Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Groovy Media Player MEDIUM 6.8
CVE-2013-2760

Buffer overflow in Groovy Media Player 3.2.0 allows remote attackers to execute arbitrary code via a long string in a .m3u file.

No fix yet
Fix from $1,600 2013-04-16
Keystone MEDIUM 6.5
CVE-2013-0270

A flaw was found in OpenStack Keystone. A remote attacker could exploit this vulnerability by sending a large HTTP request, specifically by providing…

Fix: after 2012.2.4
Fix from $1,600 2013-04-12
Anyconnect Secure Mobility Client MEDIUM 6.6
CVE-2013-1173

Heap-based buffer overflow in ciscod.exe in the Cisco Security Service in Cisco AnyConnect Secure Mobility Client (aka AnyConnect VPN Client) allows …

Mitigation only
Fix from $1,600 2013-04-11
Haproxy MEDIUM 5.1
CVE-2013-1912EPSS 5%

Buffer overflow in HAProxy 1.4 through 1.4.22 and 1.5-dev through 1.5-dev17, when HTTP keep-alive is enabled, using HTTP keywords in TCP inspection r…

Mitigation only
Fix from $1,600 2013-04-10
Flash Player HIGH 10.0
CVE-2013-1378

Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280 on Linux,…

Fix: after 3.6.0.6090
Fix from $1,950 2013-04-10
Adobe Air Sdk HIGH 10.0
CVE-2013-1379EPSS 6%

Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280 on Linux,…

Fix: after 10.3.183.68
Fix from $1,950 2013-04-10
Poppler MEDIUM 6.8
CVE-2013-1788

poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors that tr…

Fix: after 0.22.0
Fix from $1,600 2013-04-09
Poppler MEDIUM 6.8
CVE-2013-1790

poppler/Stream.cc in poppler before 0.22.1 allows context-dependent attackers to have an unspecified impact via vectors that trigger a read of uninit…

Fix: after 0.22.0
Fix from $1,600 2013-04-09
Gpu Driver HIGH 7.1
CVE-2013-0131

Buffer overflow in the NVIDIA GPU driver before 304.88, 310.x before 310.44, and 313.x before 313.30 for the X Window System on UNIX, when NoScanout …

Fix: after 304.00
Fix from $1,950 2013-04-08
Display Driver HIGH 7.2
CVE-2013-0109

The NVIDIA driver before 307.78, and Release 310 before 311.00, in the NVIDIA Display Driver service on Windows does not properly handle exceptions, …

Fix: after 307.00
Fix from $1,950 2013-04-08
Cogent Datahub HIGH 7.5
CVE-2013-0680EPSS 19%

Stack-based buffer overflow in the web server in Cogent Real-Time Systems Cogent DataHub before 7.3.0, OPC DataHub before 6.4.22, Cascade DataHub bef…

Fix: after 7.2.2
Fix from $1,950 2013-04-05
Cogent Datahub HIGH 7.5
CVE-2013-0682

Cogent Real-Time Systems Cogent DataHub before 7.3.0, OPC DataHub before 6.4.22, Cascade DataHub before 6.4.22 on Windows, and DataHub QuickTrend bef…

Fix: after 7.2.2
Fix from $1,950 2013-04-05
Hosted Collaboration Solution MEDIUM 5.0
CVE-2013-1174

Cisco Tivoli Business Service Manager (TBSM) in Hosted Collaboration Mediation (HCM) in Cisco Hosted Collaboration Solution allows remote attackers t…

Mitigation only
Fix from $1,600 2013-04-05
Firefox MEDIUM 5.0
CVE-2013-0791EPSS 5%

The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.…

Fix: 3.15 / 17.0.5+
Fix from $1,600 2013-04-03
Firefox HIGH 7.2
CVE-2013-0799

Buffer overflow in the Mozilla Maintenance Service in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, and Thu…

Fix: after 19.0.2
Fix from $1,950 2013-04-03
Cinder Folsom MEDIUM 5.0
CVE-2013-1664

The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Fol…

No fix yet
Fix from $1,600 2013-04-03
Ubuntu Linux HIGH 7.5
CVE-2012-6129EPSS 5%

Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a…

Fix: after 2.73
Fix from $1,950 2013-04-03
Open Source MEDIUM 5.0
CVE-2013-2686

main/http.c in the HTTP server in Asterisk Open Source 1.8.x before 1.8.20.2, 10.x before 10.12.2, and 11.x before 11.2.2; Certified Asterisk 1.8.15 …

Mitigation only
Fix from $1,600 2013-04-01
Open Source HIGH 7.5
CVE-2013-2685

Stack-based buffer overflow in res/res_format_attr_h264.c in Asterisk Open Source 11.x before 11.2.2 allows remote attackers to execute arbitrary cod…

Mitigation only
Fix from $1,950 2013-04-01
Coreftp MEDIUM 5.1
CVE-2013-0130

Multiple buffer overflows in Core FTP before 2.2 build 1769 allow remote FTP servers to execute arbitrary code or cause a denial of service (applicat…

Fix: after 2.2
Fix from $1,600 2013-03-29
Groupwise Messenger HIGH 9.3
CVE-2013-1085EPSS 6%

Stack-based buffer overflow in the nim: protocol handler in Novell GroupWise Messenger 2.04 and earlier, and Novell Messenger 2.1.x and 2.2.x before …

Fix: after 2.2.1
Fix from $1,950 2013-03-29
MySQL HIGH 7.5
CVE-2012-0553

Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.28, has unspecified impact and attack vectors, a different vulner…

Mitigation only
Fix from $1,950 2013-03-28
iOS HIGH 7.1
CVE-2013-1143

The RSVP protocol implementation in Cisco IOS 12.2 and 15.0 through 15.2 and IOS XE 3.1.xS through 3.4.xS before 3.4.5S and 3.5.xS through 3.7.xS bef…

Mitigation only
Fix from $1,950 2013-03-28
iOS HIGH 7.8
CVE-2013-1146

The Smart Install client functionality in Cisco IOS 12.2 and 15.0 through 15.3 on Catalyst switches allows remote attackers to cause a denial of serv…

Mitigation only
Fix from $1,950 2013-03-28
iOS HIGH 7.8
CVE-2013-1147

The Protocol Translation (PT) functionality in Cisco IOS 12.3 through 12.4 and 15.0 through 15.3, when one-step port-23 translation or a Telnet-to-PA…

Mitigation only
Fix from $1,950 2013-03-28
iOS HIGH 7.8
CVE-2013-1148

The General Responder implementation in the IP Service Level Agreement (SLA) feature in Cisco IOS 15.2 and IOS XE 3.1.xS through 3.4.xS before 3.4.5S…

Mitigation only
Fix from $1,950 2013-03-28
MySQL HIGH 7.5
CVE-2013-1492

Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.30, has unspecified impact and attack vectors, a different vulner…

Mitigation only
Fix from $1,950 2013-03-28
MariaDB MEDIUM 5.0
CVE-2013-1861EPSS 19%

MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earli…

Fix: 5.5.32 / 10.0.4+
Fix from $1,600 2013-03-28
Bind HIGH 7.8
CVE-2013-2266EPSS 43%

libdns in ISC BIND 9.7.x and 9.8.x before 9.8.4-P2, 9.8.5 before 9.8.5b2, 9.9.x before 9.9.2-P2, and 9.9.3 before 9.9.3b2 on UNIX platforms allows re…

Mitigation only
Fix from $1,950 2013-03-28
Chrome MEDIUM 5.0
CVE-2013-0917

The URL loader in Google Chrome before 26.0.1410.43 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

Fix: after 26.0.1410.42
Fix from $1,600 2013-03-28