2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-4518ibacm 1.0.7 creates files with world-writable permissions, which allows local users to overwrite the ib_acm daemon log o...
CVE-2012-4517ibacm before 1.0.6 does not properly manage reference counts for multicast connections, which allows remote attackers to...
CVE-2012-4516librdmacm 1.0.16, when ibacm.port is not specified, connects to port 6125, which allows remote attackers to specify the ...
CVE-2012-4511services/flickr/flickr.c in libsocialweb before 0.25.21 automatically connects to Flickr when no Flickr account is set, ...
CVE-2012-4507The strchr function in procmime.c in Claws Mail (aka claws-mail) 3.8.1 allows remote attackers to cause a denial of serv...
CVE-2012-4506Directory traversal vulnerability in gitolite 3.x before 3.1, when wild card repositories and a pattern matching "../" a...
CVE-2012-4436Buffer overflow in the run_last_args function in client/fwknop.c in fwknop before 2.0.3, when processing --last, might a...
CVE-2012-4435fwknop before 2.0.3 does not properly validate IP addresses, which allows remote authenticated users to cause a denial o...
CVE-2012-4406CRITICAL9.8OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing ...
CVE-2012-4232SQL injection vulnerability in admin/index.php in jCore before 1.0pre2 allows remote attackers to execute arbitrary SQL ...
CVE-2012-4231Cross-site scripting (XSS) vulnerability in admin/index.php in jCore before 1.0pre2 allows remote attackers to inject ar...
CVE-2012-3466GNOME gnome-keyring 3.4.0 through 3.4.1, when gpg-cache-method is set to "idle" or "timeout," does not properly limit th...
CVE-2012-2679Red Hat Network (RHN) Configuration Client (rhncfg-client) in rhncfg before 5.10.27-8 uses weak permissions (world-reada...
CVE-2012-1900Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers...
CVE-2012-1154mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, wh...
CVE-2012-4751Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.15, 3.0.x befor...
CVE-2012-3001Mutiny Standard before 4.5-1.12 allows remote attackers to execute arbitrary commands via the network-interface menu, re...
CVE-2012-4933The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username o...
CVE-2012-2167The IBM XIV Storage System Gen3 before 11.1.0.a allows remote attackers to cause a denial of service (device outage) via...
CVE-2012-4845The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC envi...
CVE-2012-4826Stack-based buffer overflow in the SQL/PSM (aka SQL Persistent Stored Module) Stored Procedure (SP) infrastructure in IB...
CVE-2012-2972The (1) server and (2) agent components in CA ARCserve Backup r12.5, r15, and r16 on Windows do not properly validate RP...
CVE-2012-2971The server in CA ARCserve Backup r12.5, r15, and r16 on Windows does not properly process RPC requests, which allows rem...
CVE-2012-2290The client in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 37...
CVE-2012-2284The (1) install and (2) upgrade processes in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before bui...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now