2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-4473 | — | — | 1.0% | Nov 30, 2012 | The Restrict node page view module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "view an... |
| CVE-2012-4472 | — | — | 1.4% | Nov 30, 2012 | Unrestricted file upload vulnerability in upload.php in the Drag & Drop Gallery module 6.x-1.5 and earlier for Drupal al... |
| CVE-2012-4471 | — | — | 1.3% | Nov 30, 2012 | The Search Autocomplete module 7.x-2.x before 7.x-2.4 for Drupal does not properly restrict access to the module admin p... |
| CVE-2012-4470 | — | — | 1.3% | Nov 30, 2012 | The Listhandler module 6.x-1.x before 6.x-1.1 for Drupal does not properly check permissions when importing emails, whic... |
| CVE-2012-4469 | — | — | 1.2% | Nov 30, 2012 | Cross-site scripting (XSS) vulnerability in the Hashcash module 6.x-2.x before 6.x-2.6 and 7.x-2.x before 7.x-2.2 for Dr... |
| CVE-2012-4468 | — | — | 1.2% | Nov 30, 2012 | Cross-site scripting (XSS) vulnerability in the Privatemsg module 7.x-1.x before 7.x-1.3 for Drupal allows remote attack... |
| CVE-2012-5568 | — | — | 9.6% | Nov 30, 2012 | Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP reques... |
| CVE-2012-4834 | — | — | 3.1% | Nov 30, 2012 | Directory traversal vulnerability in LayerLoader.jsp in the theme component in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 ... |
| CVE-2012-4557 | — | — | 17.5% | Nov 30, 2012 | The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon d... |
| CVE-2012-5174 | — | — | 2.6% | Nov 30, 2012 | The KYOCERA AH-K3001V, AH-K3002V, WX300K, WX310K, WX320K, and WX320KR devices allow remote attackers to cause a denial o... |
| CVE-2012-4222 | — | — | 0.7% | Nov 30, 2012 | drivers/gpu/msm/kgsl.c in the Qualcomm Innovation Center (QuIC) Graphics KGSL kernel-mode driver for Android 2.3 through... |
| CVE-2012-4221 | — | — | 2.1% | Nov 30, 2012 | Integer overflow in diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver f... |
| CVE-2012-4220 | — | — | 3.0% | Nov 30, 2012 | diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver for Android 2.3 throu... |
| CVE-2012-5530 | — | — | 0.4% | Nov 29, 2012 | The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before 3.6.10 allow local users to overwrite ar... |
| CVE-2012-4841 | — | — | 1.6% | Nov 29, 2012 | Unspecified vulnerability in Tivoli Endpoint Manager for Remote Control Broker 8.2 before 8.2.1-TIV-TEMRC821-IF0002 allo... |
| CVE-2012-3271 | — | — | 5.1% | Nov 29, 2012 | Unspecified vulnerability on the HP Integrated Lights-Out 3 (aka iLO3) with firmware before 1.50 and Integrated Lights-O... |
| CVE-2012-6051 | — | — | 0.6% | Nov 28, 2012 | Google CityHash computes hash values without properly restricting the ability to trigger hash collisions predictably, wh... |
| CVE-2012-5373 | — | — | 2.3% | Nov 28, 2012 | Oracle Java SE 7 and earlier, and OpenJDK 7 and earlier, computes hash values without properly restricting the ability t... |
| CVE-2012-5372 | — | — | 1.9% | Nov 28, 2012 | Rubinius computes hash values without properly restricting the ability to trigger hash collisions predictably, which all... |
| CVE-2012-5371 | — | — | 3.4% | Nov 28, 2012 | Ruby (aka CRuby) 1.9 before 1.9.3-p327 and 2.0 before r37575 computes hash values without properly restricting the abili... |
| CVE-2012-5370 | — | — | 2.2% | Nov 28, 2012 | JRuby computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows... |
| CVE-2012-2739 | — | — | 3.2% | Nov 28, 2012 | Oracle Java SE before 7 Update 6, and OpenJDK 7 before 7u6 build 12 and 8 before build 39, computes hash values without ... |
| CVE-2012-5136 | — | — | 1.3% | Nov 28, 2012 | Google Chrome before 23.0.1271.91 does not properly perform a cast of an unspecified variable during handling of the INP... |
| CVE-2012-5135 | — | — | 1.4% | Nov 28, 2012 | Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service o... |
| CVE-2012-5134 | — | — | 4.4% | Nov 28, 2012 | Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now