Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Age Verification MEDIUM 5.8
CVE-2012-6499EPSS 11%

Open redirect vulnerability in age-verification.php in the Age Verification plugin 0.4 and earlier for WordPress allows remote attackers to redirect …

Fix: after 0.4
Fix from $1,600 2013-01-12
Orchard MEDIUM 5.8
CVE-2011-5252EPSS 12%

Open redirect vulnerability in Users/Account/LogOff in Orchard 1.0.x before 1.0.21, 1.1.x before 1.1.31, 1.2.x before 1.2.42, and 1.3.x before 1.3.10…

No fix yet
Fix from $1,600 2013-01-12
.net Framework HIGH 9.3
CVE-2013-0004EPSS 21%

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate the permissions of objects in memory, …

Mitigation only
Fix from $1,950 2013-01-09
.net Framework HIGH 7.8
CVE-2013-0005EPSS 32%

The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Managem…

Mitigation only
Fix from $1,950 2013-01-09
Drupal MEDIUM 6.0
CVE-2012-5653

The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execut…

Patch available
Fix from $1,600 2013-01-03
Opera Browser MEDIUM 5.0
CVE-2012-6461

The X.509 certificate-validation functionality in the https implementation in Opera before 12.10 allows remote attackers to trigger a false indicatio…

Fix: after 12.10
Fix from $1,600 2013-01-02
Vbulletin MEDIUM 5.8
CVE-2011-5251

Open redirect vulnerability in forum/login.php in vBulletin 4.1.3 and earlier allows remote attackers to redirect users to arbitrary web sites and co…

Fix: after 4.1.3
Fix from $1,600 2012-12-31
Security Appscan MEDIUM 5.8
CVE-2012-0738

IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during scanning, which al…

Fix: after 8.6.0.1
Fix from $1,600 2012-12-28
Security Appscan MEDIUM 5.8
CVE-2012-0741

IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during use of the Manual …

Fix: after 8.6.0.1
Fix from $1,600 2012-12-28
Skinny Client Control Protocol Software MEDIUM 6.8
CVE-2012-5445

The kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software before 9.3.1-ES10 does not properl…

Fix: after 9.2
Fix from $1,600 2012-12-28
Squid MEDIUM 5.0
CVE-2012-5643EPSS 23%

Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x before 3.1.22, 3.2.x before 3.2.4, and 3.3.x before 3.3.0.2 allow rem…

Patch available
Fix from $1,600 2012-12-20
Endpoint Protection HIGH 7.2
CVE-2012-4348

The management console in Symantec Endpoint Protection (SEP) 11.0 before RU7-MP3 and 12.1 before RU2, and Symantec Endpoint Protection Small Business…

Mitigation only
Fix from $1,950 2012-12-18
Owncloud MEDIUM 6.5
CVE-2012-5610

Incomplete blacklist vulnerability in lib/filesystem.php in ownCloud before 4.0.9 and 4.5.x before 4.5.2 allows remote authenticated users to execute…

Fix: after 4.0.8
Fix from $1,600 2012-12-18
Xen MEDIUM 6.9
CVE-2012-5513

The XENMEM_exchange handler in Xen 4.2 and earlier does not properly check the memory address, which allows local PV guest OS administrators to cause…

Fix: after 4.2.0
Fix from $1,600 2012-12-13
Android MEDIUM 5.0
CVE-2012-6301EPSS 6%

The Browser application in Android 4.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted market: URI in the SR…

No fix yet
Fix from $1,600 2012-12-10
Ubuntu Linux HIGH 7.8
CVE-2012-5688EPSS 11%

ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled, allows remote attackers to cause a denial of service (assertion fail…

Patch available
Fix from $1,950 2012-12-06
Wireshark MEDIUM 5.0
CVE-2012-6059

The dissect_isakmp function in epan/dissectors/packet-isakmp.c in the ISAKMP dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 uses a…

No fix yet
Fix from $1,600 2012-12-05
Wireshark MEDIUM 5.0
CVE-2012-6062

The dissect_rtcp_app function in epan/dissectors/packet-rtcp.c in the RTCP dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 allows r…

Patch available
Fix from $1,600 2012-12-05
Counteract MEDIUM 5.8
CVE-2012-4982EPSS 9%

Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to arbitrary …

Mitigation only
Fix from $1,600 2012-12-05
Weechat HIGH 7.5
CVE-2012-5534

The hook_process function in the plugin API for WeeChat 0.3.0 through 0.3.9.1 allows remote attackers to execute arbitrary commands via shell metacha…

Patch available
Fix from $1,950 2012-12-03
Chrome MEDIUM 6.8
CVE-2012-5136

Google Chrome before 23.0.1271.91 does not properly perform a cast of an unspecified variable during handling of the INPUT element, which allows remo…

Fix: after 23.0.1271.89
Fix from $1,600 2012-11-28
Openvas Manager HIGH 7.5
CVE-2012-5520

The send_to_sourcefire function in manage_sql.c in OpenVAS Manager 3.x before 3.0.4 allows remote attackers to execute arbitrary commands via the (1)…

Patch available
Fix from $1,950 2012-11-26
Mahara MEDIUM 6.8
CVE-2012-2246

Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to conduct clickjacking attacks to delete arbitrary users and bypass CSRF pr…

Mitigation only
Fix from $1,600 2012-11-24
Unity Firefox Extension HIGH 7.5
CVE-2012-0960

Unity integration extension (unity-firefox-extension) before 2.4.1 for Firefox does not properly handle callbacks, which allows remote attackers to c…

Fix: after 2.4.0
Fix from $1,950 2012-11-24
Xen HIGH 7.2
CVE-2012-6030

The do_tmem_op function in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 allow local guest OS users to cause a denial of service (host cras…

Mitigation only
Fix from $1,950 2012-11-23
Xen MEDIUM 6.9
CVE-2012-6035

The do_tmem_destroy_pool function in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 does not properly validate pool ids, which allows local …

Mitigation only
Fix from $1,600 2012-11-23
Xenserver MEDIUM 6.1
CVE-2012-3495

The physdev_get_free_pirq hypercall in arch/x86/physdev.c in Xen 4.1.x and Citrix XenServer 6.0.2 and earlier uses the return value of the get_free_p…

Fix: after 6.0.2
Fix from $1,600 2012-11-23
Xen MEDIUM 6.9
CVE-2012-3497

(1) TMEMC_SAVE_GET_CLIENT_WEIGHT, (2) TMEMC_SAVE_GET_CLIENT_CAP, (3) TMEMC_SAVE_GET_CLIENT_FLAGS and (4) TMEMC_SAVE_END in the Transcendent Memory (T…

Mitigation only
Fix from $1,600 2012-11-23
Xenserver MEDIUM 5.6
CVE-2012-3498

PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6.0.2 and earlier allows local HVM guest OS kernels to cause a denial of service (host cra…

Fix: after 6.0.2
Fix from $1,600 2012-11-23
Virtualization HIGH 7.2
CVE-2012-3515

Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users…

Fix: 1.2.0+
Fix from $1,950 2012-11-23