Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Aim MEDIUM 5.8
CVE-2012-5816

AOL Instant Messenger (AIM) 1.0.1.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam…

No fix yet
Fix from $1,600 2012-11-04
Elephantdrive MEDIUM 5.8
CVE-2012-5818

ElephantDrive does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 c…

No fix yet
Fix from $1,600 2012-11-04
Admob MEDIUM 5.8
CVE-2012-5820

The developer-account sample code in Google AdMob does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or…

No fix yet
Fix from $1,600 2012-11-04
Opensourceclassifieds MEDIUM 5.8
CVE-2012-5823

Open Source Classifieds does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of t…

No fix yet
Fix from $1,600 2012-11-04
Tweepy MEDIUM 5.8
CVE-2012-5825

Tweepy does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certific…

No fix yet
Fix from $1,600 2012-11-04
Merchant Sdk MEDIUM 5.8
CVE-2012-5780

The Amazon merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of t…

No fix yet
Fix from $1,600 2012-11-04
Elastic Load Balancing MEDIUM 5.8
CVE-2012-5781

Amazon Elastic Load Balancing API Tools does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAl…

No fix yet
Fix from $1,600 2012-11-04
Flexible Payments Service MEDIUM 5.8
CVE-2012-5782

Amazon Flexible Payments Service (FPS) PHP Library does not verify that the server hostname matches a domain name in the subject's Common Name (CN) o…

No fix yet
Fix from $1,600 2012-11-04
Activemq MEDIUM 5.8
CVE-2012-5784EPSS 6%

Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service impleme…

Fix: after 5.7.0
Fix from $1,600 2012-11-04
Axis2 MEDIUM 5.8
CVE-2012-5785

Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam…

Fix: after 1.6.2
Fix from $1,600 2012-11-04
Cxf MEDIUM 5.8
CVE-2012-5786

The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that …

Fix: after 2.6.17
Fix from $1,600 2012-11-04
Merchant Sdk MEDIUM 5.8
CVE-2012-5787

The PayPal merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of t…

Patch available
Fix from $1,600 2012-11-04
Ipn MEDIUM 5.8
CVE-2012-5788

The PayPal IPN utility does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of th…

No fix yet
Fix from $1,600 2012-11-04
Payments Standard MEDIUM 5.8
CVE-2012-5789

PayPal Payments Standard PHP Library before 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN)…

No fix yet
Fix from $1,600 2012-11-04
Payments Standard MEDIUM 5.8
CVE-2012-5790

PayPal Payments Standard PHP Library 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or sub…

No fix yet
Fix from $1,600 2012-11-04
Invoicing MEDIUM 5.8
CVE-2012-5791

PayPal Invoicing does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.50…

No fix yet
Fix from $1,600 2012-11-04
Oscommerce MEDIUM 5.8
CVE-2012-5792

The Sage Pay Direct module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectA…

No fix yet
Fix from $1,600 2012-11-04
Authorize.net MEDIUM 5.8
CVE-2012-5793

The Authorize.Net module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAlt…

No fix yet
Fix from $1,600 2012-11-04
Moneybookers MEDIUM 5.8
CVE-2012-5794

The MoneyBookers module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltN…

No fix yet
Fix from $1,600 2012-11-04
Paypal Express Module MEDIUM 5.8
CVE-2012-5795

The PayPal Express module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAl…

No fix yet
Fix from $1,600 2012-11-04
Oscommerce MEDIUM 5.8
CVE-2012-5796

The PayPal Pro module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam…

No fix yet
Fix from $1,600 2012-11-04
Paypal Pro Payflow Module MEDIUM 5.8
CVE-2012-5797

The PayPal Pro PayFlow module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subje…

No fix yet
Fix from $1,600 2012-11-04
Oscommerce MEDIUM 5.8
CVE-2012-5798

The PayPal Pro PayFlow EC module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or su…

No fix yet
Fix from $1,600 2012-11-04
Prestashop MEDIUM 5.8
CVE-2012-5799

The Canada Post (aka CanadaPost) module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Name (CN…

No fix yet
Fix from $1,600 2012-11-04
Ebay Module MEDIUM 5.8
CVE-2012-5800

The eBay module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName fiel…

No fix yet
Fix from $1,600 2012-11-04
Pebble MEDIUM 5.8
CVE-2012-5170

Open redirect vulnerability in Pebble before 2.6.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via …

Fix: after 2.6.3
Fix from $1,600 2012-11-04
Intelligent Platforms Proficy Real Time Information Portal HIGH 10.0
CVE-2012-3010EPSS 5%

rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remote attack…

Mitigation only
Fix from $1,950 2012-11-01
Intelligent Platforms Proficy Real Time Information Portal HIGH 10.0
CVE-2012-3021EPSS 5%

rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remote attack…

Mitigation only
Fix from $1,950 2012-11-01
Intelligent Platforms Proficy Real Time Information Portal HIGH 10.0
CVE-2012-3026EPSS 5%

rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remote attack…

Mitigation only
Fix from $1,950 2012-11-01
Securelogin MEDIUM 5.8
CVE-2012-4489

Open redirect vulnerability in the securelogin_secure_redirect function in the Secure Login module 7.x-1.x before 7.x-1.3 for Drupal allows remote at…

Patch available
Fix from $1,600 2012-10-31