Skip to main content

Year archive

CVEs published in 2012

Archive summary

5,288 CVEs published in 2012 — 950 Critical, 794 High, 3,036 Medium, 506 Low, 2 Unrated.

CVE-2012-6371

Published Dec 31, 2012

The WPA2 implementation on the Belkin N900 F9K1104v1 router establishes a WPS PIN based on 6 digits of the LAN/WLAN MAC address, which makes it easier for remote attackers to obta…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-5251

Published Dec 31, 2012

Open redirect vulnerability in forum/login.php in vBulletin 4.1.3 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6453

Published Dec 31, 2012

Cross-site scripting (XSS) vulnerability in the RSS Reader extension before 0.2.6 for MediaWiki allows remote attackers to inject arbitrary web script or HTML via a crafted feed.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6339

Published Dec 31, 2012

Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface in Cerberus FTP Server before 5.0.6.0 allow (1) remote attackers to inject arbitrary web sc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6336

Published Dec 31, 2012

The Missing Device feature in Lookout allows physically proximate attackers to provide arbitrary location data via a "commonly available simple GPS location spoofer."

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-6335

Published Dec 31, 2012

The Anti-theft service in AVG AntiVirus for Android allows physically proximate attackers to provide arbitrary location data via a "commonly available simple GPS location spoofer."

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-5642

Published Dec 31, 2012

server/action.py in Fail2ban before 0.8.8 does not properly handle the content of the matches tag, which might allow remote attackers to trigger unsafe behavior in a custom action…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4688

Published Dec 31, 2012

The Central application in i-GEN opLYNX before 2.01.9 allows remote attackers to bypass authentication via vectors involving the disabling of browser JavaScript support.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-6369

Published Dec 28, 2012

Cross-site scripting (XSS) vulnerability in the Troubleshooting Reporting System feature in AgileBits 1Password 3.9.9 might allow remote attackers to inject arbitrary web script o…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4932

Published Dec 28, 2012

Multiple cross-site scripting (XSS) vulnerabilities in SimpleInvoices before stable-2012-1-CIS3000 allow remote attackers to inject arbitrary web script or HTML via (1) the having…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3873

Published Dec 28, 2012

Multiple SQL injection vulnerabilities in Open Constructor 3.12.0 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) data/gallery/edit.…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3872

Published Dec 28, 2012

Multiple cross-site scripting (XSS) vulnerabilities in Open Constructor 3.12.0 allow remote attackers to inject arbitrary web script or HTML via (1) the result parameter to data/f…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3871

Published Dec 28, 2012

Cross-site scripting (XSS) vulnerability in data/hybrid/i_hybrid.php in Open Constructor 3.12.0 allows remote authenticated users to inject arbitrary web script or HTML via the he…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-3870

Published Dec 28, 2012

Multiple cross-site scripting (XSS) vulnerabilities in objects/createobject.php in Open Constructor 3.12.0 allow remote authenticated users to inject arbitrary web script or HTML…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-6432

Published Dec 27, 2012

Symfony 2.0.x before 2.0.20, 2.1.x before 2.1.5, and 2.2-dev, when the internal routes configuration is enabled, allows remote attackers to access arbitrary services via vectors i…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6431

Published Dec 27, 2012

Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, which allows remote attackers to bypass intended URI restric…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5868

Published Dec 27, 2012

WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session iden…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-5532

Published Dec 27, 2012

The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.8-rc1, allows local users to cause a denial of service (daemon exit) via a…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 5,288 CVEsPage 1 of 212