2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-1101MEDIUM5.5systemd 37-1 does not properly handle non-existent services, which causes a denial of service (failure of login procedur...
CVE-2012-1096MEDIUM5.5NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connect...
CVE-2012-1094HIGH7.5JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-c...
CVE-2012-0785HIGH7.5Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by Cloud...
CVE-2012-1093HIGH7.8The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a pr...
CVE-2012-0844MEDIUM5.5Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar.
CVE-2012-0828CRITICAL9.8Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote ...
CVE-2012-6277HIGH7.8Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Micros...
CVE-2012-0063HIGH8.1Insecure plugin update mechanism in tucan through 0.3.10 could allow remote attackers to perform man-in-the-middle attac...
CVE-2012-5236Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2012-3351MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in LongTail Video JW Player through 5.10.2295 allow remote attackers...
CVE-2012-2599Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-3835. Reason: This issue was MERGED into CVE-201...
CVE-2012-5366HIGH7.5The IPv6 implementation in Apple Mac OS X (unknown versions, year 2012 and earlier) allows remote attackers to cause a d...
CVE-2012-5365HIGH7.5The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and earlier) allows remote attackers to cause...
CVE-2012-5364HIGH7.5The IPv6 implementation in Microsoft Windows 7 and earlier allows remote attackers to cause a denial of service via a fl...
CVE-2012-5363HIGH7.5The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and earlier) allows remote attackers to cause...
CVE-2012-5362HIGH7.5The IPv6 implementation in Microsoft Windows 7 and earlier allows remote attackers to cause a denial of service via a fl...
CVE-2012-2629HIGH8.8Multiple cross-site request forgery (CSRF) and cross-site scripting (XSS) vulnerabilities in Axous 1.1.1 and earlier all...
CVE-2012-0055HIGH7.8OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security chec...
CVE-2012-6685HIGH7.5Nokogiri before 1.5.4 is vulnerable to XXE attacks
CVE-2012-6614HIGH7.2D-Link DSR-250N devices before 1.08B31 allow remote authenticated users to obtain "persistent root access" via the BusyB...
CVE-2012-1932MEDIUM4.8A cross-site scripting (XSS) vulnerability in Wolf CMS 0.75 and earlier allows remote attackers to inject arbitrary web ...
CVE-2012-0718MEDIUM5.4IBM Tivoli Endpoint Manager 8 does not set the HttpOnly flag on cookies.
CVE-2012-2412Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-4531. Reason: This candidate is a duplicate of C...
CVE-2012-6091HIGH7.5Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure vulnerability.

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now