Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Esx MEDIUM 5.0
CVE-2012-5703

The vSphere API in VMware ESXi 4.1 and ESX 4.1 allows remote attackers to cause a denial of service (host daemon crash) via an invalid value in a (1)…

Mitigation only
Fix from $1,600 2012-11-20
Icecast MEDIUM 5.0
CVE-2011-4612

icecast before 2.3.3 allows remote attackers to inject control characters such as newlines into the error loc (error.log) via a crafted URL.

Fix: after 2.3.2
Fix from $1,600 2012-11-20
Django MEDIUM 6.4
CVE-2012-4520

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arb…

Patch available
Fix from $1,600 2012-11-18
Fleetcommander HIGH 7.5
CVE-2012-4945

Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to execute arbitrary commands via unspecified vectors, related to a …

Fix: after 4.0
Fix from $1,950 2012-11-18
Tomcat MEDIUM 5.0
CVE-2012-2733EPSS 9%

java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not…

Mitigation only
Fix from $1,600 2012-11-16
Websphere Application Server HIGH 7.5
CVE-2012-4850

IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1, when JAX-RS is used, does not properly validate requests, which allows remote at…

Mitigation only
Fix from $1,950 2012-11-14
Bcm4325 HIGH 7.8
CVE-2012-2619EPSS 13%

The Broadcom BCM4325 and BCM4329 Wi-Fi chips, as used in certain Acer, Apple, Asus, Ford, HTC, Kyocera, LG, Malata, Motorola, Nokia, Pantech, Samsung…

Fix: after 6.0.2
Fix from $1,950 2012-11-14
.net Framework HIGH 9.3
CVE-2012-4776EPSS 25%

The Web Proxy Auto-Discovery (WPAD) functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not validate configuration data th…

Mitigation only
Fix from $1,950 2012-11-14
Secure Access Control Server MEDIUM 5.0
CVE-2012-5424

Cisco Secure Access Control System (ACS) 5.x before 5.2 Patch 11 and 5.3 before 5.3 Patch 7, when a certain configuration involving TACACS+ and LDAP …

Mitigation only
Fix from $1,600 2012-11-07
Chrome HIGH 7.5
CVE-2012-5118

Google Chrome before 23.0.1271.64 on Mac OS X does not properly validate an integer value during the handling of GPU command buffers, which allows re…

Fix: after 23.0.1271.62
Fix from $1,950 2012-11-07
Services Twitter MEDIUM 5.8
CVE-2011-5241

Services_Twitter 0.6.3 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of th…

Mitigation only
Fix from $1,600 2012-11-06
Tmhoauth MEDIUM 5.8
CVE-2011-5242

tmhOAuth before 0.61 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the …

Fix: after 0.60
Fix from $1,600 2012-11-06
Twitteroauth MEDIUM 5.8
CVE-2011-5243

TwitterOAuth does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 ce…

Mitigation only
Fix from $1,600 2012-11-06
Eselect Plus MEDIUM 5.8
CVE-2011-5236

Moneris eSelectPlus 2.03 PHP API does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName f…

Mitigation only
Fix from $1,600 2012-11-06
Wps Toolkit MEDIUM 5.8
CVE-2011-5237

PayPal WPS ToolKit does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.…

Mitigation only
Fix from $1,600 2012-11-06
Checkout Php MEDIUM 5.8
CVE-2011-5238

google-checkout-php-sample-code before 1.3.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subj…

Fix: after 1.3.1
Fix from $1,600 2012-11-06
Civicrm MEDIUM 5.8
CVE-2011-5239

CiviCRM 4.0.5 and 4.1.1 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of t…

Mitigation only
Fix from $1,600 2012-11-06
Magento MEDIUM 5.8
CVE-2011-5240

Magento 1.5 and 1.6.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the…

Mitigation only
Fix from $1,600 2012-11-06
Ebay MEDIUM 5.8
CVE-2012-5801

The PayPal module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName fi…

No fix yet
Fix from $1,600 2012-11-04
Paypal MEDIUM 5.8
CVE-2012-5802

The PayPal module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName fiel…

No fix yet
Fix from $1,600 2012-11-04
Authorize.net Module MEDIUM 5.8
CVE-2012-5803

The Authorize.Net module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNa…

No fix yet
Fix from $1,600 2012-11-04
Cybersource MEDIUM 5.8
CVE-2012-5804

The CyberSource module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName…

No fix yet
Fix from $1,600 2012-11-04
Instant Payment Notification MEDIUM 5.8
CVE-2012-5805

The PayPal IPN functionality in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectA…

No fix yet
Fix from $1,600 2012-11-04
Payments Pro MEDIUM 5.8
CVE-2012-5806

The PayPal Payments Pro module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjec…

No fix yet
Fix from $1,600 2012-11-04
Authorize.net Echeck Module MEDIUM 5.8
CVE-2012-5807

The Authorize.Net eCheck module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subje…

No fix yet
Fix from $1,600 2012-11-04
Linkpoint MEDIUM 5.8
CVE-2012-5808

The LinkPoint module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName f…

No fix yet
Fix from $1,600 2012-11-04
Acra Library MEDIUM 5.8
CVE-2012-5812

The ACRA library for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field…

No fix yet
Fix from $1,600 2012-11-04
Android Pusher MEDIUM 5.8
CVE-2012-5813

The Android_Pusher library for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAlt…

No fix yet
Fix from $1,600 2012-11-04
Gaug.es MEDIUM 5.8
CVE-2012-5814

Weberknecht, as used in GitHub Gaug.es and other products, does not verify that the server hostname matches a domain name in the subject's Common Nam…

No fix yet
Fix from $1,600 2012-11-04
Rackspace MEDIUM 5.8
CVE-2012-5815

The Rackspace app 2.1.5 for iOS does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName fi…

No fix yet
Fix from $1,600 2012-11-04