2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-6371 | — | — | 0.9% | Dec 31, 2012 | The WPA2 implementation on the Belkin N900 F9K1104v1 router establishes a WPS PIN based on 6 digits of the LAN/WLAN MAC ... |
| CVE-2012-6453 | — | — | 1.0% | Dec 31, 2012 | Cross-site scripting (XSS) vulnerability in the RSS Reader extension before 0.2.6 for MediaWiki allows remote attackers ... |
| CVE-2012-6339 | — | — | 1.2% | Dec 31, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface in Cerberus FTP Server before 5.... |
| CVE-2012-6337 | — | — | 1.6% | Dec 31, 2012 | The Track My Mobile feature in the SamsungDive subsystem for Android on Samsung Galaxy devices shows the activation of r... |
| CVE-2012-6336 | — | — | 0.4% | Dec 31, 2012 | The Missing Device feature in Lookout allows physically proximate attackers to provide arbitrary location data via a "co... |
| CVE-2012-6335 | — | — | 0.5% | Dec 31, 2012 | The Anti-theft service in AVG AntiVirus for Android allows physically proximate attackers to provide arbitrary location ... |
| CVE-2012-6334 | — | — | 1.3% | Dec 31, 2012 | The Track My Mobile feature in the SamsungDive subsystem for Android on Samsung Galaxy devices does not properly impleme... |
| CVE-2012-5642 | — | — | 3.1% | Dec 31, 2012 | server/action.py in Fail2ban before 0.8.8 does not properly handle the content of the matches tag, which might allow rem... |
| CVE-2012-4688 | — | — | 1.6% | Dec 31, 2012 | The Central application in i-GEN opLYNX before 2.01.9 allows remote attackers to bypass authentication via vectors invol... |
| CVE-2012-6369 | — | — | 1.0% | Dec 28, 2012 | Cross-site scripting (XSS) vulnerability in the Troubleshooting Reporting System feature in AgileBits 1Password 3.9.9 mi... |
| CVE-2012-5445 | — | — | 0.4% | Dec 28, 2012 | The kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software befor... |
| CVE-2012-4932 | — | — | 1.3% | Dec 28, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in SimpleInvoices before stable-2012-1-CIS3000 allow remote attacker... |
| CVE-2012-4528 | — | — | 12.5% | Dec 28, 2012 | The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver ar... |
| CVE-2012-3873 | — | — | 0.9% | Dec 28, 2012 | Multiple SQL injection vulnerabilities in Open Constructor 3.12.0 allow remote authenticated users to execute arbitrary ... |
| CVE-2012-3872 | — | — | 1.4% | Dec 28, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in Open Constructor 3.12.0 allow remote attackers to inject arbitrar... |
| CVE-2012-3871 | — | — | 0.8% | Dec 28, 2012 | Cross-site scripting (XSS) vulnerability in data/hybrid/i_hybrid.php in Open Constructor 3.12.0 allows remote authentica... |
| CVE-2012-3870 | — | — | 0.8% | Dec 28, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in objects/createobject.php in Open Constructor 3.12.0 allow remote ... |
| CVE-2012-0741 | — | — | 0.6% | Dec 28, 2012 | IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certifica... |
| CVE-2012-0738 | — | — | 0.6% | Dec 28, 2012 | IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certifica... |
| CVE-2012-6432 | — | — | 1.2% | Dec 27, 2012 | Symfony 2.0.x before 2.0.20, 2.1.x before 2.1.5, and 2.2-dev, when the internal routes configuration is enabled, allows ... |
| CVE-2012-6431 | — | — | 1.9% | Dec 27, 2012 | Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, w... |
| CVE-2012-5868 | — | — | 2.4% | Dec 27, 2012 | WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it... |
| CVE-2012-5532 | — | — | 0.4% | Dec 27, 2012 | The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.8-rc1, allows l... |
| CVE-2012-2669 | — | — | 0.4% | Dec 27, 2012 | The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.4.5, does not v... |
| CVE-2012-6314 | — | — | 1.8% | Dec 26, 2012 | Citrix XenDesktop Virtual Desktop Agent (VDA) 5.6.x before 5.6.200, when making changes to the server-side policy that c... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now