Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Wireshark MEDIUM 5.0
CVE-2013-7112

The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.12 and 1.10.x before 1.10.4 does n…

Patch available
Fix from $1,600 2013-12-19
Wireshark MEDIUM 5.0
CVE-2013-7113

epan/dissectors/packet-bssgp.c in the BSSGP dissector in Wireshark 1.10.x before 1.10.4 incorrectly relies on a global variable, which allows remote …

Patch available
Fix from $1,600 2013-12-19
Cisco Ons 15454 System Software MEDIUM 5.0
CVE-2013-6701

The tNetTaskLimit process on the Transport Node Controller (TNC) on Cisco ONS 15454 devices with software 9.6 and earlier does not properly prioritiz…

Mitigation only
Fix from $1,600 2013-12-18
Dnp3 Master Opc Server HIGH 7.1
CVE-2013-2814

Cooper Power Systems Cybectec DNP3 Master OPC Server allows remote attackers to cause a denial of service (unhandled exception and process crash) via…

No fix yet
Fix from $1,950 2013-12-17
Smp 16 Gateway \(data Concentrator\) HIGH 7.1
CVE-2013-2813

The DNP3 component in Cooper Power Systems SMP 4, 4/DP, and 16 gateways allows remote attackers to cause a denial of service (reboot or link outage) …

Mitigation only
Fix from $1,950 2013-12-17
Webex Training Center MEDIUM 5.8
CVE-2013-6966

Open redirect vulnerability in Cisco WebEx Training Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing atta…

Mitigation only
Fix from $1,600 2013-12-17
Webex Sales Center MEDIUM 5.8
CVE-2013-6959

Open redirect vulnerability in Cisco WebEx Sales Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks…

Mitigation only
Fix from $1,600 2013-12-14
Webex Sales Center MEDIUM 5.8
CVE-2013-6967

Open redirect vulnerability in the mobile-browser subsystem in Cisco WebEx Sales Center allows remote attackers to redirect users to arbitrary web si…

No fix yet
Fix from $1,600 2013-12-14
Webex Training Center MEDIUM 5.8
CVE-2013-6971

Open redirect vulnerability in Cisco WebEx Training Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing atta…

Mitigation only
Fix from $1,600 2013-12-14
Linux Kernel HIGH 7.2
CVE-2013-4587

Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main.c in the KVM subsystem in the Linux kernel through 3.12.5 allows loca…

Fix: 3.2.54 / 3.4.75+
Fix from $1,950 2013-12-14
Linux Kernel MEDIUM 6.2
CVE-2013-6368

The KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges or cause a denial of service (system crash) via a VAPIC sy…

Fix: after 3.12.5
Fix from $1,600 2013-12-14
Devscripts MEDIUM 5.8
CVE-2013-7085

Uscan in devscripts 2.13.5, when USCAN_EXCLUSION is enabled, allows remote attackers to delete arbitrary files via a whitespace character in a filena…

No fix yet
Fix from $1,600 2013-12-14
Munin MEDIUM 5.0
CVE-2013-6048

The get_group_tree function in lib/Munin/Master/HTMLConfig.pm in Munin before 2.0.18 allows remote nodes to cause a denial of service (infinite loop …

Fix: after 2.0.17
Fix from $1,600 2013-12-13
Ffmpeg MEDIUM 6.8
CVE-2013-7015

The flashsv_decode_frame function in libavcodec/flashsv.c in FFmpeg before 2.1 does not properly validate a certain height value, which allows remote…

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7019

The get_cox function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not properly validate the reduction factor, which allows remote attackers …

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Drupal MEDIUM 5.8
CVE-2013-6389

Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.24 allows remote attackers to redirect users to arbitrary web sites and cond…

Patch available
Fix from $1,600 2013-12-07
Ffmpeg HIGH 9.3
CVE-2013-0846

Array index error in the qdm2_decode_super_block function in libavcodec/qdm2.c in FFmpeg before 1.1 allows remote attackers to have an unspecified im…

Fix: after 1.0
Fix from $1,950 2013-12-07
Ffmpeg HIGH 9.3
CVE-2013-0849

The roq_decode_init function in libavcodec/roqvideodec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted (1)…

Fix: after 1.0
Fix from $1,950 2013-12-07
Ffmpeg HIGH 9.3
CVE-2013-0854

The mjpeg_decode_scan_progressive_ac function in libavcodec/mjpegdec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via…

Fix: after 1.0
Fix from $1,950 2013-12-07
Ffmpeg HIGH 9.3
CVE-2013-0856

The lpc_prediction function in libavcodec/alac.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Apple Lossles…

Fix: after 1.0
Fix from $1,950 2013-12-07
Ffmpeg HIGH 9.3
CVE-2013-0857

The decode_frame_ilbm function in libavcodec/iff.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted height va…

Fix: after 1.0
Fix from $1,950 2013-12-07
Rails MEDIUM 5.0
CVE-2013-6414EPSS 21%

actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause …

Fix: after 4.0.1
Fix from $1,600 2013-12-07
Ons 15454 HIGH 7.1
CVE-2013-6703

The TLS/SSLv3 module on Cisco ONS 15454 controller cards allows remote attackers to cause a denial of service (card reset) via crafted (1) TLS or (2)…

Mitigation only
Fix from $1,950 2013-12-03
iOS MEDIUM 6.1
CVE-2013-6705

The IP Device Tracking (IPDT) feature in Cisco IOS and IOS XE allows remote attackers to cause a denial of service (IPDT AVL corruption and device re…

Mitigation only
Fix from $1,600 2013-12-03
Adaptive Security Appliance Software HIGH 7.1
CVE-2013-6696

Cisco Adaptive Security Appliance (ASA) Software does not properly handle errors during the processing of DNS responses, which allows remote attacker…

Mitigation only
Fix from $1,950 2013-12-02
Ios Xr MEDIUM 5.0
CVE-2013-6700

The SNMP module in Cisco IOS XR allows remote attackers to cause a denial of service (process reload) via a request for an unspecified MIB, aka Bug I…

Mitigation only
Fix from $1,600 2013-11-29
Ios Xe MEDIUM 5.4
CVE-2013-6706

The Cisco Express Forwarding processing module in Cisco IOS XE allows remote attackers to cause a denial of service (device reload) via crafted MPLS …

Mitigation only
Fix from $1,600 2013-11-29
Ffmpeg HIGH 9.3
CVE-2013-0867

The decode_slice_header function in libavcodec/h264.c in FFmpeg before 1.1.2 does not properly check when the pixel format changes, which allows remo…

Fix: after 1.1.1
Fix from $1,950 2013-11-23
Ffmpeg HIGH 10.0
CVE-2013-0873

The read_header function in libavcodec/shorten.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via an invalid channel …

Fix: after 1.1.2
Fix from $1,950 2013-11-23
Ubuntu Linux MEDIUM 5.0
CVE-2013-4474EPSS 10%

Format string vulnerability in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.3 allows remote attackers to cause a denial o…

Fix: after 0.24.1
Fix from $1,600 2013-11-23