CVEs from 2012

5,200 normalized CVEs published or assigned in this year.

Total
5,200
critical
critical 963
high
high 747
medium
medium 2,885
low
low 530
% Critical
18.5%
% with KEV
0.4%
% with exploit
3.2%

Top vendors

Top products

  • chrome 7,005
  • safari 6,451
  • itunes 4,416
  • firefox 4,272
  • seamonkey 3,619
  • opera_browser 3,599
  • mysql 2,827
  • thunderbird 2,165
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2012-1710 unknown 1.5 4y ago Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown ve…
CVE-2012-0518 unknown 1.5 4y ago Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors
CVE-2012-2539 unknown 1.5 4y ago Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data.
CVE-2012-2034 unknown 1.5 4y ago Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS).
CVE-2012-1856 unknown 1.5 4y ago The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers syst…
CVE-2012-5616 low 1.5 14y ago Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf log file, which allows local users to obtain (1) t…
CVE-2012-3145 low 1.5 14y ago Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.0.5, 5.1.0, 5.2.0, 5.3.0 through 5.3.4, and 6.2.0 allows local users to affect…
CVE-2012-6095 low 1.2 14y ago ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary files via a race condition and a symlink attack on the (1) MKD or (2) XMKD command…
CVE-2012-3500 low 1.2 14y ago scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools before 8.3, allows local users to modify arbitrary files via a symlink attack on the temporary (1) standard output or (2…
CVE-2012-2103 low 1.2 14y ago The qmailscan plugin for Munin 1.4.5 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.
CVE-2012-4676 low 1.2 14y ago The errorExitIfAttackViaString function in Tunnelblick 3.3beta20 and earlier allows local users to delete arbitrary files by constructing a (1) symlink or (2) hard link, a different vulnerability tha…
CVE-2012-3487 low 1.2 14y ago Race condition in Tunnelblick 3.3beta20 and earlier allows local users to kill unintended processes by waiting for a specific PID value to be assigned to a target process.
CVE-2012-2678 low 1.2 14y ago 389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server has been reset, allows remote attackers …
CVE-2012-2313 low 1.2 14y ago The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet…
CVE-2012-0645 low 1.2 14y ago Siri in Apple iOS before 5.1 does not properly restrict the ability of Mail.app to handle voice commands, which allows physically proximate attackers to bypass the locked state via a command that for…
CVE-2012-10026 unknown 1.0 10mo ago The WordPress plugin Asset-Manager version 2.0 and below contains an unauthenticated arbitrary file upload vulnerability in upload.php. The endpoint fails to properly validate and restrict uploaded f…
CVE-2012-1572 unknown OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space
CVE-2012-6712 unknown In the Linux kernel before 3.4, a buffer overflow occurs in drivers/net/wireless/iwlwifi/iwl-agn-sta.c, which will cause at least memory corruption.
CVE-2012-5887 unknown 4y ago Improper Authentication in Apache Tomcat
CVE-2012-3353 unknown 4y ago Apache Sling JCR ContentLoader XmlReader Arbitrary File Load
CVE-2012-3536 unknown 4y ago Apache James Hupa Webmail application Cross-site Scripting Vulnerabilities
CVE-2012-1094 unknown 4y ago JBoss AS may expose root content if excluded-contexts list is mismatched
CVE-2012-0785 unknown 4y ago Hash collision attack vulnerability in Jenkins
CVE-2012-1592 unknown 4y ago Unrestricted Upload of File with Dangerous Type in Apache Struts2
CVE-2012-4441 unknown 4y ago Jenkins CI Game Plugin allows Cross-Site Scripting (XSS)
CVE-2012-4439 unknown 4y ago Jenkins allows Cross-Site Scripting (XSS) via Crafted URL
CVE-2012-4440 unknown 4y ago Jenkins Violation Plugin allows Cross-Site Scripting (XSS)
CVE-2012-4438 unknown 4y ago Jenkins allows Data Insertion and Execution of Code by those with Read and HTTP Access
CVE-2012-2945 unknown 4y ago Hadoop symlink vulnerability