2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-6112classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in M...
CVE-2012-6106calendar/managesubscriptions.php in the Manage Subscriptions implementation in Moodle 2.4.x before 2.4.1 omits a capabil...
CVE-2012-6105blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 continues ...
CVE-2012-6104blog/rsslib.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allows remote attackers to obta...
CVE-2012-6103Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2...
CVE-2012-6102lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 a...
CVE-2012-6101Multiple open redirect vulnerabilities in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow re...
CVE-2012-6100report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enfo...
CVE-2012-6099The moodle1 backup converter in backup/converter/moodle1/lib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3....
CVE-2012-6098grade/edit/outcome/edit_form.php in Moodle 1.9.x through 1.9.19, 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2...
CVE-2012-5484The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate fro...
CVE-2012-4917The TripAdvisor app 6.6 for iOS sends cleartext credentials, which allows remote attackers to obtain sensitive informati...
CVE-2012-4914Stack-based buffer overflow in the reader in CoolPDF 3.0.2.256 allows remote attackers to execute arbitrary code via a P...
CVE-2012-6276Directory traversal vulnerability in the web-based management interface on the TP-LINK TL-WR841N router with firmware 3....
CVE-2012-0435SUSE WebYaST before 1.2 0.2.63-0.6.1 allows remote attackers to modify the hosts list, and subsequently conduct man-in-t...
CVE-2012-3278Stack-based buffer overflow in magentservice.exe in HP Diagnostics Server 8.x through 8.07 and 9.x through 9.21 allows r...
CVE-2012-6272Multiple cross-site scripting (XSS) vulnerabilities in Dell OpenManage Server Administrator 6.5.0.1, 7.0.0.1, and 7.1.0....
CVE-2012-5689ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Po...
CVE-2012-6442HIGH7.5When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2...
CVE-2012-6441An information exposure of confidential information results when the device receives a specially crafted CIP packet to P...
CVE-2012-6440MEDIUM4.8The Web server password authentication mechanism used by the products is vulnerable to a MitM and Replay attack. Success...
CVE-2012-6439When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port...
CVE-2012-6438HIGH7.5The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to ...
CVE-2012-6437CRITICAL9.8The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware imag...
CVE-2012-6436HIGH7.5The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to ...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now