Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Safari MEDIUM 5.8
CVE-2012-3689

WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to bypass the Same Origi…

Fix: after 5.1.7
Fix from $1,600 2012-07-25
Safari MEDIUM 5.8
CVE-2012-3691

WebKit in Apple Safari before 6.0 does not properly handle Cascading Style Sheets (CSS) property values, which allows remote attackers to bypass the …

Fix: after 5.1.7
Fix from $1,600 2012-07-25
Bind HIGH 7.8
CVE-2012-3817EPSS 27%

ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC …

Mitigation only
Fix from $1,950 2012-07-25
Mail Gem HIGH 7.5
CVE-2012-2140

The Mail gem before 2.4.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) sendmail or (2) exim deliv…

Fix: after 2.4.1
Fix from $1,950 2012-07-18
Websitepanel MEDIUM 5.8
CVE-2012-4032EPSS 10%

Open redirect vulnerability in the login page in WebsitePanel before 1.2.2.1 allows remote attackers to redirect users to arbitrary web sites and con…

Fix: after 1.2.1
Fix from $1,600 2012-07-17
Moodle MEDIUM 6.5
CVE-2012-0795

Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 does not validate e-mail address settings, which allows re…

Mitigation only
Fix from $1,600 2012-07-17
Moodle HIGH 7.5
CVE-2012-0801

lib/formslib.php in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 does not properly handle multiple instances of a form element, which has unspeci…

Mitigation only
Fix from $1,950 2012-07-17
Pegasys P2000 Server Software MEDIUM 5.0
CVE-2012-4026

The Johnson Controls Pegasys P2000 server with software before 3.11 allows remote attackers to trigger false alerts via crafted packets to TCP port 4…

Fix: after 3.10
Fix from $1,600 2012-07-16
Moodle MEDIUM 5.8
CVE-2011-4294

The error-message functionality in Moodle 1.9.x before 1.9.13, 2.0.x before 2.0.4, and 2.1.x before 2.1.1 does not ensure that a continuation link re…

Mitigation only
Fix from $1,600 2012-07-16
Rsa Authentication Manager MEDIUM 6.4
CVE-2012-2279

Open redirect vulnerability in the Security Console in EMC RSA Authentication Manager 7.1 before SP4 P14 and RSA SecurID Appliance 3.0 before SP4 P14…

Fix: after 7.1
Fix from $1,600 2012-07-13
Basilic HIGH 7.5
CVE-2012-3399EPSS 65%

Config/diff.php in Basilic 1.5.14 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter.

No fix yet
Fix from $1,950 2012-07-12
Moodle MEDIUM 6.8
CVE-2011-4302

mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value o…

Patch available
Fix from $1,600 2012-07-11
Sharepoint Server MEDIUM 6.8
CVE-2012-1862EPSS 11%

Open redirect vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 allows remote attackers to redirect users to arbitrary web sites a…

Mitigation only
Fix from $1,600 2012-07-10
Pidgin MEDIUM 5.0
CVE-2012-2318

msg.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.4 does not properly handle crafted characters, which allows remote servers to cau…

Fix: after 2.10.3
Fix from $1,600 2012-07-03
Tm Ac1900 MEDIUM 6.8
CVE-2011-2716

The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_N…

Fix: after 1.19.4
Fix from $1,600 2012-07-03
WordPress MEDIUM 5.0
CVE-2011-4957

The make_clickable function in wp-includes/formatting.php in WordPress before 3.1.1 does not properly check URLs before passing them to the PCRE libr…

Fix: after 3.1
Fix from $1,600 2012-06-27
Chrome MEDIUM 5.0
CVE-2012-2825

The XSL implementation in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service (incorrect read operation) via unspe…

Fix: after 20.0.1132.42
Fix from $1,600 2012-06-27
Chrome MEDIUM 6.8
CVE-2012-2819

The texSubImage2D implementation in the WebGL subsystem in Google Chrome before 20.0.1132.43 does not properly handle uploads to floating-point textu…

Fix: after 20.0.1132.42
Fix from $1,600 2012-06-27
Chrome MEDIUM 5.0
CVE-2012-2820

Google Chrome before 20.0.1132.43 does not properly implement SVG filters, which allows remote attackers to cause a denial of service (out-of-bounds …

Fix: after 20.0.1132.42
Fix from $1,600 2012-06-27
Janrain Capture MEDIUM 5.8
CVE-2012-2727

Open redirect vulnerability in the Janrain Capture module 6.x-1.0 and 7.x-1.0 for Drupal, when synchronizing user data, allows remote attackers to re…

Patch available
Fix from $1,600 2012-06-27
Global Redirect MEDIUM 5.8
CVE-2010-2021

Open redirect vulnerability in the Global Redirect module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.4 for Drupal, when non-clean to clean is en…

Patch available
Fix from $1,600 2012-06-25
Linux Kernel MEDIUM 5.4
CVE-2011-1079

The bnep_sock_ioctl function in net/bluetooth/bnep/sock.c in the Linux kernel before 2.6.39 does not ensure that a certain device field ends with a '…

Fix: after 2.6.38.8
Fix from $1,600 2012-06-21
Linux Kernel HIGH 7.8
CVE-2011-4913

The rose_parse_ccitt function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 does not validate the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_N…

Fix: after 2.6.38.8
Fix from $1,950 2012-06-21
Linux Kernel MEDIUM 6.4
CVE-2011-4914EPSS 9%

The ROSE protocol implementation in the Linux kernel before 2.6.39 does not verify that certain data-length values are consistent with the amount of …

Fix: after 2.6.38.8
Fix from $1,600 2012-06-21
Qemu HIGH 7.4
CVE-2011-1751

The pciej_write function in hw/acpi_piix4.c in the PIIX4 Power Management emulation in qemu-kvm does not check if a device is hotpluggable before unp…

Mitigation only
Fix from $1,950 2012-06-21
Qemu Kvm MEDIUM 5.8
CVE-2011-2512

The virtio_queue_notify in qemu-kvm 0.14.0 and earlier does not properly validate the virtqueue number, which allows guest users to cause a denial of…

Fix: after 0.14.0
Fix from $1,600 2012-06-21
Anyconnect Secure Mobility Client HIGH 9.3
CVE-2012-2493

The VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2.x before 2.5 MR6 on Windows, and 2.x before 2…

Mitigation only
Fix from $1,950 2012-06-20
Anyconnect Secure Mobility Client MEDIUM 6.8
CVE-2012-2496

A certain Java applet in the VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 3.x before 3.0 MR7 on …

Mitigation only
Fix from $1,600 2012-06-20
Security Appscan Source MEDIUM 5.8
CVE-2012-2159

Open redirect vulnerability in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collec…

Mitigation only
Fix from $1,600 2012-06-20
Collabtive MEDIUM 6.5
CVE-2012-2670

manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restri…

Fix: after 0.7.5
Fix from $1,600 2012-06-17