Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Subscription Manager MEDIUM 6.4
CVE-2011-5136

showImg.php in EPractize Labs Subscription Manager, possibly 1.0, allows remote attackers to overwrite arbitrary files via the db parameter.

No fix yet
Fix from $1,600 2012-08-30
Websphere Application Server MEDIUM 6.0
CVE-2012-3325

IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.5, and 8.5.x Full Profile before 8.5.0.1, whe…

Mitigation only
Fix from $1,600 2012-08-30
Munin MEDIUM 6.8
CVE-2012-2104EPSS 5%

cgi-bin/munin-cgi-graph in Munin 2.x writes data to a log file without sanitizing non-printable characters, which might allow user-assisted remote at…

No fix yet
Fix from $1,600 2012-08-26
Libgdata MEDIUM 5.1
CVE-2012-1177

libgdata before 0.10.2 and 0.11.x before 0.11.1 does not validate SSL certificates, which allows remote attackers to obtain user names and passwords …

Fix: after 0.11.0
Fix from $1,600 2012-08-26
Tunnelblick HIGH 7.2
CVE-2012-3485

Tunnelblick 3.3beta20 and earlier relies on argv[0] to determine the name of an appropriate (1) kernel module pathname or (2) executable file pathnam…

Fix: after 3.3beta20
Fix from $1,950 2012-08-26
Comodo Internet Security HIGH 10.0
CVE-2010-5185

The Antivirus component in Comodo Internet Security before 5.3.174622.1216 does not check whether X.509 certificates in signed executable files have …

Fix: after 5.0.163652.1142
Fix from $1,950 2012-08-26
Tigase Xmpp Server MEDIUM 6.4
CVE-2012-4670

Tigase XMPP Server before 5.1.0 does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spo…

Fix: after 5.1.0
Fix from $1,600 2012-08-25
Psyced MEDIUM 5.8
CVE-2012-4671

psyced before 20120821 does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domain…

Fix: after 20111122
Fix from $1,600 2012-08-25
Ichat Server MEDIUM 5.8
CVE-2012-4672

Apple iChat Server does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains vi…

Mitigation only
Fix from $1,600 2012-08-25
Jabberd2 MEDIUM 5.8
CVE-2012-3525

s2s/out.c in jabberd2 2.2.16 and earlier does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP serve…

Fix: after 2.2.16
Fix from $1,600 2012-08-25
M Link MEDIUM 5.8
CVE-2012-4669

M-Link R14.6 before R14.6v14 and R15.1 before R15.1v10 does not verify that a request was made for an XMPP Server Dialback response, which allows rem…

Mitigation only
Fix from $1,600 2012-08-25
Enterprise MEDIUM 5.0
CVE-2008-7312

The Filtering Service in Websense Enterprise 5.2 through 6.3 does not consider the IP address during URL categorization, which makes it easier for re…

Mitigation only
Fix from $1,600 2012-08-23
Ffmpeg MEDIUM 6.8
CVE-2011-3952

The decode_init function in kmvc.c in libavcodec in FFmpeg before 0.10 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0…

Fix: after 0.9.1
Fix from $1,600 2012-08-20
Ffmpeg MEDIUM 6.8
CVE-2012-0853

The decodeTonalComponents function in the Actrac3 codec (atrac3.c) in libavcodec in FFmpeg 0.7.x before 0.7.12, and 0.8.x before 0.8.11; and in Libav…

No fix yet
Fix from $1,600 2012-08-20
Winlog Pro HIGH 9.3
CVE-2012-4359

Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 do not validate the return value of the realloc function, which a…

Fix: after 2.07.17
Fix from $1,950 2012-08-19
Winlog Pro HIGH 9.3
CVE-2012-4357EPSS 7%

Array index error in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 might allow remote attackers to execute arbi…

Fix: after 2.07.16
Fix from $1,950 2012-08-19
Winlog Pro HIGH 9.3
CVE-2012-4358

Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 do not validate the return value of the realloc function, which a…

Fix: after 2.07.16
Fix from $1,950 2012-08-19
Enterprise Linux Desktop HIGH 7.8
CVE-2012-1535 KEVEPSS 70%

Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers …

Fix: 11.2.202.238 / 11.3.300.271+
Fix from $1,950 2012-08-15
Fivestar Module For Drupal MEDIUM 5.0
CVE-2012-2096

The Fivestar module 6.x-1.x before 6.x-1.20 for Drupal does not properly validate voting data, which allows remote attackers to manipulate voting ave…

Patch available
Fix from $1,600 2012-08-14
Node.js MEDIUM 6.4
CVE-2012-2330

The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allo…

Fix: after 0.6.16
Fix from $1,600 2012-08-13
Symbiosis MEDIUM 5.0
CVE-2012-2368

Bytemark Symbiosis before Revision 1322 does not properly validate passwords, which allows remote attackers to gain access to email accounts via an a…

Fix: after 1321
Fix from $1,600 2012-08-13
Breakingpoint Storm Appliance Ctm MEDIUM 5.0
CVE-2012-2964

The BreakingPoint Storm appliance before 3.0 requires cleartext credentials for establishing a session from a GUI administrative client, which allows…

Fix: after 2.0
Fix from $1,600 2012-08-12
Resin HIGH 7.5
CVE-2012-2965

Caucho Quercus, as distributed in Resin before 4.0.29, does not properly handle unspecified characters in the names of variables, which has unknown i…

Fix: after 4.0.28
Fix from $1,950 2012-08-12
Linux Kernel HIGH 7.2
CVE-2012-2136

The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before 3.4.5 does not properly validate a certain length value, which allows…

Fix: 3.0.37 / 3.2.23+
Fix from $1,950 2012-08-09
Global Security Kit MEDIUM 5.0
CVE-2012-2191

IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, does…

Fix: after 8.0.13
Fix from $1,600 2012-08-08
Bind Dyndb Ldap MEDIUM 5.0
CVE-2012-3429

The dns_to_ldap_dn_escape function in src/ldap_convert.c in bind-dyndb-ldap 1.1.0rc1 and earlier does not properly escape distinguished names (DN) fo…

Fix: after 1.1.0
Fix from $1,600 2012-08-07
Ip Communicator MEDIUM 5.0
CVE-2012-2490

Cisco IP Communicator 8.6 allows man-in-the-middle attackers to modify the Certificate Trust List via unspecified vectors, aka Bug ID CSCtz01471.

No fix yet
Fix from $1,600 2012-08-06
Kerberos 5 HIGH 9.3
CVE-2012-1015

The kdc_handle_protected_negotiation function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8.x, 1.9.x before 1.9.5, and 1.10.x…

Patch available
Fix from $1,950 2012-08-06
iOS MEDIUM 5.0
CVE-2012-1367

The MallocLite implementation in Cisco IOS 12.0, 12.2, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (Route Processor cra…

No fix yet
Fix from $1,600 2012-08-06
Django MEDIUM 5.0
CVE-2012-3443

The django.forms.ImageField class in the form system in Django before 1.3.2 and 1.4.x before 1.4.1 completely decompresses image data during image va…

Fix: after 1.3
Fix from $1,600 2012-07-31