2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-5785Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Comm...
CVE-2012-5784Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the...
CVE-2012-5783Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, d...
CVE-2012-5782Amazon Flexible Payments Service (FPS) PHP Library does not verify that the server hostname matches a domain name in the...
CVE-2012-5781Amazon Elastic Load Balancing API Tools does not verify that the server hostname matches a domain name in the subject's ...
CVE-2012-5780The Amazon merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN)...
CVE-2012-3446MEDIUM5.9Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname ma...
CVE-2012-5170Open redirect vulnerability in Pebble before 2.6.4 allows remote attackers to redirect users to arbitrary web sites and ...
CVE-2012-4987Stack-based buffer overflow in RealNetworks RealPlayer 15.0.5.109 allows user-assisted remote attackers to execute arbit...
CVE-2012-3750The Passcode Lock implementation in Apple iOS before 6.0.1 does not properly manage the lock state, which allows physica...
CVE-2012-3749The extensions APIs in the kernel in Apple iOS before 6.0.1 provide kernel addresses in responses that contain an OSBund...
CVE-2012-3748Race condition in WebKit in Apple iOS before 6.0.1 and Safari before 6.0.2 allows remote attackers to execute arbitrary ...
CVE-2012-0025Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the Fla...
CVE-2012-4498The Activism module 6.x-2.x before 6.x-2.1 for Drupal does not properly restrict access to the "Campaign" content type, ...
CVE-2012-4497Cross-site scripting (XSS) vulnerability in the "3 slide gallery" in the Elegant Theme module 7.x-1.x before 7.x-1.1 for...
CVE-2012-4493Cross-site scripting (XSS) vulnerability in the administrative interface in the Better Revisions module 7.x-1.x before 7...
CVE-2012-4487The Subuser module before 6.x-1.8 for Drupal does not properly check "switch subuser" permissions, which allows remote a...
CVE-2012-4486Cross-site request forgery (CSRF) vulnerability in the Subuser module before 6.x-1.8 for Drupal allows remote attackers ...
CVE-2012-5417Cisco Prime Data Center Network Manager (DCNM) before 6.1(1) does not properly restrict access to certain JBoss MainDepl...
CVE-2012-5416Buffer overflow in Cisco Unified MeetingPlace Web Conferencing before 7.1MR1 Patch 1, 8.0 before 8.0MR1 Patch 1, and 8.5...
CVE-2012-5705Cross-site scripting (XSS) vulnerability in the settings page (admin/settings/hotblocks) in the Hotblocks module 6.x-1.x...
CVE-2012-5704The Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the "administer hotblocks"...
CVE-2012-5687Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13...
CVE-2012-5409AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages r...
CVE-2012-3026rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now