2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-4556——The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 allows remote attackers to cause...
CVE-2012-4555——The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 does not properly handle interru...
CVE-2012-4543——Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.3 allow remote attac...
CVE-2012-3538——Pulp in Red Hat CloudForms before 1.1 logs administrative passwords in a world-readable file, which allows local users t...
CVE-2012-2696——The backend in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1 does not properly check privileges, which a...
CVE-2012-0861——The vds_installer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, uses the -k curl...
CVE-2012-0860——Multiple untrusted search path vulnerabilities in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when ad...
CVE-2012-6348——Centrify Deployment Manager 2.1.0.283, as distributed in Centrify Suite before 2012.5, allows local users to (1) overwri...
CVE-2012-6330——The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows r...
CVE-2012-6329——The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly hand...
CVE-2012-5977——Asterisk Open Source 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2; Certified Asterisk 1.8.11 befor...
CVE-2012-6090——Multiple stack-based buffer overflows in the expand function in os/pl-glob.c in SWI-Prolog before 6.2.5 and 6.3.x before...
CVE-2012-6089——Multiple stack-based buffer overflows in the canoniseFileName function in os/pl-os.c in SWI-Prolog before 6.2.5 and 6.3....
CVE-2012-5976——Multiple stack consumption vulnerabilities in Asterisk Open Source 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x ...
CVE-2012-6497——The Authlogic gem for Ruby on Rails, when used with certain versions before 3.2.10, makes potentially unsafe find_by_id ...
CVE-2012-6496——SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x...
CVE-2012-6434——Multiple cross-site request forgery (CSRF) vulnerabilities in e107_admin/download.php in e107 1.0.2 allow remote attacke...
CVE-2012-6433——Cross-site request forgery (CSRF) vulnerability in e107_admin/newspost.php in e107 1.0.1 allows remote attackers to hija...
CVE-2012-5667——Multiple integer overflows in GNU Grep before 2.11 might allow context-dependent attackers to execute arbitrary code via...
CVE-2012-6495——Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anyw...
CVE-2012-6082——Cross-site scripting (XSS) vulnerability in the rsslink function in theme/__init__.py in MoinMoin 1.9.5 allows remote at...
CVE-2012-6081——Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action...
CVE-2012-6080——Directory traversal vulnerability in the _do_attachment_move function in the AttachFile action (action/AttachFile.py) in...
CVE-2012-5666——Cross-site scripting (XSS) vulnerability in bookmarks/js/bookmarks.js in ownCloud 4.0.x before 4.0.10 and 4.5.x before 4...
CVE-2012-5665——ownCloud 4.0.x before 4.0.10 and 4.5.x before 4.5.5 does not properly restrict access to settings.php, which allows remo...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now