2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2012-6123MEDIUM6.5Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisone...
CVE-2012-0059MEDIUM4.9A flaw was found in Spacewalk-backend. This information disclosure vulnerability occurs when a system registration XML-R...
CVE-2012-6440MEDIUM4.8The Web server password authentication mechanism used by the products is vulnerable to a MitM and Replay attack. Success...
CVE-2012-5656MEDIUM5.5The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in...
CVE-2012-4550MEDIUM5.3A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Bea...
CVE-2012-4549MEDIUM6.5A flaw was found in JBoss Enterprise Application Platform. The `processInvocation` function within the `org.jboss.as.ejb...
CVE-2012-5571MEDIUM5.4A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authoriz...
CVE-2012-5821MEDIUM5.9Lynx does not verify that the server's certificate is signed by a trusted certification authority, which allows man-in-t...
CVE-2012-5810MEDIUM5.9The Chase mobile banking application for Android does not verify that the server hostname matches a domain name in the s...
CVE-2012-3446MEDIUM5.9Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname ma...
CVE-2012-0518MEDIUM4.7Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3...
CVE-2012-5380MEDIUM6.7Untrusted search path vulnerability in the installation functionality in Ruby 1.9.3-p194, when installed in the top-leve...
CVE-2012-3489MEDIUM6.5The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8...
CVE-2012-3552MEDIUM5.9Race condition in the IP implementation in the Linux kernel before 3.0 might allow remote attackers to cause a denial of...
CVE-2012-2993MEDIUM5.9Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificat...
CVE-2012-1342MEDIUM5.8Cisco Carrier Routing System (CRS) 3.9, 4.0, and 4.1 allows remote attackers to bypass ACL entries via fragmented packet...
CVE-2012-1571MEDIUM6.5file before 5.11 and libmagic allow remote attackers to cause a denial of service (crash) via a crafted Composite Docume...
CVE-2012-0037MEDIUM6.5Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x ...
CVE-2012-1872MEDIUM6.1Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to inject ar...
CVE-2012-1798MEDIUM6.5The TIFFGetEXIFProperties function in coders/tiff.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a den...
CVE-2012-1186MEDIUM5.5Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attacke...
CVE-2012-0260MEDIUM6.5The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial...
CVE-2012-0259MEDIUM6.5The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denia...
CVE-2012-0248MEDIUM5.5ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a craf...
CVE-2012-1146MEDIUM5.5The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 does not properly ha...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now