Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Zarafa MEDIUM 5.0
CVE-2014-0037

The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 5.00 before 7.1.8 beta2 allows remote attackers to cause a denial of ser…

Mitigation only
Fix from $1,600 2014-04-28
Zarafa MEDIUM 5.0
CVE-2014-0079

The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 7.1.8, 6.20.0, and earlier, when using certain build conditions, allows …

Fix: after 6.20
Fix from $1,600 2014-04-28
Openjpeg MEDIUM 5.0
CVE-2013-6053

OpenJPEG 1.5.1 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a heap-based out-of-bounds read.

No fix yet
Fix from $1,600 2014-04-27
Openjpeg MEDIUM 6.4
CVE-2013-6887

OpenJPEG 1.5.1 allows remote attackers to cause a denial of service via unspecified vectors that trigger NULL pointer dereferences, division-by-zero,…

Mitigation only
Fix from $1,600 2014-04-27
Icehouse MEDIUM 6.0
CVE-2014-0162

The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote …

Mitigation only
Fix from $1,600 2014-04-27
Chrome HIGH 7.5
CVE-2014-1733

The PointerCompare function in codegen.cc in Seccomp-BPF, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 …

Fix: 34.0.1847.131 / 34.0.1847.132+
Fix from $1,950 2014-04-26
Cm3 Acora Content Management System MEDIUM 5.8
CVE-2013-4723

Open redirect vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions allows remote a…

No fix yet
Fix from $1,600 2014-04-25
Ios Xe MEDIUM 6.1
CVE-2012-5723

Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) vi…

Fix: after 3.7s
Fix from $1,600 2014-04-24
Rsync HIGH 7.8
CVE-2014-2855

The check_secret function in authenticate.c in rsync 3.1.0 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU co…

Fix: after 3.1.0
Fix from $1,950 2014-04-23
iOS MEDIUM 6.1
CVE-2012-1366

Cisco IOS before 15.1(1)SY on ASR 1000 devices, when Multicast Listener Discovery (MLD) tracking is enabled for IPv6, allows remote attackers to caus…

Mitigation only
Fix from $1,600 2014-04-23
iOS MEDIUM 5.7
CVE-2012-3062

Cisco IOS before 15.1(1)SY, when Multicast Listener Discovery (MLD) snooping is enabled, allows remote attackers to cause a denial of service (CPU co…

Mitigation only
Fix from $1,600 2014-04-23
iOS MEDIUM 6.8
CVE-2012-5017

Cisco IOS before 15.1(1)SY1 allows remote authenticated users to cause a denial of service (device reload) by establishing a VPN session and then sen…

Fix: after 15.1
Fix from $1,600 2014-04-23
Mac Os X MEDIUM 5.0
CVE-2014-1316

Heimdal, as used in Apple OS X through 10.9.2, allows remote attackers to cause a denial of service (abort and daemon exit) via ASN.1 data encountere…

Fix: after 10.9.2
Fix from $1,600 2014-04-23
Mac Os X HIGH 10.0
CVE-2014-1318

The Intel Graphics Driver in Apple OS X through 10.9.2 does not properly validate a certain pointer, which allows attackers to execute arbitrary code…

Fix: after 10.9.2
Fix from $1,950 2014-04-23
Cyassl MEDIUM 5.0
CVE-2014-2899

wolfSSL CyaSSL before 2.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a request for the peer certificat…

Fix: after 2.9.0
Fix from $1,600 2014-04-22
Python HIGH 7.1
CVE-2013-7338EPSS 5%

Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a file size value larger than th…

Fix: after 10.10.4
Fix from $1,950 2014-04-22
Winscp MEDIUM 5.8
CVE-2014-2735

WinSCP before 5.5.3, when FTP with TLS is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or s…

Fix: after 5.5.2
Fix from $1,600 2014-04-22
Vtiger Crm MEDIUM 6.4
CVE-2014-2269EPSS 16%

modules/Users/ForgotPassword.php in vTiger 6.0 before Security Patch 2 allows remote attackers to reset the password for arbitrary users via a reques…

Patch available
Fix from $1,600 2014-04-22
Pimcore MEDIUM 6.4
CVE-2014-2922

The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.1.0 does not properly handle an obje…

No fix yet
Fix from $1,600 2014-04-21
Cns Network Registrar MEDIUM 5.0
CVE-2014-2155

The DHCPv6 server module in Cisco CNS Network Registrar 7.1 allows remote attackers to cause a denial of service (daemon reload) via a malformed DHCP…

Mitigation only
Fix from $1,600 2014-04-19
Sinema Server MEDIUM 5.0
CVE-2014-2733

Siemens SINEMA Server before 12 SP1 allows remote attackers to cause a denial of service (web-interface outage) via crafted HTTP requests to port (1)…

Fix: after 12.0
Fix from $1,600 2014-04-19
Fedora HIGH 7.5
CVE-2014-2286EPSS 16%

main/http.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.x before 1.8.15…

Patch available
Fix from $1,950 2014-04-18
Identity Manager MEDIUM 5.8
CVE-2014-2880EPSS 8%

Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows re…

No fix yet
Fix from $1,600 2014-04-17
Net Snmp MEDIUM 5.0
CVE-2014-2310

The AgentX subagent in Net-SNMP before 5.4.4 allows remote attackers to cause a denial of service (hang) by sending a multi-object request with an Ob…

Fix: after 5.4
Fix from $1,600 2014-04-17
Network Satellite MEDIUM 6.5
CVE-2013-2143EPSS 48%

The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows r…

Fix: after 1.5.0-14
Fix from $1,600 2014-04-17
Eucalyptus MEDIUM 5.0
CVE-2013-4768

The web services APIs in Eucalyptus 2.0 through 3.4.1 allow remote attackers to cause a denial of service via vectors related to the "network connect…

Mitigation only
Fix from $1,600 2014-04-16
Network Proxy MEDIUM 6.0
CVE-2010-2236

The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and …

Fix: after 2.1.147-1
Fix from $1,600 2014-04-15
Linux Kernel MEDIUM 5.5
CVE-2014-0155

The ioapic_deliver function in virt/kvm/ioapic.c in the Linux kernel through 3.14.1 does not properly validate the kvm_irq_delivery_to_apic return va…

Fix: 3.14.1+
Fix from $1,600 2014-04-14
Junos HIGH 7.1
CVE-2014-2714

The Enhanced Web Filtering (EWF) in Juniper Junos before 10.4R15, 11.4 before 11.4R9, 12.1 before 12.1R7, 12.1X44 before 12.1X44-D20, 12.1X45 before …

Mitigation only
Fix from $1,950 2014-04-14
Openafs MEDIUM 5.0
CVE-2014-2852

OpenAFS before 1.6.7 delays the listen thread when an RXS_CheckResponse fails, which allows remote attackers to cause a denial of service (performanc…

Fix: after 1.6.6
Fix from $1,600 2014-04-14