2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-5690——RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allow remote attackers to execute arbitrar...
CVE-2012-5178——Cross-site request forgery (CSRF) vulnerability in the Welcart plugin before 1.2.2 for WordPress allows remote attackers...
CVE-2012-5177——Cross-site scripting (XSS) vulnerability in the Welcart plugin before 1.2.2 for WordPress allows remote attackers to inj...
CVE-2012-4848——Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Foundations Start before 1.2.2c allow remote authentica...
CVE-2012-4846——IBM Lotus Notes 8.5.x before 8.5.3 FP3 does not include the HTTPOnly flag in a Set-Cookie header for a web-application c...
CVE-2012-4534——org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO conne...
CVE-2012-4431——org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows re...
CVE-2012-3546——org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authenticat...
CVE-2012-3329——IBM Advanced Settings Utility (ASU) through 3.62 and 3.70 through 9.21 and Bootable Media Creator (BoMC) through 2.30 an...
CVE-2012-4350——Multiple unquoted Windows search path vulnerabilities in the (1) Manager and (2) Agent components in Symantec Enterprise...
CVE-2012-4348——The management console in Symantec Endpoint Protection (SEP) 11.0 before RU7-MP3 and 12.1 before RU2, and Symantec Endpo...
CVE-2012-4898——Mesh OS before 7.9.1.1 on Tropos wireless mesh routers does not use a sufficient source of entropy for SSH keys, which m...
CVE-2012-4693——Invensys Wonderware InTouch 2012 R2 and earlier and Siemens ProcessSuite use a weak encryption algorithm for data in Ps_...
CVE-2012-4691——Memory leak in Siemens Automation License Manager (ALM) 4.x and 5.x before 5.2 allows remote attackers to cause a denial...
CVE-2012-5622——Cross-site request forgery (CSRF) vulnerability in the management console (openshift-console/app/controllers/application...
CVE-2012-5610——Incomplete blacklist vulnerability in lib/filesystem.php in ownCloud before 4.0.9 and 4.5.x before 4.5.2 allows remote a...
CVE-2012-5609——Incomplete blacklist vulnerability in lib/migrate.php in ownCloud before 4.5.2 allows remote authenticated users to exec...
CVE-2012-5608——Cross-site scripting (XSS) vulnerability in apps/user_webdavauth/settings.php in ownCloud 4.5.x before 4.5.2 allows remo...
CVE-2012-5607——The "Lost Password" reset functionality in ownCloud before 4.0.9 and 4.5.0 does not properly check the security token, w...
CVE-2012-5606——Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.9 and 4.5.0 allow remote attackers to inject ...
CVE-2012-5576——Multiple stack-based buffer overflows in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.8.2 allow remote attack...
CVE-2012-5574——lib/form/sfForm.class.php in Symfony CMS before 1.4.20 allows remote attackers to read arbitrary files via a crafted upl...
CVE-2012-5571MEDIUM5.4A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authoriz...
CVE-2012-5563——OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implement token expiration, which allows remot...
CVE-2012-5468——Heap-based buffer overflow in iconvert.c in the bogolexer component in Bogofilter before 1.2.3 allows remote attackers t...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now