2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-5892 | — | — | 1.5% | Nov 17, 2012 | Havalite CMS 1.1.0 and earlier stores sensitive information under the web root with insufficient access control, which a... |
| CVE-2012-5891 | — | — | 1.1% | Nov 17, 2012 | Multiple cross-site request forgery (CSRF) vulnerabilities in photo/pass.php in DAlbum 1.44 build 174 and earlier allow ... |
| CVE-2012-5890 | — | — | 1.4% | Nov 17, 2012 | The Front End User Registration (sr_feuser_register) extension before 2.6.2 for TYPO3 allows remote attackers to obtain ... |
| CVE-2012-5889 | — | — | 0.9% | Nov 17, 2012 | Cross-site scripting (XSS) vulnerability in the powermail extension before 1.6.5 for TYPO3 allows remote attackers to in... |
| CVE-2012-5888 | — | — | 1.8% | Nov 17, 2012 | Cross-site scripting (XSS) vulnerability in Basic SEO Features (seo_basics) extension before 0.8.2 for TYPO3 allows remo... |
| CVE-2012-5887 | — | — | 12.1% | Nov 17, 2012 | The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x be... |
| CVE-2012-5886 | — | — | 8.8% | Nov 17, 2012 | The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x be... |
| CVE-2012-5885 | — | — | 9.0% | Nov 17, 2012 | The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x b... |
| CVE-2012-5856 | — | — | 1.9% | Nov 17, 2012 | Cross-site scripting (XSS) vulnerability in the Uk Cookie (aka uk-cookie) plugin for WordPress allows remote attackers t... |
| CVE-2012-3439 | — | — | — | Nov 17, 2012 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-5885, CVE-2012-5886, CVE-2012-5887. Reason: This... |
| CVE-2012-5172 | — | — | 1.4% | Nov 16, 2012 | The Asial Monaca Debugger application before 1.4.2 for Android allows remote attackers to obtain sensitive (1) account o... |
| CVE-2012-2733 | — | — | 8.7% | Nov 16, 2012 | java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 a... |
| CVE-2012-5884 | — | — | 1.2% | Nov 16, 2012 | The User.get method in Bugzilla/WebService/User.pm in Bugzilla 4.3.2 allows remote attackers to obtain sensitive informa... |
| CVE-2012-5883 | — | — | 2.1% | Nov 16, 2012 | Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.9.0, as used in Bu... |
| CVE-2012-5882 | — | — | 2.4% | Nov 16, 2012 | Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.9.0 allows remote ... |
| CVE-2012-5881 | — | — | 2.5% | Nov 16, 2012 | Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.9.0 allows remote ... |
| CVE-2012-5475 | — | — | — | Nov 16, 2012 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-5881, CVE-2012-5882, CVE-2012-5883. Reason: This... |
| CVE-2012-4199 | — | — | 1.0% | Nov 16, 2012 | template/en/default/bug/field-events.js.tmpl in Bugzilla 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.... |
| CVE-2012-4198 | — | — | 0.9% | Nov 16, 2012 | The User.get method in Bugzilla/WebService/User.pm in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.... |
| CVE-2012-4197 | — | — | 1.5% | Nov 16, 2012 | Bugzilla/Attachment.pm in attachment.cgi in Bugzilla 2.x and 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and ... |
| CVE-2012-4189 | — | — | 1.0% | Nov 16, 2012 | Cross-site scripting (XSS) vulnerability in Bugzilla 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1, al... |
| CVE-2012-5777 | — | — | 2.2% | Nov 16, 2012 | Eval injection vulnerability in the ReplaceListVars function in the template parser in e/class/connect.php in EmpireCMS ... |
| CVE-2012-5523 | — | — | 1.9% | Nov 16, 2012 | core/email_api.php in MantisBT before 1.2.12 does not properly manage the sending of e-mail notifications about restrict... |
| CVE-2012-5522 | — | — | 1.3% | Nov 16, 2012 | MantisBT before 1.2.12 does not use an expected default value during decisions about whether a user may modify the statu... |
| CVE-2012-4613 | — | — | 0.3% | Nov 16, 2012 | EMC RSA Data Protection Manager Appliance 2.7.x and 3.x before 3.2.1 does not properly restrict the number of authentica... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now