Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Unified Computing System Central Software MEDIUM 6.8
CVE-2014-0730

Cisco Unified Computing System (UCS) Central Software 1.1 and earlier allows local users to gain privileges via a CLI copy command in a local-mgmt co…

Fix: after 1.1
Fix from $1,600 2014-02-22
Rails MEDIUM 5.0
CVE-2014-0082EPSS 6%

actionpack/lib/action_view/template/text.rb in Action View in Ruby on Rails 3.x before 3.2.17 converts MIME type strings to symbols during use of the…

Fix: after 3.2.16
Fix from $1,600 2014-02-20
Jetro Cockpit Secure Browsing HIGH 9.3
CVE-2014-1861

The client in Jetro COCKPIT Secure Browsing (JCSB) 4.3.1 and 4.3.3 does not validate the FileName element in an RDP_FILE_TRANSFER document, which all…

Mitigation only
Fix from $1,950 2014-02-18
Router Advertisement Daemon MEDIUM 5.0
CVE-2011-3605

The process_rs function in the router advertisement daemon (radvd) before 1.8.2, when UnicastOnly is enabled, allows remote attackers to cause a deni…

Fix: after 1.8.1
Fix from $1,600 2014-02-17
Jboss Operations Network MEDIUM 5.8
CVE-2012-0052

Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 does not check the JON agent key, which allows remote attackers to spoof t…

Fix: after 2.4.1
Fix from $1,600 2014-02-14
Sametime HIGH 7.5
CVE-2013-3983

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not validate URLs in Cookie headers before using them in redire…

Mitigation only
Fix from $1,950 2014-02-14
Sametime MEDIUM 6.8
CVE-2013-3988

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to conduct clickjacking attacks via unspecif…

Mitigation only
Fix from $1,600 2014-02-14
2e Web Option MEDIUM 5.1
CVE-2014-1219

CA 2E Web Option r8.1.2 accepts a predictable substring of a W2E_SSNID session token in place of the entire token, which allows remote attackers to h…

Mitigation only
Fix from $1,600 2014-02-14
Scada Dnp3 Opc Server HIGH 7.1
CVE-2013-2829

MatrikonOPC SCADA DNP3 OPC Server 1.2.2.0 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed DNP3 packe…

Fix: after 1.2.2.0
Fix from $1,950 2014-02-14
.net Framework MEDIUM 5.0
CVE-2014-0253EPSS 39%

Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine TCP connection states, which allows remote attac…

Mitigation only
Fix from $1,600 2014-02-12
.net Framework HIGH 9.3
CVE-2014-0257EPSS 70%

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine whether it is safe to execute a method,…

No fix yet
Fix from $1,950 2014-02-12
Obby MEDIUM 5.8
CVE-2011-4092

obby (aka libobby) does not verify SSL server certificates, which allows remote attackers to spoof servers via an arbitrary certificate.

No fix yet
Fix from $1,600 2014-02-10
Linux Kernel MEDIUM 6.9
CVE-2014-0038EPSS 35%

The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allows local users to gain privil…

Fix: 3.4.79 / 3.10.29+
Fix from $1,600 2014-02-06
Pidgin MEDIUM 5.0
CVE-2013-6482

Pidgin before 2.10.8 allows remote MSN servers to cause a denial of service (NULL pointer dereference and crash) via a crafted (1) SOAP response, (2)…

Fix: after 2.10.7
Fix from $1,600 2014-02-06
Pidgin MEDIUM 5.0
CVE-2014-0020

The IRC protocol plugin in libpurple in Pidgin before 2.10.8 does not validate argument counts, which allows remote IRC servers to cause a denial of …

Fix: after 2.10.7
Fix from $1,600 2014-02-06
Pidgin MEDIUM 5.0
CVE-2012-6152

The Yahoo! protocol plugin in libpurple in Pidgin before 2.10.8 does not properly validate UTF-8 data, which allows remote attackers to cause a denia…

Fix: after 2.10.7
Fix from $1,600 2014-02-06
Pidgin MEDIUM 6.4
CVE-2013-6483

The XMPP protocol plugin in libpurple in Pidgin before 2.10.8 does not properly determine whether the from address in an iq reply is consistent with …

Fix: after 2.10.7
Fix from $1,600 2014-02-06
Pidgin MEDIUM 5.0
CVE-2013-6484

The STUN protocol implementation in libpurple in Pidgin before 2.10.8 allows remote STUN servers to cause a denial of service (out-of-bounds write op…

Fix: after 2.10.7
Fix from $1,600 2014-02-06
Pidgin HIGH 9.3
CVE-2013-6486

gtkutils.c in Pidgin before 2.10.8 on Windows allows user-assisted remote attackers to execute arbitrary programs via a message containing a file: UR…

Fix: after 2.10.7
Fix from $1,950 2014-02-06
Network Satellite MEDIUM 6.5
CVE-2011-1594

A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to ar…

Patch available
Fix from $1,600 2014-02-05
25xxn HIGH 10.0
CVE-2013-6032

cgi-bin/postpf/cgi-bin/dynamic/config/config.html on Lexmark X94x before LC.BR.P142, X85x through LC4.BE.P487, X644 and X646 before LC2.MC.P374, X642…

Mitigation only
Fix from $1,950 2014-02-04
Swc 9100 HIGH 8.3
CVE-2013-7179

The ping functionality in cgi-bin/diagnostic.cgi on Seowon Intech SWC-9100 routers allows remote attackers to execute arbitrary commands via shell me…

Mitigation only
Fix from $1,950 2014-02-04
Fail2ban MEDIUM 5.0
CVE-2013-7176

config/filter.d/postfix.conf in the postfix filter in Fail2ban before 0.8.11 allows remote attackers to trigger the blocking of an arbitrary IP addre…

Fix: after 0.8.10
Fix from $1,600 2014-02-01
Fail2ban MEDIUM 5.0
CVE-2013-7177

config/filter.d/cyrus-imap.conf in the cyrus-imap filter in Fail2ban before 0.8.11 allows remote attackers to trigger the blocking of an arbitrary IP…

Fix: after 0.8.10
Fix from $1,600 2014-02-01
Telvent Sage 3030 Firmware MEDIUM 5.0
CVE-2013-6143

The Schneider Electric Telvent SAGE 3030 RTU with firmware C3413-500-001D3_P4 and C3413-500-001F0_PB allows remote attackers to cause a denial of ser…

Mitigation only
Fix from $1,600 2014-01-31
Mediawiki MEDIUM 6.0
CVE-2014-1610EPSS 43%

MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is enabled, allows remote attac…

No fix yet
Fix from $1,600 2014-01-30
Debian Linux HIGH 7.5
CVE-2013-6650

The StoreBuffer::ExemptPopularPages function in store-buffer.cc in Google V8 before 3.22.24.16, as used in Google Chrome before 32.0.1700.102, allows…

Fix: after 32.0.1700.101
Fix from $1,950 2014-01-28
Global Security Kit HIGH 7.1
CVE-2013-6747

IBM GSKit 7.x before 7.0.4.48 and 8.x before 8.0.50.16, as used in IBM Security Directory Server (ISDS) and Tivoli Directory Server (TDS), allows rem…

Mitigation only
Fix from $1,950 2014-01-27
Yum MEDIUM 5.0
CVE-2014-0022

The installUpdates function in yum-cron/yum-cron.py in yum 3.4.3 and earlier does not properly check the return value of the sigCheckPkg function, wh…

Fix: after 3.4.3
Fix from $1,600 2014-01-26
Openpne HIGH 7.5
CVE-2013-5350

The "Remember me" feature in the opSecurityUser::getRememberLoginCookie function in lib/user/opSecurityUser.class.php in OpenPNE 3.6.13 before 3.6.13…

Mitigation only
Fix from $1,950 2014-01-24