Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Filevista MEDIUM 6.5
CVE-2014-8789

GleamTech FileVista before 6.1 allows remote authenticated users to create arbitrary files and possibly execute arbitrary code via a crafted path in …

Fix: after 6.0.9
Fix from $1,600 2014-12-02
Tuleap HIGH 9.3
CVE-2014-7178EPSS 5%

Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP…

Fix: after 7.5.99.5
Fix from $1,950 2014-11-28
Fedora HIGH 7.5
CVE-2014-9093

LibreOffice before 4.3.5 allows remote attackers to cause a denial of service (invalid write operation and crash) and possibly execute arbitrary code…

Fix: after 4.3.4
Fix from $1,950 2014-11-26
Ubuntu Linux MEDIUM 6.4
CVE-2014-7142EPSS 25%

The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (crash) via a crafted (1) I…

Mitigation only
Fix from $1,600 2014-11-26
Openswan MEDIUM 5.0
CVE-2014-2037

Openswan 2.6.40 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack ex…

Mitigation only
Fix from $1,600 2014-11-26
WordPress MEDIUM 6.4
CVE-2014-9038

wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct serve…

Fix: after 3.7.4
Fix from $1,600 2014-11-25
Analyzer HIGH 9.0
CVE-2014-8420EPSS 24%

The ViewPoint web application in Dell SonicWALL Global Management System (GMS) before 7.2 SP2, SonicWALL Analyzer before 7.2 SP2, and SonicWALL UMA b…

Mitigation only
Fix from $1,950 2014-11-25
Resteasy MEDIUM 6.4
CVE-2014-7839

DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which …

Mitigation only
Fix from $1,600 2014-11-25
Debian Linux HIGH 7.1
CVE-2014-9030

The do_mmu_update function in arch/x86/mm.c in Xen 3.2.x through 4.4.x does not properly manage page references, which allows remote domains to cause…

Patch available
Fix from $1,950 2014-11-24
Asterisk MEDIUM 5.0
CVE-2014-8416

Use-after-free vulnerability in the PJSIP channel driver in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1, when using the res_pjsip_…

Fix: 12.7.1 / 13.0.1+
Fix from $1,600 2014-11-24
Asterisk MEDIUM 5.0
CVE-2014-8415

Race condition in the chan_pjsip channel driver in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1 allows remote attackers to cause a …

Fix: 12.7.1 / 13.0.1+
Fix from $1,600 2014-11-24
Moodle MEDIUM 5.0
CVE-2014-9060

The LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not properly restrict the parameters use…

Fix: after 2.4.11
Fix from $1,600 2014-11-24
Debian Linux MEDIUM 5.4
CVE-2014-8594

The do_mmu_update function in arch/x86/mm.c in Xen 4.x through 4.4.x does not properly restrict updates to only PV page tables, which allows remote P…

Patch available
Fix from $1,600 2014-11-19
Chrome MEDIUM 5.0
CVE-2014-7899

Google Chrome before 38.0.2125.101 allows remote attackers to spoof the address bar by placing a blob: substring at the beginning of the URL, followe…

Fix: after 38.0.2125.7
Fix from $1,600 2014-11-19
Mantisbt HIGH 7.5
CVE-2014-7146EPSS 51%

The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) description field o…

Patch available
Fix from $1,950 2014-11-18
Iphone Os HIGH 9.3
CVE-2014-4461

The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDataQueue object metadata, which allows attackers t…

Fix: after 10.10.1
Fix from $1,950 2014-11-18
Debian Linux MEDIUM 5.0
CVE-2014-7815

The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value.

Mitigation only
Fix from $1,600 2014-11-14
.net Framework HIGH 9.3
CVE-2014-4149EPSS 21%

Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly perform TypeFilterLevel checks, which allows remote…

Mitigation only
Fix from $1,950 2014-11-11
Linux Kernel HIGH 7.5
CVE-2014-3673EPSS 7%

The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF…

Fix: 3.2.64 / 3.4.107+
Fix from $1,950 2014-11-10
B200 M3 MEDIUM 6.8
CVE-2014-7989

Cisco Unified Computing System on B-Series blade servers allows local users to gain shell privileges via a crafted (1) ping6 or (2) traceroute6 comma…

Mitigation only
Fix from $1,600 2014-11-07
Ios Xe MEDIUM 6.8
CVE-2014-7990

Cisco IOS XE 3.5E and earlier on WS-C3850, WS-C3860, and AIR-CT5760 devices does not properly parse the "request system shell" challenge response, wh…

Fix: after 3.5e
Fix from $1,600 2014-11-07
Rv180 Firmware MEDIUM 5.0
CVE-2014-2179

The Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote attac…

Fix: after 1.0.5.8
Fix from $1,600 2014-11-07
Netweaver MEDIUM 5.0
CVE-2014-0995EPSS 10%

The Standalone Enqueue Server in SAP Netweaver 7.20, 7.01, and earlier allows remote attackers to cause a denial of service (uncontrolled recursion a…

Fix: after 7.01
Fix from $1,600 2014-11-06
Ubuntu Linux HIGH 7.5
CVE-2014-8543

libavcodec/mmvideo.c in FFmpeg before 2.4.2 does not consider all lines of HHV Intra blocks during validation of image height, which allows remote at…

Fix: after 2.4.1
Fix from $1,950 2014-11-05
Ubuntu Linux HIGH 7.5
CVE-2014-8544

libavcodec/tiff.c in FFmpeg before 2.4.2 does not properly validate bits-per-pixel fields, which allows remote attackers to cause a denial of service…

Fix: after 2.4.1
Fix from $1,950 2014-11-05
Freeipa MEDIUM 5.0
CVE-2013-0336

The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_extop.c in the directory server (dirsrv) in FreeIPA before 3.2.0 allows…

Fix: after 3.1.5
Fix from $1,600 2014-11-03
Advanced Package Tool MEDIUM 6.8
CVE-2014-0488

APT before 1.0.9 does not "invalidate repository data" when moving from an unauthenticated to authenticated state, which allows remote attackers to h…

Patch available
Fix from $1,600 2014-11-03
Advanced Package Tool HIGH 7.5
CVE-2014-0489

APT before 1.0.9, when the Acquire::GzipIndexes option is enabled, does not validate checksums, which allows remote attackers to execute arbitrary co…

Patch available
Fix from $1,950 2014-11-03
Advanced Package Tool HIGH 7.5
CVE-2014-0490

The apt-get download command in APT before 1.0.9 does not properly validate signatures for packages, which allows remote attackers to execute arbitra…

Fix: after 1.0.8
Fix from $1,950 2014-11-03
Bundler MEDIUM 5.0
CVE-2013-0334

Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same …

Fix: 1.7.0+
Fix from $1,600 2014-10-31