2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-4975 | — | — | 0.8% | Dec 12, 2012 | editrequestuser.asp in Layton Helpbox 4.4.0 allows remote authenticated users to change arbitrary support-ticket data vi... |
| CVE-2012-4974 | — | — | 1.1% | Dec 12, 2012 | Layton Helpbox 4.4.0 allows remote authenticated users to change the login context and gain privileges via a modified (1... |
| CVE-2012-4972 | — | — | 1.1% | Dec 12, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in Layton Helpbox 4.4.0 allow remote attackers to inject arbitrary w... |
| CVE-2012-4971 | — | — | 1.2% | Dec 12, 2012 | Multiple SQL injection vulnerabilities in Layton Helpbox 4.4.0 allow remote attackers to execute arbitrary SQL commands ... |
| CVE-2012-4791 | — | — | 13.4% | Dec 12, 2012 | Microsoft Exchange Server 2007 SP3 and 2010 SP1 and SP2 allows remote authenticated users to cause a denial of service (... |
| CVE-2012-4786 | — | — | 24.2% | Dec 12, 2012 | The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server ... |
| CVE-2012-4782 | — | — | 25.6% | Dec 12, 2012 | Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code v... |
| CVE-2012-4781 | — | — | 18.5% | Dec 12, 2012 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary co... |
| CVE-2012-4774 | — | — | 20.8% | Dec 12, 2012 | Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, a... |
| CVE-2012-2556 | — | — | 20.8% | Dec 12, 2012 | The OpenType Font (OTF) driver in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, ... |
| CVE-2012-2549 | — | — | 10.0% | Dec 12, 2012 | The IP-HTTPS server in Windows Server 2008 R2 and R2 SP1 and Server 2012 does not properly validate certificates, which ... |
| CVE-2012-1537 | — | — | 22.6% | Dec 12, 2012 | Heap-based buffer overflow in DirectPlay in DirectX 9.0 through 11.1 in Microsoft Windows XP SP2 and SP3, Windows Server... |
| CVE-2012-6313 | — | — | 7.2% | Dec 11, 2012 | simple-gmail-login.php in the Simple Gmail Login plugin before 1.1.4 for WordPress allows remote attackers to obtain sen... |
| CVE-2012-6312 | — | — | 3.2% | Dec 11, 2012 | Cross-site scripting (XSS) vulnerability in the Video Lead Form plugin for WordPress allows remote attackers to inject a... |
| CVE-2012-5956 | — | — | 4.1% | Dec 11, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine AssetExplorer 5.6 before service pack 5614 allow rem... |
| CVE-2012-4349 | — | — | 0.5% | Dec 11, 2012 | Unquoted Windows search path vulnerability in Symantec Network Access Control (SNAC) 12.1 before RU2 allows local users ... |
| CVE-2012-1501 | — | — | — | Dec 11, 2012 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ... |
| CVE-2012-6301 | — | — | 6.4% | Dec 10, 2012 | The Browser application in Android 4.0.3 allows remote attackers to cause a denial of service (application crash) via a ... |
| CVE-2012-5973 | — | — | 4.0% | Dec 10, 2012 | CA XCOM Data Transport r11.0 and r11.5 on UNIX and Linux allows remote attackers to execute arbitrary commands via a cra... |
| CVE-2012-4857 | — | — | 4.6% | Dec 8, 2012 | Buffer overflow in IBM Informix 11.50 through 11.50.xC9W2 and 11.70 before 11.70.xC7 allows remote authenticated users t... |
| CVE-2012-4838 | — | — | 0.4% | Dec 8, 2012 | IBM Flex System Chassis Management Module (CMM) and Integrated Management Module 2 (IMM2) allow local users to obtain se... |
| CVE-2012-4690 | — | — | 4.0% | Dec 8, 2012 | Rockwell Automation Allen-Bradley MicroLogix controller 1100, 1200, 1400, and 1500; SLC 500 controller platform; and PLC... |
| CVE-2012-4687 | — | — | 1.4% | Dec 8, 2012 | Post Oak AWAM Bluetooth Reader Traffic System does not use a sufficient source of entropy for private keys, which makes ... |
| CVE-2012-3297 | — | — | 1.1% | Dec 8, 2012 | Cross-site scripting (XSS) vulnerability in the embedded HTTP server in the Service Console in IBM Tivoli Monitoring 6.2... |
| CVE-2012-5688 | — | — | 10.9% | Dec 6, 2012 | ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled, allows remote attackers to cause a deni... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now