VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 17 hours ago
Reset
More filters (3)
Columns
EPSS ≥ 0.5Published from 2012-01-01Published to 2012-12-31
Overview 12 matches, all in RASP scope, all public PoC, all EPSS ≥ 0.5 · 3 protected · 6 KEV · 6 CISA SSVC · 0 disputed
12matches, all in RASP scope, all public PoC, all EPSS ≥ 0.5 3protected25.0% 6KEV50.0% 6CISA SSVC50.0% 0disputed0.0%
Critical 6 50.0% High 2 16.7% Medium 4 33.3% Low 0 0.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 2 16.7% Rule in development 0 0.0% Mitigation candidate 9 75.0% No exploit published 0 0.0% No fix identified 0 0.0% Mitigated by environment configuration 1 8.3% Queued for review 0 0.0% Not applicable 0 0.0% Out of RASP scope 0 0.0% Rejected 0 0.0%
blocked by ARMR today 3 25.0% not blocked 9 75.0% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 6 50.0% Working exploit published 6 50.0% Proof of concept only 0 0.0% Forecast only 0 0.0% No public exploit 0 0.0%
split by peak 4 / month
Unknown: 0None: 0Low: 0Medium: 4High: 2Critical: 6 Rejected: 0Out of RASP scope: 0Not applicable: 0Queued for review: 0Mitigated by environment configuration: 1No fix identified: 0No exploit published: 0Mitigation candidate: 9Rule in development: 0Protected by RASP: 2 unrecorded: 0not established: 0not blocked: 9blocked by ARMR today: 3 No public exploit: 0Forecast only: 0Proof of concept only: 0Working exploit published: 6Exploited in the wild: 6 January 2012: 3 CVEs February 2012: 1 CVE March 2012: 0 CVEs April 2012: 0 CVEs May 2012: 1 CVE June 2012: 2 CVEs July 2012: 0 CVEs August 2012: 1 CVE September 2012: 0 CVEs October 2012: 4 CVEs
Jan 12Feb 12Mar 12Apr 12May 12Jun 12Jul 12Aug 12Sep 12Oct 12
12 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2012-5088 High 2012-10-16 Mitigated by environment configuration Working exploit published Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.
CVE-2012-5076 Critical 2012-10-16 Mitigation candidate Exploited in the wild Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JAX-WS.
CVE-2012-3153 Medium 2012-10-16 Protected by RASP Working exploit published Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Servlet. NOTE: the previous information is from the October 2012 CPU. Oracle has not commented on claims from the original researcher that the PARSEQUERY function allows remote attackers to obtain database credentials via reports/rwservlet/parsequery, and that this issue occurs in earlier versions. NOTE: this can be leveraged with CVE-2012-3152 to execute arbitrary code by uploading a .jsp file.
CVE-2012-3152 Critical 2012-10-16 Protected by RASP Exploited in the wild Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Report Server Component. NOTE: the previous information is from the October 2012 CPU. Oracle has not commented on claims from the original researcher that the URLPARAMETER functionality allows remote attackers to read and upload arbitrary files to reports/rwservlet, and that this issue occurs in earlier versions. NOTE: this can be leveraged with CVE-2012-3153 to execute arbitrary code by uploading a .jsp file.
CVE-2012-4681 Critical 2012-08-28 Mitigation candidate Exploited in the wild Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.
CVE-2012-1723 Critical 2012-06-16 Mitigation candidate Exploited in the wild Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
CVE-2012-0507 Critical 2012-06-07 Mitigation candidate Exploited in the wild Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.
CVE-2012-0549 High 2012-05-03 Mitigation candidate Working exploit published Unspecified vulnerability in the Oracle AutoVue Office component in Oracle Supply Chain Products Suite 20.1.1 allows remote attackers to affect confidentiality, integrity, and availability, related to Desktop API.
CVE-2012-1006 Medium 2012-02-07 Mitigation candidate Working exploit published Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) lastName parameter to struts2-showcase/person/editPerson.action, or the (3) clientName parameter to struts2-rest-showcase/orders.
CVE-2012-0392 Medium 2012-01-08 Mitigation candidate Working exploit published The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method.
CVE-2012-0391 Critical 2012-01-08 Mitigation candidate Exploited in the wild The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.
CVE-2011-4858 Medium 2012-01-05 Mitigation candidate Working exploit published Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.