Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Gallery HIGH 7.5
CVE-2013-2138

The (1) uploadify and (2) flowplayer SWF files in Gallery 3 before 3.0.8 do not properly remove query parameters and fragments, which allows remote a…

Fix: after 3.0.7
Fix from $1,950 2013-10-10
Joomla\! MEDIUM 6.8
CVE-2013-5576EPSS 48%

administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote authentic…

Patch available
Fix from $1,600 2013-10-09
.net Framework HIGH 7.8
CVE-2013-3860EPSS 31%

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly parse a DTD during XML digital-signature validation, which allows…

Mitigation only
Fix from $1,950 2013-10-09
.net Framework HIGH 7.8
CVE-2013-3861EPSS 82%

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 allows remote attackers to cause a denial of service (application crash or hang) vi…

Mitigation only
Fix from $1,950 2013-10-09
Nx Os MEDIUM 5.0
CVE-2012-4091

The RIP service engine in Cisco NX-OS allows remote attackers to cause a denial of service (engine restart) via a malformed (1) RIPv4 or (2) RIPv6 me…

Mitigation only
Fix from $1,600 2013-10-05
Nx Os MEDIUM 5.0
CVE-2012-4098

The BGP implementation in Cisco NX-OS does not properly filter AS paths, which allows remote attackers to cause a denial of service (BGP service rese…

Mitigation only
Fix from $1,600 2013-10-05
Nx Os MEDIUM 6.2
CVE-2012-4122

The CLI parser in Cisco NX-OS allows local users to bypass intended access restrictions, and overwrite or create arbitrary files, via shell output re…

Mitigation only
Fix from $1,600 2013-10-05
Netscaler Application Delivery Controller Firmware HIGH 7.8
CVE-2013-6011

Citrix NetScaler Application Delivery Controller (ADC) 10.0 before 10.0-76.7 allows remote attackers to cause a denial of service (nsconfigd crash an…

Mitigation only
Fix from $1,950 2013-10-04
Glibc MEDIUM 5.1
CVE-2013-4788EPSS 11%

The PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and Embedded GLIBC (EGLIBC) does not initialize the r…

Fix: after 2.17
Fix from $1,600 2013-10-04
Unified Computing System MEDIUM 6.8
CVE-2012-4102

The activate firmware command in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges by e…

Mitigation only
Fix from $1,600 2013-10-02
Unified Computing System MEDIUM 6.8
CVE-2012-4103

ethanalyzer in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges by embedding commands …

Mitigation only
Fix from $1,600 2013-10-02
Unified Computing System MEDIUM 6.8
CVE-2012-4109

The clear sshkey command in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges by embedd…

Mitigation only
Fix from $1,600 2013-10-02
Unified Computing System MEDIUM 6.8
CVE-2012-4110

run-script in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges by embedding commands i…

Mitigation only
Fix from $1,600 2013-10-02
Unified Computing System MEDIUM 6.8
CVE-2012-4111

The create certreq command in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges by embe…

Mitigation only
Fix from $1,600 2013-10-02
Unified Computing System MEDIUM 5.5
CVE-2012-4095

The local file editor in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges, and read or…

Mitigation only
Fix from $1,600 2013-10-02
Db2 MEDIUM 5.0
CVE-2013-4032

The Fast Communications Manager (FCM) in IBM DB2 Enterprise Server Edition and Advanced Enterprise Server Edition 10.1 before FP3 and 10.5, when a mu…

Mitigation only
Fix from $1,600 2013-10-02
MongoDB MEDIUM 6.0
CVE-2013-1892EPSS 45%

MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote aut…

Fix: after 2.0.8
Fix from $1,600 2013-10-01
Ubuntu Linux HIGH 7.1
CVE-2013-5745EPSS 9%

The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, …

Fix: after 3.7.3
Fix from $1,950 2013-10-01
Unified Computing System MEDIUM 6.2
CVE-2012-4096

The local file editor in the Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) allows local users to gain privileges and …

Mitigation only
Fix from $1,600 2013-10-01
Squid HIGH 7.8
CVE-2013-1839EPSS 18%

The strHdrAcptLangGetItem function in errorpage.cc in Squid 3.2.x before 3.2.9 and 3.3.x before 3.3.3 allows remote attackers to cause a denial of se…

Mitigation only
Fix from $1,950 2013-09-30
Ios Xr MEDIUM 5.0
CVE-2013-5498

The PPTP-ALG component in CRS Carrier Grade Services Engine (CGSE) and ASR 9000 Integrated Service Module (ISM) in Cisco IOS XR allows remote attacke…

Mitigation only
Fix from $1,600 2013-09-27
Ios Xe HIGH 7.1
CVE-2013-5472

The NTP implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.1, and IOS XE 2.1 through 3.3, does not properly handle encapsulation of mu…

Mitigation only
Fix from $1,950 2013-09-27
Ios Xe HIGH 7.8
CVE-2013-5475

Cisco IOS 12.2 through 12.4 and 15.0 through 15.3, and IOS XE 2.1 through 3.9, allows remote attackers to cause a denial of service (device reload) v…

Mitigation only
Fix from $1,950 2013-09-27
iOS HIGH 7.8
CVE-2013-5476

The Zone-Based Firewall (ZFW) feature in Cisco IOS 15.1 through 15.2, when content filtering or HTTP ALG inspection is enabled, allows remote attacke…

Mitigation only
Fix from $1,950 2013-09-27
iOS HIGH 7.8
CVE-2013-5477

The T1/E1 driver-queue functionality in Cisco IOS 12.2 and 15.0 through 15.3, when an HDLC32 driver is used, allows remote attackers to cause a denia…

Mitigation only
Fix from $1,950 2013-09-27
iOS HIGH 7.8
CVE-2013-5478

Cisco IOS 15.0 through 15.3 and IOS XE 3.2 through 3.8, when a VRF interface exists, allows remote attackers to cause a denial of service (interface …

Mitigation only
Fix from $1,950 2013-09-27
iOS HIGH 7.8
CVE-2013-5479

The DNS-over-TCP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (devi…

Mitigation only
Fix from $1,950 2013-09-27
iOS HIGH 7.8
CVE-2013-5480

The DNS-over-TCP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (devi…

Mitigation only
Fix from $1,950 2013-09-27
iOS HIGH 7.1
CVE-2013-5481

The PPTP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (device reloa…

Mitigation only
Fix from $1,950 2013-09-27
Unified Computing System MEDIUM 5.8
CVE-2012-4092

The management interface in the Central Software component in Cisco Unified Computing System (UCS) does not properly validate the identity of vCenter…

Mitigation only
Fix from $1,600 2013-09-26