Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Devscripts HIGH 9.3
CVE-2012-0210EPSS 5%

debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to obtain system information and execute arbitrary co…

Mitigation only
Fix from $1,950 2012-06-16
Devscripts HIGH 9.3
CVE-2012-0211EPSS 6%

debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via a crafted tarball file …

Mitigation only
Fix from $1,950 2012-06-16
Devscripts HIGH 9.3
CVE-2012-0212EPSS 6%

debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via shell metacharacters in…

Mitigation only
Fix from $1,950 2012-06-16
Workstation HIGH 9.3
CVE-2012-3288

VMware Workstation 7.x before 7.1.6 and 8.x before 8.0.4, VMware Player 3.x before 3.1.6 and 4.x before 4.0.4, VMware Fusion 4.x before 4.1.3, VMware…

Mitigation only
Fix from $1,950 2012-06-14
Opera Browser HIGH 9.3
CVE-2012-3556

Opera before 11.65 does not properly restrict the opening of a pop-up window in response to the first click of a double-click action, which makes it …

Fix: after 11.62
Fix from $1,950 2012-06-14
Windows 2003 Server HIGH 7.2
CVE-2012-1864

win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, a…

Mitigation only
Fix from $1,950 2012-06-12
Windows 2003 Server HIGH 7.2
CVE-2012-1865

win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, a…

Mitigation only
Fix from $1,950 2012-06-12
Windows 2003 Server HIGH 7.2
CVE-2012-1866

win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, a…

Mitigation only
Fix from $1,950 2012-06-12
Wincc MEDIUM 5.8
CVE-2012-3003

Open redirect vulnerability in an unspecified web application in Siemens WinCC 7.0 SP3 before Update 2 allows remote attackers to redirect users to a…

Mitigation only
Fix from $1,600 2012-06-08
Deltav HIGH 7.5
CVE-2012-1817

Buffer overflow in Emerson DeltaV and DeltaV Workstations 9.3.1, 10.3.1, 11.3, and 11.3.1 and DeltaV ProEssentials Scientific Graph 5.0.0.6 allows us…

Mitigation only
Fix from $1,950 2012-06-08
Debian Linux HIGH 8.8
CVE-2012-0247

ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via craf…

Patch available
Fix from $1,950 2012-06-05
Rpm MEDIUM 6.8
CVE-2012-0060

RPM before 4.9.1.3 does not properly validate region tags, which allows remote attackers to cause a denial of service (crash) and possibly execute ar…

Fix: after 4.9.1.2
Fix from $1,600 2012-06-04
Rpm MEDIUM 6.8
CVE-2012-0061

The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly validate region tags, which allows user-assisted remote attackers to …

Fix: after 4.9.1.2
Fix from $1,600 2012-06-04
Ios Xr HIGH 7.8
CVE-2012-2488

Cisco IOS XR before 4.2.1 on ASR 9000 series devices and CRS series devices allows remote attackers to cause a denial of service (packet transmission…

Fix: after 4.2.0
Fix from $1,950 2012-05-31
TYPO3 MEDIUM 6.8
CVE-2010-5099

The fileDenyPattern functionality in the PHP file inclusion protection API in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 d…

No fix yet
Fix from $1,600 2012-05-30
Linux Kernel MEDIUM 6.5
CVE-2011-3363

The setup_cifs_sb function in fs/cifs/connect.c in the Linux kernel before 2.6.39 does not properly handle DFS referrals, which allows remote CIFS se…

Fix: 2.6.39+
Fix from $1,600 2012-05-24
Tornado MEDIUM 5.0
CVE-2012-2374

CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote attackers to inject arbitrar…

Fix: after 2.2
Fix from $1,600 2012-05-23
Mobiletrack HIGH 7.6
CVE-2012-2562

The Xelex MobileTrack application 2.3.7 and earlier for Android does not verify the origin of SMS commands, which allows remote attackers to execute …

Fix: after 2.3.7
Fix from $1,950 2012-05-22
Connman HIGH 10.0
CVE-2012-2321EPSS 6%

The loopback plug-in in ConnMan before 0.85 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) host name or (2…

Fix: after 0.84
Fix from $1,950 2012-05-18
X11 HIGH 10.0
CVE-2012-2118

Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service or possibl…

Patch available
Fix from $1,950 2012-05-18
Drupal MEDIUM 5.8
CVE-2012-1589

Open redirect vulnerability in the Form API in Drupal 7.x before 7.13 allows remote attackers to redirect users to arbitrary web sites and conduct ph…

Mitigation only
Fix from $1,600 2012-05-18
Linux Kernel MEDIUM 5.5
CVE-2012-1090

The cifs_lookup function in fs/cifs/dir.c in the Linux kernel before 3.2.10 allows local users to cause a denial of service (OOPS) via attempted acce…

Fix: 3.2.10+
Fix from $1,600 2012-05-17
Chrome HIGH 10.0
CVE-2011-3097

The PDF functionality in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other im…

Fix: after 19.0.1084.45
Fix from $1,950 2012-05-16
Chrome HIGH 10.0
CVE-2011-3092

The regex implementation in Google V8, as used in Google Chrome before 19.0.1084.46, allows remote attackers to cause a denial of service (invalid wr…

Fix: after 19.0.1084.45
Fix from $1,950 2012-05-16
Chrome MEDIUM 5.0
CVE-2011-3093

Google Chrome before 19.0.1084.46 does not properly handle glyphs, which allows remote attackers to cause a denial of service (out-of-bounds read) vi…

Fix: after 19.0.1084.45
Fix from $1,600 2012-05-16
Chrome MEDIUM 5.0
CVE-2011-3094

Google Chrome before 19.0.1084.46 does not properly handle Tibetan text, which allows remote attackers to cause a denial of service (out-of-bounds re…

Fix: after 19.0.1084.45
Fix from $1,600 2012-05-16
Chrome HIGH 10.0
CVE-2011-3095

The OGG container in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact…

Fix: after 19.0.1084.45
Fix from $1,950 2012-05-16
Netweaver HIGH 9.3
CVE-2012-2611EPSS 45%

The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EH…

No fix yet
Fix from $1,950 2012-05-15
Safari MEDIUM 5.0
CVE-2012-0676

WebKit in Apple Safari before 5.1.7 does not properly track state information during the processing of form input, which allows remote attackers to f…

Fix: after 5.1.6
Fix from $1,600 2012-05-11
Visio Viewer HIGH 9.3
CVE-2012-0018EPSS 25%

Microsoft Visio Viewer 2010 Gold and SP1 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary cod…

Mitigation only
Fix from $1,950 2012-05-09