Skip to main content

Year archive

CVEs published in 2012

Archive summary

5,288 CVEs published in 2012 — 950 Critical, 794 High, 3,036 Medium, 506 Low, 2 Unrated.

CVE-2012-4494

Published Oct 31, 2012

The Shibboleth authentication module 7.x-4.0 for Drupal does not properly check the active status of users, which allows remote blocked users to access bypass intended access rest…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4492

Published Oct 31, 2012

Multiple cross-site scripting (XSS) vulnerabilities in the Shorten URLs module 6.x-1.x before 6.x-1.13 and 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-4490

Published Oct 31, 2012

Multiple cross-site scripting (XSS) vulnerabilities in the Excluded Users module 6.x-1.x before 6.x-1.1 for Drupal allow remote attackers to inject arbitrary web script or HTML vi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4489

Published Oct 31, 2012

Open redirect vulnerability in the securelogin_secure_redirect function in the Secure Login module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to redirect users to a…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4484

Published Oct 31, 2012

Cross-site scripting (XSS) vulnerability in the administrative interface in the Campaign Monitor module before 6.x-2.5 for Drupal allows remote attackers to inject arbitrary web s…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4483

Published Oct 31, 2012

The commons_discussion_views_default_views function in modules/features/commons_discussion/commons_discussion.views_default.inc in the Drupal Commons module 6.x-2.x before 6.x-2.8…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2625

Published Oct 31, 2012

The PyGrub boot loader in Xen unstable before changeset 25589:60f09d1ab1fe, 4.2.x, and 4.1.x allows local para-virtualized guest users to cause a denial of service (memory consump…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-4934

Published Oct 31, 2012

TomatoCart 1.1.7, when the PayPal Express Checkout module is enabled in sandbox mode, allows remote authenticated users to bypass intended payment requirements by modifying a cert…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-4610

Published Oct 31, 2012

EMC Avamar Client for VMware 6.1 stores the cleartext server root password on the proxy client, which might allow remote attackers to obtain sensitive information by leveraging "n…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-0023

Published Oct 30, 2012

Double free vulnerability in the get_chunk_header function in modules/demux/ty.c in VideoLAN VLC media player 0.9.0 through 1.1.12 allows remote attackers to cause a denial of ser…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-4663

Published Oct 29, 2012

The DCERPC inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with softw…

CVSS 7.1 · High

CVE-2012-4662

Published Oct 29, 2012

The DCERPC inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with softw…

CVSS 7.1 · High

CVE-2012-4661

Published Oct 29, 2012

Stack-based buffer overflow in the DCERPC inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst…

CVSS 9.0 · Critical

CVE-2012-4660

Published Oct 29, 2012

The SIP inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software…

CVSS 7.8 · High

CVE-2012-4659

Published Oct 29, 2012

The AAA functionality in the IPv4 SSL VPN implementations on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 65…

CVSS 7.1 · High

CVE-2012-4643

Published Oct 29, 2012

The DHCP server on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 7.0 befor…

CVSS 7.1 · High

CVE-2012-4196

Published Oct 29, 2012

Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers…

CVSS 6.4 · Medium

CVE-2012-4195

Published Oct 29, 2012

The nsLocation::CheckURL function in Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey…

CVSS 4.3 · Medium
Showing 701-725 of 5,288 CVEsPage 29 of 212