2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-1565 | — | — | 2.0% | Oct 6, 2012 | Unspecified vulnerability in ez Publish 4.1.4, 4.2, 4.3, 4.4, 4.5, and 4.6 has unknown impact and attack vectors related... |
| CVE-2012-1564 | — | — | 1.2% | Oct 6, 2012 | Cross-site scripting (XSS) vulnerability in administration/create_album.php in YVS Image Gallery allows remote attackers... |
| CVE-2012-1153 | — | — | 32.4% | Oct 6, 2012 | Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote ... |
| CVE-2012-0987 | — | — | 1.5% | Oct 6, 2012 | Directory traversal vulnerability in edituser.php in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final al... |
| CVE-2012-0986 | — | — | 1.7% | Oct 6, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final ... |
| CVE-2012-0065 | — | — | 0.8% | Oct 6, 2012 | Heap-based buffer overflow in the receive_packet function in libusbmuxd/libusbmuxd.c in usbmuxd 1.0.5 through 1.0.7 allo... |
| CVE-2012-5303 | — | — | 0.3% | Oct 5, 2012 | Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file, as dem... |
| CVE-2012-4442 | — | — | 0.3% | Oct 5, 2012 | Monkey HTTP Daemon 0.9.3 retains the supplementary group IDs of the root account during operations with a non-root effec... |
| CVE-2012-1150 | — | — | 5.1% | Oct 5, 2012 | Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 computes hash values without restricti... |
| CVE-2012-0845 | — | — | 5.6% | Oct 5, 2012 | SimpleXMLRPCServer.py in SimpleXMLRPCServer in Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x befo... |
| CVE-2012-5051 | — | — | 2.8% | Oct 5, 2012 | Directory traversal vulnerability in VMware CapacityIQ 1.5.x allows remote attackers to read arbitrary files via unspeci... |
| CVE-2012-5050 | — | — | 2.0% | Oct 5, 2012 | Cross-site scripting (XSS) vulnerability in the server in VMware vCenter Operations (aka vCOps) before 5.0.x allows remo... |
| CVE-2012-4897 | — | — | 0.4% | Oct 5, 2012 | Untrusted search path vulnerability in the installer in VMware Movie Decoder before 9.0 allows local users to gain privi... |
| CVE-2012-4443 | — | — | 0.4% | Oct 5, 2012 | Monkey HTTP Daemon 0.9.3 uses a real UID of root and a real GID of root during execution of CGI scripts, which might all... |
| CVE-2012-4896 | — | — | 5.2% | Oct 5, 2012 | Heap-based buffer overflow in SumatraPDF before 2.1 allows remote attackers to execute arbitrary code via a crafted PDF ... |
| CVE-2012-4895 | — | — | 5.2% | Oct 5, 2012 | Heap-based buffer overflow in SumatraPDF before 2.1 allows remote attackers to execute arbitrary code via a crafted PDF ... |
| CVE-2012-4894 | — | — | 5.3% | Oct 5, 2012 | Google SketchUp before 8.0.14346 (aka 8 Maintenance 3) allows user-assisted remote attackers to execute arbitrary code o... |
| CVE-2012-4018 | — | — | 1.2% | Oct 5, 2012 | Cross-site scripting (XSS) vulnerability in Final Beta Laboratory MyWebSearch before 1.23 allows remote attackers to inj... |
| CVE-2012-5301 | — | — | 1.2% | Oct 4, 2012 | The default configuration of Cerberus FTP Server before 5.0.4.0 supports the DES cipher for SSH sessions, which makes it... |
| CVE-2012-5240 | — | — | 1.4% | Oct 4, 2012 | Buffer overflow in the dissect_tlv function in epan/dissectors/packet-ldp.c in the LDP dissector in Wireshark 1.8.x befo... |
| CVE-2012-5238 | — | — | 0.9% | Oct 4, 2012 | epan/dissectors/packet-ppp.c in the PPP dissector in Wireshark 1.8.x before 1.8.3 uses incorrect OUI data structures dur... |
| CVE-2012-5237 | — | — | 0.9% | Oct 4, 2012 | The dissect_hsrp function in epan/dissectors/packet-hsrp.c in the HSRP dissector in Wireshark 1.8.x before 1.8.3 allows ... |
| CVE-2012-2999 | — | — | 1.2% | Oct 4, 2012 | Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in Cerberus FTP Server before 5.0.5.0 al... |
| CVE-2012-5300 | — | — | 1.3% | Oct 4, 2012 | SQL injection vulnerability in art_catalogo.php in MyStore Xpress Tienda Virtual 2.0 allows remote attackers to execute ... |
| CVE-2012-5299 | — | — | 1.7% | Oct 4, 2012 | Mavili Guestbook, as released in November 2007, allows remote attackers to edit, delete, and approve arbitrary messages ... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now