | — | — | 1.3% | May 23, 2013 | engine/lib/users.php in Elgg before 1.8.5 does not properly specify permissions for the useradd action, which allows rem... |
| CVE-2012-6561 | — | — | 1.2% | May 23, 2013 | Cross-site scripting (XSS) vulnerability in engine/lib/views.php in Elgg before 1.8.5 allows remote attackers to inject ... |
| CVE-2012-6560 | — | — | 1.1% | May 23, 2013 | SQL injection vulnerability in deviceadd.php in FreeNAC 3.02 allows remote attackers to execute arbitrary SQL commands v... |
| CVE-2012-6559 | — | — | 1.6% | May 23, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in FreeNAC 3.02 allow remote attackers to inject arbitrary web scrip... |
| CVE-2012-6558 | — | — | 5.5% | May 23, 2013 | Heap-based buffer overflow in HeavenTools PE Explorer 1.99 R6 allows remote attackers to execute arbitrary code via the ... |
| CVE-2012-6557 | — | — | 1.6% | May 23, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in the AboutMe plugin 1.1.1 for Vanilla Forums allow remote attacker... |
| CVE-2012-6556 | — | — | 1.7% | May 23, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in the FirstLastNames plugin 1.1.1 for Vanilla Forums allow remote a... |
| CVE-2012-6555 | — | — | 2.1% | May 23, 2013 | Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to i... |
| CVE-2012-6554 | — | — | 16.7% | May 23, 2013 | functions/html_to_text.php in the Chat module before 1.5.2 for activeCollab allows remote authenticated users to execute... |
| CVE-2012-6553 | — | — | 5.5% | May 23, 2013 | Heap-based buffer overflow in Resource Hacker 3.6.0.92 allows remote attackers to execute arbitrary code via a Portable ... |
| CVE-2012-6137 | — | — | 0.9% | May 21, 2013 | rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager does not verify the Red Hat Network Classic server's X.... |
| CVE-2012-6552 | — | — | 1.7% | May 10, 2013 | Unspecified vulnerability in admin/action.php in phpVMS 2.1.x before 2.1.935 has unknown impact and attack vectors. |
| CVE-2012-5657 | — | — | 1.7% | May 2, 2013 | The (1) Zend_Feed_Rss and (2) Zend_Feed_Atom classes in Zend_Feed in Zend Framework 1.11.x before 1.11.15 and 1.12.x bef... |
| CVE-2012-4481 | — | — | 1.9% | May 2, 2013 | The safe-level feature in Ruby 1.8.7 allows context-dependent attackers to modify strings via the NameError#to_s method ... |
| CVE-2012-0864 | — | — | 2.7% | May 2, 2013 | Integer overflow in the vfprintf function in stdio-common/vfprintf.c in glibc 2.14 and other versions allows context-dep... |
| CVE-2012-5222 | — | — | 2.2% | May 2, 2013 | HP Service Manager Web Tier 9.31 before 9.31.2004 p2 allows remote attackers to obtain sensitive information via unspeci... |
| CVE-2012-4952 | — | — | 1.8% | May 1, 2013 | Henry Schein Dentrix G5 before 15.1.294 has a single internal-database password that is shared across different customer... |
| CVE-2012-5947 | — | — | 3.5% | Apr 30, 2013 | Buffer overflow in the vsflex7l ActiveX control in IBM SPSS SamplePower 3.0 before FP1 allows remote attackers to execut... |
| CVE-2012-5946 | — | — | 33.8% | Apr 30, 2013 | Buffer overflow in the c1sizer ActiveX control in C1sizer.ocx in IBM SPSS SamplePower 3.0 before FP1 allows remote attac... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now