Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Enterprise Virtualization MEDIUM 5.0
CVE-2013-4282

Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service …

Patch available
Fix from $1,600 2013-11-02
Xen MEDIUM 5.2
CVE-2013-4416

The Ocaml xenstored implementation (oxenstored) in Xen 4.1.x, 4.2.x, and 4.3.x allows local guest domains to cause a denial of service (domain shutdo…

Mitigation only
Fix from $1,600 2013-11-02
Strongswan MEDIUM 5.0
CVE-2013-6075

The compare_dn function in utils/identification.c in strongSwan 4.3.3 through 5.1.1 allows (1) remote attackers to cause a denial of service (out-of-…

Patch available
Fix from $1,600 2013-11-02
Adaptive Security Appliance Software MEDIUM 6.3
CVE-2013-5551

Cisco Adaptive Security Appliance (ASA) Software, when certain same-security-traffic and management-access options are enabled, allows remote authent…

Mitigation only
Fix from $1,600 2013-11-01
Varnish MEDIUM 5.0
CVE-2013-4484

Varnish before 3.0.5 allows remote attackers to cause a denial of service (child-process crash and temporary caching outage) via a GET request with t…

Fix: after 3.0.4
Fix from $1,600 2013-11-01
Firefox MEDIUM 6.8
CVE-2013-5596

The cycle collection (CC) implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before …

Fix: after 24.0.1
Fix from $1,600 2013-10-30
Firefox HIGH 10.0
CVE-2013-5602EPSS 5%

The Worker::SetEventListener function in the Web workers implementation in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x befo…

Fix: after 24.0.1
Fix from $1,950 2013-10-30
Firefox HIGH 9.3
CVE-2013-5604EPSS 6%

The txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1,…

Fix: after 24.0.1
Fix from $1,950 2013-10-30
Linux MEDIUM 6.8
CVE-2010-1159EPSS 7%

Multiple heap-based buffer overflows in Aircrack-ng before 1.1 allow remote attackers to cause a denial of service (crash) and execute arbitrary code…

Fix: after 1.0
Fix from $1,600 2013-10-28
Snack Sound Toolkit MEDIUM 6.8
CVE-2012-6303EPSS 10%

Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in WaveSurfer 1.8.8p4, allows re…

No fix yet
Fix from $1,600 2013-10-28
Polarssl MEDIUM 6.8
CVE-2013-5914

Buffer overflow in the ssl_read_record function in ssl_tls.c in PolarSSL before 1.1.8, when using TLS 1.1, might allow remote attackers to execute ar…

Fix: after 1.1.7
Fix from $1,600 2013-10-26
Mac Os X MEDIUM 6.8
CVE-2013-5170

Buffer underflow in CoreGraphics in Apple Mac OS X before 10.9 allows remote attackers to execute arbitrary code or cause a denial of service (applic…

Fix: after 10.8.5
Fix from $1,600 2013-10-24
Dir 100 HIGH 8.5
CVE-2013-6027

Stack-based buffer overflow in the RuntimeDiagnosticPing function in /bin/webs on D-Link DIR-100 routers might allow remote authenticated administrat…

No fix yet
Fix from $1,950 2013-10-19
Fireware HIGH 9.3
CVE-2013-6021EPSS 12%

Buffer overflow in WGagent in WatchGuard WSM and Fireware before 11.8 allows remote attackers to execute arbitrary code via a long sessionid value in…

Fix: after 11.7.4
Fix from $1,950 2013-10-19
Org.apache.sling.servlets.post MEDIUM 5.0
CVE-2013-2254

The deepGetOrCreateNode function in impl/operations/AbstractCreateOperation.java in org.apache.sling.servlets.post.bundle 2.2.0 and 2.3.0 in Apache S…

Patch available
Fix from $1,600 2013-10-17
Junos MEDIUM 6.8
CVE-2013-6013

Buffer overflow in the flow daemon (flowd) in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R7-S2, 12.1.X44 before 12.1X44-D15, 12.1X45 before 1…

Fix: after 10.4
Fix from $1,600 2013-10-17
Adaptive Security Appliance Software HIGH 7.1
CVE-2013-5513

Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(7), 8.5.x before 8.5(1.18), 8.6.x b…

Mitigation only
Fix from $1,950 2013-10-13
Adaptive Security Appliance Software HIGH 7.8
CVE-2013-5515

The Clientless SSL VPN feature in Cisco Adaptive Security Appliance (ASA) Software 8.x before 8.2(5.44), 8.3.x before 8.3(2.39), 8.4.x before 8.4(5.7…

Mitigation only
Fix from $1,950 2013-10-13
Adaptive Security Appliance Software HIGH 7.8
CVE-2013-3415

Cisco Adaptive Security Appliance (ASA) Software 8.4.x before 8.4(3) and 8.6.x before 8.6(1.3) does not properly manage memory upon an AnyConnect SSL…

Mitigation only
Fix from $1,950 2013-10-13
Wonderware Intouch MEDIUM 6.9
CVE-2012-4709

Invensys Wonderware InTouch HMI 2012 R2 and earlier allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause…

Fix: after 2012
Fix from $1,600 2013-10-13
Vlc Media Player MEDIUM 6.8
CVE-2013-4388

Buffer overflow in the mp4a packetizer (modules/packetizer/mpeg4audio.c) in VideoLAN VLC Media Player before 2.0.8 allows remote attackers to cause a…

Fix: after 2.0.7
Fix from $1,600 2013-10-11
Easy Lan Folder Share HIGH 7.2
CVE-2013-6079

Buffer overflow in MostGear Soft Easy LAN Folder Share 3.2.0.100 allows local users to cause a denial of service (application crash) and possibly exe…

No fix yet
Fix from $1,950 2013-10-11
Linux Kernel MEDIUM 6.1
CVE-2013-4387

net/ipv6/ip6_output.c in the Linux kernel through 3.11.4 does not properly determine the need for UDP Fragmentation Offload (UFO) processing of small…

Fix: after 3.11.4
Fix from $1,600 2013-10-10
Glibc MEDIUM 5.1
CVE-2012-4424

Stack-based buffer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-dependent attackers to ca…

Fix: after 2.17
Fix from $1,600 2013-10-09
Glibc MEDIUM 6.8
CVE-2013-4237

sysdeps/posix/readdir_r.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allows context-dependent attackers to cause a denial of service …

Fix: after 2.18
Fix from $1,600 2013-10-09
Chicken HIGH 7.5
CVE-2013-4385

Buffer overflow in the "read-string!" procedure in the "extras" unit in CHICKEN stable before 4.8.0.5 and development snapshots before 4.8.3 allows r…

Fix: after 4.8.0.4
Fix from $1,950 2013-10-09
Robohelp HIGH 10.0
CVE-2013-5327

MDBMS.dll in Adobe RoboHelp 10 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

Patch available
Fix from $1,950 2013-10-09
Excel HIGH 9.3
CVE-2013-3889EPSS 27%

Microsoft Excel 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office for Mac 2011; Excel Viewe…

Mitigation only
Fix from $1,950 2013-10-09
Excel HIGH 9.3
CVE-2013-3890EPSS 20%

Microsoft Excel 2007 SP3, Excel Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office docum…

Mitigation only
Fix from $1,950 2013-10-09
Word HIGH 9.3
CVE-2013-3891EPSS 19%

Microsoft Word 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Memory Corruption Vulnerability."

Mitigation only
Fix from $1,950 2013-10-09