Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Unified Communications Domain Manager MEDIUM 6.8
CVE-2014-3337

The SIP implementation in Cisco Unified Communications Manager (CM) 8.6(.2) and earlier allows remote authenticated users to cause a denial of servic…

Fix: after 8.6
Fix from $1,600 2014-08-12
Substation Server HIGH 7.1
CVE-2014-2357

The GPT library in the Telegyr 8979 Master Protocol application in SUBNET SubSTATION Server 2 before SSNET 2.12 HF18808 allows remote attackers to ca…

Fix: after 2.12
Fix from $1,950 2014-08-11
iOS HIGH 7.8
CVE-2014-3327

The EnergyWise module in Cisco IOS 12.2, 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.2.xXO, 3.3.xSG, 3.4.xSG, and 3.5.xE before 3.5.3E allows remote atta…

Mitigation only
Fix from $1,950 2014-08-11
Resin MEDIUM 5.0
CVE-2014-2966

The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended…

Fix: after 4.0.39
Fix from $1,600 2014-07-26
Sensor Wireless I\/o Module HIGH 7.5
CVE-2014-2360

OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules allow remote attackers to execute arbitrary code via packets that report a high ba…

Mitigation only
Fix from $1,950 2014-07-24
Ios Xr MEDIUM 6.1
CVE-2014-3322

Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of IP packets, which allows remote attackers to cause…

Fix: after 4.3.2
Fix from $1,600 2014-07-24
Drupal MEDIUM 5.0
CVE-2014-5019

The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host head…

Patch available
Fix from $1,600 2014-07-22
Chrome MEDIUM 6.4
CVE-2014-3159

The WebContentsDelegateAndroid::OpenURLFromTab function in components/web_contents_delegate_android/web_contents_delegate_android.cc in Google Chrome…

Fix: after 36.0.1985.106
Fix from $1,600 2014-07-20
Enterprise Mrg MEDIUM 5.0
CVE-2012-2682

Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, allows attackers with certain database privileges to cause a denial of ser…

Mitigation only
Fix from $1,600 2014-07-19
Dpc3010 HIGH 10.0
CVE-2014-3306EPSS 7%

The web server on Cisco DPC3010, DPC3212, DPC3825, DPC3925, DPQ3925, EPC3010, EPC3212, EPC3825, and EPC3925 Wireless Residential Gateway products all…

Mitigation only
Fix from $1,950 2014-07-18
Ios Xr MEDIUM 5.7
CVE-2014-3321

Cisco IOS XR 4.3.4 and earlier on ASR 9000 devices, when bridge-group virtual interface (BVI) routing is enabled, allows remote attackers to cause a …

Fix: after 4.3.4
Fix from $1,600 2014-07-18
Junos HIGH 7.8
CVE-2014-3815

Juniper Junos 12.1X46 before 12.1X46-D20 and 12.1X47 before 12.1X47-D10 on SRX Series devices allows remote attackers to cause a denial of service (f…

Mitigation only
Fix from $1,950 2014-07-11
Junos HIGH 7.8
CVE-2014-3817

Juniper Junos 11.4 before 11.4R12, 12.1X44 before 12.1X44-D32, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, and 12.1X47 before 12.1X47-D10…

Mitigation only
Fix from $1,950 2014-07-11
Junos HIGH 7.8
CVE-2014-3819

Juniper Junos 11.4 before 11.4R12, 12.1 before 12.1R10, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, 12.1X47 b…

Mitigation only
Fix from $1,950 2014-07-11
Junos MEDIUM 5.4
CVE-2014-3822

Juniper Junos 11.4 before 11.4R8, 12.1 before 12.1R5, 12.1X44 before 12.1X44-D20, 12.1X45 before 12.1X45-D15, 12.1X46 before 12.1X46-D10, and 12.1X47…

Mitigation only
Fix from $1,600 2014-07-11
PHP MEDIUM 6.5
CVE-2014-0207EPSS 17%

The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allo…

Fix: 5.3.29 / 5.4.30+
Fix from $1,600 2014-07-09
PHP MEDIUM 6.5
CVE-2014-3480EPSS 11%

The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not p…

Fix: 5.3.29 / 5.4.30+
Fix from $1,600 2014-07-09
Documentum Content Server HIGH 8.2
CVE-2014-2513

EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P15, 7.0 before P15, and 7.1 before P06 does not properly check authorization after …

Fix: after 6.7
Fix from $1,950 2014-07-08
Documentum Content Server HIGH 8.2
CVE-2014-2514

EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P15, 7.0 before P15, and 7.1 before P06 does not properly check authorization and do…

Fix: after 6.7
Fix from $1,950 2014-07-08
Ios Xr MEDIUM 6.4
CVE-2014-3308

Cisco IOS XR on Trident line cards in ASR 9000 devices lacks a static punt policer, which allows remote attackers to cause a denial of service (CPU c…

Mitigation only
Fix from $1,600 2014-07-07
Linux Kernel MEDIUM 5.0
CVE-2014-4611EPSS 8%

Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decomp…

Fix: 3.15.2+
Fix from $1,600 2014-07-03
Sx 2000wg Firmware MEDIUM 5.0
CVE-2014-3889

silex SX-2000WG devices with firmware before 1.5.4 allow remote attackers to cause a denial of service (connectivity outage) via crafted data in the …

Fix: after 1.5.3
Fix from $1,600 2014-07-02
Sx 2000wg Firmware MEDIUM 5.0
CVE-2014-3890

silex SX-2000WG devices with firmware before 1.5.4 allow remote attackers to cause a denial of service (connectivity outage) via a crafted IP packet,…

Fix: after 1.5.3
Fix from $1,600 2014-07-02
Debian Linux MEDIUM 5.0
CVE-2014-4617

The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of…

Mitigation only
Fix from $1,600 2014-06-25
iOS MEDIUM 6.8
CVE-2014-3299

Cisco IOS allows remote authenticated users to cause a denial of service (device reload) via malformed IPsec packets, aka Bug ID CSCui79745.

Mitigation only
Fix from $1,600 2014-06-25
Ichitaro HIGH 7.6
CVE-2014-2003

JustSystems JUST Online Update, as used in Ichitaro through 2014 and other products, does not properly validate signatures of update modules, which a…

Fix: after 2014
Fix from $1,950 2014-06-16
Screenos HIGH 7.8
CVE-2014-3814

The Juniper Networks NetScreen Firewall devices with ScreenOS before 6.3r17, when configured to use the internal DNS lookup client, allows remote att…

Fix: after 6.3.0
Fix from $1,950 2014-06-13
Monkey MEDIUM 5.0
CVE-2013-2163

Monkey HTTP Daemon (monkeyd) before 1.2.2 allows remote attackers to cause a denial of service (infinite loop) via an offset equal to the file size i…

Fix: after 1.2.1
Fix from $1,600 2014-06-13
Bind MEDIUM 5.0
CVE-2014-3859EPSS 7%

libdns in ISC BIND 9.10.0 before P2 does not properly handle EDNS options, which allows remote attackers to cause a denial of service (REQUIRE assert…

Mitigation only
Fix from $1,600 2014-06-13
Firefox MEDIUM 5.0
CVE-2014-1539

Mozilla Firefox before 30.0 and Thunderbird through 24.6 on OS X do not ensure visibility of the cursor after interaction with a Flash object and a D…

Fix: after 29.0.1
Fix from $1,600 2014-06-11