2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2012-1109HIGH7.5mwlib 0.13 through 0.13.4 has a denial of service vulnerability when parsing #iferror magic functions
CVE-2012-0051HIGH7.4Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon re...
CVE-2012-2979HIGH7.5FreeBSD NSD before 3.2.13 allows remote attackers to crash a NSD child server process (SIGSEGV) and cause a denial of se...
CVE-2012-6122HIGH7.5Buffer overflow in the thread scheduler in Chicken before 4.8.0.1 allows attackers to cause a denial of service (crash) ...
CVE-2012-2945HIGH7.5Hadoop 1.0.3 contains a symlink vulnerability.
CVE-2012-0046HIGH7.5mediawiki allows deleted text to be exposed
CVE-2012-5577HIGH7.5Python keyring lib before 0.10 created keyring files with world-readable permissions.
CVE-2012-6711HIGH7A heap-based buffer overflow exists in GNU Bash before 4.3 when wide characters, not supported by the current locale set...
CVE-2012-6704HIGH7.8The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5 mishandles negative values of sk_sndbuf a...
CVE-2012-6703HIGH7.8Integer overflow in the snd_compr_allocate_buffer function in sound/core/compress_offload.c in the ALSA subsystem in the...
CVE-2012-6701HIGH7.8Integer overflow in fs/aio.c in the Linux kernel before 3.4.1 allows local users to cause a denial of service or possibl...
CVE-2012-6689HIGH7.8The netlink_sendmsg function in net/netlink/af_netlink.c in the Linux kernel before 3.5.5 does not validate the dst_pid ...
CVE-2012-6442HIGH7.5When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2...
CVE-2012-6438HIGH7.5The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to ...
CVE-2012-6436HIGH7.5The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to ...
CVE-2012-6435HIGH7.5When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2...
CVE-2012-4792HIGH8.8Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary cod...
CVE-2012-2539HIGH7.8Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office ...
CVE-2012-5830HIGH8.8Use-after-free vulnerability in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, T...
CVE-2012-4775HIGH8.8Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a cr...
CVE-2012-1539HIGH8.1Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a cr...
CVE-2012-5822HIGH7.4The contribution feature in Zamboni does not verify that the server hostname matches a domain name in the subject's Comm...
CVE-2012-5819HIGH7.4FilesAnywhere does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjec...
CVE-2012-5817HIGH7.4Codehaus XFire 1.2.6 and earlier, as used in the Amazon EC2 API Tools Java library and other products, does not verify t...
CVE-2012-5379HIGH7.3Untrusted search path vulnerability in the installation functionality in ActivePython 3.2.2.3, when installed in the top...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now