Skip to main content

Year archive

CVEs published in 2012

Archive summary

5,288 CVEs published in 2012 — 950 Critical, 794 High, 3,036 Medium, 506 Low, 2 Unrated.

CVE-2012-3748

Published Nov 3, 2012

Race condition in WebKit in Apple iOS before 6.0.1 and Safari before 6.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via v…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0025

Published Nov 2, 2012

Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the FlashPix PlugIn 4.2.2.0 for IrfanView, allows remote attackers…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4498

Published Nov 2, 2012

The Activism module 6.x-2.x before 6.x-2.1 for Drupal does not properly restrict access to the "Campaign" content type, which might allow remote attackers to bypass access restric…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4497

Published Nov 2, 2012

Cross-site scripting (XSS) vulnerability in the "3 slide gallery" in the Elegant Theme module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "adminis…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-4493

Published Nov 2, 2012

Cross-site scripting (XSS) vulnerability in the administrative interface in the Better Revisions module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with th…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-4487

Published Nov 2, 2012

The Subuser module before 6.x-1.8 for Drupal does not properly check "switch subuser" permissions, which allows remote authenticated parent users to change their role by switching…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4486

Published Nov 2, 2012

Cross-site request forgery (CSRF) vulnerability in the Subuser module before 6.x-1.8 for Drupal allows remote attackers to hijack the authentication of arbitrary users for request…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5417

Published Nov 2, 2012

Cisco Prime Data Center Network Manager (DCNM) before 6.1(1) does not properly restrict access to certain JBoss MainDeployer functionality, which allows remote attackers to execut…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-5416

Published Nov 2, 2012

Buffer overflow in Cisco Unified MeetingPlace Web Conferencing before 7.1MR1 Patch 1, 8.0 before 8.0MR1 Patch 1, and 8.5 before 8.5MR3 allows remote attackers to cause a denial of…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5705

Published Nov 1, 2012

Cross-site scripting (XSS) vulnerability in the settings page (admin/settings/hotblocks) in the Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated user…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-5704

Published Nov 1, 2012

The Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the "administer hotblocks" permission to cause a denial of service (infinite loop and…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-5409

Published Nov 1, 2012

AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet network, which allows remote attac…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-4940

Published Oct 31, 2012

Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote attackers to read or delete arbitrary files via a .. (dot dot)…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5671

Published Oct 31, 2012

Heap-based buffer overflow in the dkim_exim_query_dns_txt function in dkim.c in Exim 4.70 through 4.80, when DKIM support is enabled and acl_smtp_connect and acl_smtp_rcpt are not…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4544

Published Oct 31, 2012

The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-4532

Published Oct 31, 2012

Cross-site scripting (XSS) vulnerability in modules/mod_languages/tmpl/default.php in the Language Switcher module for Joomla! 2.5.x before 2.5.7 allows remote attackers to inject…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4531

Published Oct 31, 2012

Cross-site scripting (XSS) vulnerability in Joomla! 2.5.x before 2.5.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4499

Published Oct 31, 2012

The contact formatter page in the Email Field module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to email the stored address in the entity…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4496

Published Oct 31, 2012

Cross-site scripting (XSS) vulnerability in the Custom Publishing Options module 6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users with the "administer nodes" pe…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 676-700 of 5,288 CVEsPage 28 of 212