Skip to main content

Year archive

CVEs published in 2012

Archive summary

5,288 CVEs published in 2012 — 950 Critical, 794 High, 3,036 Medium, 506 Low, 2 Unrated.

CVE-2012-5796

Published Nov 4, 2012

The PayPal Pro module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certifica…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5791

Published Nov 4, 2012

PayPal Invoicing does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows ma…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5790

Published Nov 4, 2012

PayPal Payments Standard PHP Library 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5789

Published Nov 4, 2012

PayPal Payments Standard PHP Library before 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of th…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5788

Published Nov 4, 2012

The PayPal IPN utility does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which all…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5787

Published Nov 4, 2012

The PayPal merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which al…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5786

Published Nov 4, 2012

The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that the server hostname matches a…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5785

Published Nov 4, 2012

Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certifica…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5783

Published Nov 4, 2012

Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain na…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5782

Published Nov 4, 2012

Amazon Flexible Payments Service (FPS) PHP Library does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5781

Published Nov 4, 2012

Amazon Elastic Load Balancing API Tools does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certi…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5780

Published Nov 4, 2012

The Amazon merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which al…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3446

Published Nov 4, 2012

Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the subject's Common Name (CN) or su…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5170

Published Nov 4, 2012

Open redirect vulnerability in Pebble before 2.6.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4987

Published Nov 4, 2012

Stack-based buffer overflow in RealNetworks RealPlayer 15.0.5.109 allows user-assisted remote attackers to execute arbitrary code via a crafted ZIP file that triggers incorrect pr…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3750

Published Nov 3, 2012

The Passcode Lock implementation in Apple iOS before 6.0.1 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requ…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-3749

Published Nov 3, 2012

The extensions APIs in the kernel in Apple iOS before 6.0.1 provide kernel addresses in responses that contain an OSBundleMachOHeaders key, which makes it easier for remote attack…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 651-675 of 5,288 CVEsPage 27 of 212