Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Echo MEDIUM 5.0
CVE-2009-5135EPSS 10%

The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read arbitrary files via a request containing an external e…

Fix: after 2.1.0
Fix from $1,600 2013-05-02
FreeBSD HIGH 7.5
CVE-2013-3266

The nfsrvd_readdir function in sys/fs/nfsserver/nfs_nfsdport.c in the new NFS server in FreeBSD 8.0 through 9.1-RELEASE-p3 does not verify that a REA…

Patch available
Fix from $1,950 2013-05-02
Rio 47100 Plc HIGH 7.1
CVE-2013-0699

The Galil RIO-47100 Pocket PLC allows remote attackers to cause a denial of service via a session that includes "repeated requests."

Patch available
Fix from $1,950 2013-05-01
Telepresence Management Suite MEDIUM 5.0
CVE-2013-1229

TMSSNMPService.exe in TelePresence Manager in Cisco TelePresence Management Suite (TMS) on 64-bit platforms allows remote attackers to cause a denial…

Mitigation only
Fix from $1,600 2013-05-01
Application Networking Manager MEDIUM 6.8
CVE-2013-1196

The command-line interface in Cisco Secure Access Control System (ACS), Identity Services Engine Software, Context Directory Agent, Application Netwo…

Mitigation only
Fix from $1,600 2013-04-29
Multi Xml HIGH 7.5
CVE-2013-0175

multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which all…

Patch available
Fix from $1,950 2013-04-25
Nx Os HIGH 7.8
CVE-2013-1181

Cisco NX-OS on Nexus 5500 devices 4.x and 5.x before 5.0(3)N2(2), Nexus 3000 devices 5.x before 5.0(3)U3(2), and Unified Computing System (UCS) 6200 …

Mitigation only
Fix from $1,950 2013-04-25
Unified Computing System Infrastructure And Unified Computing System Software HIGH 7.8
CVE-2013-1184

The management API in the XML API management service in the Manager component in Cisco Unified Computing System (UCS) 1.x before 1.2(1b) allows remot…

Mitigation only
Fix from $1,950 2013-04-25
Adaptive Security Appliance Device Manager HIGH 9.3
CVE-2013-1192

The JAR files on Cisco Device Manager for Cisco MDS 9000 devices before 5.2.8, and Cisco Device Manager for Cisco Nexus 5000 devices, allow remote at…

Fix: after 5.2.5
Fix from $1,950 2013-04-25
Rails MEDIUM 6.4
CVE-2013-3221

The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used …

No fix yet
Fix from $1,600 2013-04-22
Telepresence Mcu 4500 Series Software HIGH 7.1
CVE-2013-1176

The DSP card on Cisco TelePresence MCU 4500 and 4501 devices before 4.3(2.30), TelePresence MCU MSE 8510 devices before 4.3(2.30), and TelePresence S…

Fix: after 4.3
Fix from $1,950 2013-04-18
Rslinx Enterprise HIGH 7.1
CVE-2012-4695

LogReceiver.exe in Rockwell Automation RSLinx Enterprise CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remo…

Mitigation only
Fix from $1,950 2013-04-18
Jabber Extensible Communications Platform MEDIUM 5.0
CVE-2013-1187

The Connection Manager in Cisco Jabber Extensible Communications Platform (aka Jabber XCP) does not properly validate login data, which allows remote…

Mitigation only
Fix from $1,600 2013-04-16
Unified Presence MEDIUM 6.8
CVE-2013-1197

The XML parser in the server in Cisco Unified Presence (CUP) allows remote authenticated users to cause a denial of service (jabberd daemon crash) vi…

Mitigation only
Fix from $1,600 2013-04-16
Anyconnect Secure Mobility Client MEDIUM 6.6
CVE-2013-1172

The Cisco Security Service in Cisco AnyConnect Secure Mobility Client (aka AnyConnect VPN Client) does not properly verify files, which allows local …

Mitigation only
Fix from $1,600 2013-04-11
Ubr10012 MEDIUM 5.7
CVE-2013-1189

Cisco Universal Broadband (aka uBR) 10000 series routers, when an IPv4/IPv6 dual-stack modem is used, allow remote attackers to cause a denial of ser…

Mitigation only
Fix from $1,600 2013-04-11
Ios Xe HIGH 7.8
CVE-2013-2779

Cisco IOS XE 3.4 before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR) does not properly implement the …

Mitigation only
Fix from $1,950 2013-04-11
Adaptive Security Appliance Software HIGH 7.1
CVE-2013-1151

Cisco Adaptive Security Appliances (ASA) devices with software 7.x before 7.2(5.10), 8.0 before 8.0(5.31), 8.1 and 8.2 before 8.2(5.38), 8.3 before 8…

Mitigation only
Fix from $1,950 2013-04-11
Ios Xe HIGH 7.8
CVE-2013-1165

Cisco IOS XE 2.x and 3.x before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR) allows remote attackers …

Fix: after 3.4.3s
Fix from $1,950 2013-04-11
Asr 1001 HIGH 7.8
CVE-2013-1166

Cisco IOS XE 3.2 through 3.4 before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR), when VRF-aware NAT …

Mitigation only
Fix from $1,950 2013-04-11
Windows Defender HIGH 7.2
CVE-2013-0078

The Microsoft Antimalware Client in Windows Defender on Windows 8 and Windows RT uses an incorrect pathname for MsMpEng.exe, which allows local users…

Mitigation only
Fix from $1,950 2013-04-09
Active Directory MEDIUM 5.0
CVE-2013-1282EPSS 27%

The LDAP service in Microsoft Active Directory, Active Directory Application Mode (ADAM), Active Directory Lightweight Directory Service (AD LDS), an…

Mitigation only
Fix from $1,600 2013-04-09
Ruby MEDIUM 5.0
CVE-2013-1821EPSS 7%

lib/rexml/text.rb in the REXML parser in Ruby before 1.9.3-p392 allows remote attackers to cause a denial of service (memory consumption and crash) v…

Fix: after 1.9.3
Fix from $1,600 2013-04-09
Nori Gem HIGH 7.5
CVE-2013-0285

The nori gem 2.0.x before 2.0.2, 1.1.x before 1.1.4, and 1.0.x before 1.0.3 for Ruby does not properly restrict casts of string values, which allows …

Mitigation only
Fix from $1,950 2013-04-09
Kanaka MEDIUM 5.8
CVE-2013-2770

The installation functionality in the Novell Kanaka component before 2.8 for Novell Open Enterprise Server (OES) on Mac OS X does not verify the serv…

Fix: after 2.7.1
Fix from $1,600 2013-04-07
Cogent Datahub MEDIUM 5.0
CVE-2013-0681

Cogent Real-Time Systems Cogent DataHub before 7.3.0, OPC DataHub before 6.4.22, Cascade DataHub before 6.4.22 on Windows, and DataHub QuickTrend bef…

Fix: after 7.2.2
Fix from $1,600 2013-04-05
Wonderware Win Xml Exporter HIGH 9.3
CVE-2012-4710

Invensys Wonderware Win-XML Exporter 1522.148.0.0 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a…

Mitigation only
Fix from $1,950 2013-04-04
Ldoce MEDIUM 6.8
CVE-2013-1911

lib/ldoce/word.rb in the ldoce 0.0.2 gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in (1) an mp3 URL or…

No fix yet
Fix from $1,600 2013-04-03
Chrome MEDIUM 6.8
CVE-2013-0926

Google Chrome before 26.0.1410.43 does not properly handle active content in an EMBED element during a copy-and-paste operation, which allows user-as…

Fix: after 26.0.1410.42
Fix from $1,600 2013-03-28
Jabber Im MEDIUM 6.3
CVE-2013-1161

The XML parser in the Cisco Jabber IM application for Android allows remote authenticated users to cause a denial of service (blocked connection) by …

Mitigation only
Fix from $1,600 2013-03-26