2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-6123 | MEDIUM | 6.5 | 1.3% | Oct 31, 2019 | Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisone... |
| CVE-2012-0059 | MEDIUM | 4.9 | 1.6% | Feb 5, 2014 | A flaw was found in Spacewalk-backend. This information disclosure vulnerability occurs when a system registration XML-R... |
| CVE-2012-6440 | MEDIUM | 4.8 | 8.1% | Jan 24, 2013 | The Web server password authentication mechanism used by the products is vulnerable to a MitM and Replay attack. Success... |
| CVE-2012-5656 | MEDIUM | 5.5 | 1.2% | Jan 18, 2013 | The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in... |
| CVE-2012-4550 | MEDIUM | 5.3 | 2.1% | Jan 5, 2013 | A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Bea... |
| CVE-2012-4549 | MEDIUM | 6.5 | 1.3% | Jan 5, 2013 | A flaw was found in JBoss Enterprise Application Platform. The `processInvocation` function within the `org.jboss.as.ejb... |
| CVE-2012-5571 | MEDIUM | 5.4 | 2.0% | Dec 18, 2012 | A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authoriz... |
| CVE-2012-5821 | MEDIUM | 5.9 | 0.8% | Nov 4, 2012 | Lynx does not verify that the server's certificate is signed by a trusted certification authority, which allows man-in-t... |
| CVE-2012-5810 | MEDIUM | 5.9 | 0.4% | Nov 4, 2012 | The Chase mobile banking application for Android does not verify that the server hostname matches a domain name in the s... |
| CVE-2012-3446 | MEDIUM | 5.9 | 1.2% | Nov 4, 2012 | Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname ma... |
| CVE-2012-0518 | MEDIUM | 4.7 | 4.7% | Oct 16, 2012 | Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3... |
| CVE-2012-5380 | MEDIUM | 6.7 | 1.0% | Oct 11, 2012 | Untrusted search path vulnerability in the installation functionality in Ruby 1.9.3-p194, when installed in the top-leve... |
| CVE-2012-3489 | MEDIUM | 6.5 | 3.1% | Oct 3, 2012 | The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8... |
| CVE-2012-3552 | MEDIUM | 5.9 | 2.9% | Oct 3, 2012 | Race condition in the IP implementation in the Linux kernel before 3.0 might allow remote attackers to cause a denial of... |
| CVE-2012-2993 | MEDIUM | 5.9 | 3.6% | Sep 18, 2012 | Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificat... |
| CVE-2012-1342 | MEDIUM | 5.8 | 1.5% | Aug 6, 2012 | Cisco Carrier Routing System (CRS) 3.9, 4.0, and 4.1 allows remote attackers to bypass ACL entries via fragmented packet... |
| CVE-2012-1571 | MEDIUM | 6.5 | 4.1% | Jul 17, 2012 | file before 5.11 and libmagic allow remote attackers to cause a denial of service (crash) via a crafted Composite Docume... |
| CVE-2012-0037 | MEDIUM | 6.5 | 13.7% | Jun 17, 2012 | Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x ... |
| CVE-2012-1872 | MEDIUM | 6.1 | 6.4% | Jun 12, 2012 | Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to inject ar... |
| CVE-2012-1798 | MEDIUM | 6.5 | 2.4% | Jun 5, 2012 | The TIFFGetEXIFProperties function in coders/tiff.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a den... |
| CVE-2012-1186 | MEDIUM | 5.5 | 1.9% | Jun 5, 2012 | Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attacke... |
| CVE-2012-0260 | MEDIUM | 6.5 | 2.4% | Jun 5, 2012 | The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial... |
| CVE-2012-0259 | MEDIUM | 6.5 | 2.4% | Jun 5, 2012 | The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denia... |
| CVE-2012-0248 | MEDIUM | 5.5 | 2.1% | Jun 5, 2012 | ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a craf... |
| CVE-2012-1146 | MEDIUM | 5.5 | 0.5% | May 17, 2012 | The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 does not properly ha... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now