2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-2099——Multiple cross-site scripting (XSS) vulnerabilities in Wikidforum 2.10 allow remote attackers to inject arbitrary web sc...
CVE-2012-1922——Multiple cross-site request forgery (CSRF) vulnerabilities in Sitecom WLM-2501 allow remote attackers to hijack the auth...
CVE-2012-6315——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-0209. Reason: This candidate is a reservation ...
CVE-2012-6096——Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga...
CVE-2012-5616——Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive i...
CVE-2012-4918——Call of Duty Elite for iOS 2.0.1 does not properly validate the server SSL certificate, which allows remote attackers to...
CVE-2012-4461——The KVM subsystem in the Linux kernel before 3.6.9, when running on hosts that use qemu userspace without XSAVE, allows ...
CVE-2012-4414——Multiple SQL injection vulnerabilities in the replication code in Oracle MySQL possibly before 5.5.29, and MariaDB 5.1.x...
CVE-2012-3364——Multiple stack-based buffer overflows in the Near Field Communication Controller Interface (NCI) in the Linux kernel bef...
CVE-2012-2372——The rds_ib_xmit function in net/rds/ib_send.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linu...
CVE-2012-2137——Buffer overflow in virt/kvm/irq_comm.c in the KVM subsystem in the Linux kernel before 3.2.24 allows local users to caus...
CVE-2012-2119——Buffer overflow in the macvtap device driver in the Linux kernel before 3.4.5, when running in certain configurations, a...
CVE-2012-6502——Microsoft Internet Explorer before 10 allows remote attackers to obtain sensitive information about the existence of fil...
CVE-2012-6069CRITICAL10The CoDeSys Runtime Toolkit’s file transfer functionality does not perform input validation, which allows an attacker t...
CVE-2012-6068CRITICAL9.8The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attac...
CVE-2012-2291——EMC Avamar Client 4.x, 5.x, and 6.x on HP-UX and Mac OS X, and the EMC Avamar plugin 4.x, 5.x, and 6.x for Oracle, uses ...
CVE-2012-6113——The openssl_encrypt function in ext/openssl/openssl.c in PHP 5.3.9 through 5.3.13 does not initialize a certain variable...
CVE-2012-6396——Cisco NX-OS on Nexus 7000 series switches does not properly handle certain line-card replacements, which might allow rem...
CVE-2012-5185——Directory traversal vulnerability in the Olive Toast Documents Pro File Viewer (formerly Files HD) app before 1.11.1 for...
CVE-2012-5184——Cross-site scripting (XSS) vulnerability in the Olive Toast Documents Pro File Viewer (formerly Files HD) app before 1.1...
CVE-2012-6395——Cisco Adaptive Security Appliances (ASA) devices with firmware 8.4 do not properly validate unspecified input related to...
CVE-2012-6360——Cross-site scripting (XSS) vulnerability in IBM Intelligent Operations Center 1.5.0 allows remote attackers to inject ar...
CVE-2012-6359——IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.11, 6.2.1 before 6.2.1.3, and 6.2.2 before 6.2.2.2 and T...
CVE-2012-5717——Cisco Adaptive Security Appliances (ASA) devices with firmware 8.x through 8.4(1) do not properly manage SSH sessions, w...
CVE-2012-6088——The rpmpkgRead function in lib/package.c in RPM 4.10.x before 4.10.2 does not return an error code in certain situations...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now