2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-4518——ibacm 1.0.7 creates files with world-writable permissions, which allows local users to overwrite the ib_acm daemon log o...
CVE-2012-4517——ibacm before 1.0.6 does not properly manage reference counts for multicast connections, which allows remote attackers to...
CVE-2012-4516——librdmacm 1.0.16, when ibacm.port is not specified, connects to port 6125, which allows remote attackers to specify the ...
CVE-2012-4511——services/flickr/flickr.c in libsocialweb before 0.25.21 automatically connects to Flickr when no Flickr account is set, ...
CVE-2012-4507——The strchr function in procmime.c in Claws Mail (aka claws-mail) 3.8.1 allows remote attackers to cause a denial of serv...
CVE-2012-4506——Directory traversal vulnerability in gitolite 3.x before 3.1, when wild card repositories and a pattern matching "../" a...
CVE-2012-4436——Buffer overflow in the run_last_args function in client/fwknop.c in fwknop before 2.0.3, when processing --last, might a...
CVE-2012-4435——fwknop before 2.0.3 does not properly validate IP addresses, which allows remote authenticated users to cause a denial o...
CVE-2012-4406CRITICAL9.8OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing ...
CVE-2012-4232——SQL injection vulnerability in admin/index.php in jCore before 1.0pre2 allows remote attackers to execute arbitrary SQL ...
CVE-2012-4231——Cross-site scripting (XSS) vulnerability in admin/index.php in jCore before 1.0pre2 allows remote attackers to inject ar...
CVE-2012-3466——GNOME gnome-keyring 3.4.0 through 3.4.1, when gpg-cache-method is set to "idle" or "timeout," does not properly limit th...
CVE-2012-2679——Red Hat Network (RHN) Configuration Client (rhncfg-client) in rhncfg before 5.10.27-8 uses weak permissions (world-reada...
CVE-2012-1900——Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers...
CVE-2012-1154——mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, wh...
CVE-2012-4751——Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.15, 3.0.x befor...
CVE-2012-3001——Mutiny Standard before 4.5-1.12 allows remote attackers to execute arbitrary commands via the network-interface menu, re...
CVE-2012-4933——The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username o...
CVE-2012-2167——The IBM XIV Storage System Gen3 before 11.1.0.a allows remote attackers to cause a denial of service (device outage) via...
CVE-2012-4845——The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC envi...
CVE-2012-4826——Stack-based buffer overflow in the SQL/PSM (aka SQL Persistent Stored Module) Stored Procedure (SP) infrastructure in IB...
CVE-2012-2972——The (1) server and (2) agent components in CA ARCserve Backup r12.5, r15, and r16 on Windows do not properly validate RP...
CVE-2012-2971——The server in CA ARCserve Backup r12.5, r15, and r16 on Windows does not properly process RPC requests, which allows rem...
CVE-2012-2290——The client in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 37...
CVE-2012-2284——The (1) install and (2) upgrade processes in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before bui...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now