Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Adx MEDIUM 5.4
CVE-2013-7306

The OSPF implementation on Brocade routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) pack…

Mitigation only
Fix from $1,600 2014-01-23
Telepresence Video Communication Server Software HIGH 7.1
CVE-2014-0662

The SIP module in Cisco TelePresence Video Communication Server (VCS) before 8.1 allows remote attackers to cause a denial of service (process failur…

Mitigation only
Fix from $1,950 2014-01-22
Nx Os MEDIUM 5.0
CVE-2014-0677

The Label Distribution Protocol (LDP) functionality in Cisco NX-OS allows remote attackers to cause a denial of service (temporary LDP session outage…

Mitigation only
Fix from $1,600 2014-01-22
Telepresence Isdn Gateway Software HIGH 7.1
CVE-2014-0660

Cisco TelePresence ISDN Gateway with software before 2.2(1.92) allows remote attackers to cause a denial of service (D-channel call outage) via a cra…

Fix: after 2.1
Fix from $1,950 2014-01-22
Mediasense MEDIUM 5.8
CVE-2014-0671

Open redirect vulnerability in Cisco MediaSense allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an …

Mitigation only
Fix from $1,600 2014-01-22
Powerconnect 3348 HIGH 10.0
CVE-2013-3594

The SSH service on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote attackers to cause a denial of service (de…

Mitigation only
Fix from $1,950 2014-01-20
Powerconnect 3348 MEDIUM 6.8
CVE-2013-3595

The OpenManage web application 2.5 build 1.19 on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote authenticate…

Mitigation only
Fix from $1,600 2014-01-20
Powerconnect 3348 HIGH 7.8
CVE-2013-3606

The login page in the GoAhead web server on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote attackers to caus…

Mitigation only
Fix from $1,950 2014-01-20
Tomcat HIGH 7.5
CVE-2013-2185EPSS 7%

The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Re…

Fix: after 7.0.39
Fix from $1,950 2014-01-19
Secure Access Control System HIGH 10.0
CVE-2014-0650

The web interface in Cisco Secure Access Control System (ACS) 5.x before 5.4 Patch 3 allows remote attackers to execute arbitrary operating-system co…

Fix: after 5.4.0.46.2
Fix from $1,950 2014-01-16
Libreswan MEDIUM 5.0
CVE-2013-7294

The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (restart) via…

Fix: after 3.6
Fix from $1,600 2014-01-16
Nagios MEDIUM 5.5
CVE-2013-7108EPSS 60%

Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote a…

Fix: after 4.0.2
Fix from $1,600 2014-01-15
Android Msm MEDIUM 6.9
CVE-2013-6123

Multiple array index errors in drivers/media/video/msm/server/msm_cam_server.c in the MSM camera driver for the Linux kernel 3.x, as used in Qualcomm…

Patch available
Fix from $1,600 2014-01-14
Unified Ip Phones 9900 Series Firmware MEDIUM 5.4
CVE-2014-0658

Cisco 9900 Unified IP phones allow remote attackers to cause a denial of service (unregistration) via a crafted SIP header, aka Bug ID CSCul24898.

Mitigation only
Fix from $1,600 2014-01-10
C54apm Firmware MEDIUM 5.8
CVE-2014-1405

Multiple open redirect vulnerabilities on the Conceptronic C54APM access point with runtime code 1.26 allow remote attackers to redirect users to arb…

Mitigation only
Fix from $1,600 2014-01-10
Atlas Ediscovery Process Management MEDIUM 6.4
CVE-2013-6334

IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1.5 and earlier and 6.0.2, and G…

Fix: after 6.0.1.5
Fix from $1,600 2014-01-10
Xen MEDIUM 5.5
CVE-2011-1166

Xen, possibly before 4.0.2, allows local 64-bit PV guests to cause a denial of service (host crash) by specifying user mode execution without user-mo…

Fix: after 4.0.1
Fix from $1,600 2014-01-07
Xen MEDIUM 6.1
CVE-2011-1780

The instruction emulation in Xen 3.0.3 allows local SMP guest users to cause a denial of service (host crash) by replacing the instruction that cause…

Mitigation only
Fix from $1,600 2014-01-07
Opsview MEDIUM 5.8
CVE-2013-7255

Open redirect vulnerability in Opsview before 4.4.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via…

Fix: after 4.4.1
Fix from $1,600 2014-01-03
Linux MEDIUM 5.0
CVE-2013-5211EPSS 98%

The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via …

Fix: 4.2.7+
Fix from $1,600 2014-01-02
I HIGH 8.5
CVE-2013-5385

The OSPF implementation in IBM i 6.1 and 7.1, in z/OS on zSeries servers, and in Networking Operating System (aka NOS, formerly BLADE Operating Syste…

Mitigation only
Fix from $1,950 2014-01-02
Textwrangler MEDIUM 6.4
CVE-2013-3667

The software update mechanism as used in Bare Bones Software Yojimbo before 4.0, TextWrangler before 4.5.3, and BBEdit before 10.5.5 does not properl…

Fix: after 10.5.4
Fix from $1,600 2013-12-31
Hotbox Router Firmware MEDIUM 6.1
CVE-2013-5220

goform/login on the HOT HOTBOX router with software 2.1.11 allows remote attackers to cause a denial of service (device crash) via crafted HTTP POST …

No fix yet
Fix from $1,600 2013-12-30
Ios Xe MEDIUM 5.4
CVE-2013-6981

Cisco IOS XE 3.7S(.1) and earlier allows remote attackers to cause a denial of service (Packet Processor crash) via fragmented MPLS IP packets, aka B…

Fix: after 3.7s
Fix from $1,600 2013-12-28
TYPO3 MEDIUM 5.8
CVE-2013-7079

Open redirect vulnerability in the OpenID extension in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.…

Mitigation only
Fix from $1,600 2013-12-23
Optimizepress MEDIUM 6.8
CVE-2013-7102EPSS 15%

Multiple unrestricted file upload vulnerabilities in (1) media-upload.php, (2) media-upload-lncthumb.php, and (3) media-upload-sq_button.php in lib/a…

Fix: after 1.60
Fix from $1,600 2013-12-23
Qt MEDIUM 5.0
CVE-2013-4549

QXmlSimpleReader in Qt before 5.2 allows context-dependent attackers to cause a denial of service (memory consumption) via an XML Entity Expansion (X…

Fix: after 5.1.0
Fix from $1,600 2013-12-23
Leed MEDIUM 5.0
CVE-2013-2629

Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to bypass authorization via vectors related to the (1) importForm, (2) importF…

Fix: after 1.4
Fix from $1,600 2013-12-23
Orion5 Dnp Master HIGH 7.1
CVE-2013-2821

NovaTech Orion Substation Automation Platform OrionLX DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier and Orion5/Orion5r DNP Master 1.27.38 and …

Mitigation only
Fix from $1,950 2013-12-21
Spss Collaboration And Deployment Services MEDIUM 5.8
CVE-2013-4046

Open redirect vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to …

Mitigation only
Fix from $1,600 2013-12-21