Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Ubuntu Linux MEDIUM 5.0
CVE-2013-4402EPSS 5%

The compressed packet parser in GnuPG 1.4.x before 1.4.15 and 2.0.x before 2.0.22 allows remote attackers to cause a denial of service (infinite recu…

Mitigation only
Fix from $1,600 2013-10-28
Jboss Enterprise Brms Platform HIGH 7.5
CVE-2013-2186EPSS 13%

The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss …

Fix: after 3.1
Fix from $1,950 2013-10-28
Big Ip Global Traffic Manager HIGH 7.8
CVE-2013-6016

The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, APM, ASM, Edge Gateway, GTM, Link Controller, and WOM 10.0.0 through 10.2.2 and 11.0.0; An…

Mitigation only
Fix from $1,950 2013-10-26
Timthumb MEDIUM 6.8
CVE-2011-4106EPSS 23%

TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote attackers to upload and execut…

Fix: after 1.99
Fix from $1,600 2013-10-26
Vlc Media Player HIGH 7.5
CVE-2013-6283EPSS 10%

VideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a lo…

Fix: after 2.0.8
Fix from $1,950 2013-10-25
Secure Access Control System MEDIUM 5.0
CVE-2013-5536

Cisco Secure Access Control System (ACS) does not properly implement an incoming-packet firewall rule, which allows remote attackers to cause a denia…

Mitigation only
Fix from $1,600 2013-10-24
Web Security Appliance HIGH 7.8
CVE-2013-5537

The web framework on Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance (SMA) devices does…

Mitigation only
Fix from $1,950 2013-10-24
Mac Os X MEDIUM 6.8
CVE-2013-5168

Console in Apple Mac OS X before 10.9 allows user-assisted remote attackers to execute arbitrary applications by triggering a log entry with a crafte…

Fix: after 10.8.5
Fix from $1,600 2013-10-24
Mac Os X MEDIUM 6.6
CVE-2013-5175

The kernel in Apple Mac OS X before 10.9 allows local users to obtain sensitive information or cause a denial of service (out-of-bounds read and syst…

Fix: after 10.8.5
Fix from $1,600 2013-10-24
Sling MEDIUM 5.8
CVE-2013-4390

Open redirect vulnerability in the AbstractAuthenticationFormServlet in the Auth Core (org.apache.sling.auth.core) bundle before 1.1.4 in Apache Slin…

Fix: after 1.1.2
Fix from $1,600 2013-10-24
Node.js MEDIUM 5.0
CVE-2013-4450EPSS 37%

The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and CPU consump…

Patch available
Fix from $1,600 2013-10-21
Esx HIGH 7.1
CVE-2013-5970

hostd-vmdb in VMware ESXi 4.0 through 5.0 and ESX 4.0 through 4.1 allows remote attackers to cause a denial of service (hostd-vmdb service outage) by…

Mitigation only
Fix from $1,950 2013-10-21
Unified Computing System MEDIUM 5.8
CVE-2012-4117

The fabric-interconnect component in Cisco Unified Computing System (UCS) does not properly verify X.509 certificates, which allows man-in-the-middle…

Mitigation only
Fix from $1,600 2013-10-19
Storwize V7000 Unified Software MEDIUM 5.4
CVE-2013-0500

IBM Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.2.0 does not properly handle device files that are created with the NFS protocol but accessed w…

Mitigation only
Fix from $1,600 2013-10-17
Webex Meetings Server MEDIUM 6.8
CVE-2013-5529

The deployment module in the server in Cisco WebEx Meeting Center does not properly validate the passphrase, which allows remote attackers to launch …

Mitigation only
Fix from $1,600 2013-10-16
Identity Services Engine Software MEDIUM 6.0
CVE-2013-5539

The upload-dialog implementation in Cisco Identity Services Engine (ISE) allows remote authenticated users to upload files with an arbitrary file typ…

Mitigation only
Fix from $1,600 2013-10-16
Nx Os MEDIUM 6.8
CVE-2012-4076

Cisco NX-OS allows local users to gain privileges and execute arbitrary commands via shell metacharacters in a command that calls the system library …

Mitigation only
Fix from $1,600 2013-10-14
Adaptive Security Appliance Software HIGH 7.1
CVE-2013-5508

The SQL*Net inspection engine in Cisco Adaptive Security Appliance (ASA) Software 7.x before 7.2(5.12), 8.x before 8.2(5.44), 8.3.x before 8.3(2.39),…

Mitigation only
Fix from $1,950 2013-10-13
E Terracontrol HIGH 7.8
CVE-2013-2787

Alstom e-terracontrol 3.5, 3.6, and 3.7 allows remote attackers to cause a denial of service (infinite loop) via crafted DNP3 packets.

Mitigation only
Fix from $1,950 2013-10-13
Unified Ip Phones 9900 Series Firmware MEDIUM 5.0
CVE-2013-5532

Buffer overflow in the web-application interface on Cisco 9900 IP phones allows remote attackers to cause a denial of service (webapp interface outag…

Mitigation only
Fix from $1,600 2013-10-11
Unified Ip Phones 9900 Series Firmware MEDIUM 6.0
CVE-2013-5533

The image-upgrade functionality on Cisco 9900 Unified IP phones allows local users to gain privileges by placing shell commands in an unspecified par…

Mitigation only
Fix from $1,600 2013-10-11
Unified Ip Phone 9951 HIGH 7.1
CVE-2013-5526

Cisco 9900 fourth-generation IP phones do not properly perform SDP negotiation, which allows remote attackers to cause a denial of service (device re…

Mitigation only
Fix from $1,950 2013-10-10
iOS MEDIUM 5.7
CVE-2013-5527

The OSPF functionality in Cisco IOS and IOS XE allows remote attackers to cause a denial of service (device reload) via crafted options in an LSA typ…

Mitigation only
Fix from $1,600 2013-10-10
Gallery HIGH 7.5
CVE-2013-2138

The (1) uploadify and (2) flowplayer SWF files in Gallery 3 before 3.0.8 do not properly remove query parameters and fragments, which allows remote a…

Fix: after 3.0.7
Fix from $1,950 2013-10-10
Joomla\! MEDIUM 6.8
CVE-2013-5576EPSS 48%

administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote authentic…

Patch available
Fix from $1,600 2013-10-09
.net Framework HIGH 7.8
CVE-2013-3860EPSS 31%

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly parse a DTD during XML digital-signature validation, which allows…

Mitigation only
Fix from $1,950 2013-10-09
.net Framework HIGH 7.8
CVE-2013-3861EPSS 82%

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 allows remote attackers to cause a denial of service (application crash or hang) vi…

Mitigation only
Fix from $1,950 2013-10-09
Nx Os MEDIUM 5.0
CVE-2012-4091

The RIP service engine in Cisco NX-OS allows remote attackers to cause a denial of service (engine restart) via a malformed (1) RIPv4 or (2) RIPv6 me…

Mitigation only
Fix from $1,600 2013-10-05
Nx Os MEDIUM 5.0
CVE-2012-4098

The BGP implementation in Cisco NX-OS does not properly filter AS paths, which allows remote attackers to cause a denial of service (BGP service rese…

Mitigation only
Fix from $1,600 2013-10-05
Nx Os MEDIUM 6.2
CVE-2012-4122

The CLI parser in Cisco NX-OS allows local users to bypass intended access restrictions, and overwrite or create arbitrary files, via shell output re…

Mitigation only
Fix from $1,600 2013-10-05