2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-2099Multiple cross-site scripting (XSS) vulnerabilities in Wikidforum 2.10 allow remote attackers to inject arbitrary web sc...
CVE-2012-1922Multiple cross-site request forgery (CSRF) vulnerabilities in Sitecom WLM-2501 allow remote attackers to hijack the auth...
CVE-2012-6315Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-0209. Reason: This candidate is a reservation ...
CVE-2012-6096Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga...
CVE-2012-5616Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive i...
CVE-2012-4918Call of Duty Elite for iOS 2.0.1 does not properly validate the server SSL certificate, which allows remote attackers to...
CVE-2012-4461The KVM subsystem in the Linux kernel before 3.6.9, when running on hosts that use qemu userspace without XSAVE, allows ...
CVE-2012-4414Multiple SQL injection vulnerabilities in the replication code in Oracle MySQL possibly before 5.5.29, and MariaDB 5.1.x...
CVE-2012-3364Multiple stack-based buffer overflows in the Near Field Communication Controller Interface (NCI) in the Linux kernel bef...
CVE-2012-2372The rds_ib_xmit function in net/rds/ib_send.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linu...
CVE-2012-2137Buffer overflow in virt/kvm/irq_comm.c in the KVM subsystem in the Linux kernel before 3.2.24 allows local users to caus...
CVE-2012-2119Buffer overflow in the macvtap device driver in the Linux kernel before 3.4.5, when running in certain configurations, a...
CVE-2012-6502Microsoft Internet Explorer before 10 allows remote attackers to obtain sensitive information about the existence of fil...
CVE-2012-6069CRITICAL10The CoDeSys Runtime Toolkit’s file transfer functionality does not perform input validation, which allows an attacker t...
CVE-2012-6068CRITICAL9.8The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attac...
CVE-2012-2291EMC Avamar Client 4.x, 5.x, and 6.x on HP-UX and Mac OS X, and the EMC Avamar plugin 4.x, 5.x, and 6.x for Oracle, uses ...
CVE-2012-6113The openssl_encrypt function in ext/openssl/openssl.c in PHP 5.3.9 through 5.3.13 does not initialize a certain variable...
CVE-2012-6396Cisco NX-OS on Nexus 7000 series switches does not properly handle certain line-card replacements, which might allow rem...
CVE-2012-5185Directory traversal vulnerability in the Olive Toast Documents Pro File Viewer (formerly Files HD) app before 1.11.1 for...
CVE-2012-5184Cross-site scripting (XSS) vulnerability in the Olive Toast Documents Pro File Viewer (formerly Files HD) app before 1.1...
CVE-2012-6395Cisco Adaptive Security Appliances (ASA) devices with firmware 8.4 do not properly validate unspecified input related to...
CVE-2012-6360Cross-site scripting (XSS) vulnerability in IBM Intelligent Operations Center 1.5.0 allows remote attackers to inject ar...
CVE-2012-6359IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.11, 6.2.1 before 6.2.1.3, and 6.2.2 before 6.2.2.2 and T...
CVE-2012-5717Cisco Adaptive Security Appliances (ASA) devices with firmware 8.x through 8.4(1) do not properly manage SSH sessions, w...
CVE-2012-6088The rpmpkgRead function in lib/package.c in RPM 4.10.x before 4.10.2 does not return an error code in certain situations...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now