Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Ios Xr MEDIUM 5.0
CVE-2013-1162

The traffic engineering (TE) processing subsystem in Cisco IOS XR allows remote attackers to cause a denial of service (process restart) via crafted …

Mitigation only
Fix from $1,600 2013-03-26
Linux Kernel MEDIUM 6.2
CVE-2013-1798

The ioapic_read_indirect function in virt/kvm/ioapic.c in the Linux kernel through 3.8.4 does not properly handle a certain combination of invalid IO…

Fix: after 3.8.4
Fix from $1,600 2013-03-22
Linux Kernel MEDIUM 6.9
CVE-2013-1828

The sctp_getsockopt_assoc_stats function in net/sctp/socket.c in the Linux kernel before 3.8.4 does not validate a size value before proceeding to a …

Fix: 3.8.4+
Fix from $1,600 2013-03-22
Linux Kernel MEDIUM 6.2
CVE-2013-1848

fs/ext3/super.c in the Linux kernel before 3.8.4 uses incorrect arguments to functions in certain circumstances related to printk input, which allows…

Fix: after 3.8.3
Fix from $1,600 2013-03-22
Matomo MEDIUM 5.0
CVE-2013-2633

Piwik before 1.11 accepts input from a POST request instead of a GET request in unspecified circumstances, which might allow attackers to obtain sens…

Fix: after 1.10.1
Fix from $1,600 2013-03-21
2010 HIGH 7.5
CVE-2013-2279

CA SiteMinder Federation (FSS) 12.5, 12.0, and r6; Federation (Standalone) 12.1 and 12.0; Agent for SharePoint 2010; and SiteMinder for Secure Proxy …

Mitigation only
Fix from $1,950 2013-03-21
Vxworks HIGH 7.8
CVE-2013-0711

IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote attackers to cause a denial of service (daemon outage) via a crafted a…

Mitigation only
Fix from $1,950 2013-03-20
Vxworks MEDIUM 6.8
CVE-2013-0712

IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote authenticated users to cause a denial of service (daemon outage) via a…

Mitigation only
Fix from $1,600 2013-03-20
Vxworks MEDIUM 6.8
CVE-2013-0713

IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote authenticated users to cause a denial of service (daemon outage) via a…

Mitigation only
Fix from $1,600 2013-03-20
Vxworks HIGH 10.0
CVE-2013-0714EPSS 6%

IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote attackers to execute arbitrary code or cause a denial of service (daem…

Mitigation only
Fix from $1,950 2013-03-20
Vxworks MEDIUM 5.0
CVE-2013-0716

The web server in Wind River VxWorks 5.5 through 6.9 allows remote attackers to cause a denial of service (daemon crash) via a crafted URI.

Mitigation only
Fix from $1,600 2013-03-20
Puppet HIGH 7.5
CVE-2013-1655

Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via vectors re…

Mitigation only
Fix from $1,950 2013-03-20
Rails MEDIUM 5.0
CVE-2013-1854

The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by convertin…

Mitigation only
Fix from $1,600 2013-03-19
Rails MEDIUM 5.8
CVE-2013-1856

The ActiveSupport::XmlMini_JDOM backend in lib/active_support/xml_mini/jdom.rb in the Active Support component in Ruby on Rails 3.0.x and 3.1.x befor…

Mitigation only
Fix from $1,600 2013-03-19
Sterling Multi Channel Fulfillment Solution MEDIUM 5.5
CVE-2013-0505

IBM Sterling Order Management 8.0 before HF127, 8.5 before HF89, 9.0 before HF69, 9.1.0 before FP41, and 9.2.0 before FP13 allows remote authenticate…

Mitigation only
Fix from $1,600 2013-03-19
Boost MEDIUM 5.0
CVE-2013-0252

boost::locale::utf::utf_traits in the Boost.Locale library in Boost 1.48 through 1.52 does not properly detect certain invalid UTF-8 sequences, which…

Mitigation only
Fix from $1,600 2013-03-12
Privoxy MEDIUM 5.8
CVE-2013-2503

Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and Proxy-Authorization headers in the client-server data stream, which makes it ea…

Fix: after 3.0.20
Fix from $1,600 2013-03-11
Wireshark MEDIUM 5.0
CVE-2013-2488

The DTLS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not validate the fragment offset before invoking the reassembly state…

Mitigation only
Fix from $1,600 2013-03-07
Dovecot MEDIUM 5.8
CVE-2011-4318

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server ho…

Mitigation only
Fix from $1,600 2013-03-07
Dbus Glib HIGH 7.2
CVE-2013-0292

The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, …

Fix: after 0.100
Fix from $1,950 2013-03-05
Enterprise Linux Desktop MEDIUM 5.0
CVE-2012-3411EPSS 5%

Dnsmasq before 2.63test1, when used with certain libvirt configurations, replies to requests from prohibited interfaces, which allows remote attacker…

Fix: after 2.62
Fix from $1,600 2013-03-05
Dnsmasq MEDIUM 5.0
CVE-2013-0198

Dnsmasq before 2.66test2, when used with certain libvirt configurations, replies to queries from prohibited interfaces, which allows remote attackers…

Fix: after 2.65
Fix from $1,600 2013-03-05
Cognos Business Intelligence HIGH 9.3
CVE-2012-4858

IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 does not properly validate Java seria…

Mitigation only
Fix from $1,950 2013-03-05
Linux Kernel HIGH 7.2
CVE-2013-1763

Array index error in the __sock_diag_rcv_msg function in net/core/sock_diag.c in the Linux kernel before 3.7.10 allows local users to gain privileges…

Fix: 3.4.34 / 3.7.10+
Fix from $1,950 2013-02-28
Unified Communications Manager HIGH 7.8
CVE-2013-1133

Cisco Unified Communications Manager (CUCM) 8.6 before 8.6(2a)su2, 8.6 BE3k before 8.6(4) BE3k, and 9.x before 9.0(1) allows remote attackers to caus…

Mitigation only
Fix from $1,950 2013-02-27
Prime Central For Hosted Collaboration Solution Assurance HIGH 7.1
CVE-2013-1135

Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.0 allows remote attackers to cause a denial of service (CPU consumpti…

Mitigation only
Fix from $1,950 2013-02-27
Jenkins MEDIUM 5.8
CVE-2012-6073

Open redirect vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.4…

Fix: after 1.466.2
Fix from $1,600 2013-02-24
Openshift MEDIUM 5.8
CVE-2012-5647

Open redirect vulnerability in node-util/www/html/restorer.php in Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to redirect users t…

Fix: after 1.0.5
Fix from $1,600 2013-02-24
Openshift HIGH 7.5
CVE-2012-5646

node-util/www/html/restorer.php in the Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to execute arbitrary commands via a crafted uu…

Fix: after 1.0.5
Fix from $1,950 2013-02-24
Codesys Gateway Server HIGH 10.0
CVE-2012-4704

Array index error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted packet.

Fix: after 2.3.9.20
Fix from $1,950 2013-02-24