2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-4970Cross-site scripting (XSS) vulnerability in the web management interface on Polycom HDX Video End Points with UC APL sof...
CVE-2012-6371The WPA2 implementation on the Belkin N900 F9K1104v1 router establishes a WPS PIN based on 6 digits of the LAN/WLAN MAC ...
CVE-2012-6453Cross-site scripting (XSS) vulnerability in the RSS Reader extension before 0.2.6 for MediaWiki allows remote attackers ...
CVE-2012-6339Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface in Cerberus FTP Server before 5....
CVE-2012-6337The Track My Mobile feature in the SamsungDive subsystem for Android on Samsung Galaxy devices shows the activation of r...
CVE-2012-6336The Missing Device feature in Lookout allows physically proximate attackers to provide arbitrary location data via a "co...
CVE-2012-6335The Anti-theft service in AVG AntiVirus for Android allows physically proximate attackers to provide arbitrary location ...
CVE-2012-6334The Track My Mobile feature in the SamsungDive subsystem for Android on Samsung Galaxy devices does not properly impleme...
CVE-2012-5642server/action.py in Fail2ban before 0.8.8 does not properly handle the content of the matches tag, which might allow rem...
CVE-2012-4688The Central application in i-GEN opLYNX before 2.01.9 allows remote attackers to bypass authentication via vectors invol...
CVE-2012-4792HIGH8.8Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary cod...
CVE-2012-6369Cross-site scripting (XSS) vulnerability in the Troubleshooting Reporting System feature in AgileBits 1Password 3.9.9 mi...
CVE-2012-5445The kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software befor...
CVE-2012-4932Multiple cross-site scripting (XSS) vulnerabilities in SimpleInvoices before stable-2012-1-CIS3000 allow remote attacker...
CVE-2012-4528The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver ar...
CVE-2012-3873Multiple SQL injection vulnerabilities in Open Constructor 3.12.0 allow remote authenticated users to execute arbitrary ...
CVE-2012-3872Multiple cross-site scripting (XSS) vulnerabilities in Open Constructor 3.12.0 allow remote attackers to inject arbitrar...
CVE-2012-3871Cross-site scripting (XSS) vulnerability in data/hybrid/i_hybrid.php in Open Constructor 3.12.0 allows remote authentica...
CVE-2012-3870Multiple cross-site scripting (XSS) vulnerabilities in objects/createobject.php in Open Constructor 3.12.0 allow remote ...
CVE-2012-0741IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certifica...
CVE-2012-0738IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certifica...
CVE-2012-6432Symfony 2.0.x before 2.0.20, 2.1.x before 2.1.5, and 2.2-dev, when the internal routes configuration is enabled, allows ...
CVE-2012-6431Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, w...
CVE-2012-5868WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it...
CVE-2012-5532The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.8-rc1, allows l...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now