Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Ubercart Securetrading Payment Method Module MEDIUM 5.0
CVE-2012-4482

The Ubercart SecureTrading Payment Method module 6.x for Drupal does not properly verify payment notification information, which allows remote attack…

Mitigation only
Fix from $1,600 2012-10-31
Unclassified MEDIUM 5.0
CVE-2012-2972

The (1) server and (2) agent components in CA ARCserve Backup r12.5, r15, and r16 on Windows do not properly validate RPC requests, which allows remo…

No fix yet
Fix from $1,600 2012-10-20
Ubuntu Software Properties MEDIUM 5.8
CVE-2012-5356

The apt-add-repository tool in Ubuntu Software Properties 0.75.x before 0.75.10.3, 0.80.x before 0.80.9.2, 0.81.x before 0.81.13.5, 0.82.x before 0.8…

Mitigation only
Fix from $1,600 2012-10-10
Midnight Commander MEDIUM 5.1
CVE-2012-4463

Midnight Commander (mc) 4.8.5 does not properly handle the (1) MC_EXT_SELECTED or (2) MC_EXT_ONLYTAGGED environment variables when multiple files are…

Mitigation only
Fix from $1,600 2012-10-10
Openttd MEDIUM 5.0
CVE-2012-3436

OpenTTD 0.6.0 through 1.2.1 does not properly validate requests to clear a water tile, which allows remote attackers to cause a denial of service (NU…

No fix yet
Fix from $1,600 2012-10-09
Tikiwiki Cms\/groupware MEDIUM 5.8
CVE-2012-5321EPSS 14%

tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attack…

No fix yet
Fix from $1,600 2012-10-08
Lotus Notes Traveler MEDIUM 5.8
CVE-2012-4824

Open redirect vulnerability in servlet/traveler in IBM Lotus Notes Traveler 8.5.3 before 8.5.3.3 Interim Fix 1 allows remote attackers to redirect us…

No fix yet
Fix from $1,600 2012-10-08
Joomla\! MEDIUM 5.0
CVE-2011-4911

Joomla! before 1.5.12 does not perform a JEXEC check in unspecified files, which allows remote attackers to obtain the installation path via unspecif…

Fix: after 1.5.11
Fix from $1,600 2012-10-07
Tivoli Federated Identity Manager MEDIUM 5.8
CVE-2012-3314

IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1, 6.2.0, 6.2.1, and 6.2.2 allow rem…

Patch available
Fix from $1,600 2012-10-02
Ocportal MEDIUM 5.8
CVE-2012-5234

Open redirect vulnerability in index.php in ocPortal before 7.1.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishi…

Fix: after 7.1.5
Fix from $1,600 2012-10-01
Devscripts HIGH 7.5
CVE-2012-2240

scripts/dscverify.pl in devscripts before 2.12.3 allows remote attackers to execute arbitrary commands via unspecified vectors related to "arguments …

Fix: after 2.12.2
Fix from $1,950 2012-10-01
Devscripts MEDIUM 5.0
CVE-2012-2241

scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete arbitrary files via a crafted (1) .dsc or (2) .changes file, probably r…

Fix: after 2.12.2
Fix from $1,600 2012-10-01
Devscripts MEDIUM 6.8
CVE-2012-2242

scripts/dget.pl in devscripts before 2.10.73 allows remote attackers to execute arbitrary commands via a crafted (1) .dsc or (2) .changes file, relat…

Fix: after 2.10.72
Fix from $1,600 2012-10-01
Optima Plc HIGH 7.8
CVE-2012-5049

APIFTP Server in Optimalog Optima PLC 1.5.2 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

Fix: after 1.5.2
Fix from $1,950 2012-09-28
Ios Xe HIGH 7.8
CVE-2012-4623

The DHCPv6 server in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x, 3.1.xS before 3.1.4S, 3.1.xSG and 3.2.xSG befo…

Mitigation only
Fix from $1,950 2012-09-27
Unified Communications Manager HIGH 7.8
CVE-2012-3949

The SIP implementation in Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su5, 8.x before 8.5(1)su4, and 8.6 before 8.6(2a)su1;…

Mitigation only
Fix from $1,950 2012-09-27
iOS HIGH 7.1
CVE-2012-4617

The BGP implementation in Cisco IOS 15.2, IOS XE 3.5.xS before 3.5.2S, and IOS XR 4.1.0 through 4.2.2 allows remote attackers to cause a denial of se…

Mitigation only
Fix from $1,950 2012-09-27
Chrome MEDIUM 5.0
CVE-2012-2877

The extension system in Google Chrome before 22.0.1229.79 does not properly handle modal dialogs, which allows remote attackers to cause a denial of …

Fix: after 22.0.1229.78
Fix from $1,600 2012-09-26
Chrome MEDIUM 6.8
CVE-2012-2882

FFmpeg, as used in Google Chrome before 22.0.1229.79, does not properly handle OGG containers, which allows remote attackers to cause a denial of ser…

Fix: after 22.0.1229.78
Fix from $1,600 2012-09-26
Secure Desktop HIGH 9.3
CVE-2012-4655

The WebLaunch feature in Cisco Secure Desktop before 3.6.6020 does not properly validate binaries that are received by the downloader process, which …

Mitigation only
Fix from $1,950 2012-09-24
Mac Os X MEDIUM 6.8
CVE-2012-3719

Mail in Apple Mac OS X before 10.7.5 does not properly handle embedded web plugins, which allows remote attackers to execute arbitrary plugin code vi…

Fix: after 10.7.4
Fix from $1,600 2012-09-20
Mr804 Firmware MEDIUM 6.1
CVE-2012-4999EPSS 7%

Mercury MR804 Router 8.0 3.8.1 Build 101220 Rel.53006nB allows remote attackers to cause a denial of service (service hang) via a crafted string in H…

No fix yet
Fix from $1,600 2012-09-19
Silverstripe MEDIUM 6.8
CVE-2011-4962

code/sitefeatures/PageCommentInterface.php in SilverStripe 2.4.x before 2.4.6 might allow remote attackers to execute arbitrary code via a crafted co…

Patch available
Fix from $1,600 2012-09-17
Mod Pagespeed MEDIUM 5.0
CVE-2012-4001

The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger…

Fix: after 0.10.22.4
Fix from $1,600 2012-09-15
Tor MEDIUM 5.0
CVE-2012-4922

The tor_timegm function in common/util.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.22-rc, does not properly validate time values, which allows…

Fix: after 0.2.2.38
Fix from $1,600 2012-09-14
Mymesyuarat MEDIUM 6.0
CVE-2012-3572

Open Source Competency Center (OSCC) MyMeeting 3.0.1 and earlier, and MyMesyuarat 09b-1, does not properly verify uploaded documents, which allows re…

Fix: after 3.0.1
Fix from $1,600 2012-09-11
Webmin MEDIUM 6.0
CVE-2012-2981

Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary Perl code via a crafted file associated with the type (aka monitor ty…

Fix: after 1.590
Fix from $1,600 2012-09-11
Horizon MEDIUM 5.8
CVE-2012-3540

Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbit…

Patch available
Fix from $1,600 2012-09-05
X.org HIGH 8.5
CVE-2010-4818EPSS 5%

The GLX extension in X.Org xserver 1.7.7 allows remote authenticated users to cause a denial of service (server crash) and possibly execute arbitrary…

Patch available
Fix from $1,950 2012-09-05
TYPO3 MEDIUM 5.0
CVE-2012-1608

The t3lib_div::RemoveXSS API method in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to…

Mitigation only
Fix from $1,600 2012-09-04