Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Ioquake3 Engine HIGH 7.8
CVE-2010-5077

server/sv_main.c in Quake3 Arena, as used in ioquake3 before r1762, OpenArena, Tremulous, and other products, allows remote attackers to cause a deni…

Mitigation only
Fix from $1,950 2014-10-27
FreeBSD MEDIUM 5.0
CVE-2014-3955

routed in FreeBSD 8.4 through 10.1-RC2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an RIP request fr…

Patch available
Fix from $1,600 2014-10-27
Cobbler MEDIUM 6.8
CVE-2011-4953

The set_mgmt_parameters function in item.py in cobbler before 2.2.2 allows context-dependent attackers to execute arbitrary code via vectors related …

Fix: after 2.2.1
Fix from $1,600 2014-10-27
Cloudforms 3.0 Management Engine MEDIUM 5.0
CVE-2014-0136

The (1) get and (2) log methods in the AgentController in Red Hat CloudForms 3.0 Management Engine (CFME) 5.x allow remote attackers to insert arbitr…

Fix: after 5.2.5.3
Fix from $1,600 2014-10-27
Piston HIGH 7.5
CVE-2011-4103

emitters.py in Django Piston before 0.2.3 and 0.2.x before 0.2.2.1 does not properly deserialize YAML data, which allows remote attackers to execute …

Fix: after 0.2.2.0
Fix from $1,950 2014-10-27
Tastypie HIGH 7.5
CVE-2011-4104

The from_yaml method in serializers.py in Django Tastypie before 0.9.10 does not properly deserialize YAML data, which allows remote attackers to exe…

Fix: after 0.9.9
Fix from $1,950 2014-10-27
Bottle MEDIUM 6.8
CVE-2014-3137

Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to …

Patch available
Fix from $1,600 2014-10-25
Python Gnupg HIGH 7.5
CVE-2014-1927

The shell_quote function in python-gnupg 0.3.5 does not properly quote strings, which allows context-dependent attackers to execute arbitrary code vi…

No fix yet
Fix from $1,950 2014-10-25
Tririga Application Platform HIGH 7.5
CVE-2014-4840

IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote attacke…

Mitigation only
Fix from $1,950 2014-10-19
Qradar Security Information And Event Manager MEDIUM 6.5
CVE-2014-4833

IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allows remote authenticated users to gain privileges via invalid input.

No fix yet
Fix from $1,600 2014-10-19
Websphere Application Server MEDIUM 5.0
CVE-2014-3021

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 does not properly handle HTTP headers, which …

Mitigation only
Fix from $1,600 2014-10-19
Mac Os X HIGH 7.8
CVE-2014-4443

Apple OS X before 10.10 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted ASN.1 data.

Fix: after 10.9.5
Fix from $1,950 2014-10-18
Mac Os X MEDIUM 5.0
CVE-2014-4417

Safari in Apple OS X before 10.10 allows remote attackers to cause a denial of service (universal Push Notification outage) via a web site that trigg…

Fix: after 10.9.5
Fix from $1,600 2014-10-18
Enterprise Virtualization Manager MEDIUM 6.5
CVE-2014-3573

The oVirt Engine backend module, as used in Red Hat Enterprise Virtualization Manager before 3.4.2, uses an "insecure DocumentBuilderFactory," which …

Fix: after 3.4.1
Fix from $1,600 2014-10-18
Seeddms MEDIUM 5.1
CVE-2014-2278

Unrestricted file upload vulnerability in op/op.AddFile2.php in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allows remote attackers to execute …

Fix: after 4.3.3
Fix from $1,600 2014-10-17
Network Camera View MEDIUM 6.8
CVE-2014-8755

Panasonic Network Camera View 3 and 4 allows remote attackers to execute arbitrary code via a crafted page, which triggers an invalid pointer derefer…

Patch available
Fix from $1,600 2014-10-17
Businessobjects HIGH 7.1
CVE-2014-8310

The CMS CORBA listener in SAP BusinessObjects BI Edge 4.0 allows remote attackers to cause a denial of service (server shutdown) via crafted OSCAFact…

No fix yet
Fix from $1,950 2014-10-16
Ubuntu Linux MEDIUM 6.8
CVE-2014-3686

wpa_supplicant and hostapd 0.7.2 through 2.2, when running with certain configurations and using wpa_cli or hostapd_cli with action scripts, allows r…

Mitigation only
Fix from $1,600 2014-10-16
Office HIGH 9.3
CVE-2014-4117EPSS 17%

Microsoft Office 2007 SP3, Word 2007 SP3, Office 2010 SP1 and SP2, Word 2010 SP1 and SP2, Office for Mac 2011, Office Compatibility Pack SP3, Word Au…

Mitigation only
Fix from $1,950 2014-10-15
Junos MEDIUM 6.8
CVE-2014-3825

The Juniper SRX Series devices with Junos 11.4 before 11.4R12-S4, 12.1X44 before 12.1X44-D40, 12.1X45 before 12.1X45-D30, 12.1X46 before 12.1X46-D25,…

Mitigation only
Fix from $1,600 2014-10-14
Adaptive Security Appliance Software MEDIUM 6.8
CVE-2014-3390

The Virtual Network Management Center (VNMC) policy implementation in Cisco ASA Software 8.7 before 8.7(1.14), 9.2 before 9.2(2.8), and 9.3 before 9.…

Mitigation only
Fix from $1,600 2014-10-10
Adaptive Security Appliance Software MEDIUM 6.8
CVE-2014-3391

Untrusted search path vulnerability in Cisco ASA Software 8.x before 8.4(3), 8.5, and 8.7 before 8.7(1.13) allows local users to gain privileges by p…

Mitigation only
Fix from $1,600 2014-10-10
Vyatta 5400 Vrouter Software HIGH 7.2
CVE-2014-4870

/opt/vyatta/bin/sudo-users/vyatta-clear-dhcp-lease.pl on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 does not properly validate param…

Mitigation only
Fix from $1,950 2014-10-07
Mac Os X HIGH 9.3
CVE-2014-7861

The IOHIDSecurePromptClient function in Apple OS X does not properly validate pointer values, which allows remote attackers to execute arbitrary code…

Mitigation only
Fix from $1,950 2014-10-05
Sbg3300 N Firmware MEDIUM 5.0
CVE-2014-7278

The login page on the ZyXEL SBG-3300 Security Gateway with firmware 1.00(AADY.4)C0 and earlier allows remote attackers to cause a denial of service (…

Fix: after 1.00
Fix from $1,600 2014-10-04
Ab Micrologix Controller HIGH 7.1
CVE-2014-5410

The DNP3 feature on Rockwell Automation Allen-Bradley MicroLogix 1400 1766-Lxxxxx A FRN controllers 7 and earlier and 1400 1766-Lxxxxx B FRN controll…

Mitigation only
Fix from $1,950 2014-10-03
News HIGH 7.5
CVE-2014-6290

The News (tt_news) extension before 3.5.2 for TYPO3 allows remote attackers to have unspecified impact via vectors related to an "insecure unserializ…

Fix: after 3.5.1
Fix from $1,950 2014-10-03
Webex Meetings Server MEDIUM 5.0
CVE-2014-3395

Cisco WebEx Meetings Server (WMS) 2.5 allows remote attackers to trigger the download of arbitrary files via a crafted URL, aka Bug ID CSCup10343.

Mitigation only
Fix from $1,600 2014-09-30
Ekiga MEDIUM 5.0
CVE-2012-5621

lib/engine/components/opal/opal-call.cpp in ekiga before 4.0.0 allows remote attackers to cause a denial of service (crash) via an OPAL connection wi…

Fix: after 3.9.90
Fix from $1,600 2014-09-29
iOS HIGH 7.8
CVE-2014-3354

Cisco IOS 12.0, 12.2, 12.4, 15.0, 15.1, 15.2, and 15.3 and IOS XE 2.x and 3.x before 3.7.4S; 3.2.xSE and 3.3.xSE before 3.3.2SE; 3.3.xSG and 3.4.xSG …

Mitigation only
Fix from $1,950 2014-09-25