2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-6565——Cross-site scripting (XSS) vulnerability in REDCap before 4.14.3 allows remote authenticated users to inject arbitrary w...
CVE-2012-6564——Cross-site scripting (XSS) vulnerability in REDCap before 4.14.5 allows remote attackers to inject arbitrary web script ...
CVE-2012-3544——Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer codi...
CVE-2012-6399——Cisco WebEx 4.1 on iOS does not verify that the server hostname matches a domain name in the subject's Common Name (CN) ...
CVE-2012-4697——TURCK BL20 Programmable Gateway and BL67 Programmable Gateway have hardcoded accounts, which allows remote attackers to ...
CVE-2012-6563——engine/lib/access.php in Elgg before 1.8.5 does not properly clear cached access lists during plugin boot, which allows ...
CVE-2012-6562——engine/lib/users.php in Elgg before 1.8.5 does not properly specify permissions for the useradd action, which allows rem...
CVE-2012-6561——Cross-site scripting (XSS) vulnerability in engine/lib/views.php in Elgg before 1.8.5 allows remote attackers to inject ...
CVE-2012-6560——SQL injection vulnerability in deviceadd.php in FreeNAC 3.02 allows remote attackers to execute arbitrary SQL commands v...
CVE-2012-6559——Multiple cross-site scripting (XSS) vulnerabilities in FreeNAC 3.02 allow remote attackers to inject arbitrary web scrip...
CVE-2012-6558——Heap-based buffer overflow in HeavenTools PE Explorer 1.99 R6 allows remote attackers to execute arbitrary code via the ...
CVE-2012-6557——Multiple cross-site scripting (XSS) vulnerabilities in the AboutMe plugin 1.1.1 for Vanilla Forums allow remote attacker...
CVE-2012-6556——Multiple cross-site scripting (XSS) vulnerabilities in the FirstLastNames plugin 1.1.1 for Vanilla Forums allow remote a...
CVE-2012-6555——Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to i...
CVE-2012-6554——functions/html_to_text.php in the Chat module before 1.5.2 for activeCollab allows remote authenticated users to execute...
CVE-2012-6553——Heap-based buffer overflow in Resource Hacker 3.6.0.92 allows remote attackers to execute arbitrary code via a Portable ...
CVE-2012-6137——rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager does not verify the Red Hat Network Classic server's X....
CVE-2012-6552——Unspecified vulnerability in admin/action.php in phpVMS 2.1.x before 2.1.935 has unknown impact and attack vectors.
CVE-2012-5657——The (1) Zend_Feed_Rss and (2) Zend_Feed_Atom classes in Zend_Feed in Zend Framework 1.11.x before 1.11.15 and 1.12.x bef...
CVE-2012-4481——The safe-level feature in Ruby 1.8.7 allows context-dependent attackers to modify strings via the NameError#to_s method ...
CVE-2012-0864——Integer overflow in the vfprintf function in stdio-common/vfprintf.c in glibc 2.14 and other versions allows context-dep...
CVE-2012-5222——HP Service Manager Web Tier 9.31 before 9.31.2004 p2 allows remote attackers to obtain sensitive information via unspeci...
CVE-2012-4952——Henry Schein Dentrix G5 before 15.1.294 has a single internal-database password that is shared across different customer...
CVE-2012-5947——Buffer overflow in the vsflex7l ActiveX control in IBM SPSS SamplePower 3.0 before FP1 allows remote attackers to execut...
CVE-2012-5946——Buffer overflow in the c1sizer ActiveX control in C1sizer.ocx in IBM SPSS SamplePower 3.0 before FP1 allows remote attac...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now