Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Pan Os MEDIUM 6.3
CVE-2012-6597

Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to cause a denial of service (management-server cras…

Fix: after 3.1.10
Fix from $1,600 2013-08-31
Ios Xr MEDIUM 5.0
CVE-2013-3470

The RIP process in Cisco IOS XR allows remote attackers to cause a denial of service (process crash) via a crafted version-2 RIP packet, aka Bug ID C…

Mitigation only
Fix from $1,600 2013-08-30
Unified Ip Phone 8945 HIGH 7.8
CVE-2013-3468

The Cisco Unified IP Phone 8945 with software 9.3(2) allows remote attackers to cause a denial of service (device hang) via a malformed PNG file, aka…

Mitigation only
Fix from $1,950 2013-08-29
Fail2ban MEDIUM 5.0
CVE-2013-2178

The apache-auth.conf, apache-nohome.conf, apache-noscript.conf, and apache-overflows.conf files in Fail2ban before 0.8.10 do not properly validate lo…

Fix: after 0.8.9
Fix from $1,600 2013-08-28
Python Glanceclient MEDIUM 5.8
CVE-2013-4111

The Python client library for Glance (python-glanceclient) before 0.10.0 does not properly check the preverify_ok value, which prevents the server ho…

Mitigation only
Fix from $1,600 2013-08-28
Top Server HIGH 7.1
CVE-2013-2804

The DNP Master Driver in Software Toolbox TOP Server before 5.12.140.0 allows remote attackers to cause a denial of service (master-station infinite …

Fix: after 5.12
Fix from $1,950 2013-08-28
Linux Kernel MEDIUM 6.9
CVE-2013-4254

The validate_event function in arch/arm/kernel/perf_event.c in the Linux kernel before 3.10.8 on the ARM platform allows local users to gain privileg…

Fix: after 3.10.7
Fix from $1,600 2013-08-25
Enterprise Mrg MEDIUM 5.8
CVE-2013-1909

The Python client in Apache Qpid before 2.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subje…

Fix: after 0.20
Fix from $1,600 2013-08-23
Global Console Manager 16 Firmware HIGH 8.5
CVE-2013-0526EPSS 6%

ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) before 1.20.0.22575 on the IBM Avocent 1754 KVM switch allows rem…

Fix: after 1.18.0.22011
Fix from $1,950 2013-08-21
Puppet Enterprise MEDIUM 5.8
CVE-2013-4762

Puppet Enterprise before 3.0.1 does not sufficiently invalidate a session when a user logs out, which might allow remote attackers to hijack sessions…

Fix: after 3.0.0
Fix from $1,600 2013-08-20
Puppet Enterprise MEDIUM 5.8
CVE-2013-4955

Open redirect vulnerability in the login page in Puppet Enterprise before 3.0.1 allows remote attackers to redirect users to arbitrary web sites and …

Fix: after 3.0.0
Fix from $1,600 2013-08-20
Xml Security For C\+\+ MEDIUM 5.8
CVE-2013-2155EPSS 6%

Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which allows remote attackers to ca…

Fix: after 1.7.0
Fix from $1,600 2013-08-20
Ubuntu Linux HIGH 7.5
CVE-2013-3567

Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to …

Fix: after 2.8.1
Fix from $1,950 2013-08-19
Debian Linux MEDIUM 5.0
CVE-2013-2175

HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows…

Patch available
Fix from $1,600 2013-08-19
Ofbiz HIGH 10.0
CVE-2013-2250EPSS 12%

Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute ar…

Patch available
Fix from $1,950 2013-08-15
Ioserver HIGH 7.8
CVE-2013-2790

The master-station DNP3 driver before driver19.exe, and Beta2041.exe, in IOServer allows remote attackers to cause a denial of service (infinite loop…

Mitigation only
Fix from $1,950 2013-08-13
Sel 2241 HIGH 7.1
CVE-2013-2792

Schweitzer Engineering Laboratories (SEL) SEL-2241, SEL-3505, and SEL-3530 RTAC master devices allow remote attackers to cause a denial of service (i…

Mitigation only
Fix from $1,950 2013-08-09
Firefox HIGH 10.0
CVE-2013-1710EPSS 40%

The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17…

Fix: after 22.0
Fix from $1,950 2013-08-07
Pip MEDIUM 6.8
CVE-2013-1629EPSS 6%

pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-i…

Fix: 1.3+
Fix from $1,600 2013-08-06
Pyshop MEDIUM 6.8
CVE-2013-1630

pyshop before 0.7.1 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows …

Fix: after 0.7
Fix from $1,600 2013-08-06
Setuptools MEDIUM 6.8
CVE-2013-1633

easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package conte…

Fix: after 0.7b4
Fix from $1,600 2013-08-06
Monkey MEDIUM 5.0
CVE-2013-3724EPSS 14%

The mk_request_header_process function in mk_request.c in Monkey 1.1.1 allows remote attackers to cause a denial of service (thread crash and service…

Patch available
Fix from $1,600 2013-08-01
Wide Area Application Services HIGH 10.0
CVE-2013-3443EPSS 6%

The web service framework in Cisco WAAS Software 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1 in a Central Manager (CM) con…

Mitigation only
Fix from $1,950 2013-08-01
Wincc MEDIUM 5.8
CVE-2013-4912

Open redirect vulnerability in Siemens WinCC (TIA Portal) 11 and 12 before 12 SP1 allows remote attackers to redirect users to arbitrary web sites an…

Mitigation only
Fix from $1,600 2013-08-01
Websphere Commerce MEDIUM 6.4
CVE-2013-2994

IBM WebSphere Commerce 7.0 Feature Pack 4 and Feature Pack 5 incorrectly maintains a valid session after unspecified interaction with REST services, …

Mitigation only
Fix from $1,600 2013-08-01
Web Gateway MEDIUM 5.8
CVE-2013-4673

The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 does not properly implement RADIUS authentication, which allows remot…

Fix: after 5.1
Fix from $1,600 2013-08-01
Subversion HIGH 7.1
CVE-2013-2088EPSS 31%

contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary …

Fix: after 1.6.21
Fix from $1,950 2013-07-31
Wireshark MEDIUM 5.0
CVE-2013-4924

epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissector in Wireshark 1.10.x before 1.10.1 does not properly validate certain inde…

Patch available
Fix from $1,600 2013-07-30
Wireshark MEDIUM 5.0
CVE-2013-4926

epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissector in Wireshark 1.10.x before 1.10.1 does not properly determine whether the…

Patch available
Fix from $1,600 2013-07-30
Wireshark MEDIUM 5.0
CVE-2013-4930

The dissect_dvbci_tpdu_hdr function in epan/dissectors/packet-dvbci.c in the DVB-CI dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.…

Patch available
Fix from $1,600 2013-07-30