KEV 2012

22 CISA Known Exploited Vulnerabilities from 2012

CVE-2012-1710

Oracle Fusion Middleware — Oracle Fusion Middleware Unspecified Vulnerability

CVSS 9.8

CVE-2012-5076

Oracle Java SE — Oracle Java SE Sandbox Bypass Vulnerability

CVSS 9.8

CVE-2012-1823

PHP PHP — PHP-CGI Query String Parameter Vulnerability

CVSS 9.8

CVE-2012-0507

Oracle Java SE — Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

CVSS 9.8

CVE-2012-1723

Oracle Java SE — Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

CVSS 9.8

CVE-2012-4681

Oracle Java SE — Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

CVSS 9.8

CVE-2012-0391

Apache Struts 2 — Apache Struts 2 Improper Input Validation Vulnerability

CVSS 9.8

CVE-2012-3152

Oracle Fusion Middleware — Oracle Fusion Middleware Unspecified Vulnerability

CVSS 9.1

CVE-2012-4792

Microsoft Internet Explorer — Microsoft Internet Explorer Use-After-Free Vulnerability

CVSS 8.8

CVE-2012-1889

Microsoft XML Core Services — Microsoft XML Core Services Memory Corruption Vulnerability

CVSS 8.8

CVE-2012-5054

Adobe Flash Player — Adobe Flash Player Integer Overflow Vulnerability

CVSS 8.8

CVE-2012-1856

Microsoft Office — Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability

CVSS 8.8

CVE-2012-0158

Microsoft MSCOMCTL.OCX — Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability

CVSS 8.8

CVE-2012-0754

Adobe Flash Player — Adobe Flash Player Memory Corruption Vulnerability

CVSS 8.1

CVE-2012-4969

Microsoft Internet Explorer — Microsoft Internet Explorer Use-After-Free Vulnerability

CVSS 8.1

CVE-2012-1854

Microsoft VBA — DLL Hijacking via Untrusted Search Path in Office Applications

CVSS 7.8

CVE-2012-0151

Microsoft Windows — Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability

CVSS 7.8

CVE-2012-2539

Microsoft Word — Microsoft Word Remote Code Execution Vulnerability

CVSS 7.8

CVE-2012-1535

Adobe Flash Player — Adobe Flash Player Arbitrary Code Execution Vulnerability

CVSS 7.8

CVE-2012-2034

Adobe Flash Player — Adobe Flash Player Memory Corruption Vulnerability

CVSS 7.5

CVE-2012-0767

Adobe Flash Player — Adobe Flash Player Cross-Site Scripting (XSS) Vulnerability

CVSS 6.1

CVE-2012-0518

Oracle Fusion Middleware — Oracle Fusion Middleware Unspecified Vulnerability

CVSS 4.7