Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Unified Computing System MEDIUM 6.8
CVE-2012-4082

MCTools in the Cisco Management Controller in Cisco Unified Computing System (UCS) allows local users to gain privileges by entering crafted command-…

Mitigation only
Fix from $1,600 2013-09-20
Iphone Os HIGH 7.1
CVE-2013-5155

The Sandbox subsystem in Apple iOS before 7 allows attackers to cause a denial of service (infinite loop) via an application that writes crafted valu…

Fix: after 6.1.4
Fix from $1,950 2013-09-19
Iphone Os HIGH 7.8
CVE-2013-5140

The kernel in Apple iOS before 7 allows remote attackers to cause a denial of service (assertion failure and device restart) via an invalid packet fr…

Fix: after 6.1.4
Fix from $1,950 2013-09-19
Mac Os X MEDIUM 6.1
CVE-2011-2391

The IPv6 implementation in the kernel in Apple iOS before 7 allows remote attackers to cause a denial of service (CPU consumption) via crafted ICMPv6…

Fix: after 12.1
Fix from $1,600 2013-09-19
Firefox MEDIUM 6.8
CVE-2013-1731

Untrusted search path vulnerability in the GL tracing functionality in Mozilla Firefox before 24.0 on Android allows attackers to execute arbitrary c…

Fix: after 23.0.1
Fix from $1,600 2013-09-18
Firefox HIGH 9.3
CVE-2013-1735

Use-after-free vulnerability in the mozilla::layout::ScrollbarActivity function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thund…

Fix: after 23.0.1
Fix from $1,950 2013-09-18
Junos Pulse Secure Access Service MEDIUM 5.4
CVE-2013-5650

Junos Pulse Secure Access Service (IVE) 7.1 before 7.1r5, 7.2 before 7.2r10, 7.3 before 7.3r6, and 7.4 before 7.4r3 and Junos Pulse Access Control Se…

Mitigation only
Fix from $1,600 2013-09-16
Squid MEDIUM 5.0
CVE-2013-4123EPSS 80%

client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a crafted port nu…

Patch available
Fix from $1,600 2013-09-16
Openstack MEDIUM 5.0
CVE-2013-4180

The (1) power and (2) ipmi_boot actions in the HostController in Foreman before 1.2.2 allow remote attackers to cause a denial of service (memory con…

Fix: after 1.2.1
Fix from $1,600 2013-09-16
Moodle MEDIUM 5.8
CVE-2012-6087

repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not verif…

Fix: after 2.2.11
Fix from $1,600 2013-09-16
Nx Os MEDIUM 6.3
CVE-2013-5496

Open Network Environment Platform (ONEP) in Cisco NX-OS allows remote authenticated users to cause a denial of service (network-element reload) via a…

Mitigation only
Fix from $1,600 2013-09-16
Iphone Os MEDIUM 5.8
CVE-2013-1028

The IPSec implementation in Apple Mac OS X before 10.8.5, when Hybrid Auth is used, does not verify X.509 certificates from security gateways, which …

Fix: after 10.8.4
Fix from $1,600 2013-09-16
Identity Driven Manager HIGH 10.0
CVE-2013-4811EPSS 71%

UpdateDomainControllerServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manag…

Mitigation only
Fix from $1,950 2013-09-16
Identity Driven Manager HIGH 10.0
CVE-2013-4812EPSS 52%

UpdateCertificatesServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (…

Mitigation only
Fix from $1,950 2013-09-16
Linux Kernel MEDIUM 6.2
CVE-2013-2888

Multiple array index errors in drivers/hid/hid-core.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11 allow physically…

Fix: after 3.11
Fix from $1,600 2013-09-16
Virtualization Experience Client 6000 MEDIUM 6.8
CVE-2013-5493

The diagnostic module in the firmware on Cisco Virtualization Experience Client 6000 devices allows local users to bypass intended access restriction…

Mitigation only
Fix from $1,600 2013-09-13
WordPress HIGH 7.5
CVE-2013-4339EPSS 7%

WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection r…

Fix: after 3.6
Fix from $1,950 2013-09-12
Digital Media Manager MEDIUM 5.8
CVE-2013-3446

Open redirect vulnerability in the login page in Cisco Digital Media Manager (DMM) allows remote attackers to redirect users to arbitrary web sites a…

Mitigation only
Fix from $1,600 2013-09-12
Prime Lan Management Solution MEDIUM 5.0
CVE-2013-5488

Cisco Common Services, as used in Cisco Prime LAN Management Solution (LMS), Cisco Security Manager, Cisco Unified Service Monitor, and Cisco Unified…

Mitigation only
Fix from $1,600 2013-09-12
Sharepoint Foundation HIGH 10.0
CVE-2013-1330EPSS 27%

The default configuration of Microsoft SharePoint Portal Server 2003 SP3, SharePoint Server 2007 SP3 and 2010 SP1 and SP2, and Office Web Apps 2010 d…

Mitigation only
Fix from $1,950 2013-09-11
Active Directory Lightweight Directory Service MEDIUM 5.0
CVE-2013-3868EPSS 37%

Microsoft Active Directory Lightweight Directory Service (AD LDS) on Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Window…

Mitigation only
Fix from $1,600 2013-09-11
Sharepoint Foundation MEDIUM 5.0
CVE-2013-0081EPSS 77%

Microsoft SharePoint Portal Server 2003 SP3 and SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 do not properly process unassigned workflows, …

Mitigation only
Fix from $1,600 2013-09-11
389 Directory Server MEDIUM 5.0
CVE-2013-4283

ns-slapd in 389 Directory Server before 1.3.0.8 allows remote attackers to cause a denial of service (server crash) via a crafted Distinguished Name …

Fix: after 1.3.0.7
Fix from $1,600 2013-09-10
Asterisk MEDIUM 5.0
CVE-2013-5642EPSS 12%

The SIP channel driver (channels/chan_sip.c) in Asterisk Open Source 1.8.x before 1.8.23.1, 10.x before 10.12.3, and 11.x before 11.5.1; Certified As…

Patch available
Fix from $1,600 2013-09-09
H8dcl 6f HIGH 10.0
CVE-2013-3608EPSS 6%

The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, …

Mitigation only
Fix from $1,950 2013-09-08
H8dcl 6f HIGH 10.0
CVE-2013-3609EPSS 5%

The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, …

Mitigation only
Fix from $1,950 2013-09-08
Coursemill Learning Management System HIGH 9.3
CVE-2013-3599

userlogin.jsp in Coursemill Learning Management System (LMS) 6.6 and 6.8 allows remote attackers to gain privileges via a modified user-role value to…

Mitigation only
Fix from $1,950 2013-09-06
Coursemill Learning Management System HIGH 8.5
CVE-2013-3600

Coursemill Learning Management System (LMS) 6.6 allows remote authenticated users to gain privileges via a modified userid value to unspecified funct…

Mitigation only
Fix from $1,950 2013-09-06
Rsa Archer Egrc MEDIUM 5.8
CVE-2013-3277

Open redirect vulnerability in EMC RSA Archer GRC 5.x before 5.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishin…

Mitigation only
Fix from $1,600 2013-09-05
Secure Access Control System MEDIUM 5.0
CVE-2013-5470

Cisco Secure Access Control System (ACS) does not properly handle requests to read from the TACACS+ socket, which allows remote attackers to cause a …

Mitigation only
Fix from $1,600 2013-09-04