2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-3021rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through...
CVE-2012-3010rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through...
CVE-2012-4940Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote att...
CVE-2012-4939Cross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface before 3.0-HotFix1 in SolarWi...
CVE-2012-5671Heap-based buffer overflow in the dkim_exim_query_dns_txt function in dkim.c in Exim 4.70 through 4.80, when DKIM suppor...
CVE-2012-4544The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after...
CVE-2012-4532Cross-site scripting (XSS) vulnerability in modules/mod_languages/tmpl/default.php in the Language Switcher module for J...
CVE-2012-4531Cross-site scripting (XSS) vulnerability in Joomla! 2.5.x before 2.5.7 allows remote attackers to inject arbitrary web s...
CVE-2012-4500The Announcements module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users with the "access announceme...
CVE-2012-4499The contact formatter page in the Email Field module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows...
CVE-2012-4496Cross-site scripting (XSS) vulnerability in the Custom Publishing Options module 6.x-1.x before 6.x-1.4 for Drupal allow...
CVE-2012-4495The Mime Mail module 6.x-1.x before 6.x-1.1 for Drupal does not properly restrict access to files outside Drupal's publi...
CVE-2012-4494The Shibboleth authentication module 7.x-4.0 for Drupal does not properly check the active status of users, which allows...
CVE-2012-4492Multiple cross-site scripting (XSS) vulnerabilities in the Shorten URLs module 6.x-1.x before 6.x-1.13 and 7.x-1.x befor...
CVE-2012-4491The Monthly Archive by Node Type module 6.x for Drupal does not properly check permissions defined by node_access module...
CVE-2012-4490Multiple cross-site scripting (XSS) vulnerabilities in the Excluded Users module 6.x-1.x before 6.x-1.1 for Drupal allow...
CVE-2012-4489Open redirect vulnerability in the securelogin_secure_redirect function in the Secure Login module 7.x-1.x before 7.x-1....
CVE-2012-4488The Location module 6.x before 6.x-3.2 and 7.x before 7.x-3.0-alpha1 for Drupal does not properly check user or node acc...
CVE-2012-4485Multiple cross-site scripting (XSS) vulnerabilities in the galleryformatter_field_formatter_view functiuon in galleryfor...
CVE-2012-4484Cross-site scripting (XSS) vulnerability in the administrative interface in the Campaign Monitor module before 6.x-2.5 f...
CVE-2012-4483The commons_discussion_views_default_views function in modules/features/commons_discussion/commons_discussion.views_defa...
CVE-2012-4482The Ubercart SecureTrading Payment Method module 6.x for Drupal does not properly verify payment notification informatio...
CVE-2012-2625The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4.2.x, and 4.1.x allows local para-virtualiz...
CVE-2012-5692Unspecified vulnerability in admin/sources/base/core.php in Invision Power Board (aka IPB or IP.Board) 3.1.x through 3.3...
CVE-2012-4934TomatoCart 1.1.7, when the PayPal Express Checkout module is enabled in sandbox mode, allows remote authenticated users ...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now