2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-4493 | — | — | 0.9% | Nov 2, 2012 | Cross-site scripting (XSS) vulnerability in the administrative interface in the Better Revisions module 7.x-1.x before 7... |
| CVE-2012-4487 | — | — | 1.1% | Nov 2, 2012 | The Subuser module before 6.x-1.8 for Drupal does not properly check "switch subuser" permissions, which allows remote a... |
| CVE-2012-4486 | — | — | 0.6% | Nov 2, 2012 | Cross-site request forgery (CSRF) vulnerability in the Subuser module before 6.x-1.8 for Drupal allows remote attackers ... |
| CVE-2012-5417 | — | — | 3.1% | Nov 2, 2012 | Cisco Prime Data Center Network Manager (DCNM) before 6.1(1) does not properly restrict access to certain JBoss MainDepl... |
| CVE-2012-5416 | — | — | 2.0% | Nov 2, 2012 | Buffer overflow in Cisco Unified MeetingPlace Web Conferencing before 7.1MR1 Patch 1, 8.0 before 8.0MR1 Patch 1, and 8.5... |
| CVE-2012-5705 | — | — | 1.0% | Nov 1, 2012 | Cross-site scripting (XSS) vulnerability in the settings page (admin/settings/hotblocks) in the Hotblocks module 6.x-1.x... |
| CVE-2012-5704 | — | — | 1.1% | Nov 1, 2012 | The Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the "administer hotblocks"... |
| CVE-2012-5687 | — | — | 68.7% | Nov 1, 2012 | Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13... |
| CVE-2012-5409 | — | — | 15.8% | Nov 1, 2012 | AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages r... |
| CVE-2012-3026 | — | — | 5.0% | Nov 1, 2012 | rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through... |
| CVE-2012-3021 | — | — | 5.0% | Nov 1, 2012 | rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through... |
| CVE-2012-3010 | — | — | 5.0% | Nov 1, 2012 | rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through... |
| CVE-2012-4940 | — | — | 83.6% | Oct 31, 2012 | Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote att... |
| CVE-2012-4939 | — | — | 7.2% | Oct 31, 2012 | Cross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface before 3.0-HotFix1 in SolarWi... |
| CVE-2012-5671 | — | — | 8.4% | Oct 31, 2012 | Heap-based buffer overflow in the dkim_exim_query_dns_txt function in dkim.c in Exim 4.70 through 4.80, when DKIM suppor... |
| CVE-2012-4544 | — | — | 0.4% | Oct 31, 2012 | The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after... |
| CVE-2012-4532 | — | — | 1.4% | Oct 31, 2012 | Cross-site scripting (XSS) vulnerability in modules/mod_languages/tmpl/default.php in the Language Switcher module for J... |
| CVE-2012-4531 | — | — | 2.0% | Oct 31, 2012 | Cross-site scripting (XSS) vulnerability in Joomla! 2.5.x before 2.5.7 allows remote attackers to inject arbitrary web s... |
| CVE-2012-4500 | — | — | 1.0% | Oct 31, 2012 | The Announcements module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users with the "access announceme... |
| CVE-2012-4499 | — | — | 1.3% | Oct 31, 2012 | The contact formatter page in the Email Field module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows... |
| CVE-2012-4496 | — | — | 1.1% | Oct 31, 2012 | Cross-site scripting (XSS) vulnerability in the Custom Publishing Options module 6.x-1.x before 6.x-1.4 for Drupal allow... |
| CVE-2012-4495 | — | — | 1.2% | Oct 31, 2012 | The Mime Mail module 6.x-1.x before 6.x-1.1 for Drupal does not properly restrict access to files outside Drupal's publi... |
| CVE-2012-4494 | — | — | 1.1% | Oct 31, 2012 | The Shibboleth authentication module 7.x-4.0 for Drupal does not properly check the active status of users, which allows... |
| CVE-2012-4492 | — | — | 1.0% | Oct 31, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in the Shorten URLs module 6.x-1.x before 6.x-1.13 and 7.x-1.x befor... |
| CVE-2012-4491 | — | — | 1.2% | Oct 31, 2012 | The Monthly Archive by Node Type module 6.x for Drupal does not properly check permissions defined by node_access module... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now