2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2012-4615EMC Smarts Network Configuration Manager (NCM) before 9.1 uses a hardcoded encryption key for the storage of credentials...
CVE-2012-4614The default configuration of EMC Smarts Network Configuration Manager (NCM) before 9.1 does not require authentication f...
CVE-2012-4611Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Adaptive Authentication On-Premise (AAOP) before 7.0 allo...
CVE-2012-6050The winbox service in MikroTik RouterOS 5.15 and earlier allows remote attackers to cause a denial of service (CPU consu...
CVE-2012-6049Open Solution Quick.Cart 5.0 allows remote attackers to obtain sensitive information via (1) a long string or (2) invali...
CVE-2012-6048Guitar Pro 6.1.1 r10791 allows remote attackers to cause a denial of service (crash) via a long string in a gpx file.
CVE-2012-6047Cross-site request forgery (CSRF) vulnerability in X7 Chat 2.0.5.1 and earlier allows remote attackers to hijack the aut...
CVE-2012-6046Static code injection vulnerability in admin/banners.php in PHP Enter allows remote attackers to inject arbitrary PHP co...
CVE-2012-6045Cross-site scripting (XSS) vulnerability in gb/user/index.php in Ramui Forum, possibly 1.0 Beta, allows remote attackers...
CVE-2012-6044M-Player 0.4 allows remote attackers to cause a denial of service (crash) via a crafted MP3 file.
CVE-2012-6043Cross-site scripting (XSS) vulnerability in downloads.php in PHP-Fusion 7.02.04 allows remote attackers to inject arbitr...
CVE-2012-6042GPSMapEdit 1.1.73.2 allows user-assisted remote attackers to cause a denial of service (crash) via a long string in a ls...
CVE-2012-6041Double free vulnerability in GreenBrowser before 6.0.1002, when the keyword search bar (F6) is activated, allows remote ...
CVE-2012-6040Cross-site scripting (XSS) vulnerability in users.php in File King Advanced File Management 1.4 allows remote attackers ...
CVE-2012-6039SQL injection vulnerability in view_comments.php in YABSoft Advanced Image Hosting (AIH) Script, possibly 2.3, allows re...
CVE-2012-6038admin/core/admin_func.php in razorCMS before 1.2.1 does not properly restrict access to certain administrator directorie...
CVE-2012-5520The send_to_sourcefire function in manage_sql.c in OpenVAS Manager 3.x before 3.0.4 allows remote attackers to execute a...
CVE-2012-2438ar web content manager (AWCM) 2.2 does not restrict the number of comment records that can be submitted through HTTP req...
CVE-2012-2437cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to ge...
CVE-2012-0698tcsd in TrouSerS before 0.3.10 allows remote attackers to cause a denial of service (daemon crash) via a crafted type_of...
CVE-2012-6037Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4, and other versi...
CVE-2012-5533The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial o...
CVE-2012-4538The HVMOP_pagetable_dying hypercall in Xen 4.0, 4.1, and 4.2 does not properly check the pagetable state when running on...
CVE-2012-4522The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlevel 286 and Ruby 2.0.0 before r37163 allows context...
CVE-2012-3433Xen 4.0 and 4.1 allows local HVM guest OS kernels to cause a denial of service (domain 0 VCPU hang and kernel panic) by ...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now