Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
.net Framework HIGH 9.3
CVE-2012-0160EPSS 23%

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly serialize input data, which allows remote attack…

Mitigation only
Fix from $1,950 2012-05-09
.net Framework HIGH 9.3
CVE-2012-0161EPSS 22%

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly handle an unspecified exception during use of pa…

Mitigation only
Fix from $1,950 2012-05-09
Office HIGH 9.3
CVE-2012-0165EPSS 25%

GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2 and Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1 does not properly validate recor…

Mitigation only
Fix from $1,950 2012-05-09
Office HIGH 9.3
CVE-2012-0167EPSS 29%

Heap-based buffer overflow in the Office GDI+ library in Microsoft Office 2003 SP3 and 2007 SP2 and SP3 allows remote attackers to execute arbitrary …

Mitigation only
Fix from $1,950 2012-05-09
iOS MEDIUM 6.3
CVE-2011-4231

Cisco IOS 15.1 and 15.2 and IOS XE 3.x, when configured as an IPsec hub with X.509 certificates in use, allows remote authenticated users to cause a …

Mitigation only
Fix from $1,600 2012-05-03
Rational Appscan HIGH 7.6
CVE-2012-0735

IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly scan file: URLs, which allows man-in-the-middle attackers to obtain sens…

Mitigation only
Fix from $1,950 2012-05-03
Rational Appscan HIGH 9.3
CVE-2012-0736

IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly create scan jobs, which allows remote attackers to execute arbitrary cod…

Mitigation only
Fix from $1,950 2012-05-03
Snmp Agents For Linux HIGH 8.3
CVE-2012-2002

Open redirect vulnerability in HP SNMP Agents for Linux before 9.0.0 allows remote attackers to redirect users to arbitrary web sites and conduct phi…

Fix: after 8.7.0
Fix from $1,950 2012-05-02
Insight Management Agents HIGH 8.3
CVE-2012-2004

Open redirect vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to redirect users …

Fix: after 8.70.0.0
Fix from $1,950 2012-05-02
iOS MEDIUM 5.0
CVE-2012-0338

Cisco IOS 12.2 through 12.4 and 15.0 does not recognize the vrf-also keyword during enforcement of access-class commands, which allows remote attacke…

Mitigation only
Fix from $1,600 2012-05-02
iOS MEDIUM 5.0
CVE-2012-0339

Cisco IOS 12.2 through 12.4 and 15.0 does not recognize the vrf-also keyword during enforcement of access-class commands, which allows remote attacke…

Mitigation only
Fix from $1,600 2012-05-02
Unified Contact Center Express MEDIUM 5.0
CVE-2011-2583

Cisco Unified Contact Center Express (aka CCX) 8.0 and 8.5 allows remote attackers to cause a denial of service via network traffic, as demonstrated …

No fix yet
Fix from $1,600 2012-05-02
iOS MEDIUM 5.4
CVE-2011-2586

The HTTP client in Cisco IOS 12.4 and 15.0 allows user-assisted remote attackers to cause a denial of service (device crash) via a malformed HTTP res…

Mitigation only
Fix from $1,600 2012-05-02
Carrier Routing System MEDIUM 5.0
CVE-2011-3283

Cisco Carrier Routing System 3.9.1 allows remote attackers to cause a denial of service (Metro subsystem crash) via a fragmented GRE packet, aka Bug …

Patch available
Fix from $1,600 2012-05-02
Adaptive Security Appliance Software MEDIUM 5.0
CVE-2011-3285

CRLF injection vulnerability in /+CSCOE+/logon.html on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 through 8.4 all…

Mitigation only
Fix from $1,600 2012-05-02
Ios Xr HIGH 7.8
CVE-2011-3295

The NETIO and IPV4_IO processes in Cisco IOS XR 3.8 through 4.1, as used in Cisco Carrier Routing System and other products, allow remote attackers t…

Mitigation only
Fix from $1,950 2012-05-02
Adaptive Security Appliance Software HIGH 7.8
CVE-2011-4006

The ESMTP inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.5 allows remote attackers to…

Mitigation only
Fix from $1,950 2012-05-02
iOS MEDIUM 5.4
CVE-2011-4007

Cisco IOS 15.0 and 15.1 and IOS XE 3.x do not properly handle the "set mpls experimental imposition" command, which allows remote attackers to cause …

Mitigation only
Fix from $1,600 2012-05-02
iOS MEDIUM 5.0
CVE-2011-4015

Cisco IOS 15.2S allows remote attackers to cause a denial of service (interface queue wedge) via malformed UDP traffic on port 465, aka Bug ID CSCts4…

Mitigation only
Fix from $1,600 2012-05-02
iOS MEDIUM 5.4
CVE-2011-4016

The PPP implementation in Cisco IOS 12.2 and 15.0 through 15.2, when Point-to-Point Termination and Aggregation (PTA) and L2TP are used, allows remot…

Mitigation only
Fix from $1,600 2012-05-02
Owncloud MEDIUM 5.8
CVE-2012-2270EPSS 6%

Open redirect vulnerability in index.php (aka the Login Page) in ownCloud before 3.0.3 allows remote attackers to redirect users to arbitrary web sit…

Fix: after 3.0.2
Fix from $1,600 2012-04-20
Opcsystems.net MEDIUM 5.0
CVE-2011-4871

Open Automation Software OPC Systems.NET before 5.0 allows remote attackers to cause a denial of service via a malformed .NET RPC packet on TCP port …

Fix: after 4.0
Fix from $1,600 2012-04-18
Unitronics Uniopc MEDIUM 6.8
CVE-2011-5086

https50.ocx in IP*Works! SSL in the server in Unitronics UniOPC before 2.0.0 does not properly implement an unspecified function, which allows remote…

Fix: after 1.3.8
Fix from $1,600 2012-04-18
Helix Server MEDIUM 5.0
CVE-2012-2268

master.exe in the SNMP Master Agent in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to cause a denial…

Mitigation only
Fix from $1,600 2012-04-17
Webmi2ads MEDIUM 5.0
CVE-2011-4883

The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 does not properly validate values in HTTP requests, which allows remote attackers …

Fix: after 2.0.1
Fix from $1,600 2012-04-13
Forefront Unified Access Gateway MEDIUM 5.8
CVE-2012-0146EPSS 11%

Open redirect vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 allows remote attackers to redirect users t…

Mitigation only
Fix from $1,600 2012-04-10
Windows 7 HIGH 7.8
CVE-2012-0151 KEVEPSS 89%

The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008…

Patch available
Fix from $1,950 2012-04-10
.net Framework HIGH 9.3
CVE-2012-0163EPSS 38%

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate function parameters, which allows remote attack…

Mitigation only
Fix from $1,950 2012-04-10
Onboard Administrator MEDIUM 5.8
CVE-2012-0128

HP Onboard Administrator (OA) before 3.50 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecifi…

Fix: after 3.32
Fix from $1,600 2012-04-05
Factorytalk MEDIUM 5.0
CVE-2012-0221EPSS 10%

The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 does no…

Mitigation only
Fix from $1,600 2012-04-02