Skip to main content

Year archive

CVEs published in 2012

Archive summary

5,288 CVEs published in 2012 — 950 Critical, 794 High, 3,036 Medium, 506 Low, 2 Unrated.

CVE-2012-1005

Published Feb 7, 2012

Multiple cross-site scripting (XSS) vulnerabilities in Sphinx Software Mobile Web Server 3.1.2.47 allow remote attackers to inject arbitrary web script or HTML via the comment par…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0992

Published Feb 7, 2012

interface/fax/fax_dispatch.php in OpenEMR 4.1.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the file parameter.

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-0991

Published Feb 7, 2012

Multiple directory traversal vulnerabilities in OpenEMR 4.1.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the formname parameter to (1) contrib/…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-0990

Published Feb 7, 2012

Cross-site request forgery (CSRF) vulnerability in admin/settings/update in DClassifieds 0.1 final allows remote attackers to hijack the authentication of administrators for reque…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-1007

Published Feb 7, 2012

Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter to struts-exam…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1006

Published Feb 7, 2012

Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) lastNam…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1003

Published Feb 7, 2012

Multiple integer overflows in Opera 11.60 and earlier allow remote attackers to cause a denial of service (application crash) via a large integer argument to the (1) Int32Array, (…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0830

Published Feb 6, 2012

The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, relat…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2012-0396

Published Feb 6, 2012

EMC Documentum xPlore 1.0, 1.1 before P07, and 1.2 does not properly enforce the requirement for BROWSE permission, which allows remote authenticated users to determine the existe…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0194

Published Feb 6, 2012

The TCP implementation in IBM AIX 5.3, 6.1, and 7.1, when the Large Send Offload option is enabled, allows remote attackers to cause a denial of service (assertion failure and pan…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4041

Published Feb 6, 2012

webvrpcs.exe in Advantech/BroadWin WebAccess allows remote attackers to execute arbitrary code or obtain a security-code value via a long string in an RPC request to TCP port 4592.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 4,901-4,925 of 5,288 CVEsPage 197 of 212