Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
iOS MEDIUM 6.1
CVE-2013-6705

The IP Device Tracking (IPDT) feature in Cisco IOS and IOS XE allows remote attackers to cause a denial of service (IPDT AVL corruption and device re…

Mitigation only
Fix from $1,600 2013-12-03
Adaptive Security Appliance Software HIGH 7.1
CVE-2013-6696

Cisco Adaptive Security Appliance (ASA) Software does not properly handle errors during the processing of DNS responses, which allows remote attacker…

Mitigation only
Fix from $1,950 2013-12-02
Ios Xr MEDIUM 5.0
CVE-2013-6700

The SNMP module in Cisco IOS XR allows remote attackers to cause a denial of service (process reload) via a request for an unspecified MIB, aka Bug I…

Mitigation only
Fix from $1,600 2013-11-29
Ios Xe MEDIUM 5.4
CVE-2013-6706

The Cisco Express Forwarding processing module in Cisco IOS XE allows remote attackers to cause a denial of service (device reload) via crafted MPLS …

Mitigation only
Fix from $1,600 2013-11-29
Ffmpeg HIGH 9.3
CVE-2013-0867

The decode_slice_header function in libavcodec/h264.c in FFmpeg before 1.1.2 does not properly check when the pixel format changes, which allows remo…

Fix: after 1.1.1
Fix from $1,950 2013-11-23
Ffmpeg HIGH 10.0
CVE-2013-0873

The read_header function in libavcodec/shorten.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via an invalid channel …

Fix: after 1.1.2
Fix from $1,950 2013-11-23
Ubuntu Linux MEDIUM 5.0
CVE-2013-4474EPSS 10%

Format string vulnerability in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.3 allows remote attackers to cause a denial o…

Fix: after 0.24.1
Fix from $1,600 2013-11-23
Catapult Dnp3 I\/o Driver HIGH 7.1
CVE-2013-2811

The (1) Catapult DNP3 I/O driver before 7.2.0.60 and the (2) GE Intelligent Platforms Proficy DNP3 I/O driver before 7.20k, as used in DNPDrv.exe (ak…

Fix: after 7.20.56
Fix from $1,950 2013-11-22
Document Sciences Xpression MEDIUM 5.8
CVE-2013-6174

Multiple open redirect vulnerabilities in xAdmin in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patc…

No fix yet
Fix from $1,600 2013-11-21
Netweaver MEDIUM 5.8
CVE-2013-6814

The J2EE Engine in SAP NetWeaver 6.40, 7.02, and earlier allows remote attackers to redirect users to arbitrary web sites, conduct phishing attacks, …

Fix: after 7.02
Fix from $1,600 2013-11-20
Netweaver MEDIUM 5.0
CVE-2013-6815

The SHSTI_UPLOAD_XML function in the Application Server for ABAP (AS ABAP) in SAP NetWeaver 7.31 and earlier allows remote attackers to cause a denia…

Fix: after 7.31
Fix from $1,600 2013-11-20
Linux Kernel HIGH 8.8
CVE-2013-6282 KEVEPSS 40%

The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, w…

Fix: 3.2.54 / 3.4.12+
Fix from $1,950 2013-11-20
Network Security Services HIGH 7.5
CVE-2013-5605

Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly ha…

Patch available
Fix from $1,950 2013-11-18
iOS MEDIUM 6.8
CVE-2013-6686

The SSL VPN implementation in Cisco IOS 15.3(1)T2 and earlier allows remote authenticated users to cause a denial of service (interface queue wedge) …

Fix: after 15.3
Fix from $1,600 2013-11-18
Unified Communications Manager MEDIUM 6.9
CVE-2013-6689

Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier allows local users to bypass file permissions, and read, modify, or create arbit…

Fix: after 9.1
Fix from $1,600 2013-11-18
Cognos Business Intelligence MEDIUM 5.0
CVE-2013-3030

The servlet gateway in IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2,…

Mitigation only
Fix from $1,600 2013-11-18
Service Portal MEDIUM 6.8
CVE-2013-3406

The "Files Available for Download" implementation in the Cisco Intelligent Automation for Cloud component in Cisco Services Portal 9.4(1) allows remo…

Mitigation only
Fix from $1,600 2013-11-18
Windows 7 HIGH 7.1
CVE-2013-3876EPSS 5%

DirectAccess in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 S…

Mitigation only
Fix from $1,950 2013-11-18
Xen MEDIUM 5.7
CVE-2013-4551

Xen 4.2.x and 4.3.x, when nested virtualization is disabled, does not properly check the emulation paths for (1) VMLAUNCH and (2) VMRESUME, which all…

Mitigation only
Fix from $1,600 2013-11-18
Adaptive Security Appliance Software MEDIUM 6.4
CVE-2013-6682

The phone-proxy implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier does not properly validate X.509 certificates,…

Fix: after 9.0.3
Fix from $1,600 2013-11-13
Nx Os MEDIUM 6.1
CVE-2013-6683

The IPv6 implementation in Cisco NX-OS does not properly handle neighbor-table adjacencies, which allows remote attackers to cause a denial of servic…

Mitigation only
Fix from $1,600 2013-11-13
Wireless Lan Controller MEDIUM 6.8
CVE-2013-6684

The web framework on Cisco Wireless LAN Controller (WLC) devices does not properly validate configuration parameters, which allows remote authenticat…

Mitigation only
Fix from $1,600 2013-11-13
Adaptive Security Appliance Software MEDIUM 5.4
CVE-2013-5560

The IPv6 implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1.3 and earlier, when NAT64 or NAT66 is enabled, does not properly proc…

Fix: after 9.1
Fix from $1,600 2013-11-13
Adaptive Security Appliance Software HIGH 7.1
CVE-2013-5568

The auto-update implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier allows remote attackers to cause a denial of s…

Fix: after 9.0.3
Fix from $1,950 2013-11-13
Silverstripe MEDIUM 5.8
CVE-2013-2653

security/MemberLoginForm.php in SilverStripe 3.0.3 supports login using a GET request, which makes it easier for remote attackers to conduct phishing…

Patch available
Fix from $1,600 2013-11-13
Windows 7 MEDIUM 5.0
CVE-2013-3869EPSS 18%

Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8…

Patch available
Fix from $1,600 2013-11-13
Quic Mobile Station Modem Kernel MEDIUM 6.9
CVE-2013-6122

goodix_tool.c in the Goodix gt915 touchscreen driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for…

Patch available
Fix from $1,600 2013-11-12
Junos HIGH 9.0
CVE-2013-6618EPSS 11%

jsdm/ajax/port.php in J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1 before 12.1R5, 12.2 before 12.2R3, and 12.3 before 12.3R1 allow…

Fix: after 10.4
Fix from $1,950 2013-11-05
Salt HIGH 9.3
CVE-2013-4436

The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, which allows remote attackers t…

Patch available
Fix from $1,950 2013-11-05
Adaptive Security Appliance Cx Context Aware Security Software MEDIUM 5.0
CVE-2013-5561

The Safe Search enforcement feature in Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security Software does not properly perform filtering…

Mitigation only
Fix from $1,600 2013-11-04