2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-5796 | — | — | 0.6% | Nov 4, 2012 | The PayPal Pro module in osCommerce does not verify that the server hostname matches a domain name in the subject's Comm... |
| CVE-2012-5795 | — | — | 0.6% | Nov 4, 2012 | The PayPal Express module in osCommerce does not verify that the server hostname matches a domain name in the subject's ... |
| CVE-2012-5794 | — | — | 0.6% | Nov 4, 2012 | The MoneyBookers module in osCommerce does not verify that the server hostname matches a domain name in the subject's Co... |
| CVE-2012-5793 | — | — | 0.6% | Nov 4, 2012 | The Authorize.Net module in osCommerce does not verify that the server hostname matches a domain name in the subject's C... |
| CVE-2012-5792 | — | — | 0.6% | Nov 4, 2012 | The Sage Pay Direct module in osCommerce does not verify that the server hostname matches a domain name in the subject's... |
| CVE-2012-5791 | — | — | 0.6% | Nov 4, 2012 | PayPal Invoicing does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or sub... |
| CVE-2012-5790 | — | — | 0.6% | Nov 4, 2012 | PayPal Payments Standard PHP Library 20120427 does not verify that the server hostname matches a domain name in the subj... |
| CVE-2012-5789 | — | — | 0.6% | Nov 4, 2012 | PayPal Payments Standard PHP Library before 20120427 does not verify that the server hostname matches a domain name in t... |
| CVE-2012-5788 | — | — | 0.6% | Nov 4, 2012 | The PayPal IPN utility does not verify that the server hostname matches a domain name in the subject's Common Name (CN) ... |
| CVE-2012-5787 | — | — | 0.9% | Nov 4, 2012 | The PayPal merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN)... |
| CVE-2012-5786 | — | — | 1.1% | Nov 4, 2012 | The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF befor... |
| CVE-2012-5785 | — | — | 2.2% | Nov 4, 2012 | Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Comm... |
| CVE-2012-5784 | — | — | 5.7% | Nov 4, 2012 | Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the... |
| CVE-2012-5783 | — | — | 9.3% | Nov 4, 2012 | Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, d... |
| CVE-2012-5782 | — | — | 0.6% | Nov 4, 2012 | Amazon Flexible Payments Service (FPS) PHP Library does not verify that the server hostname matches a domain name in the... |
| CVE-2012-5781 | — | — | 0.7% | Nov 4, 2012 | Amazon Elastic Load Balancing API Tools does not verify that the server hostname matches a domain name in the subject's ... |
| CVE-2012-5780 | — | — | 0.6% | Nov 4, 2012 | The Amazon merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN)... |
| CVE-2012-5170 | — | — | 1.3% | Nov 4, 2012 | Open redirect vulnerability in Pebble before 2.6.4 allows remote attackers to redirect users to arbitrary web sites and ... |
| CVE-2012-4987 | — | — | 3.0% | Nov 4, 2012 | Stack-based buffer overflow in RealNetworks RealPlayer 15.0.5.109 allows user-assisted remote attackers to execute arbit... |
| CVE-2012-3750 | — | — | 0.4% | Nov 3, 2012 | The Passcode Lock implementation in Apple iOS before 6.0.1 does not properly manage the lock state, which allows physica... |
| CVE-2012-3749 | — | — | 2.2% | Nov 3, 2012 | The extensions APIs in the kernel in Apple iOS before 6.0.1 provide kernel addresses in responses that contain an OSBund... |
| CVE-2012-3748 | — | — | 14.4% | Nov 3, 2012 | Race condition in WebKit in Apple iOS before 6.0.1 and Safari before 6.0.2 allows remote attackers to execute arbitrary ... |
| CVE-2012-0025 | — | — | 6.4% | Nov 2, 2012 | Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the Fla... |
| CVE-2012-4498 | — | — | 1.5% | Nov 2, 2012 | The Activism module 6.x-2.x before 6.x-2.1 for Drupal does not properly restrict access to the "Campaign" content type, ... |
| CVE-2012-4497 | — | — | 1.1% | Nov 2, 2012 | Cross-site scripting (XSS) vulnerability in the "3 slide gallery" in the Elegant Theme module 7.x-1.x before 7.x-1.1 for... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now