2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-1897 | — | — | 1.1% | Oct 1, 2012 | Multiple cross-site request forgery (CSRF) vulnerabilities in Wolf CMS 0.75 and earlier allow remote attackers to hijack... |
| CVE-2012-1639 | — | — | 1.1% | Oct 1, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in product/commerce_product.module in the Drupal Commerce module for... |
| CVE-2012-1576 | — | — | 2.0% | Oct 1, 2012 | The myuser_delete function in libathemecore/account.c in Atheme 5.x before 5.2.7, 6.x before 6.0.10, and 7.x before 7.0.... |
| CVE-2012-4833 | — | — | 0.4% | Oct 1, 2012 | fuser in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly restrict the -k option, which allows local... |
| CVE-2012-4830 | — | — | 1.4% | Oct 1, 2012 | Unspecified vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11 and 7.0 through 7.0.0.6 allows remote attackers... |
| CVE-2012-3319 | — | — | 1.4% | Oct 1, 2012 | IBM Rational Business Developer 8.x before 8.0.1.4 allows remote attackers to obtain potentially sensitive information v... |
| CVE-2012-3035 | — | — | 2.2% | Oct 1, 2012 | Buffer overflow in Emerson DeltaV 9.3.1 and 10.3 through 11.3.1 allows remote attackers to cause a denial of service (da... |
| CVE-2012-0748 | — | — | 0.6% | Oct 1, 2012 | Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified services in IBM Rational Team Concert (RTC) 4.... |
| CVE-2012-4450 | — | — | 1.9% | Oct 1, 2012 | 389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allow... |
| CVE-2012-4437 | — | — | 2.5% | Oct 1, 2012 | Cross-site scripting (XSS) vulnerability in the SmartyException class in Smarty (aka smarty-php) before 3.1.12 allows re... |
| CVE-2012-4432 | — | — | 5.2% | Oct 1, 2012 | Use-after-free vulnerability in opngreduc.c in OptiPNG Hg and 0.7.x before 0.7.3 might allow remote attackers to execute... |
| CVE-2012-4427 | — | — | 1.3% | Oct 1, 2012 | The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extens... |
| CVE-2012-4415 | — | — | 13.6% | Oct 1, 2012 | Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote a... |
| CVE-2012-4429 | — | — | 2.4% | Oct 1, 2012 | Vino 2.28, 2.32, 3.4.2, and earlier allows remote attackers to read clipboard activity by listening on TCP port 5900. |
| CVE-2012-3500 | — | — | 0.3% | Oct 1, 2012 | scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools before 8.3, allows local users to modify ... |
| CVE-2012-2242 | — | — | 1.7% | Oct 1, 2012 | scripts/dget.pl in devscripts before 2.10.73 allows remote attackers to execute arbitrary commands via a crafted (1) .ds... |
| CVE-2012-2241 | — | — | 1.5% | Oct 1, 2012 | scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete arbitrary files via a crafted (1) .dsc or ... |
| CVE-2012-2240 | — | — | 3.2% | Oct 1, 2012 | scripts/dscverify.pl in devscripts before 2.12.3 allows remote attackers to execute arbitrary commands via unspecified v... |
| CVE-2012-2153 | — | — | 1.9% | Oct 1, 2012 | Drupal 7.x before 7.14 does not properly restrict access to nodes in a list when using a "contributed node access module... |
| CVE-2012-1591 | — | — | 2.4% | Oct 1, 2012 | The image module in Drupal 7.x before 7.14 does not properly check permissions when caching derivative image styles of p... |
| CVE-2012-1590 | — | — | 1.4% | Oct 1, 2012 | The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which all... |
| CVE-2012-1588 | — | — | 1.2% | Oct 1, 2012 | Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.mod... |
| CVE-2012-4448 | — | — | 1.1% | Sep 28, 2012 | Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hija... |
| CVE-2012-1833 | — | — | 1.4% | Sep 28, 2012 | VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allo... |
| CVE-2012-5197 | — | — | 1.7% | Sep 28, 2012 | Multiple unspecified vulnerabilities in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 have unknown impact and attack... |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now