2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-5899 | — | — | 1.6% | Nov 17, 2012 | Cross-site scripting (XSS) vulnerability in admin/action/objects.php in SAMEDIA LandShop 0.9.2 allows remote attackers t... |
| CVE-2012-5898 | — | — | 1.1% | Nov 17, 2012 | Cross-site request forgery (CSRF) vulnerability in SAMEDIA LandShop 0.9.2 allows remote attackers to hijack the authenti... |
| CVE-2012-5897 | — | — | 3.8% | Nov 17, 2012 | The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and e... |
| CVE-2012-5896 | — | — | 69.4% | Nov 17, 2012 | The Annotation Objects Extension ActiveX control in AnnotateX.dll in Quest InTrust 10.4.0.853 and earlier does not prope... |
| CVE-2012-5895 | — | — | 1.7% | Nov 17, 2012 | Multiple unspecified vulnerabilities in iRODS before 3.1 have unknown impact and attack vectors. |
| CVE-2012-5894 | — | — | 1.1% | Nov 17, 2012 | SQL injection vulnerability in hava_post.php in Havalite CMS 1.1.0 and earlier allows remote attackers to execute arbitr... |
| CVE-2012-5893 | — | — | 2.8% | Nov 17, 2012 | Unrestricted file upload vulnerability in hava_upload.php in Havalite CMS 1.1.0 and earlier allows remote attackers to e... |
| CVE-2012-5892 | — | — | 1.5% | Nov 17, 2012 | Havalite CMS 1.1.0 and earlier stores sensitive information under the web root with insufficient access control, which a... |
| CVE-2012-5891 | — | — | 1.1% | Nov 17, 2012 | Multiple cross-site request forgery (CSRF) vulnerabilities in photo/pass.php in DAlbum 1.44 build 174 and earlier allow ... |
| CVE-2012-5890 | — | — | 1.4% | Nov 17, 2012 | The Front End User Registration (sr_feuser_register) extension before 2.6.2 for TYPO3 allows remote attackers to obtain ... |
| CVE-2012-5889 | — | — | 0.9% | Nov 17, 2012 | Cross-site scripting (XSS) vulnerability in the powermail extension before 1.6.5 for TYPO3 allows remote attackers to in... |
| CVE-2012-5888 | — | — | 1.8% | Nov 17, 2012 | Cross-site scripting (XSS) vulnerability in Basic SEO Features (seo_basics) extension before 0.8.2 for TYPO3 allows remo... |
| CVE-2012-5887 | — | — | 12.1% | Nov 17, 2012 | The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x be... |
| CVE-2012-5886 | — | — | 8.8% | Nov 17, 2012 | The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x be... |
| CVE-2012-5885 | — | — | 9.0% | Nov 17, 2012 | The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x b... |
| CVE-2012-5856 | — | — | 1.9% | Nov 17, 2012 | Cross-site scripting (XSS) vulnerability in the Uk Cookie (aka uk-cookie) plugin for WordPress allows remote attackers t... |
| CVE-2012-3439 | — | — | — | Nov 17, 2012 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-5885, CVE-2012-5886, CVE-2012-5887. Reason: This... |
| CVE-2012-5172 | — | — | 1.4% | Nov 16, 2012 | The Asial Monaca Debugger application before 1.4.2 for Android allows remote attackers to obtain sensitive (1) account o... |
| CVE-2012-2733 | — | — | 8.7% | Nov 16, 2012 | java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 a... |
| CVE-2012-5884 | — | — | 1.2% | Nov 16, 2012 | The User.get method in Bugzilla/WebService/User.pm in Bugzilla 4.3.2 allows remote attackers to obtain sensitive informa... |
| CVE-2012-5883 | — | — | 2.1% | Nov 16, 2012 | Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.9.0, as used in Bu... |
| CVE-2012-5882 | — | — | 2.4% | Nov 16, 2012 | Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.9.0 allows remote ... |
| CVE-2012-5881 | — | — | 2.5% | Nov 16, 2012 | Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.9.0 allows remote ... |
| CVE-2012-5475 | — | — | — | Nov 16, 2012 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-5881, CVE-2012-5882, CVE-2012-5883. Reason: This... |
| CVE-2012-4199 | — | — | 1.0% | Nov 16, 2012 | template/en/default/bug/field-events.js.tmpl in Bugzilla 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now