2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-4615 | — | — | 0.2% | Nov 27, 2012 | EMC Smarts Network Configuration Manager (NCM) before 9.1 uses a hardcoded encryption key for the storage of credentials... |
| CVE-2012-4614 | — | — | 2.3% | Nov 27, 2012 | The default configuration of EMC Smarts Network Configuration Manager (NCM) before 9.1 does not require authentication f... |
| CVE-2012-4611 | — | — | 1.4% | Nov 27, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Adaptive Authentication On-Premise (AAOP) before 7.0 allo... |
| CVE-2012-6050 | — | — | 9.4% | Nov 27, 2012 | The winbox service in MikroTik RouterOS 5.15 and earlier allows remote attackers to cause a denial of service (CPU consu... |
| CVE-2012-6049 | — | — | 1.4% | Nov 27, 2012 | Open Solution Quick.Cart 5.0 allows remote attackers to obtain sensitive information via (1) a long string or (2) invali... |
| CVE-2012-6048 | — | — | 2.4% | Nov 27, 2012 | Guitar Pro 6.1.1 r10791 allows remote attackers to cause a denial of service (crash) via a long string in a gpx file. |
| CVE-2012-6047 | — | — | 0.9% | Nov 27, 2012 | Cross-site request forgery (CSRF) vulnerability in X7 Chat 2.0.5.1 and earlier allows remote attackers to hijack the aut... |
| CVE-2012-6046 | — | — | 4.1% | Nov 27, 2012 | Static code injection vulnerability in admin/banners.php in PHP Enter allows remote attackers to inject arbitrary PHP co... |
| CVE-2012-6045 | — | — | 1.6% | Nov 27, 2012 | Cross-site scripting (XSS) vulnerability in gb/user/index.php in Ramui Forum, possibly 1.0 Beta, allows remote attackers... |
| CVE-2012-6044 | — | — | 2.5% | Nov 26, 2012 | M-Player 0.4 allows remote attackers to cause a denial of service (crash) via a crafted MP3 file. |
| CVE-2012-6043 | — | — | 1.6% | Nov 26, 2012 | Cross-site scripting (XSS) vulnerability in downloads.php in PHP-Fusion 7.02.04 allows remote attackers to inject arbitr... |
| CVE-2012-6042 | — | — | 2.1% | Nov 26, 2012 | GPSMapEdit 1.1.73.2 allows user-assisted remote attackers to cause a denial of service (crash) via a long string in a ls... |
| CVE-2012-6041 | — | — | 3.7% | Nov 26, 2012 | Double free vulnerability in GreenBrowser before 6.0.1002, when the keyword search bar (F6) is activated, allows remote ... |
| CVE-2012-6040 | — | — | 1.6% | Nov 26, 2012 | Cross-site scripting (XSS) vulnerability in users.php in File King Advanced File Management 1.4 allows remote attackers ... |
| CVE-2012-6039 | — | — | 1.1% | Nov 26, 2012 | SQL injection vulnerability in view_comments.php in YABSoft Advanced Image Hosting (AIH) Script, possibly 2.3, allows re... |
| CVE-2012-6038 | — | — | 2.7% | Nov 26, 2012 | admin/core/admin_func.php in razorCMS before 1.2.1 does not properly restrict access to certain administrator directorie... |
| CVE-2012-5520 | — | — | 3.1% | Nov 26, 2012 | The send_to_sourcefire function in manage_sql.c in OpenVAS Manager 3.x before 3.0.4 allows remote attackers to execute a... |
| CVE-2012-2438 | — | — | 1.6% | Nov 26, 2012 | ar web content manager (AWCM) 2.2 does not restrict the number of comment records that can be submitted through HTTP req... |
| CVE-2012-2437 | — | — | 2.4% | Nov 26, 2012 | cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to ge... |
| CVE-2012-0698 | — | — | 10.5% | Nov 26, 2012 | tcsd in TrouSerS before 0.3.10 allows remote attackers to cause a denial of service (daemon crash) via a crafted type_of... |
| CVE-2012-6037 | — | — | 1.8% | Nov 24, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4, and other versi... |
| CVE-2012-5533 | — | — | 12.0% | Nov 24, 2012 | The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial o... |
| CVE-2012-4538 | — | — | 0.4% | Nov 24, 2012 | The HVMOP_pagetable_dying hypercall in Xen 4.0, 4.1, and 4.2 does not properly check the pagetable state when running on... |
| CVE-2012-4522 | — | — | 2.2% | Nov 24, 2012 | The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlevel 286 and Ruby 2.0.0 before r37163 allows context... |
| CVE-2012-3433 | — | — | 0.4% | Nov 24, 2012 | Xen 4.0 and 4.1 allows local HVM guest OS kernels to cause a denial of service (domain 0 VCPU hang and kernel panic) by ... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now