2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-5785 | — | — | 2.2% | Nov 4, 2012 | Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Comm... |
| CVE-2012-5784 | — | — | 5.7% | Nov 4, 2012 | Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the... |
| CVE-2012-5783 | — | — | 9.3% | Nov 4, 2012 | Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, d... |
| CVE-2012-5782 | — | — | 0.6% | Nov 4, 2012 | Amazon Flexible Payments Service (FPS) PHP Library does not verify that the server hostname matches a domain name in the... |
| CVE-2012-5781 | — | — | 0.7% | Nov 4, 2012 | Amazon Elastic Load Balancing API Tools does not verify that the server hostname matches a domain name in the subject's ... |
| CVE-2012-5780 | — | — | 0.6% | Nov 4, 2012 | The Amazon merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN)... |
| CVE-2012-3446 | MEDIUM | 5.9 | 1.2% | Nov 4, 2012 | Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname ma... |
| CVE-2012-5170 | — | — | 1.3% | Nov 4, 2012 | Open redirect vulnerability in Pebble before 2.6.4 allows remote attackers to redirect users to arbitrary web sites and ... |
| CVE-2012-4987 | — | — | 3.0% | Nov 4, 2012 | Stack-based buffer overflow in RealNetworks RealPlayer 15.0.5.109 allows user-assisted remote attackers to execute arbit... |
| CVE-2012-3750 | — | — | 0.4% | Nov 3, 2012 | The Passcode Lock implementation in Apple iOS before 6.0.1 does not properly manage the lock state, which allows physica... |
| CVE-2012-3749 | — | — | 2.2% | Nov 3, 2012 | The extensions APIs in the kernel in Apple iOS before 6.0.1 provide kernel addresses in responses that contain an OSBund... |
| CVE-2012-3748 | — | — | 14.4% | Nov 3, 2012 | Race condition in WebKit in Apple iOS before 6.0.1 and Safari before 6.0.2 allows remote attackers to execute arbitrary ... |
| CVE-2012-0025 | — | — | 6.4% | Nov 2, 2012 | Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the Fla... |
| CVE-2012-4498 | — | — | 1.5% | Nov 2, 2012 | The Activism module 6.x-2.x before 6.x-2.1 for Drupal does not properly restrict access to the "Campaign" content type, ... |
| CVE-2012-4497 | — | — | 1.1% | Nov 2, 2012 | Cross-site scripting (XSS) vulnerability in the "3 slide gallery" in the Elegant Theme module 7.x-1.x before 7.x-1.1 for... |
| CVE-2012-4493 | — | — | 0.9% | Nov 2, 2012 | Cross-site scripting (XSS) vulnerability in the administrative interface in the Better Revisions module 7.x-1.x before 7... |
| CVE-2012-4487 | — | — | 1.1% | Nov 2, 2012 | The Subuser module before 6.x-1.8 for Drupal does not properly check "switch subuser" permissions, which allows remote a... |
| CVE-2012-4486 | — | — | 0.6% | Nov 2, 2012 | Cross-site request forgery (CSRF) vulnerability in the Subuser module before 6.x-1.8 for Drupal allows remote attackers ... |
| CVE-2012-5417 | — | — | 3.1% | Nov 2, 2012 | Cisco Prime Data Center Network Manager (DCNM) before 6.1(1) does not properly restrict access to certain JBoss MainDepl... |
| CVE-2012-5416 | — | — | 2.0% | Nov 2, 2012 | Buffer overflow in Cisco Unified MeetingPlace Web Conferencing before 7.1MR1 Patch 1, 8.0 before 8.0MR1 Patch 1, and 8.5... |
| CVE-2012-5705 | — | — | 1.0% | Nov 1, 2012 | Cross-site scripting (XSS) vulnerability in the settings page (admin/settings/hotblocks) in the Hotblocks module 6.x-1.x... |
| CVE-2012-5704 | — | — | 1.1% | Nov 1, 2012 | The Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the "administer hotblocks"... |
| CVE-2012-5687 | — | — | 68.7% | Nov 1, 2012 | Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13... |
| CVE-2012-5409 | — | — | 15.8% | Nov 1, 2012 | AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages r... |
| CVE-2012-3026 | — | — | 5.0% | Nov 1, 2012 | rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now