Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Windows 7 HIGH 9.3
CVE-2014-1818EPSS 20%

GDI+ in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Serv…

Patch available
Fix from $1,950 2014-06-11
Unified Communications Manager MEDIUM 5.5
CVE-2014-3292

The Real Time Monitoring Tool (RTMT) implementation in Cisco Unified Communications Manager (Unified CM) allows remote authenticated users to (1) rea…

Mitigation only
Fix from $1,600 2014-06-10
Wireless Lan Controller MEDIUM 5.7
CVE-2014-3291

Cisco Wireless LAN Controller (WLC) devices allow remote attackers to cause a denial of service (NULL pointer dereference and device restart) via a z…

Mitigation only
Fix from $1,600 2014-06-08
Documentum Content Server HIGH 7.5
CVE-2014-2508

EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P14, 7.0 before P15, and 7.1 before P05 allows remote authenticated users to conduct…

Fix: after 6.7
Fix from $1,950 2014-06-08
Documentum Digital Asset Manager HIGH 7.5
CVE-2014-2503

The thumbnail proxy server in EMC Documentum Digital Asset Manager (DAM) 6.5 SP3, 6.5 SP4, 6.5 SP5, and 6.5 SP6 before P13 allows remote attackers to…

No fix yet
Fix from $1,950 2014-06-06
Zenon Dnp3 Ng Driver HIGH 7.1
CVE-2014-2345

COPA-DATA zenon DNP3 NG driver (DNP3 master) 7.10 and 7.11 through 7.11 SP0 build 10238 and zenon DNP3 Process Gateway (DNP3 outstation) 7.11 SP0 bui…

Mitigation only
Fix from $1,950 2014-06-05
TYPO3 MEDIUM 5.0
CVE-2014-3941

TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, 6.1.0 before 6.1.9, and 6.2.0 before 6.2.3 allows remote attackers to have unspe…

Mitigation only
Fix from $1,600 2014-06-03
Fedora MEDIUM 5.0
CVE-2013-2014

OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption and crash) via multiple long req…

Fix: 2013.1+
Fix from $1,600 2014-06-02
Tomcat MEDIUM 5.0
CVE-2014-0095EPSS 8%

java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread c…

Patch available
Fix from $1,600 2014-05-31
Scada Data Gateway MEDIUM 5.0
CVE-2014-2342

Triangle MicroWorks SCADA Data Gateway before 3.00.0635 allows remote attackers to cause a denial of service (excessive data processing) via a crafte…

Fix: after 3.00.0633
Fix from $1,600 2014-05-30
Suricata MEDIUM 5.0
CVE-2013-5919

Suricata before 1.4.6 allows remote attackers to cause a denial of service (crash) via a malformed SSL record.

Fix: after 1.4.5
Fix from $1,600 2014-05-30
Dancer MEDIUM 5.0
CVE-2012-5572

CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie.pm) in Dancer before 1.3114 allows remote attackers to inject arbitrary HTTP hea…

Fix: after 1.3113
Fix from $1,600 2014-05-30
Unified Communications Domain Manager MEDIUM 5.8
CVE-2014-3283

Open redirect vulnerability in Self-Care Client Portal applications in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM)…

Fix: after 9.0
Fix from $1,600 2014-05-29
Wide Area Application Services MEDIUM 5.0
CVE-2014-3285

Cisco Wide Area Application Services (WAAS) 5.3(.5a) and earlier, when SharePoint acceleration is enabled, does not properly parse SharePoint respons…

Fix: after 5.3
Fix from $1,600 2014-05-29
Samba MEDIUM 5.0
CVE-2014-0239EPSS 67%

The internal DNS server in Samba 4.x before 4.0.18 does not check the QR field in the header section of an incoming DNS message before sending a resp…

Fix: 4.0.18 / 4.1.8+
Fix from $1,600 2014-05-28
Dovecot MEDIUM 5.0
CVE-2013-2111

The IMAP functionality in Dovecot before 2.2.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via invalid A…

Fix: after 2.2.1
Fix from $1,600 2014-05-27
Mantisbt MEDIUM 5.0
CVE-2013-1883

Mantis Bug Tracker (aka MantisBT) 1.2.12 before 1.2.15 allows remote attackers to cause a denial of service (resource consumption) via a filter using…

Patch available
Fix from $1,600 2014-05-27
Sametime MEDIUM 5.0
CVE-2013-3980

The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to cause a denial of service (room unusability…

Mitigation only
Fix from $1,600 2014-05-26
Tidal Enterprise Scheduler MEDIUM 6.0
CVE-2014-3272

The Agent in Cisco Tidal Enterprise Scheduler (TES) 6.1 and earlier allows local users to gain privileges via crafted Tidal Job Buffers (TJB) paramet…

Fix: after 6.1
Fix from $1,600 2014-05-26
Websphere Commerce HIGH 7.1
CVE-2014-0943

IBM WebSphere Commerce 6.0 Feature Pack 2 through Feature Pack 5, 7.0.0.0 through 7.0.0.8, and 7.0 Feature Pack 1 through Feature Pack 7 allows remot…

Mitigation only
Fix from $1,950 2014-05-25
Ios Xe MEDIUM 6.1
CVE-2014-3284

Cisco IOS XE on ASR1000 devices, when PPPoE termination is enabled, allows remote attackers to cause a denial of service (device reload) via a malfor…

Mitigation only
Fix from $1,600 2014-05-25
Safari MEDIUM 5.0
CVE-2014-1346

WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, does not properly interpret Unicode encoding, which allows remote attackers to spo…

Fix: after 6.1.3
Fix from $1,600 2014-05-22
Libgadu HIGH 7.5
CVE-2014-3775

libgadu before 1.11.4 and 1.12.0 before 1.12.0-rc3, as used in Pidgin and other products, allows remote Gadu-Gadu file relay servers to cause a denia…

Fix: after 1.11.4
Fix from $1,950 2014-05-22
Websphere Portal MEDIUM 6.8
CVE-2014-0954

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 does not validate …

Patch available
Fix from $1,600 2014-05-22
Debug Interface Access Software Development Kit MEDIUM 6.8
CVE-2014-3802EPSS 11%

msdia.dll in Microsoft Debug Interface Access (DIA) SDK, as distributed in Microsoft Visual Studio before 2013, does not properly validate an unspeci…

Fix: after 2012
Fix from $1,600 2014-05-20
Zenoss MEDIUM 5.8
CVE-2014-3739

Open redirect vulnerability in zport/acl_users/cookieAuthHelper/login_form in Zenoss 4.2.5 allows remote attackers to redirect users to arbitrary web…

No fix yet
Fix from $1,600 2014-05-20
TYPO3 MEDIUM 6.5
CVE-2013-4250

The (1) file upload component and (2) File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.3 do not properly check file exte…

Mitigation only
Fix from $1,600 2014-05-20
iOS MEDIUM 5.0
CVE-2014-3268

Cisco IOS 15.2(4)M4 on Cisco Unified Border Element (CUBE) devices allows remote attackers to cause a denial of service (input-queue consumption and …

Mitigation only
Fix from $1,600 2014-05-20
Ios Xe MEDIUM 6.8
CVE-2014-3269

The SNMP module in Cisco IOS XE 3.5E allows remote authenticated users to cause a denial of service (device reload) by polling frequently, aka Bug ID…

Mitigation only
Fix from $1,600 2014-05-20
Ios Xr MEDIUM 5.0
CVE-2014-3270

The DHCPv6 implementation in Cisco IOS XR allows remote attackers to cause a denial of service (process hang) via a malformed packet, aka Bug ID CSCu…

Mitigation only
Fix from $1,600 2014-05-20