Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Debian Linux MEDIUM 6.8
CVE-2015-2754

FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) and possibly execute arbitrary code via a crafted workbo…

Fix: after 1.0.0h
Fix from $1,600 2015-03-31
Debian Linux MEDIUM 6.8
CVE-2015-2753

FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) or possibly execute arbitrary code via a crafted sector …

Fix: after 1.0.0h
Fix from $1,600 2015-03-31
Opensuse HIGH 7.5
CVE-2014-9462

The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted repository name i…

Fix: after 3.2.3
Fix from $1,950 2015-03-31
Fedora MEDIUM 5.0
CVE-2015-1609

MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of service via a crafted UTF-8 string in a BSON request.

Fix: after 2.4.12
Fix from $1,600 2015-03-30
PHP HIGH 7.5
CVE-2014-9653

readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider…

Fix: after 5.21
Fix from $1,950 2015-03-30
Wireless Lan Controller Software MEDIUM 6.1
CVE-2015-0679

The web-authentication functionality on Cisco Wireless LAN Controller (WLC) devices 7.3(103.8) and 7.4(110.0) allows remote attackers to cause a deni…

Mitigation only
Fix from $1,600 2015-03-28
Nx Os HIGH 7.9
CVE-2015-0658

The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which a…

Mitigation only
Fix from $1,950 2015-03-28
iOS HIGH 7.8
CVE-2015-0649

Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 allows remote attackers to cause a denial of service (device reload) via malformed Common Industrial Proto…

Mitigation only
Fix from $1,950 2015-03-26
Ios Xe HIGH 7.8
CVE-2015-0650

The Service Discovery Gateway (aka mDNS Gateway) in Cisco IOS 12.2, 12.4, 15.0, 15.1, 15.2, 15.3, and 15.4 and IOS XE 3.9.xS and 3.10.xS before 3.10.…

Mitigation only
Fix from $1,950 2015-03-26
iOS HIGH 7.8
CVE-2015-0647

Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 allows remote attackers to cause a denial of service (device reload) via malformed Common Industrial Proto…

Mitigation only
Fix from $1,950 2015-03-26
Ios Xe HIGH 7.8
CVE-2015-0645

The Layer 4 Redirect (L4R) feature in Cisco IOS XE 2.x and 3.x before 3.10.4S, 3.11 before 3.11.3S, 3.12 before 3.12.2S, 3.13 before 3.13.1S, 3.14 be…

Mitigation only
Fix from $1,950 2015-03-26
Ios Xe HIGH 7.8
CVE-2015-0644

AppNav in Cisco IOS XE 3.8 through 3.10 before 3.10.3S, 3.11 before 3.11.3S, 3.12 before 3.12.1S, 3.13 before 3.13.0S, 3.14 before 3.14.0S, and 3.15 …

Mitigation only
Fix from $1,950 2015-03-26
Ios Xe HIGH 7.8
CVE-2015-0641

Cisco IOS XE 2.x and 3.x before 3.9.0S, 3.10 before 3.10.0S, 3.11 before 3.11.0S, 3.12 before 3.12.0S, 3.13 before 3.13.0S, 3.14 before 3.14.0S, and …

Mitigation only
Fix from $1,950 2015-03-26
Ios Xe HIGH 7.8
CVE-2015-0642

Cisco IOS 12.2, 12.4, 15.0, 15.1, 15.2, 15.3, and 15.4 and IOS XE 2.5.x, 2.6.x, 3.1.xS through 3.12.xS before 3.12.3S, 3.2.xE through 3.7.xE before 3…

Mitigation only
Fix from $1,950 2015-03-26
Ios Xe HIGH 7.8
CVE-2015-0640

The high-speed logging (HSL) feature in Cisco IOS XE 2.x and 3.x before 3.10.4S, 3.11 before 3.11.3S, 3.12 before 3.12.1S, 3.13 before 3.13.0S, 3.14 …

Mitigation only
Fix from $1,950 2015-03-26
Ios Xe HIGH 7.8
CVE-2015-0639

The Common Flow Table (CFT) feature in Cisco IOS XE 3.6 and 3.7 before 3.7.1S, 3.8 before 3.8.0S, 3.9 before 3.9.0S, 3.10 before 3.10.0S, 3.11 before…

Mitigation only
Fix from $1,950 2015-03-26
iOS HIGH 7.1
CVE-2015-0638

Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3, when a VRF interface is configured, allows remote attackers to cause a denial of service (interface queue…

Mitigation only
Fix from $1,950 2015-03-26
Ios Xe HIGH 7.8
CVE-2015-0637

The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS b…

Mitigation only
Fix from $1,950 2015-03-26
Ios Xe HIGH 7.8
CVE-2015-0636

The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS b…

Mitigation only
Fix from $1,950 2015-03-26
Ios Xe HIGH 9.0
CVE-2015-0635

The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS b…

Mitigation only
Fix from $1,950 2015-03-26
Debian Linux MEDIUM 5.0
CVE-2015-0252EPSS 40%

internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafte…

Fix: after 3.1.1
Fix from $1,600 2015-03-24
iOS MEDIUM 6.4
CVE-2015-0669

The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 15.4S and 15.4(3)S allows remote attackers to modify configuration settings…

Mitigation only
Fix from $1,600 2015-03-21
Bacnet Opc Server HIGH 9.0
CVE-2015-0980

Format string vulnerability in BACnOPCServer.exe in the SOAP web interface in SCADA Engine BACnet OPC Server before 2.1.371.24 allows remote attacker…

Fix: after 2.1.359.22
Fix from $1,950 2015-03-14
Debian Linux MEDIUM 6.8
CVE-2015-1782

The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact vi…

Fix: after 1.4.3
Fix from $1,600 2015-03-13
Expressway Software HIGH 7.8
CVE-2015-0652

The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X8.2 and Cis…

Mitigation only
Fix from $1,950 2015-03-13
Rsa Certificate Manager HIGH 7.8
CVE-2015-0523

EMC RSA Certificate Manager (RCM) before 6.9 build 558 and RSA Registration Manager (RRM) before 6.9 build 558 allow remote attackers to cause an Adm…

Fix: after 6.8
Fix from $1,950 2015-03-12
Wireshark MEDIUM 5.0
CVE-2015-2187

The dissect_atn_cpdlc_heur function in asn1/atn-cpdlc/packet-atn-cpdlc-template.c in the ATN-CPDLC dissector in Wireshark 1.12.x before 1.12.4 does n…

Mitigation only
Fix from $1,600 2015-03-08
HTTP Server MEDIUM 5.0
CVE-2015-0228EPSS 19%

The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a de…

Fix: after 2.4.12
Fix from $1,600 2015-03-08
Simatic S7 300 Cpu Firmware HIGH 7.5
CVE-2015-2177EPSS 35%

Siemens SIMATIC S7-300 CPU devices allow remote attackers to cause a denial of service (defect-mode transition) via crafted packets on (1) TCP port 1…

No fix yet
Fix from $1,950 2015-03-07
Spc5000 Firmware HIGH 7.8
CVE-2014-9369

Siemens SPC controllers SPC4000, SPC5000, and SPC6000 before 3.6.0 allow remote attackers to cause a denial of service (device restart) via crafted p…

Fix: after 3.5.9
Fix from $1,950 2015-03-07