Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Adobe Air Sdk And Compiler HIGH 10.0
CVE-2015-0301EPSS 5%

Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 1…

Fix: after 15.0.0.356
Fix from $1,950 2015-01-13
Nx Os MEDIUM 5.0
CVE-2015-0582

The High Availability (HA) subsystem in Cisco NX-OS on MDS 9000 devices allows remote attackers to cause a denial of service via crafted traffic, aka…

Mitigation only
Fix from $1,600 2015-01-10
Wireshark MEDIUM 5.0
CVE-2015-0563

epan/dissectors/packet-smtp.c in the SMTP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 uses an incorrect length value for ce…

Mitigation only
Fix from $1,600 2015-01-10
Wireshark MEDIUM 5.0
CVE-2015-0561EPSS 6%

asn1/lpp/lpp.cnf in the LPP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 does not validate a certain index value, which allo…

Mitigation only
Fix from $1,600 2015-01-10
Webex Meetings Server MEDIUM 5.0
CVE-2014-8036

The outlookpa component in Cisco WebEx Meetings Server does not properly validate API input, which allows remote attackers to modify a meeting's invi…

Mitigation only
Fix from $1,600 2015-01-10
TYPO3 HIGH 7.5
CVE-2014-9509

The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, when config.prefixLocalAnchors…

No fix yet
Fix from $1,950 2015-01-04
Hs Tftp Server MEDIUM 5.0
CVE-2011-4720

Hillstone HS TFTP Server 1.3.2 allows remote attackers to cause a denial of service (daemon crash) via a long filename in a (1) RRQ or (2) WRQ operat…

No fix yet
Fix from $1,600 2014-12-28
Cray Linux Environment HIGH 7.2
CVE-2014-0748

apinit on Cray devices with CLE before 4.2.UP02 and 5.x before 5.1.UP00 does not use alpsauth data to validate the UID in a launch message, which all…

Fix: after 4.2
Fix from $1,950 2014-12-27
Chrome HIGH 7.5
CVE-2011-1798

rendering/svg/RenderSVGText.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 does not properly perform a cast of an unspecified variable …

Fix: after 11.0.696.64
Fix from $1,950 2014-12-26
Chrome HIGH 7.5
CVE-2011-1793

rendering/svg/RenderSVGResourceFilter.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of servi…

Fix: after 11.0.696.65
Fix from $1,950 2014-12-26
MongoDB MEDIUM 5.0
CVE-2014-3971

The CmdAuthenticate::_authenticateX509 function in db/commands/authentication_commands.cpp in mongod in MongoDB 2.6.x before 2.6.2 allows remote atta…

Patch available
Fix from $1,600 2014-12-25
Linux HIGH 7.5
CVE-2004-2771EPSS 7%

The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands…

Fix: after 12.5
Fix from $1,950 2014-12-24
Meraki Mr Firmware MEDIUM 5.4
CVE-2014-7994

Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote attackers to execute arbitrary commands by leveraging knowledge of a…

Fix: after 2014-09-24
Fix from $1,600 2014-12-24
Ettercap HIGH 7.5
CVE-2014-9378

Ettercap 0.8.1 does not validate certain return values, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitr…

Patch available
Fix from $1,950 2014-12-19
Tsutaya MEDIUM 6.8
CVE-2014-7241

The TSUTAYA application 5.3 and earlier for Android allows remote attackers to execute arbitrary Java methods via a crafted HTML document.

Fix: after 5.3
Fix from $1,600 2014-12-19
Manageengine Desktop Central HIGH 10.0
CVE-2014-9371EPSS 19%

The NativeAppServlet in ManageEngine Desktop Central MSP before 90075 allows remote attackers to execute arbitrary code via a crafted JSON object.

Fix: after 9.0
Fix from $1,950 2014-12-16
Docker MEDIUM 6.4
CVE-2014-9358

Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via …

Fix: after 1.3.2
Fix from $1,600 2014-12-16
Debian Linux HIGH 7.5
CVE-2014-6052EPSS 7%

The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibVNCServer 0.9.9 and earlier does not check certain malloc return values, which a…

Fix: after 0.9.9
Fix from $1,950 2014-12-15
Enterprise Linux Desktop HIGH 7.5
CVE-2014-7840

The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers to execute arbitrary code via…

Fix: after 2.1.3
Fix from $1,950 2014-12-12
Linux Kernel HIGH 7.5
CVE-2014-4323

The mdp_lut_hw_update function in drivers/video/msm/mdp.c in the MDP display driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (…

Fix: after 3.16.1
Fix from $1,950 2014-12-12
Firefox MEDIUM 6.8
CVE-2014-1594

Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 might allow remote attackers to execute…

Fix: after 33.0
Fix from $1,600 2014-12-11
Firefox MEDIUM 6.8
CVE-2014-1587

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and…

Fix: after 33.0
Fix from $1,600 2014-12-11
Bind MEDIUM 5.4
CVE-2014-8680EPSS 9%

The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial of service (assertion failure and named exit) via…

Mitigation only
Fix from $1,600 2014-12-11
Unified Communications Domain Manager MEDIUM 6.5
CVE-2014-8010

The web framework in Cisco Unified Communications Domain Manager 8 allows remote authenticated administrators to execute arbitrary OS commands via cr…

Mitigation only
Fix from $1,600 2014-12-10
Unified Computing System HIGH 7.2
CVE-2014-8003

Cisco Integrated Management Controller in Cisco Unified Computing System 2.2(2c)A and earlier allows local users to obtain shell access via a crafted…

Fix: after 2.2
Fix from $1,950 2014-12-10
Safari MEDIUM 5.0
CVE-2014-4465

WebKit in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1 allows remote attackers to bypass the Same Origin Policy via crafted Casc…

Fix: after 8.1.2
Fix from $1,600 2014-12-10
Teeworlds MEDIUM 6.4
CVE-2014-9351

engine/server/server.cpp in Teeworlds 0.6.x before 0.6.3 allows remote attackers to read memory and cause a denial of service (crash) via unspecified…

Patch available
Fix from $1,600 2014-12-09
Design Review MEDIUM 6.8
CVE-2014-9268

The AdView.AdViewer.1 ActiveX control in Autodesk Design Review (ADR) before 2013 Hotfix 1 allows remote attackers to execute arbitrary code via a cr…

Fix: after 2013
Fix from $1,600 2014-12-08
Libyaml MEDIUM 5.0
CVE-2014-9130EPSS 13%

scanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to cause a denial…

Patch available
Fix from $1,600 2014-12-08
Debian Linux MEDIUM 5.0
CVE-2012-6656

iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via …

Fix: after 2.16
Fix from $1,600 2014-12-05