Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Allwebmenus Plugin HIGH 7.5
CVE-2012-1010EPSS 9%

Unrestricted file upload vulnerability in actions.php in the AllWebMenus plugin before 1.1.8 for WordPress allows remote attackers to execute arbitra…

Fix: after 1.1.7
Fix from $1,950 2012-02-07
Openemr HIGH 8.5
CVE-2012-0992

interface/fax/fax_dispatch.php in OpenEMR 4.1.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the file …

Patch available
Fix from $1,950 2012-02-07
Wincc Flexible HIGH 8.5
CVE-2011-4879EPSS 13%

miniweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; th…

No fix yet
Fix from $1,950 2012-02-03
Wincc Flexible HIGH 7.1
CVE-2011-4877EPSS 8%

HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and M…

No fix yet
Fix from $1,950 2012-02-03
Jboss Enterprise Application Platform MEDIUM 5.8
CVE-2011-4314

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework …

Fix: after 1.0.1
Fix from $1,600 2012-01-27
Websphere Application Server MEDIUM 5.0
CVE-2012-0193

IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.43, 6.1 before 6.1.0.43, 7.0 before 7.0.0.23, and 8.0 before 8.0.0.3 computes hash values fo…

Patch available
Fix from $1,600 2012-01-20
Ntr Activex Control HIGH 9.3
CVE-2012-0267EPSS 39%

The StopModule method in the NTR ActiveX control before 2.0.4.8 allows remote attackers to execute arbitrary code via a crafted lModule parameter tha…

Fix: after 1.1.8
Fix from $1,950 2012-01-15
Digest HIGH 7.5
CVE-2011-3597EPSS 14%

Eval injection vulnerability in the Digest module before 1.17 for Perl allows context-dependent attackers to execute arbitrary commands via the new c…

Patch available
Fix from $1,950 2012-01-13
Automation License Manager MEDIUM 5.0
CVE-2011-4530

Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 does not properly copy fields obtained from clients, which allows remote attackers …

Fix: after 5.1
Fix from $1,600 2012-01-08
Automation License Manager MEDIUM 5.0
CVE-2011-4531EPSS 8%

Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allows remote attackers to cause a denial of service (NULL pointer dereference and …

Fix: after 5.1
Fix from $1,600 2012-01-08
Maradns MEDIUM 5.0
CVE-2011-5055

MaraDNS 1.3.07.12 and 1.4.08 computes hash values for DNS data without properly restricting the ability to trigger hash collisions predictably, which…

Patch available
Fix from $1,600 2012-01-08
Plone MEDIUM 5.0
CVE-2011-4462

Plone 4.1.3 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows…

Fix: after 4.1.3
Fix from $1,600 2011-12-30
Ruby HIGH 7.8
CVE-2011-4815

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-…

Fix: after 1.8.7-p352
Fix from $1,950 2011-12-30
Geronimo HIGH 7.8
CVE-2011-5034EPSS 81%

Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, wh…

Fix: after 2.2.1
Fix from $1,950 2011-12-30
Glassfish Server MEDIUM 5.0
CVE-2011-5035EPSS 68%

Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 and 8.2, and possibly other pr…

Fix: after 3.1.1
Fix from $1,600 2011-12-30
V8 MEDIUM 5.0
CVE-2011-5037

Google V8 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attack…

Mitigation only
Fix from $1,600 2011-12-30
Idapython HIGH 9.3
CVE-2011-4783

The IDAPython plugin before 1.5.2.3 in IDA Pro allows user-assisted remote attackers to execute arbitrary code via a crafted IDB file, related to imp…

Fix: after 1.5.2
Fix from $1,950 2011-12-27
Stereoscopic 3d Driver HIGH 7.2
CVE-2011-4784

The NVIDIA Stereoscopic 3D driver before 7.17.12.7565 does not properly handle commands sent to a named pipe, which allows local users to gain privil…

Fix: after 7.17.12.7536
Fix from $1,950 2011-12-27
Pidgin MEDIUM 5.0
CVE-2011-4601

family_feedbag.c in the oscar protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, wh…

Fix: after 2.10.0
Fix from $1,600 2011-12-25
Pidgin MEDIUM 5.0
CVE-2011-4603

The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 valid…

Fix: after 2.10.0
Fix from $1,600 2011-12-17
Pidgin MEDIUM 5.0
CVE-2011-4602

The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly handle missing fields in (1) voice-chat and (2) video-chat stanzas, w…

Fix: after 2.10.0
Fix from $1,600 2011-12-17
Parallels Plesk Small Business Panel HIGH 10.0
CVE-2011-4755

Parallels Plesk Small Business Panel 10.2.0 does not properly validate string data that is intended for storage in an XML document, which allows remo…

Mitigation only
Fix from $1,950 2011-12-16
Parallels Plesk Panel HIGH 10.0
CVE-2011-4727

The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not properly validate string data that is intended for storag…

Mitigation only
Fix from $1,950 2011-12-16
Publisher HIGH 9.3
CVE-2011-3410EPSS 29%

Array index error in Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher fi…

Mitigation only
Fix from $1,950 2011-12-14
Ubuntu Linux MEDIUM 5.0
CVE-2011-4539EPSS 15%

dhcpd in ISC DHCP 4.x before 4.2.3-P1 and 4.1-ESV before 4.1-ESV-R4 does not properly handle regular expressions in dhcpd.conf, which allows remote a…

Mitigation only
Fix from $1,600 2011-12-08
Opera Browser MEDIUM 5.0
CVE-2011-4685

Dragonfly in Opera before 11.60 allows remote attackers to cause a denial of service (application crash) via unspecified content on a web page, as de…

Fix: after 11.60
Fix from $1,600 2011-12-07
One Click Orgs MEDIUM 5.5
CVE-2011-4554

One Click Orgs before 1.2.3 allows remote authenticated users to trigger crafted SMTP traffic via (1) " (double quote) and newline characters in an o…

Fix: after 1.2.2
Fix from $1,600 2011-12-06
One Click Orgs MEDIUM 5.8
CVE-2011-4553

Multiple open redirect vulnerabilities in One Click Orgs before 1.2.3 allow (1) remote attackers to redirect users to arbitrary web sites and conduct…

Fix: after 1.2.2
Fix from $1,600 2011-12-06
Connected Backup HIGH 10.0
CVE-2011-2397EPSS 5%

The Agent service in Iron Mountain Connected Backup 8.4 allows remote attackers to execute arbitrary code via a crafted opcode 13 request that trigge…

Mitigation only
Fix from $1,950 2011-12-05
Arora MEDIUM 5.0
CVE-2011-3367

Arora, possibly 0.11 and other versions, does not use a certain font when rendering certificate fields in a security dialog, which allows remote atta…

Mitigation only
Fix from $1,600 2011-11-29