Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Powerconnect 6248p HIGH 7.8
CVE-2013-0120

The web interface on Dell PowerConnect 6248P switches allows remote attackers to cause a denial of service (device crash) via a malformed request.

Mitigation only
Fix from $1,950 2013-02-24
Enterprise Linux MEDIUM 6.2
CVE-2012-5536

A certain Red Hat build of the pam_ssh_agent_auth module on Red Hat Enterprise Linux (RHEL) 6 and Fedora Rawhide calls the glibc error function inste…

Patch available
Fix from $1,600 2013-02-22
Application Networking Manager MEDIUM 6.8
CVE-2013-1125

The command-line interface in Cisco Identity Services Engine Software, Secure Access Control System (ACS), Application Networking Manager (ANM), Prim…

Mitigation only
Fix from $1,600 2013-02-19
Linux Kernel MEDIUM 5.2
CVE-2013-0216

The Xen netback functionality in the Linux kernel before 3.7.8 allows guest OS users to cause a denial of service (loop) by triggering ring pointer c…

Fix: after 3.7.8
Fix from $1,600 2013-02-18
Nx Os MEDIUM 5.0
CVE-2013-1122

Cisco NX-OS on the Nexus 7000, when a certain Overlay Transport Virtualization (OTV) configuration is used, allows remote attackers to cause a denial…

Mitigation only
Fix from $1,600 2013-02-13
Zend Framework MEDIUM 6.4
CVE-2012-6531

(1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 do not properly handle SimpleXMLElement …

Mitigation only
Fix from $1,600 2013-02-13
Json Gem HIGH 7.5
CVE-2013-0269EPSS 14%

The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consump…

Mitigation only
Fix from $1,950 2013-02-13
Ircd Hybrid MEDIUM 5.0
CVE-2013-0238EPSS 10%

The try_parse_v4_netmask function in hostmask.c in IRCD-Hybrid before 8.0.6 does not properly validate masks, which allows remote attackers to cause …

Fix: after 8.0.5
Fix from $1,600 2013-02-13
PostgreSQL MEDIUM 6.8
CVE-2013-0255

PostgreSQL 9.2.x before 9.2.3, 9.1.x before 9.1.8, 9.0.x before 9.0.12, 8.4.x before 8.4.16, and 8.3.x before 8.3.23 does not properly declare the en…

Mitigation only
Fix from $1,600 2013-02-13
Workstation HIGH 7.2
CVE-2013-1406

The Virtual Machine Communication Interface (VMCI) implementation in vmci.sys in VMware Workstation 8.x before 8.0.5 and 9.x before 9.0.1 on Windows,…

Mitigation only
Fix from $1,950 2013-02-11
Rsa Archer Smartsuite MEDIUM 6.8
CVE-2012-2294

EMC RSA Archer SmartSuite Framework 4.x and RSA Archer GRC 5.x before 5.2SP1 allow remote attackers to conduct clickjacking attacks via a crafted web…

Mitigation only
Fix from $1,600 2013-02-06
Samba MEDIUM 5.1
CVE-2013-0213

The Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to conduct cli…

Mitigation only
Fix from $1,600 2013-02-02
Carrier Routing System MEDIUM 5.0
CVE-2013-1112

Cisco Carrier Routing System (CRS) allows remote attackers to cause a denial of service (packet loss) via short malformed packets that trigger ineffi…

Mitigation only
Fix from $1,600 2013-01-31
Infosphere Information Server MEDIUM 5.8
CVE-2012-0703

Open redirect vulnerability in Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 allows remote a…

Mitigation only
Fix from $1,600 2013-01-31
Infosphere Information Server HIGH 7.1
CVE-2012-0705

InfoSphere Import Export Manager in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP…

Mitigation only
Fix from $1,950 2013-01-31
Moodle MEDIUM 5.8
CVE-2012-6101

Multiple open redirect vulnerabilities in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to redirect us…

Mitigation only
Fix from $1,600 2013-01-27
Intelligent Platforms Proficy Hmi\/scada Cimplicity HIGH 9.3
CVE-2013-0654

CimWebServer in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote …

Mitigation only
Fix from $1,950 2013-01-27
Enterprise Linux Desktop HIGH 7.1
CVE-2012-5689EPSS 12%

ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA …

Mitigation only
Fix from $1,950 2013-01-25
Chrome HIGH 7.5
CVE-2013-0841

Array index error in the content-blocking functionality in Google Chrome before 24.0.1312.56 allows remote attackers to cause a denial of service or …

Fix: after 24.0.1312.55
Fix from $1,950 2013-01-24
Gnupg MEDIUM 5.8
CVE-2012-6085

The read_block function in g10/import.c in GnuPG 1.4.x before 1.4.13 and 2.0.x through 2.0.19, when importing a key, allows remote attackers to corru…

No fix yet
Fix from $1,600 2013-01-24
Call Of Duty Elite MEDIUM 5.8
CVE-2012-4918

Call of Duty Elite for iOS 2.0.1 does not properly validate the server SSL certificate, which allows remote attackers to obtain sensitive information…

Mitigation only
Fix from $1,600 2013-01-22
Software Update Utility HIGH 9.3
CVE-2013-0655

The client in Schneider Electric Software Update (SESU) Utility 1.0.x and 1.1.x does not ensure that updates have a valid origin, which allows man-in…

Mitigation only
Fix from $1,950 2013-01-21
Adaptive Security Appliance Software MEDIUM 6.3
CVE-2012-6395

Cisco Adaptive Security Appliances (ASA) devices with firmware 8.4 do not properly validate unspecified input related to UNC share pathnames, which a…

Mitigation only
Fix from $1,600 2013-01-18
Prime Lan Management Solution HIGH 10.0
CVE-2012-6392

Cisco Prime LAN Management Solution (LMS) 4.1 through 4.2.2 on Linux does not properly validate authentication and authorization requests in TCP sess…

Mitigation only
Fix from $1,950 2013-01-17
Chrome HIGH 7.5
CVE-2013-0837

Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related …

Fix: after 24.0.1312.51
Fix from $1,950 2013-01-15
Chrome HIGH 7.5
CVE-2012-5148

The hyphenation functionality in Google Chrome before 24.0.1312.52 does not properly validate file names, which has unspecified impact and attack vec…

Fix: after 24.0.1312.51
Fix from $1,950 2013-01-15
Chrome HIGH 7.5
CVE-2013-0830

The IPC layer in Google Chrome before 24.0.1312.52 on Windows omits a NUL character required for termination of an unspecified data structure, which …

Fix: after 24.0.1312.51
Fix from $1,950 2013-01-15
Rails HIGH 7.5
CVE-2013-0156EPSS 99%

active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does no…

Fix: 2.3.15 / 3.0.19+
Fix from $1,950 2013-01-13
Firefox HIGH 9.3
CVE-2013-0757EPSS 61%

The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird…

Fix: 2.15 / 17.0.2+
Fix from $1,950 2013-01-13
Firefox MEDIUM 6.8
CVE-2013-0747

The gPluginHandler.handleEvent function in the plugin handler in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0…

Fix: 2.15 / 17.0.2+
Fix from $1,600 2013-01-13