Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Mbed Mqtt HIGH 7.5
CVE-2019-17210

A denial-of-service issue was discovered in the MQTT library in Arm Mbed OS 2017-11-02. The function readMQTTLenString() is called by the function MQ…

Mitigation only
Fix from $1,950 2019-11-04
Shadow HIGH 7.8
CVE-2005-4890

There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to…

Fix: after 4.1.5
Fix from $1,950 2019-11-04
Cryptocat CRITICAL 9.8
CVE-2013-2259

Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview

Fix: 2.0.22+
Fix from $2,300 2019-11-04
Cryptocat CRITICAL 9.8
CVE-2013-4103EPSS 7%

Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input

Fix: 2.0.22+
Fix from $2,300 2019-11-04
Cryptocat HIGH 7.5
CVE-2013-4100

Cryptocat before 2.0.22 has Remote Denial of Service via username

Fix: 2.0.22+
Fix from $1,950 2019-11-04
Cryptocat MEDIUM 5.3
CVE-2013-4101

Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weakness

Fix: 2.0.22+
Fix from $1,600 2019-11-04
Openshift HIGH 7.3
CVE-2013-0165

cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp.

Mitigation only
Fix from $1,950 2019-11-01
Redis MEDIUM 5.5
CVE-2013-0178

Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.

Fix: 2.6.0+
Fix from $1,600 2019-11-01
Redis MEDIUM 5.5
CVE-2013-0180

Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.

Patch available
Fix from $1,600 2019-11-01
Debian Linux HIGH 7.5
CVE-2013-2227EPSS 13%

GLPI 0.83.7 has Local File Inclusion in common.tabs.php.

No fix yet
Fix from $1,950 2019-11-01
Debian Linux MEDIUM 5.5
CVE-2013-3718

evince is missing a check on number of pages which can lead to a segmentation fault

Patch available
Fix from $1,600 2019-11-01
Symfony HIGH 8.1
CVE-2013-4751

php-symfony2-Validator has loss of information during serialization

Fix: 2.0.24 / 2.1.12+
Fix from $1,950 2019-11-01
H2w2pc1m Firmware HIGH 7.5
CVE-2019-18228

Honeywell equIP series IP cameras Multiple equIP Series Cameras, A vulnerability exists in the affected products where a specially crafted HTTP packe…

Mitigation only
Fix from $1,950 2019-10-31
Debian Linux MEDIUM 6.5
CVE-2012-6123

Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."

Fix: 4.8.0+
Fix from $1,600 2019-10-31
Chicken CRITICAL 9.8
CVE-2012-6125

Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.

Fix: 4.8.0+
Fix from $2,300 2019-10-31
Debian Linux CRITICAL 9.8
CVE-2013-1910

yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Tro…

Mitigation only
Fix from $2,300 2019-10-31
Debian Linux MEDIUM 6.5
CVE-2010-2490

Mumble: murmur-server has DoS due to malformed client query

Patch available
Fix from $1,600 2019-10-31
Debian Linux CRITICAL 9.8
CVE-2010-0748

Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr a…

Fix: 1.92+
Fix from $2,300 2019-10-30
Rpcbind HIGH 7.8
CVE-2010-2061

rpcbind 0.2.0 does not properly validate (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr, which can be created by an attacker before the daemon is star…

Mitigation only
Fix from $1,950 2019-10-29
Mapserver HIGH 7.5
CVE-2010-1678

Mapserver 5.2, 5.4 and 5.6 before 5.6.5-2 improperly validates symbol index values during Mapfile parsing.

Fix: 5.6.5.-2+
Fix from $1,950 2019-10-29
Sugarcrm CRITICAL 9.8
CVE-2012-0694EPSS 67%

SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code.

Fix: after 6.3.1
Fix from $2,300 2019-10-29
Debian Linux MEDIUM 5.5
CVE-2010-3373

paxtest handles temporary files insecurely

No fix yet
Fix from $1,600 2019-10-29
Qtparted CRITICAL 9.8
CVE-2010-3375

qtparted has insecure library loading which may allow arbitrary code execution

Mitigation only
Fix from $2,300 2019-10-29
Mailscanner MEDIUM 5.5
CVE-2010-3293

mailscanner can allow local users to prevent virus signatures from being updated

Fix: 4.79.11-2+
Fix from $1,600 2019-10-28
Tikiwiki Cms\/groupware CRITICAL 9.8
CVE-2010-4239EPSS 13%

Tiki Wiki CMS Groupware 5.2 has Local File Inclusion

No fix yet
Fix from $2,300 2019-10-28
Snoopy CRITICAL 9.8
CVE-2002-2444

Snoopy before 2.0.0 has a security hole in exec cURL

Patch available
Fix from $2,300 2019-10-28
Nessus MEDIUM 6.5
CVE-2019-3982

Nessus versions 8.6.0 and earlier were found to contain a Denial of Service vulnerability due to improper validation of specific imported scan types.…

Fix: after 8.6.0
Fix from $1,600 2019-10-23
Open Sdn Controller HIGH 7.5
CVE-2014-2304

A vulnerability in version 0.90 of the Open Floodlight SDN controller software could result in a denial of service attack and crashing of the control…

No fix yet
Fix from $1,950 2019-10-23
Open Sdn Controller HIGH 7.5
CVE-2013-7333

A vulnerability in version 0.90 of the Open Floodlight SDN controller software could allow an attacker with access to the OpenFlow control network to…

No fix yet
Fix from $1,950 2019-10-23
Libidn2 HIGH 7.5
CVE-2019-12290

GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it p…

Fix: 2.2.0+
Fix from $1,950 2019-10-22