2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-1712 | — | — | 2.1% | Dec 21, 2012 | Directory traversal vulnerability in the Liferay component in Oracle Sun GlassFish Web Space Server before 10.0 Update 7... |
| CVE-2012-1699 | — | — | 0.4% | Dec 21, 2012 | The ProcSetEventMask function in difs/events.c in the xfs font server for X.Org X11R6 through X11R6.6 and XFree86 before... |
| CVE-2012-0882 | — | — | 5.3% | Dec 21, 2012 | Buffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before 5.5.22 and 5.1.x be... |
| CVE-2012-0841 | — | — | 3.2% | Dec 21, 2012 | libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which ... |
| CVE-2012-6271 | — | — | 2.7% | Dec 20, 2012 | Adobe Shockwave Player through 11.6.8.638 allows remote attackers to trigger installation of arbitrary signed Xtras via ... |
| CVE-2012-6270 | — | — | 2.5% | Dec 20, 2012 | Adobe Shockwave Player through 11.6.8.638 allows remote attackers to trigger installation of a Shockwave Player 10.4.0.0... |
| CVE-2012-5955 | — | — | 4.4% | Dec 20, 2012 | Unspecified vulnerability in the IBM HTTP Server component 5.3 in IBM WebSphere Application Server (WAS) for z/OS allows... |
| CVE-2012-5765 | — | — | 1.4% | Dec 20, 2012 | The Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows remote a... |
| CVE-2012-5643 | — | — | 23.2% | Dec 20, 2012 | Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x before 3.1.22, 3.2.x before 3.2.4, and 3... |
| CVE-2012-5638 | — | — | 0.3% | Dec 20, 2012 | The setup_logging function in log.h in SANLock uses world-writable permissions for /var/log/sanlock.log, which allows lo... |
| CVE-2012-5469 | — | — | 23.7% | Dec 20, 2012 | The Portable phpMyAdmin plugin before 1.3.1 for WordPress allows remote attackers to bypass authentication and obtain ph... |
| CVE-2012-4856 | — | — | 1.2% | Dec 20, 2012 | The Service Processor in the IBM Power 5 91##-### and 940#-### before SF240_418_382 does not ensure that firewall code i... |
| CVE-2012-4839 | — | — | 1.2% | Dec 20, 2012 | The OSLC interface in the Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8... |
| CVE-2012-3428 | — | — | 1.4% | Dec 20, 2012 | The IronJacamar container before 1.0.12.Final for JBoss Application Server, when allow-multiple-users is enabled in conj... |
| CVE-2012-6007 | — | — | 3.7% | Dec 19, 2012 | Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) dev... |
| CVE-2012-5992 | — | — | 1.8% | Dec 19, 2012 | Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) devices with software ... |
| CVE-2012-5991 | — | — | 5.5% | Dec 19, 2012 | screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote a... |
| CVE-2012-5978 | — | — | 2.8% | Dec 19, 2012 | Multiple directory traversal vulnerabilities in the (1) View Connection Server and (2) View Security Server in VMware Vi... |
| CVE-2012-5970 | — | — | 1.5% | Dec 19, 2012 | The Huawei E585 device allows remote attackers to cause a denial of service (NULL pointer dereference and device outage)... |
| CVE-2012-5969 | — | — | 0.7% | Dec 19, 2012 | Multiple directory traversal vulnerabilities on the Huawei E585 device allow remote attackers to (1) read arbitrary file... |
| CVE-2012-5968 | — | — | 0.4% | Dec 19, 2012 | The Huawei E585 device does not validate the status of admin sessions, which allows remote attackers to obtain sensitive... |
| CVE-2012-5967 | — | — | 3.3% | Dec 19, 2012 | SQL injection vulnerability in menuXML.php in Centreon 2.3.3 through 2.3.9-4 (fixed in Centreon web 2.6.0) allows remote... |
| CVE-2012-5691 | — | — | 52.7% | Dec 19, 2012 | Buffer overflow in RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers... |
| CVE-2012-5690 | — | — | 3.1% | Dec 19, 2012 | RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allow remote attackers to execute arbitrar... |
| CVE-2012-5178 | — | — | 1.1% | Dec 19, 2012 | Cross-site request forgery (CSRF) vulnerability in the Welcart plugin before 1.2.2 for WordPress allows remote attackers... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now