Skip to main content

Year archive

CVEs published in 2012

Archive summary

5,288 CVEs published in 2012 — 950 Critical, 794 High, 3,036 Medium, 506 Low, 2 Unrated.

CVE-2012-0149

Published Feb 14, 2012

afd.sys in the Ancillary Function Driver in Microsoft Windows Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain pr…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2012-0138

Published Feb 14, 2012

Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attribute…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-0137

Published Feb 14, 2012

Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attribute…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-0136

Published Feb 14, 2012

Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attribute…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-0020

Published Feb 14, 2012

Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attribute…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-0019

Published Feb 14, 2012

Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attribute…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-0017

Published Feb 14, 2012

Cross-site scripting (XSS) vulnerability in inplview.aspx in Microsoft SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via J…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5085

Published Feb 14, 2012

Multiple cross-site request forgery (CSRF) vulnerabilities in admin/update_user in Hulihan Amethyst 0.1.5, and possibly earlier, allow remote attackers to hijack the authenticatio…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5084

Published Feb 14, 2012

The cross-site request forgery (CSRF) protection mechanism in e107 before 0.7.23 uses a predictable random token based on the creation date of the administrator account, which all…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5083

Published Feb 14, 2012

SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url parameter in an Add action to modules.ph…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1087

Published Feb 14, 2012

Cross-site scripting (XSS) vulnerability in the Post data records to facebook (bc_post2facebook) extension before 0.2.2 for TYPO3 allows remote attackers to inject arbitrary web s…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1086

Published Feb 14, 2012

Cross-site scripting (XSS) vulnerability in the UrlTool (aeurltool) extension 0.1.0 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vector…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1085

Published Feb 14, 2012

Unspecified vulnerability in the BE User Switch (beuserswitch) extension 0.0.1 for TYPO3 allows remote attackers to obtain sensitive information via unknown vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1084

Published Feb 14, 2012

Cross-site scripting (XSS) vulnerability in the BE User Switch (beuserswitch) extension 0.0.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecif…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1083

Published Feb 14, 2012

Cross-site request forgery (CSRF) vulnerability in the Terminal PHP Shell (terminal) extension 0.3.2 and earlier for TYPO3 allows remote attackers to hijack the authentication of…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1082

Published Feb 14, 2012

Cross-site scripting (XSS) vulnerability in the Terminal PHP Shell (terminal) extension 0.3.2 and earlier for TYPO3 allows remote authenticated users to inject arbitrary web scrip…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-1081

Published Feb 14, 2012

Cross-site scripting (XSS) vulnerability in the Yet another Google search (ya_googlesearch) extension before 0.3.10 for TYPO3 allows remote attackers to inject arbitrary web scrip…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 4,776-4,800 of 5,288 CVEsPage 192 of 212