2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-5655The Context module 6.x-3.x before 6.x-3.1 and 7.x-3.x before 7.x-3.0-beta6 for Drupal does not properly restrict access ...
CVE-2012-5654The Nodewords: D6 Meta Tags module before 6.x-1.14 for Drupal, when configured to automatically generate description met...
CVE-2012-5653The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the pr...
CVE-2012-5652Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed o...
CVE-2012-5651Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to...
CVE-2012-4545The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using ...
CVE-2012-2379Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-...
CVE-2012-6472Opera before 12.12 on UNIX uses weak permissions for the profile directory, which allows local users to obtain sensitive...
CVE-2012-6471Opera before 12.12 allows remote attackers to spoof the address field via a high rate of HTTP requests.
CVE-2012-6470Opera before 12.12 does not properly allocate memory for GIF images, which allows remote attackers to execute arbitrary ...
CVE-2012-6469Opera before 12.11 allows remote attackers to determine the existence of arbitrary local files via vectors involving web...
CVE-2012-6468Heap-based buffer overflow in Opera before 12.11 allows remote attackers to execute arbitrary code or cause a denial of ...
CVE-2012-6467Opera before 12.10 follows Internet shortcuts that are referenced by a (1) IMG element or (2) other inline element, whic...
CVE-2012-6466Opera before 12.10 does not properly handle incorrect size data in a WebP image, which allows remote attackers to obtain...
CVE-2012-6465Opera before 12.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) vi...
CVE-2012-6464Cross-site scripting (XSS) vulnerability in Opera before 12.10 allows remote attackers to inject arbitrary web script or...
CVE-2012-6463Cross-site scripting (XSS) vulnerability in Opera before 12.10 allows remote attackers to inject arbitrary web script or...
CVE-2012-6462Opera before 12.10 does not properly implement the Cross-Origin Resource Sharing (CORS) specification, which allows remo...
CVE-2012-6461The X.509 certificate-validation functionality in the https implementation in Opera before 12.10 allows remote attackers...
CVE-2012-6460Opera before 11.67 and 12.x before 12.02 allows remote attackers to cause truncation of a dialog, and possibly trigger d...
CVE-2012-6459ConnMan 1.3 on Tizen continues to list the bluetooth service after offline mode has been enabled, which might allow remo...
CVE-2012-6426LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote ...
CVE-2012-6084modules/m_capab.c in (1) ircd-ratbox before 3.0.8 and (2) Charybdis before 3.4.2 does not properly support capability ne...
CVE-2012-5769IBM SPSS Modeler 14.0, 14.1, 14.2 through FP3, and 15.0 before FP2 allows remote attackers to read arbitrary files, and ...
CVE-2012-5573The connection_edge_process_relay_cell function in or/relay.c in Tor before 0.2.3.25 maintains circuits even if an unexp...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now