Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
iOS HIGH 7.8
CVE-2012-0385

The Smart Install feature in Cisco IOS 12.2, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (device reload) by sending a m…

Mitigation only
Fix from $1,950 2012-03-29
Opera Browser MEDIUM 6.4
CVE-2012-1927

Opera before 11.62 allows remote attackers to spoof the address field by triggering the launch of a dialog window associated with a different domain.

Fix: after 11.61
Fix from $1,600 2012-03-28
Opera Browser MEDIUM 6.4
CVE-2012-1928

Opera before 11.62 allows remote attackers to spoof the address field by triggering a page reload followed by a redirect to a different domain.

Fix: after 11.61
Fix from $1,600 2012-03-28
Opera Browser MEDIUM 6.4
CVE-2012-1929

Opera before 11.62 on Mac OS X allows remote attackers to spoof the address field and security dialogs via crafted styling that causes page content t…

Fix: after 11.61
Fix from $1,600 2012-03-28
Arcserve Backup MEDIUM 5.0
CVE-2012-1662

CA ARCserve Backup r12.0 through SP2, r12.5 before SP2, r15 through SP1, and r16 before SP1 on Windows allows remote attackers to cause a denial of s…

Mitigation only
Fix from $1,600 2012-03-22
Db2 MEDIUM 5.0
CVE-2012-0710

IBM DB2 9.1 before FP11, 9.5 before FP9, 9.7 before FP5, and 9.8 before FP4 allows remote attackers to cause a denial of service (daemon crash) via a…

Mitigation only
Fix from $1,600 2012-03-20
Tiny Server HIGH 7.8
CVE-2012-1783

Tiny Server 1.1.9 and earlier allows remote attackers to cause a denial of service (crash) via a long string in a GET request without an HTTP version…

Fix: after 1.1.9
Fix from $1,950 2012-03-19
Video Embed \& Thumbnail Generator HIGH 7.5
CVE-2012-1785

kg_callffmpeg.php in the Video Embed & Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to execute arbitrary commands via …

Fix: after 1.1
Fix from $1,950 2012-03-19
Adaptive Security Appliance Software HIGH 7.8
CVE-2012-0355

Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with softwar…

Mitigation only
Fix from $1,950 2012-03-15
Firewall Services Module Software HIGH 7.8
CVE-2012-0356

Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with softwar…

Mitigation only
Fix from $1,950 2012-03-15
Adaptive Security Appliance Software HIGH 7.1
CVE-2012-0353

The UDP inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500…

Mitigation only
Fix from $1,950 2012-03-15
Adaptive Security Appliance Software HIGH 7.1
CVE-2012-0354

The Threat Detection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6…

Mitigation only
Fix from $1,950 2012-03-15
Firefox HIGH 7.5
CVE-2012-0463

The nsWindow implementation in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird …

Fix: after 10.0
Fix from $1,950 2012-03-14
Vcenter Chargeback Manager MEDIUM 6.4
CVE-2012-1472

VMware vCenter Chargeback Manager (aka CBM) before 2.0.1 does not properly handle XML API requests, which allows remote attackers to read arbitrary f…

Fix: after 2.0.0
Fix from $1,600 2012-03-13
Safari MEDIUM 6.4
CVE-2012-0584

The Internationalized Domain Name (IDN) feature in Apple Safari before 5.1.4 on Windows does not properly restrict the characters in URLs, which allo…

Fix: after 5.1.2
Fix from $1,600 2012-03-12
Iphone Os MEDIUM 5.0
CVE-2012-0641

CFNetwork in Apple iOS before 5.1 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensiti…

Fix: 5.1+
Fix from $1,600 2012-03-08
Pcanywhere MEDIUM 5.0
CVE-2012-0292EPSS 7%

The awhost32 service in Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Al…

Fix: after 12.5
Fix from $1,600 2012-03-08
Struts HIGH 10.0
CVE-2012-0838EPSS 14%

Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to m…

Fix: after 2.2.3
Fix from $1,950 2012-03-02
Libvpx MEDIUM 5.0
CVE-2012-0823

VP8 Codec SDK (libvpx) before 1.0.0 "Duclair" allows remote attackers to cause a denial of service (application crash) via (1) unspecified "corrupt i…

Fix: after 0.9.7
Fix from $1,600 2012-02-23
Pcanywhere MEDIUM 5.0
CVE-2012-0291

Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management …

Fix: after 12.5
Fix from $1,600 2012-02-22
Cubecart MEDIUM 5.8
CVE-2012-0865

Multiple open redirect vulnerabilities in CubeCart 3.0.20 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phi…

Fix: after 3.0.20
Fix from $1,600 2012-02-21
Basic Analysis And Security Engine HIGH 7.5
CVE-2012-1198EPSS 5%

base_ag_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allows remote attackers to execute arbitrary code by uploading contents of the fi…

No fix yet
Fix from $1,950 2012-02-18
Djbdns MEDIUM 6.4
CVE-2012-1191

The resolver in dnscache in Daniel J. Bernstein djbdns 1.05 overwrites cached server names and TTL values in NS records during the processing of a re…

No fix yet
Fix from $1,600 2012-02-17
Irfaq MEDIUM 5.8
CVE-2011-5079

Open redirect vulnerability in the Modern FAQ (irfaq) extension 1.1.2 and other versions before 1.1.4 for TYPO3 allows remote attackers to redirect u…

Fix: after 1.1.2
Fix from $1,600 2012-02-14
Portable Runtime MEDIUM 5.0
CVE-2012-0840EPSS 43%

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash col…

Fix: after 1.4.5
Fix from $1,600 2012-02-10
Chrome MEDIUM 5.8
CVE-2011-3964

Google Chrome before 17.0.963.46 does not properly implement the drag-and-drop feature, which makes it easier for remote attackers to spoof the URL b…

Fix: 17.0.963.46+
Fix from $1,600 2012-02-09
Ada Web Services MEDIUM 5.0
CVE-2012-1035

AdaCore Ada Web Services (AWS) before 2.10.2 computes hash values for form parameters without restricting the ability to trigger hash collisions pred…

Fix: after 2.10.1
Fix from $1,600 2012-02-08
Ocaml MEDIUM 5.0
CVE-2012-0839

OCaml 3.12.1 and earlier computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent …

Fix: after 3.12.1
Fix from $1,600 2012-02-08
Officesip Server MEDIUM 5.0
CVE-2012-1008EPSS 12%

OfficeSIP Server 3.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted To header in a SIP INVITE message.

No fix yet
Fix from $1,600 2012-02-08
4images MEDIUM 5.8
CVE-2012-1023

Open redirect vulnerability in admin/index.php in 4images 1.7.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishin…

No fix yet
Fix from $1,600 2012-02-08