Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Squid MEDIUM 5.0
CVE-2014-0128EPSS 33%

Squid 3.1 before 3.3.12 and 3.4 before 3.4.4, when SSL-Bump is enabled, allows remote attackers to cause a denial of service (assertion failure) via …

Mitigation only
Fix from $1,600 2014-04-14
Pi Interface HIGH 7.1
CVE-2013-2809

The DNP Master Driver in the OSIsoft PI Interface before 3.1.2.54 for DNP3 allows remote attackers to cause a denial of service (interface shutdown) …

Fix: after 3.1.2
Fix from $1,950 2014-04-12
Vsphere Client HIGH 9.3
CVE-2014-1209

VMware vSphere Client 4.0, 4.1, 5.0 before Update 3, and 5.1 before Update 2 does not properly validate updates to Client files, which allows remote …

Mitigation only
Fix from $1,950 2014-04-11
Redmine MEDIUM 5.8
CVE-2014-1985

Open redirect vulnerability in the redirect_back_or_default function in app/controllers/application_controller.rb in Redmine before 2.4.5 and 2.5.x b…

Fix: after 2.4.4
Fix from $1,600 2014-04-11
Metronome HIGH 7.8
CVE-2014-2744

plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compression while a session is una…

Fix: after 3.4
Fix from $1,950 2014-04-11
Openmanage Server Administrator MEDIUM 5.8
CVE-2013-0740

Open redirect vulnerability in Dell OpenManage Server Administrator (OMSA) before 7.3.0 allows remote attackers to redirect users to arbitrary web si…

Fix: after 7.2.0
Fix from $1,600 2014-04-10
Adaptive Security Appliance Software HIGH 7.1
CVE-2014-2129

The SIP inspection engine in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.48), 8.4 before 8.4(6.5), 9.0 before 9.0(3.1), and 9.1…

Mitigation only
Fix from $1,950 2014-04-10
Adaptive Security Appliance Software HIGH 8.5
CVE-2014-2127EPSS 11%

Cisco Adaptive Security Appliance (ASA) Software 8.x before 8.2(5.48), 8.3 before 8.3(2.40), 8.4 before 8.4(7.9), 8.6 before 8.6(1.13), 9.0 before 9.…

Mitigation only
Fix from $1,950 2014-04-10
Chrome MEDIUM 5.0
CVE-2014-1725

The base64DecodeInternal function in wtf/text/Base64.cpp in Blink, as used in Google Chrome before 34.0.1847.116, does not properly handle string dat…

Fix: after 34.0.1847.115
Fix from $1,600 2014-04-09
Chrome HIGH 7.5
CVE-2014-1723

The UnescapeURLWithOffsetsImpl function in net/base/escape.cc in Google Chrome before 34.0.1847.116 does not properly handle bidirectional Internatio…

Fix: after 34.0.1847.115
Fix from $1,950 2014-04-09
Fedora MEDIUM 6.9
CVE-2012-2095

The SetWiredProperty function in the D-Bus interface in WICD before 1.7.2 allows local users to write arbitrary configuration settings and gain privi…

Fix: after 1.7.1
Fix from $1,600 2014-04-07
Ios Xr MEDIUM 6.1
CVE-2014-2144

Cisco IOS XR does not properly throttle ICMPv6 redirect packets, which allows remote attackers to cause a denial of service (IPv4 and IPv6 transit ou…

Mitigation only
Fix from $1,600 2014-04-05
Safari MEDIUM 5.0
CVE-2014-1297

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, does not properly validate WebProcess IPC messages, which allows remote attackers …

Fix: after 6.1.2
Fix from $1,600 2014-04-02
P 660h 61 HIGH 7.8
CVE-2013-3588

The web management interface on Zyxel P660 devices allows remote attackers to cause a denial of service (reboot) via a flood of TCP SYN packets.

Mitigation only
Fix from $1,950 2014-04-02
Vplex Geosynchrony HIGH 7.7
CVE-2014-0633

The GUI in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not properly validate session-timeout values, which might make it easier for remote att…

Mitigation only
Fix from $1,950 2014-04-01
Vplex Geosynchrony MEDIUM 6.0
CVE-2014-0634

EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it eas…

Mitigation only
Fix from $1,600 2014-04-01
Superuser HIGH 10.0
CVE-2013-6769

The CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android allows attackers to gain privileges via shell metacharacters in the -c optio…

Mitigation only
Fix from $1,950 2014-03-31
Couchdb MEDIUM 5.0
CVE-2014-2668EPSS 22%

Apache CouchDB 1.5.0 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via the count parameter to /_uuids.

Fix: after 1.5.0
Fix from $1,600 2014-03-28
Wp Symposium MEDIUM 5.8
CVE-2013-2694

Open redirect vulnerability in invite.php in the WP Symposium plugin 13.04 for WordPress allows remote attackers to redirect users to arbitrary web s…

Mitigation only
Fix from $1,600 2014-03-28
iOS HIGH 7.8
CVE-2014-2108

Cisco IOS 12.2 and 15.0 through 15.3 and IOS XE 3.2 through 3.7 before 3.7.5S and 3.8 through 3.10 before 3.10.1S allow remote attackers to cause a d…

Mitigation only
Fix from $1,950 2014-03-27
iOS HIGH 7.8
CVE-2014-2109

The TCP Input module in Cisco IOS 12.2 through 12.4 and 15.0 through 15.4, when NAT is used, allows remote attackers to cause a denial of service (me…

Mitigation only
Fix from $1,950 2014-03-27
iOS HIGH 7.1
CVE-2014-2111

The Application Layer Gateway (ALG) module in Cisco IOS 12.2 through 12.4 and 15.0 through 15.4, when NAT is used, allows remote attackers to cause a…

Mitigation only
Fix from $1,950 2014-03-27
iOS HIGH 7.8
CVE-2014-2112

The SSL VPN (aka WebVPN) feature in Cisco IOS 15.1 through 15.4 allows remote attackers to cause a denial of service (memory consumption) via crafted…

Mitigation only
Fix from $1,950 2014-03-27
iOS HIGH 7.8
CVE-2014-2113

Cisco IOS 15.1 through 15.3 and IOS XE 3.3 and 3.5 before 3.5.2E; 3.7 before 3.7.5S; and 3.8, 3.9, and 3.10 before 3.10.2S allow remote attackers to …

Mitigation only
Fix from $1,950 2014-03-27
iOS HIGH 7.8
CVE-2014-2106

Cisco IOS 15.3M before 15.3(3)M2 and IOS XE 3.10.xS before 3.10.2S allow remote attackers to cause a denial of service (device reload) via crafted SI…

Mitigation only
Fix from $1,950 2014-03-27
iOS HIGH 7.1
CVE-2014-2107

Cisco IOS 12.2 and 15.0 through 15.3, when used with the Kailash FPGA before 2.6 on RSP720-3C-10GE and RSP720-3CXL-10GE devices, allows remote attack…

Mitigation only
Fix from $1,950 2014-03-27
Openssh MEDIUM 6.5
CVE-2014-2653

The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR c…

Fix: after 6.6
Fix from $1,600 2014-03-27
Security Appscan HIGH 7.6
CVE-2014-0904

The update process in IBM Security AppScan Standard 7.9 through 8.8 does not require integrity checks of downloaded files, which allows remote attack…

Mitigation only
Fix from $1,950 2014-03-26
Bsafe Micro Edition Suite MEDIUM 5.0
CVE-2014-0628

The server in EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.5 does not properly process certificate chains, which allows remote attackers …

Mitigation only
Fix from $1,600 2014-03-25
Net Snmp MEDIUM 5.0
CVE-2014-2284

The Linux implementation of the ICMP-MIB in Net-SNMP 5.5 before 5.5.2.1, 5.6.x before 5.6.2.1, and 5.7.x before 5.7.2.1 does not properly validate in…

Mitigation only
Fix from $1,600 2014-03-24