2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-6565Cross-site scripting (XSS) vulnerability in REDCap before 4.14.3 allows remote authenticated users to inject arbitrary w...
CVE-2012-6564Cross-site scripting (XSS) vulnerability in REDCap before 4.14.5 allows remote attackers to inject arbitrary web script ...
CVE-2012-3544Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer codi...
CVE-2012-6399Cisco WebEx 4.1 on iOS does not verify that the server hostname matches a domain name in the subject's Common Name (CN) ...
CVE-2012-4697TURCK BL20 Programmable Gateway and BL67 Programmable Gateway have hardcoded accounts, which allows remote attackers to ...
CVE-2012-6563engine/lib/access.php in Elgg before 1.8.5 does not properly clear cached access lists during plugin boot, which allows ...
CVE-2012-6562engine/lib/users.php in Elgg before 1.8.5 does not properly specify permissions for the useradd action, which allows rem...
CVE-2012-6561Cross-site scripting (XSS) vulnerability in engine/lib/views.php in Elgg before 1.8.5 allows remote attackers to inject ...
CVE-2012-6560SQL injection vulnerability in deviceadd.php in FreeNAC 3.02 allows remote attackers to execute arbitrary SQL commands v...
CVE-2012-6559Multiple cross-site scripting (XSS) vulnerabilities in FreeNAC 3.02 allow remote attackers to inject arbitrary web scrip...
CVE-2012-6558Heap-based buffer overflow in HeavenTools PE Explorer 1.99 R6 allows remote attackers to execute arbitrary code via the ...
CVE-2012-6557Multiple cross-site scripting (XSS) vulnerabilities in the AboutMe plugin 1.1.1 for Vanilla Forums allow remote attacker...
CVE-2012-6556Multiple cross-site scripting (XSS) vulnerabilities in the FirstLastNames plugin 1.1.1 for Vanilla Forums allow remote a...
CVE-2012-6555Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to i...
CVE-2012-6554functions/html_to_text.php in the Chat module before 1.5.2 for activeCollab allows remote authenticated users to execute...
CVE-2012-6553Heap-based buffer overflow in Resource Hacker 3.6.0.92 allows remote attackers to execute arbitrary code via a Portable ...
CVE-2012-6137rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager does not verify the Red Hat Network Classic server's X....
CVE-2012-6552Unspecified vulnerability in admin/action.php in phpVMS 2.1.x before 2.1.935 has unknown impact and attack vectors.
CVE-2012-5657The (1) Zend_Feed_Rss and (2) Zend_Feed_Atom classes in Zend_Feed in Zend Framework 1.11.x before 1.11.15 and 1.12.x bef...
CVE-2012-4481The safe-level feature in Ruby 1.8.7 allows context-dependent attackers to modify strings via the NameError#to_s method ...
CVE-2012-0864Integer overflow in the vfprintf function in stdio-common/vfprintf.c in glibc 2.14 and other versions allows context-dep...
CVE-2012-5222HP Service Manager Web Tier 9.31 before 9.31.2004 p2 allows remote attackers to obtain sensitive information via unspeci...
CVE-2012-4952Henry Schein Dentrix G5 before 15.1.294 has a single internal-database password that is shared across different customer...
CVE-2012-5947Buffer overflow in the vsflex7l ActiveX control in IBM SPSS SamplePower 3.0 before FP1 allows remote attackers to execut...
CVE-2012-5946Buffer overflow in the c1sizer ActiveX control in C1sizer.ocx in IBM SPSS SamplePower 3.0 before FP1 allows remote attac...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now