2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-5690RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allow remote attackers to execute arbitrar...
CVE-2012-5178Cross-site request forgery (CSRF) vulnerability in the Welcart plugin before 1.2.2 for WordPress allows remote attackers...
CVE-2012-5177Cross-site scripting (XSS) vulnerability in the Welcart plugin before 1.2.2 for WordPress allows remote attackers to inj...
CVE-2012-4848Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Foundations Start before 1.2.2c allow remote authentica...
CVE-2012-4846IBM Lotus Notes 8.5.x before 8.5.3 FP3 does not include the HTTPOnly flag in a Set-Cookie header for a web-application c...
CVE-2012-4534org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO conne...
CVE-2012-4431org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows re...
CVE-2012-3546org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authenticat...
CVE-2012-3329IBM Advanced Settings Utility (ASU) through 3.62 and 3.70 through 9.21 and Bootable Media Creator (BoMC) through 2.30 an...
CVE-2012-4350Multiple unquoted Windows search path vulnerabilities in the (1) Manager and (2) Agent components in Symantec Enterprise...
CVE-2012-4348The management console in Symantec Endpoint Protection (SEP) 11.0 before RU7-MP3 and 12.1 before RU2, and Symantec Endpo...
CVE-2012-4898Mesh OS before 7.9.1.1 on Tropos wireless mesh routers does not use a sufficient source of entropy for SSH keys, which m...
CVE-2012-4693Invensys Wonderware InTouch 2012 R2 and earlier and Siemens ProcessSuite use a weak encryption algorithm for data in Ps_...
CVE-2012-4691Memory leak in Siemens Automation License Manager (ALM) 4.x and 5.x before 5.2 allows remote attackers to cause a denial...
CVE-2012-5622Cross-site request forgery (CSRF) vulnerability in the management console (openshift-console/app/controllers/application...
CVE-2012-5610Incomplete blacklist vulnerability in lib/filesystem.php in ownCloud before 4.0.9 and 4.5.x before 4.5.2 allows remote a...
CVE-2012-5609Incomplete blacklist vulnerability in lib/migrate.php in ownCloud before 4.5.2 allows remote authenticated users to exec...
CVE-2012-5608Cross-site scripting (XSS) vulnerability in apps/user_webdavauth/settings.php in ownCloud 4.5.x before 4.5.2 allows remo...
CVE-2012-5607The "Lost Password" reset functionality in ownCloud before 4.0.9 and 4.5.0 does not properly check the security token, w...
CVE-2012-5606Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.9 and 4.5.0 allow remote attackers to inject ...
CVE-2012-5576Multiple stack-based buffer overflows in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.8.2 allow remote attack...
CVE-2012-5574lib/form/sfForm.class.php in Symfony CMS before 1.4.20 allows remote attackers to read arbitrary files via a crafted upl...
CVE-2012-5571MEDIUM5.4A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authoriz...
CVE-2012-5563OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implement token expiration, which allows remot...
CVE-2012-5468Heap-based buffer overflow in iconvert.c in the bogolexer component in Bogofilter before 1.2.3 allows remote attackers t...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now