Skip to main content

Year archive

CVEs published in 2012

Archive summary

5,288 CVEs published in 2012 — 950 Critical, 794 High, 3,036 Medium, 506 Low, 2 Unrated.

CVE-2012-5123

Published Nov 7, 2012

Skia, as used in Google Chrome before 23.0.1271.64, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5122

Published Nov 7, 2012

Google Chrome before 23.0.1271.64 does not properly perform a cast of an unspecified variable during handling of input, which allows remote attackers to cause a denial of service…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5121

Published Nov 7, 2012

Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors relate…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5119

Published Nov 7, 2012

Race condition in Pepper, as used in Google Chrome before 23.0.1271.64, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5118

Published Nov 7, 2012

Google Chrome before 23.0.1271.64 on Mac OS X does not properly validate an integer value during the handling of GPU command buffers, which allows remote attackers to cause a deni…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5117

Published Nov 7, 2012

Google Chrome before 23.0.1271.64 does not properly restrict the loading of an SVG subresource in the context of an IMG element, which has unspecified impact and remote attack vec…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5116

Published Nov 7, 2012

Use-after-free vulnerability in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors relate…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5115

Published Nov 7, 2012

Google Chrome before 23.0.1271.64 on Mac OS X does not properly mitigate improper write behavior in graphics drivers, which allows remote attackers to cause a denial of service or…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-5243

Published Nov 6, 2012

TwitterOAuth does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5242

Published Nov 6, 2012

tmhOAuth before 0.61 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allow…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5241

Published Nov 6, 2012

Services_Twitter 0.6.3 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which all…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5240

Published Nov 6, 2012

Magento 1.5 and 1.6.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allo…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5239

Published Nov 6, 2012

CiviCRM 4.0.5 and 4.1.1 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which al…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5238

Published Nov 6, 2012

google-checkout-php-sample-code before 1.3.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5237

Published Nov 6, 2012

PayPal WPS ToolKit does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5236

Published Nov 6, 2012

Moneris eSelectPlus 2.03 PHP API does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate,…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5825

Published Nov 4, 2012

Tweepy does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-m…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 601-625 of 5,288 CVEsPage 25 of 212