2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-3498PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest OS kernels to cause ...
CVE-2012-3497(1) TMEMC_SAVE_GET_CLIENT_WEIGHT, (2) TMEMC_SAVE_GET_CLIENT_CAP, (3) TMEMC_SAVE_GET_CLIENT_FLAGS and (4) TMEMC_SAVE_END ...
CVE-2012-3496XENMEM_populate_physmap in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when translating paging mode i...
CVE-2012-3495The physdev_get_free_pirq hypercall in arch/x86/physdev.c in Xen 4.1.x and Citrix XenServer 6.0.2 and earlier uses the r...
CVE-2012-3494The set_debugreg hypercall in include/asm-x86/debugreg.h in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlie...
CVE-2012-3431The Teiid Java Database Connectivity (JDBC) socket, as used in JBoss Enterprise Data Services Platform before 5.3.0, doe...
CVE-2012-2377JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platfo...
CVE-2012-2086SQL injection vulnerability in the get_last_conversation_lines function in common/logger.py in Gajim before 0.15 allows ...
CVE-2012-1167The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before...
CVE-2012-0818RESTEasy before 2.3.1 allows remote attackers to read arbitrary files via an external entity reference in a DOM document...
CVE-2012-5864These Sinapsi devices do not check if users that visit pages within the device have properly authenticated. By directl...
CVE-2012-5863These Sinapsi devices do not check for special elements in commands sent to the system. By accessing certain pages with...
CVE-2012-5862These Sinapsi devices store hard-coded passwords in the PHP file of the device. By using the hard-coded passwords in th...
CVE-2012-5861These Sinapsi devices do not check the validity of the data before executing queries. By accessing the SQL table of cer...
CVE-2012-5759The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 allows remote authenticat...
CVE-2012-5758The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 does not require authenti...
CVE-2012-5756The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2, when a collective config...
CVE-2012-5173Session fixation vulnerability in BIGACE before 2.7.8 allows remote attackers to hijack web sessions via unspecified vec...
CVE-2012-2211Cross-site scripting (XSS) vulnerability in phpgwapi/inc/common_functions_inc.php in eGroupware before 1.8.004.20120405 ...
CVE-2012-2084Cross-site scripting (XSS) vulnerability in the Printer, email and PDF versions module 6.x-1.x before 6.x-1.15 and 7.x-1...
CVE-2012-5526CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might a...
CVE-2012-4539Xen 4.0 through 4.2, when running 32-bit x86 PV guests on 64-bit hypervisors, allows local guest OS administrators to ca...
CVE-2012-4537Xen 3.4 through 4.2, and possibly earlier versions, does not properly synchronize the p2m and m2p tables when the set_p2...
CVE-2012-4536The (1) domain_pirq_to_emuirq and (2) physdev_unmap_pirq functions in Xen 2.2 allows local guest OS administrators to ca...
CVE-2012-4535Xen 3.4 through 4.2, and possibly earlier versions, allows local guest OS administrators to cause a denial of service (X...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now