Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Wireshark MEDIUM 5.0
CVE-2013-4932

Multiple array index errors in epan/dissectors/packet-gsm_a_common.c in the GSM A Common dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before …

Patch available
Fix from $1,600 2013-07-30
Struts MEDIUM 5.8
CVE-2013-2248EPSS 95%

Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and cond…

Mitigation only
Fix from $1,600 2013-07-20
Linux Kernel HIGH 7.8
CVE-2013-1943

The KVM subsystem in the Linux kernel before 3.0 does not check whether kernel addresses are specified during allocation of memory slots for use in a…

Fix: 3.0+
Fix from $1,950 2013-07-16
Nx Os MEDIUM 6.8
CVE-2013-3400

The license-installation module in Cisco NX-OS on Nexus 1000V devices allows local users to execute arbitrary commands via crafted "install license" …

Mitigation only
Fix from $1,600 2013-07-10
Chrome HIGH 7.5
CVE-2013-2871

Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service or possibly have unspecified o…

Fix: after 28.0.1500.70
Fix from $1,950 2013-07-10
Opensuse HIGH 7.5
CVE-2013-1362EPSS 66%

Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary s…

Fix: after 2.13
Fix from $1,950 2013-07-09
Gnutls MEDIUM 5.0
CVE-2013-2116

The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over…

Mitigation only
Fix from $1,600 2013-07-03
Crowd MEDIUM 5.8
CVE-2013-3925

Atlassian Crowd 2.5.x before 2.5.4, 2.6.x before 2.6.3, 2.3.8, and 2.4.9 allows remote attackers to read arbitrary files and send HTTP requests to in…

No fix yet
Fix from $1,600 2013-07-01
Authentication Server MEDIUM 5.0
CVE-2013-4098

ServerAdmin/ErrorViewer.jsp in DS3 Authentication Server allow remote attackers to inject arbitrary error-page text via the message parameter.

No fix yet
Fix from $1,600 2013-06-28
Securesphere MEDIUM 6.5
CVE-2013-4095EPSS 6%

plain/actionsets.html in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated user…

No fix yet
Fix from $1,600 2013-06-28
Authentication Server HIGH 9.0
CVE-2013-4096EPSS 9%

ServerAdmin/TestTelnetConnection.jsp in DS3 Authentication Server allows remote authenticated users to execute arbitrary commands via shell metachara…

No fix yet
Fix from $1,950 2013-06-28
Securesphere MEDIUM 6.5
CVE-2013-4094EPSS 6%

The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated…

No fix yet
Fix from $1,600 2013-06-28
Js Yaml MEDIUM 6.8
CVE-2013-4660EPSS 17%

The JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, which allows remote attackers to …

Fix: after 2.0.4
Fix from $1,600 2013-06-28
Adaptive Security Appliance HIGH 7.8
CVE-2013-3382

The Next-Generation Firewall (aka NGFW, formerly CX Context-Aware Security) module 9.x before 9.1.1.9 and 9.1.2.x before 9.1.2.12 for Cisco Adaptive …

Mitigation only
Fix from $1,950 2013-06-26
Jabber MEDIUM 5.0
CVE-2013-3393

The Precision Video Engine component in Cisco Jabber for Windows and Cisco Virtualization Experience Media Engine allows remote attackers to cause a …

Mitigation only
Fix from $1,600 2013-06-26
Firefox HIGH 7.5
CVE-2013-1694

The PreserveWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.…

Fix: after 21.0
Fix from $1,950 2013-06-26
Mg3100 Printer MEDIUM 5.0
CVE-2013-4615EPSS 16%

The Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers allow remote attackers to cause a denial of service (device h…

Mitigation only
Fix from $1,600 2013-06-21
Tivoli Monitoring MEDIUM 5.0
CVE-2013-0551

The Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in…

Mitigation only
Fix from $1,600 2013-06-21
Aix HIGH 7.1
CVE-2013-3035

The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allows remote attackers to cause a denial of serv…

Mitigation only
Fix from $1,950 2013-06-21
Telepresence Tc Software HIGH 7.8
CVE-2013-3378

Cisco TelePresence TC Software before 6.1 and TE Software before 4.1.3 allow remote attackers to cause a denial of service (temporary device hang) vi…

Fix: after 6.0.1
Fix from $1,950 2013-06-21
Access Router HIGH 7.8
CVE-2013-4632

The Huawei Access Router (AR) before V200R002SPC003 allows remote attackers to cause a denial of service (device reset) via a crafted field in a DHCP…

Mitigation only
Fix from $1,950 2013-06-20
Asa Cx Context Aware Security Software MEDIUM 5.4
CVE-2013-1203

Cisco ASA CX Context-Aware Security Software allows remote attackers to cause a denial of service (device reload) via crafted TCP packets that appear…

Mitigation only
Fix from $1,600 2013-06-18
Redcap MEDIUM 6.5
CVE-2012-6567

REDCap before 4.14.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the logic of a custom rule.

Fix: after 4.13.18
Fix from $1,600 2013-06-17
Zenworks Configuration Management MEDIUM 5.8
CVE-2013-1093

Open redirect vulnerability in the fwdToURL function in the ZCC login page in zcc-framework.jar in Novell ZENworks Configuration Management (ZCM) 11.…

Mitigation only
Fix from $1,600 2013-06-17
Libxinerama MEDIUM 6.8
CVE-2013-1985

Integer overflow in X.org libXinerama 1.1.2 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vecto…

Fix: after 1.1.2
Fix from $1,600 2013-06-15
Ioserver HIGH 7.1
CVE-2013-2783

The DNP3 driver in IOServer drivers 1.0.19.0 allows remote attackers to cause a denial of service (infinite loop) or obtain unspecified control via c…

Patch available
Fix from $1,950 2013-06-14
Insight Diagnostics HIGH 10.0
CVE-2013-3573

HP Insight Diagnostics 9.4.0.4710 allows remote attackers to conduct unspecified injection attacks via unknown vectors.

No fix yet
Fix from $1,950 2013-06-14
Insight Diagnostics HIGH 7.8
CVE-2013-3574

Absolute path traversal vulnerability in hpdiags/frontend2/commands/saveCompareConfig.php in HP Insight Diagnostics 9.4.0.4710 allows remote attacker…

Mitigation only
Fix from $1,950 2013-06-14
Insight Diagnostics MEDIUM 5.0
CVE-2013-3575

hpdiags/frontend2/help/pageview.php in HP Insight Diagnostics 9.4.0.4710 does not properly restrict PHP include or require statements, which allows r…

Mitigation only
Fix from $1,600 2013-06-14
Wireshark MEDIUM 5.0
CVE-2013-4078

epan/dissectors/packet-rdp.c in the RDP dissector in Wireshark 1.8.x before 1.8.8 does not validate return values during checks for data availability…

Mitigation only
Fix from $1,600 2013-06-09