Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Wireshark MEDIUM 5.0
CVE-2013-4083

The dissect_pft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.6.x before 1.6.16, 1.8.x before 1.8.8, and 1.1…

Patch available
Fix from $1,600 2013-06-09
Mac Os X MEDIUM 6.9
CVE-2013-3954

The posix_spawn system call in the XNU kernel in Apple Mac OS X 10.8.x does not properly validate the data for file actions and port actions, which a…

Fix: after 6.1.4
Fix from $1,600 2013-06-05
Iphone Os MEDIUM 6.2
CVE-2013-3955

The get_xattrinfo function in the XNU kernel in Apple iOS 5.x and 6.x through 6.1.3 on iPad devices does not properly validate the header of an Apple…

No fix yet
Fix from $1,600 2013-06-05
Mac Os X MEDIUM 6.8
CVE-2013-1024

CoreMedia Playback in Apple Mac OS X before 10.8.4 does not properly initialize memory during the processing of text tracks, which allows remote atta…

Fix: after 10.8.3
Fix from $1,600 2013-06-05
Tomcat MEDIUM 5.0
CVE-2012-3544EPSS 11%

Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attac…

Patch available
Fix from $1,600 2013-06-01
Ec Cube MEDIUM 5.0
CVE-2013-2315

data/class/pages/forgot/LC_Page_Forgot.php in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 does not properly validate the input to the password reminder …

Mitigation only
Fix from $1,600 2013-05-29
Fedora MEDIUM 5.0
CVE-2002-2443EPSS 6%

schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses,…

Patch available
Fix from $1,600 2013-05-29
Webex MEDIUM 5.8
CVE-2012-6399

Cisco WebEx 4.1 on iOS does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of th…

Mitigation only
Fix from $1,600 2013-05-27
Moodle MEDIUM 5.0
CVE-2013-2083

The MoodleQuickForm class in lib/formslib.php in Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not prop…

Patch available
Fix from $1,600 2013-05-25
Debian Linux MEDIUM 5.0
CVE-2013-3555

epan/dissectors/packet-gtpv2.c in the GTPv2 dissector in Wireshark 1.8.x before 1.8.7 calls incorrect functions in certain contexts related to cipher…

Patch available
Fix from $1,600 2013-05-25
Wireshark MEDIUM 5.0
CVE-2013-3556

The fragment_add_seq_common function in epan/reassemble.c in the ASN.1 BER dissector in Wireshark before r48943 has an incorrect pointer dereference …

Mitigation only
Fix from $1,600 2013-05-25
Scalance X200irt Firmware HIGH 7.5
CVE-2013-3634

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (Versions < V5.0.0 for CVE-2013-3633 and versions < V…

Fix: after 5.0.0
Fix from $1,950 2013-05-24
Activecollab Chat Module MEDIUM 6.5
CVE-2012-6554EPSS 17%

functions/html_to_text.php in the Chat module before 1.5.2 for activeCollab allows remote authenticated users to execute arbitrary PHP code via the m…

No fix yet
Fix from $1,600 2013-05-23
Freenac HIGH 7.5
CVE-2012-6560

SQL injection vulnerability in deviceadd.php in FreeNAC 3.02 allows remote attackers to execute arbitrary SQL commands via the status parameter.

No fix yet
Fix from $1,950 2013-05-23
Telepathy Idle MEDIUM 5.8
CVE-2007-6746

telepathy-idle before 0.1.15 does not verify (1) that the issuer is a trusted CA, (2) that the server hostname matches a domain name in the subject's…

Fix: after 0.1.14.1
Fix from $1,600 2013-05-21
Acrobat Reader HIGH 10.0
CVE-2013-3342

Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 do not properly handle operating-system domain blacklists, whi…

Patch available
Fix from $1,950 2013-05-16
Telepresence Supervisor Mse 8050 Software HIGH 7.8
CVE-2013-1236

Cisco TelePresence Supervisor MSE 8050 before 2.3(1.31) allows remote attackers to cause a denial of service (CPU consumption or device reload) by es…

Fix: after 2.2
Fix from $1,950 2013-05-16
Publisher HIGH 9.3
CVE-2013-1316EPSS 22%

Microsoft Publisher 2003 SP3 does not properly validate the size of an unspecified array, which allows remote attackers to execute arbitrary code via…

Mitigation only
Fix from $1,950 2013-05-15
Publisher HIGH 10.0
CVE-2013-1318EPSS 26%

Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers access to an invalid pointe…

Mitigation only
Fix from $1,950 2013-05-15
Publisher HIGH 9.3
CVE-2013-1321EPSS 22%

Microsoft Publisher 2003 SP3 does not properly check the data type of an unspecified return value, which allows remote attackers to execute arbitrary…

Mitigation only
Fix from $1,950 2013-05-15
.net Framework MEDIUM 5.0
CVE-2013-1336EPSS 19%

The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check signatures, which allows remote…

Mitigation only
Fix from $1,600 2013-05-15
Documentum Records Manager MEDIUM 5.8
CVE-2013-0939

EMC Documentum Webtop before 6.7 SP2, Documentum WDK before 6.7 SP2, Documentum Taskspace before 6.7 SP2, and Documentum Records Manager before 6.7 S…

Mitigation only
Fix from $1,600 2013-05-10
Unified Customer Voice Portal HIGH 7.8
CVE-2013-1223

The log viewer in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly validate an unspecified parameter, which al…

Fix: after 9.0
Fix from $1,950 2013-05-09
Wonderware Information Server HIGH 9.3
CVE-2013-0686

Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackers to read arbitrary files, send HTTP requ…

Mitigation only
Fix from $1,950 2013-05-09
Groundwork Monitor MEDIUM 5.8
CVE-2013-3511

Open redirect vulnerability in the NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote attackers to redirect users to arbitrary web s…

No fix yet
Fix from $1,600 2013-05-08
Groundwork Monitor MEDIUM 6.5
CVE-2013-3512

The Cacti component in GroundWork Monitor Enterprise 6.7.0 does not properly perform authorization checks, which allows remote authenticated users to…

Mitigation only
Fix from $1,600 2013-05-08
Webex Meetings Server MEDIUM 5.0
CVE-2013-1232

The HTTP implementation in Cisco WebEx Node for MCS, WebEx Meetings Server, and WebEx Node for ASR 1000 Series allows remote attackers to read the co…

Mitigation only
Fix from $1,600 2013-05-04
Joomla\! MEDIUM 5.5
CVE-2013-3242

plugins/system/remember/remember.php in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 does not properly handle an object obtained by unserializi…

No fix yet
Fix from $1,600 2013-05-03
Avamar HIGH 9.3
CVE-2013-0945

EMC Avamar Client before 6.1.101-89 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam…

Fix: after 6.1.101-87
Fix from $1,950 2013-05-03
Webex Meetings Server MEDIUM 5.0
CVE-2013-1231

The HTTP implementation in Cisco WebEx Node for MCS and WebEx Meetings Server allows remote attackers to read cache files via a crafted request, aka …

Mitigation only
Fix from $1,600 2013-05-03