Skip to main content

Year archive

CVEs published in 2012

Archive summary

5,288 CVEs published in 2012 — 950 Critical, 794 High, 3,036 Medium, 506 Low, 2 Unrated.

CVE-2012-0978

Published Feb 2, 2012

Stack-based buffer overflow in npjp2.dll in LuraWave JP2 Browser Plug-In 1.1.1.11 and other versions before 2.1.1.11 allows remote attackers to execute arbitrary code via a JPEG20…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0977

Published Feb 2, 2012

Stack-based buffer overflow in jp2_x.dll in LuraWave JP2 ActiveX Control 2.1.5.5 and other versions before 2.1.5.11 allows remote attackers to execute arbitrary code via a JPEG200…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-0976

Published Feb 2, 2012

Cross-site scripting (XSS) vulnerability in admin/EditForm in SilverStripe 2.4.6 allows remote authenticated users with Content Authors privileges to inject arbitrary web script o…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-0975

Published Feb 2, 2012

Cross-site scripting (XSS) vulnerability in misc.php in Image Hosting Script DPI 1.0, 1.3, and earlier allows remote attackers to inject arbitrary web script or HTML via the shows…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2393

Published Feb 2, 2012

The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD, NetBSD, and possibly other BSD-based operating systems allows remote attackers to cause a denial…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4563

Published Feb 2, 2012

The Linux kernel, when using IPv6, allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4144

Published Feb 2, 2012

Unspecified vulnerability in EMC Documentum Content Server 6.0, 6.5 before SP2 P02, 6.5 SP3 before SP3 P02, and 6.6 before P02 allows local users to obtain "highest super user pri…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1573

Published Feb 2, 2012

net/sctp/sm_make_chunk.c in the Linux kernel before 2.6.34, when addip_enable and auth_enable are used, does not consider the amount of zero padding during calculation of chunk le…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0057

Published Feb 2, 2012

PHP before 5.3.9 has improper libxslt security settings, which allows remote attackers to create arbitrary files via a crafted XSLT stylesheet that uses the libxslt output extensi…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4790

Published Feb 2, 2012

Unspecified vulnerability in HP Network Automation 7.5x, 7.6x, 9.0, and 9.10 allows remote attackers to execute arbitrary code via unknown vectors.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-0444

Published Feb 1, 2012

Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures,…

CVSS 10.0 · Critical

CVE-2012-0809

Published Feb 1, 2012

Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8.3p1 allows local users to execute arbitrary code via format string sequences in the program name f…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2012-0937

Published Jan 30, 2012

wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not limit the number of MySQL queries sent to external MySQL database servers, which al…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 4,951-4,975 of 5,288 CVEsPage 199 of 212