Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Linux Kernel HIGH 10.0
CVE-2014-2523EPSS 10%

net/netfilter/nf_conntrack_proto_dccp.c in the Linux kernel through 3.13.6 uses a DCCP header pointer incorrectly, which allows remote attackers to c…

Fix: 3.2.57 / 3.4.86+
Fix from $1,950 2014-03-24
Domain Technologie Control MEDIUM 6.5
CVE-2011-3195

shared/inc/sql/lists.php in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary commands via shell …

Fix: after 0.32.11
Fix from $1,600 2014-03-21
Hosted Collaboration Solution MEDIUM 5.0
CVE-2014-2121

The Java-based software in Cisco Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (closing of TCP ports) via …

No fix yet
Fix from $1,600 2014-03-19
Hosted Collaboration Solution MEDIUM 5.0
CVE-2014-2122

Memory leak in the GUI in the Impact server in Cisco Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (memory…

Mitigation only
Fix from $1,600 2014-03-19
Ubuntu Linux MEDIUM 6.8
CVE-2014-2241

The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft.c in FreeType before 2.5.3 do not properly check if a sub…

Fix: after 2.5.2
Fix from $1,600 2014-03-18
Chrome HIGH 7.5
CVE-2014-1714

The ScopedClipboardWriter::WritePickledData function in ui/base/clipboard/scoped_clipboard_writer.cc in Google Chrome before 33.0.1750.152 on OS X an…

Fix: 33.0.1750.152 / 33.0.1750.154+
Fix from $1,950 2014-03-16
Owncloud MEDIUM 5.8
CVE-2013-2044

Open redirect vulnerability in the Login Page (index.php) in ownCloud before 5.0.6 allows remote attackers to redirect users to arbitrary web sites a…

Fix: after 5.0.5
Fix from $1,600 2014-03-14
Owncloud Server MEDIUM 5.0
CVE-2013-1939

The HTML\Browser plugin in SabreDAV before 1.6.9, 1.7.x before 1.7.7, and 1.8.x before 1.8.5, as used in ownCloud, when running on Windows, does not …

Fix: 1.6.9 / 1.7.7+
Fix from $1,600 2014-03-14
Tvos MEDIUM 5.8
CVE-2014-1267

The Configuration Profiles component in Apple iOS before 7.1 and Apple TV before 6.1 does not properly evaluate the expiration date of a mobile confi…

Fix: after 7.0.6
Fix from $1,600 2014-03-14
Iphone Os HIGH 7.8
CVE-2014-1271

CoreCapture in Apple iOS before 7.1 and Apple TV before 6.1 does not properly validate IOKit API calls, which allows attackers to cause a denial of s…

Fix: after 7.0.6
Fix from $1,950 2014-03-14
Tvos MEDIUM 5.8
CVE-2014-1273

dyld in Apple iOS before 7.1 and Apple TV before 6.1 allows attackers to bypass code-signing requirements by leveraging use of text-relocation instru…

Fix: after 7.0.6
Fix from $1,600 2014-03-14
Mac Os X MEDIUM 6.6
CVE-2014-0106

Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local…

Fix: after 10.10.4
Fix from $1,600 2014-03-11
Plone MEDIUM 5.8
CVE-2013-4195

Multiple open redirect vulnerabilities in (1) marmoset_patch.py, (2) publish.py, and (3) principiaredirect.py in Plone 2.1 through 4.1, 4.2.x through…

Patch available
Fix from $1,600 2014-03-11
Plone MEDIUM 5.5
CVE-2013-4197

member_portrait.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to modify or delete portr…

Patch available
Fix from $1,600 2014-03-11
MongoDB MEDIUM 6.4
CVE-2012-6619

The default configuration for MongoDB before 2.3.2 does not validate objects, which allows remote authenticated users to cause a denial of service (c…

Fix: after 2.3.1
Fix from $1,600 2014-03-06
Mac Os X MEDIUM 6.4
CVE-2014-2234

A certain Apple patch for OpenSSL in Apple OS X 10.9.2 and earlier uses a Trust Evaluation Agent (TEA) feature without terminating certain TLS/SSL ha…

Fix: after 10.9.2
Fix from $1,600 2014-03-05
Cordova HIGH 7.5
CVE-2012-6637EPSS 9%

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expressions, which allows remote a…

Fix: after 3.3.0
Fix from $1,950 2014-03-03
Android HIGH 9.3
CVE-2013-4710EPSS 43%

Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView class, whi…

Mitigation only
Fix from $1,950 2014-03-03
Ffmpeg MEDIUM 6.8
CVE-2014-2097

The tak_decode_frame function in libavcodec/takdec.c in FFmpeg before 2.1.4 does not properly validate a certain bits-per-sample value, which allows …

Fix: after 2.1.3
Fix from $1,600 2014-03-02
Intrusion Prevention System MEDIUM 6.8
CVE-2014-2103

Cisco Intrusion Prevention System (IPS) Software allows remote attackers to cause a denial of service (MainApp process outage) via malformed SNMP pac…

Mitigation only
Fix from $1,600 2014-02-27
Prime Infrastructure HIGH 9.0
CVE-2014-0679

Cisco Prime Infrastructure 1.2 and 1.3 before 1.3.0.20-2, 1.4 before 1.4.0.45-2, and 2.0 before 2.0.0.0.294-2 allows remote authenticated users to ex…

Mitigation only
Fix from $1,950 2014-02-27
Unified Communications Manager MEDIUM 6.2
CVE-2014-0742

The Certificate Authority Proxy Function (CAPF) CLI implementation in the CSR management feature in Cisco Unified Communications Manager (Unified CM)…

Fix: after 10.0
Fix from $1,600 2014-02-27
Unified Communications Manager MEDIUM 6.8
CVE-2014-0747

The Certificate Authority Proxy Function (CAPF) CLI implementation in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows lo…

Fix: after 10.0
Fix from $1,600 2014-02-27
Mac Os X HIGH 7.5
CVE-2014-1255

Apple Type Services (ATS) in Apple OS X before 10.9.2 does not properly validate calls to the free function, which allows attackers to bypass the App…

Fix: after 10.9.1
Fix from $1,950 2014-02-27
Jboss Enterprise Portal Platform MEDIUM 5.8
CVE-2011-2941

Open redirect vulnerability in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allows remote attackers to redirect users to arbitrary web sites…

Fix: after 5.1.1
Fix from $1,600 2014-02-26
Tomcat MEDIUM 5.8
CVE-2013-4286EPSS 17%

Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is used, does not properly handle c…

Mitigation only
Fix from $1,600 2014-02-26
Genesis32 HIGH 9.3
CVE-2014-0758

An ActiveX control in GenLaunch.htm in ICONICS GENESIS32 8.0, 8.02, 8.04, and 8.05 allows remote attackers to execute arbitrary programs via a crafte…

Mitigation only
Fix from $1,950 2014-02-24
Chrome HIGH 7.5
CVE-2013-6654

The SVGAnimateElement::calculateAnimatedValue function in core/svg/SVGAnimateElement.cpp in Blink, as used in Google Chrome before 33.0.1750.117, doe…

Fix: after 33.0.1750.116
Fix from $1,950 2014-02-24
Ips Sensor Software HIGH 7.1
CVE-2014-0718

The produce-verbose-alert feature in Cisco IPS Software 7.1 before 7.1(8)E4 and 7.2 before 7.2(2)E4 allows remote attackers to cause a denial of serv…

Mitigation only
Fix from $1,950 2014-02-22
Ips Sensor Software HIGH 7.1
CVE-2014-0720

Cisco IPS Software 7.1 before 7.1(8)E4 and 7.2 before 7.2(2)E4 allows remote attackers to cause a denial of service (Analysis Engine process outage) …

Fix: after 7.1
Fix from $1,950 2014-02-22