2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2012-1897Multiple cross-site request forgery (CSRF) vulnerabilities in Wolf CMS 0.75 and earlier allow remote attackers to hijack...
CVE-2012-1639Multiple cross-site scripting (XSS) vulnerabilities in product/commerce_product.module in the Drupal Commerce module for...
CVE-2012-1576The myuser_delete function in libathemecore/account.c in Atheme 5.x before 5.2.7, 6.x before 6.0.10, and 7.x before 7.0....
CVE-2012-4833fuser in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly restrict the -k option, which allows local...
CVE-2012-4830Unspecified vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11 and 7.0 through 7.0.0.6 allows remote attackers...
CVE-2012-3319IBM Rational Business Developer 8.x before 8.0.1.4 allows remote attackers to obtain potentially sensitive information v...
CVE-2012-3035Buffer overflow in Emerson DeltaV 9.3.1 and 10.3 through 11.3.1 allows remote attackers to cause a denial of service (da...
CVE-2012-0748Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified services in IBM Rational Team Concert (RTC) 4....
CVE-2012-4450389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allow...
CVE-2012-4437Cross-site scripting (XSS) vulnerability in the SmartyException class in Smarty (aka smarty-php) before 3.1.12 allows re...
CVE-2012-4432Use-after-free vulnerability in opngreduc.c in OptiPNG Hg and 0.7.x before 0.7.3 might allow remote attackers to execute...
CVE-2012-4427The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extens...
CVE-2012-4415Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote a...
CVE-2012-4429Vino 2.28, 2.32, 3.4.2, and earlier allows remote attackers to read clipboard activity by listening on TCP port 5900.
CVE-2012-3500scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools before 8.3, allows local users to modify ...
CVE-2012-2242scripts/dget.pl in devscripts before 2.10.73 allows remote attackers to execute arbitrary commands via a crafted (1) .ds...
CVE-2012-2241scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete arbitrary files via a crafted (1) .dsc or ...
CVE-2012-2240scripts/dscverify.pl in devscripts before 2.12.3 allows remote attackers to execute arbitrary commands via unspecified v...
CVE-2012-2153Drupal 7.x before 7.14 does not properly restrict access to nodes in a list when using a "contributed node access module...
CVE-2012-1591The image module in Drupal 7.x before 7.14 does not properly check permissions when caching derivative image styles of p...
CVE-2012-1590The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which all...
CVE-2012-1588Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.mod...
CVE-2012-4448Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hija...
CVE-2012-1833VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allo...
CVE-2012-5197Multiple unspecified vulnerabilities in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 have unknown impact and attack...

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now