Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Netbackup Opscenter HIGH 7.5
CVE-2015-1483

Symantec NetBackup OpsCenter 7.6.0.2 through 7.6.1 on Linux and UNIX allows remote attackers to execute arbitrary JavaScript code via unspecified vec…

Mitigation only
Fix from $1,950 2015-03-06
Ios Xr MEDIUM 5.0
CVE-2015-0657

Cisco IOS XR allows remote attackers to cause a denial of service (RSVP process reload) via a malformed RSVP packet, aka Bug ID CSCur69192.

Mitigation only
Fix from $1,600 2015-03-06
Linux Kernel MEDIUM 5.0
CVE-2014-8160EPSS 5%

net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables …

Fix: 3.18+
Fix from $1,600 2015-03-02
Unified Computing System MEDIUM 6.8
CVE-2015-0633

The Integrated Management Controller (IMC) in Cisco Unified Computing System (UCS) 1.4(7h) and earlier on C-Series servers allows remote attackers to…

Mitigation only
Fix from $1,600 2015-02-26
Gpon 2520 Firmware HIGH 7.8
CVE-2015-2055

Zhone GPON 2520 with firmware R4.0.2.566b allows remote attackers to cause a denial of service via a long string in the oldpassword parameter.

No fix yet
Fix from $1,950 2015-02-23
Desktop Collaboration Experience Dx650 HIGH 7.2
CVE-2015-0584

The image-upgrade implementation on Cisco Desktop Collaboration Experience (aka Collaboration Desk Experience or DX) DX650 endpoints allows local use…

Mitigation only
Fix from $1,950 2015-02-20
Adminsystems Cms MEDIUM 6.5
CVE-2015-1604

Unrestricted file upload vulnerability in asys/site/files.php in Adminsystems CMS before 4.0.2 allows remote authenticated users to execute arbitrary…

Fix: after 4.0.0
Fix from $1,600 2015-02-19
Fcgi MEDIUM 5.0
CVE-2012-6687EPSS 6%

FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial of service (segmentation fault and crash) via a large number of connec…

Mitigation only
Fix from $1,600 2015-02-19
Wireless Lan Controller HIGH 7.1
CVE-2015-0622

The Wireless Intrusion Detection (aka WIDS) functionality on Cisco Wireless LAN Controller (WLC) devices allows remote attackers to cause a denial of…

Mitigation only
Fix from $1,950 2015-02-19
Unified Ip Phones 9900 Series Firmware MEDIUM 5.0
CVE-2015-0600

The mobility extension on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to cause a denial of service (logoff…

Fix: after 9.4
Fix from $1,600 2015-02-07
Webex Meetings Server HIGH 9.0
CVE-2015-0589

The administrative web interface in Cisco WebEx Meetings Server 1.0 through 1.5 allows remote authenticated users to execute arbitrary OS commands wi…

Mitigation only
Fix from $1,950 2015-02-07
Unified Ip Phones 9971 Firmware MEDIUM 5.0
CVE-2015-0604

The web framework on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to upload files to arbitrary locations on…

Mitigation only
Fix from $1,600 2015-02-07
Debian Linux MEDIUM 5.0
CVE-2015-1382

parsers.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to an HTTP time …

Fix: after 3.0.22
Fix from $1,600 2015-02-03
Privoxy MEDIUM 5.0
CVE-2015-1380

jcc.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (abort) via a crafted chunk-encoded body.

Fix: after 3.0.22
Fix from $1,600 2015-02-03
Scalance X 200 Series Firmware MEDIUM 6.8
CVE-2015-1049

The web server on Siemens SCALANCE X-200IRT switches with firmware before 5.2.0 allows remote attackers to hijack sessions via unspecified vectors.

Fix: after 5.1.1
Fix from $1,600 2015-02-02
Webex Meetings Server MEDIUM 5.0
CVE-2015-0597

The Forgot Password feature in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to enumerate administrative accounts via c…

Fix: after 1.5
Fix from $1,600 2015-02-02
Mac Os X HIGH 10.0
CVE-2014-8836

The Bluetooth driver in Apple OS X before 10.10.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (ar…

Fix: after 10.10.1
Fix from $1,950 2015-01-30
Mac Os X HIGH 7.2
CVE-2014-8825

The kernel in Apple OS X before 10.10.2 does not properly perform identitysvc validation of certain directory-service functionality, which allows loc…

Fix: after 10.10.1
Fix from $1,950 2015-01-30
Mac Os X HIGH 10.0
CVE-2014-8824

The kernel in Apple OS X before 10.10.2 does not properly validate IODataQueue object metadata fields, which allows attackers to execute arbitrary co…

Fix: after 10.10.1
Fix from $1,950 2015-01-30
Iphone Os MEDIUM 6.8
CVE-2014-4494

Springboard in Apple iOS before 8.1.3 does not properly validate signatures when determining whether to solicit an app trust decision from the user, …

Fix: after 8.1.2
Fix from $1,600 2015-01-30
Ferretcms HIGH 7.5
CVE-2015-1371EPSS 8%

Unrestricted file upload vulnerability in ferretCMS 1.0.4-alpha allows remote administrators to execute arbitrary code by uploading a file with an ex…

No fix yet
Fix from $1,950 2015-01-27
Scalance X 408 Firmware MEDIUM 6.8
CVE-2014-8479

The FTP server on Siemens SCALANCE X-300 switches with firmware before 4.0 and SCALANCE X 408 switches with firmware before 4.0 allows remote authent…

Fix: after 3.9.3
Fix from $1,600 2015-01-21
Vlc Media Player MEDIUM 6.8
CVE-2014-9598EPSS 6%

The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial…

Mitigation only
Fix from $1,600 2015-01-21
Vlc Media Player MEDIUM 6.8
CVE-2014-9597EPSS 7%

The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause…

Mitigation only
Fix from $1,600 2015-01-21
Symantec Critical System Protection HIGH 9.0
CVE-2014-3440

The Agent Control Interface in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security…

Mitigation only
Fix from $1,950 2015-01-21
Ffmpeg HIGH 7.5
CVE-2014-9603

The vmd_decode function in libavcodec/vmdvideo.c in FFmpeg before 2.5.2 does not validate the relationship between a certain length value and the fra…

Fix: after 2.5.1
Fix from $1,950 2015-01-16
Pillow MEDIUM 5.0
CVE-2014-9601

Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is …

Fix: after 2.6.2
Fix from $1,600 2015-01-16
Junos HIGH 7.1
CVE-2014-6382

The Juniper MX Series routers with Junos 13.3R3 through 13.3Rx before 13.3R6, 14.1 before 14.1R4, 14.1X50 before 14.1X50-D70, and 14.2 before 14.2R2,…

Mitigation only
Fix from $1,950 2015-01-16
Adaptive Security Appliance Software MEDIUM 5.7
CVE-2015-0578

Cisco Adaptive Security Appliance (ASA) Software, when a DHCPv6 relay is configured, allows remote attackers to cause a denial of service (device rel…

Mitigation only
Fix from $1,600 2015-01-14
Anyconnect Secure Mobility Client MEDIUM 5.0
CVE-2014-3314

Cisco AnyConnect on Android and OS X does not properly verify the host type, which allows remote attackers to spoof authentication forms and possibly…

Mitigation only
Fix from $1,600 2015-01-14