2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2012-2248HIGH8.1An issue was discovered in dhclient 4.3.1-6 due to an embedded path variable.
CVE-2012-6639HIGH8.8An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitte...
CVE-2012-5631HIGH8.8ipa 3.0 does not properly check server identity before sending credential containing cookies
CVE-2012-5617HIGH7.8gksu-polkit: permissive PolicyKit policy configuration file allows privilege escalation
CVE-2012-5535HIGH7.5gnome-system-log polkit policy allows arbitrary files on the system to be read
CVE-2012-5518HIGH7.5vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching...
CVE-2012-6079HIGH7.5W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download th...
CVE-2012-6078HIGH7.5W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the ...
CVE-2012-6077HIGH7.5W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of d...
CVE-2012-0877HIGH7.5PyXML: Hash table collisions CPU usage Denial of Service
CVE-2012-3407HIGH7.8plow has local buffer overflow vulnerability
CVE-2012-2079HIGH8.8A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal.
CVE-2012-4524HIGH7.5xlockmore before 5.43 'dclock' security bypass vulnerability
CVE-2012-3543HIGH7.5mono 2.10.x ASP.NET Web Form Hash collision DoS
CVE-2012-2350HIGH7.5pam_shield before 0.9.4: Default configuration does not perform protective action
CVE-2012-2238HIGH7.5trytond 2.4: ModelView.button fails to validate authorization
CVE-2012-6135HIGH7.5RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.
CVE-2012-6071HIGH7.5nuSOAP before 0.7.3-5 does not properly check the hostname of a cert.
CVE-2012-6070HIGH7.5Falconpl before 0.9.6.9-git20120606 misuses the libcurl API which may allow remote attackers to interfere with security ...
CVE-2012-4438HIGH8.8Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins mas...
CVE-2012-1170HIGH7.5Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough
CVE-2012-1168HIGH8.2Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is re...
CVE-2012-1156HIGH7.5Moodle before 2.2.2 has users' private files included in course backups
CVE-2012-1155HIGH7.5Moodle has a database activity export permission issue where the export function of the database activity module exports...
CVE-2012-1572HIGH7.5OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now