2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2012-1564——Cross-site scripting (XSS) vulnerability in administration/create_album.php in YVS Image Gallery allows remote attackers...
CVE-2012-1153——Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote ...
CVE-2012-0987——Directory traversal vulnerability in edituser.php in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final al...
CVE-2012-0986——Multiple cross-site scripting (XSS) vulnerabilities in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final ...
CVE-2012-0065——Heap-based buffer overflow in the receive_packet function in libusbmuxd/libusbmuxd.c in usbmuxd 1.0.5 through 1.0.7 allo...
CVE-2012-5303——Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file, as dem...
CVE-2012-4442——Monkey HTTP Daemon 0.9.3 retains the supplementary group IDs of the root account during operations with a non-root effec...
CVE-2012-1150——Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 computes hash values without restricti...
CVE-2012-0845——SimpleXMLRPCServer.py in SimpleXMLRPCServer in Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x befo...
CVE-2012-5051——Directory traversal vulnerability in VMware CapacityIQ 1.5.x allows remote attackers to read arbitrary files via unspeci...
CVE-2012-5050——Cross-site scripting (XSS) vulnerability in the server in VMware vCenter Operations (aka vCOps) before 5.0.x allows remo...
CVE-2012-4897——Untrusted search path vulnerability in the installer in VMware Movie Decoder before 9.0 allows local users to gain privi...
CVE-2012-4443——Monkey HTTP Daemon 0.9.3 uses a real UID of root and a real GID of root during execution of CGI scripts, which might all...
CVE-2012-4896——Heap-based buffer overflow in SumatraPDF before 2.1 allows remote attackers to execute arbitrary code via a crafted PDF ...
CVE-2012-4895——Heap-based buffer overflow in SumatraPDF before 2.1 allows remote attackers to execute arbitrary code via a crafted PDF ...
CVE-2012-4894——Google SketchUp before 8.0.14346 (aka 8 Maintenance 3) allows user-assisted remote attackers to execute arbitrary code o...
CVE-2012-4018——Cross-site scripting (XSS) vulnerability in Final Beta Laboratory MyWebSearch before 1.23 allows remote attackers to inj...
CVE-2012-5301——The default configuration of Cerberus FTP Server before 5.0.4.0 supports the DES cipher for SSH sessions, which makes it...
CVE-2012-5240——Buffer overflow in the dissect_tlv function in epan/dissectors/packet-ldp.c in the LDP dissector in Wireshark 1.8.x befo...
CVE-2012-5238——epan/dissectors/packet-ppp.c in the PPP dissector in Wireshark 1.8.x before 1.8.3 uses incorrect OUI data structures dur...
CVE-2012-5237——The dissect_hsrp function in epan/dissectors/packet-hsrp.c in the HSRP dissector in Wireshark 1.8.x before 1.8.3 allows ...
CVE-2012-2999——Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in Cerberus FTP Server before 5.0.5.0 al...
CVE-2012-5300——SQL injection vulnerability in art_catalogo.php in MyStore Xpress Tienda Virtual 2.0 allows remote attackers to execute ...
CVE-2012-5299——Mavili Guestbook, as released in November 2007, allows remote attackers to edit, delete, and approve arbitrary messages ...
CVE-2012-5298——Mavili Guestbook, as released in November 2007, stores guestbook.mdb under the web root with insufficient access control...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now