Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Realplayer HIGH 10.0
CVE-2011-4249

Array index error in the RV30 codec in RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via unspecified vector…

Fix: after 14.0.7
Fix from $1,950 2011-11-24
Resourcespace MEDIUM 5.0
CVE-2011-4311

ResourceSpace before 4.2.2833 does not properly validate access keys, which allows remote attackers to bypass intended resource restrictions via unsp…

Fix: after 4.2.2816
Fix from $1,600 2011-11-19
phpMyAdmin MEDIUM 5.0
CVE-2011-3646

phpmyadmin.css.php in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to obtain sensitive information via an array-typed js_frame parameter to …

Patch available
Fix from $1,600 2011-11-17
Mahara MEDIUM 5.0
CVE-2011-2772

The get_dataroot_image_path function in lib/file.php in Mahara before 1.4.1 does not properly validate uploaded image files, which allows remote atta…

Fix: after 1.4.0
Fix from $1,600 2011-11-15
Firefox HIGH 9.3
CVE-2011-3647

The JSSubScriptLoader in Mozilla Firefox before 3.6.24 and Thunderbird before 3.1.6 does not properly handle XPCNativeWrappers during calls to the lo…

Fix: after 3.6.23
Fix from $1,950 2011-11-09
Chrome HIGH 7.5
CVE-2011-3880

Google Chrome before 15.0.874.102 does not prevent use of an unspecified special character as a delimiter in HTTP headers, which has unknown impact a…

Fix: 15.0.874.102+
Fix from $1,950 2011-10-25
Chrome MEDIUM 6.8
CVE-2011-3884

Google Chrome before 15.0.874.102 does not properly address timing issues during DOM traversal, which allows remote attackers to cause a denial of se…

Fix: 15.0.874.102+
Fix from $1,600 2011-10-25
V8 MEDIUM 6.8
CVE-2011-3886

Google V8, as used in Google Chrome before 15.0.874.102, allows remote attackers to cause a denial of service or possibly have unspecified other impa…

Mitigation only
Fix from $1,600 2011-10-25
iOS HIGH 7.5
CVE-2011-2057

The cat6000-dot1x component in Cisco IOS 12.2 before 12.2(33)SXI7 does not properly handle (1) a loop between a dot1x enabled port and an open-authen…

Fix: 12.2+
Fix from $1,950 2011-10-22
iOS HIGH 7.5
CVE-2011-2058

The cat6000-dot1x component in Cisco IOS 12.2 before 12.2(33)SXI7 does not properly handle an external loop between a pair of dot1x enabled ports, wh…

Fix: 12.2+
Fix from $1,950 2011-10-22
Open Source MEDIUM 6.8
CVE-2011-4063

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.7.1 and 10.x before 10.0.0-rc1 does not properly initialize variables d…

Mitigation only
Fix from $1,600 2011-10-21
Kerberos 5 HIGH 7.8
CVE-2011-4151

The krb5_db2_lockout_audit function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4, when the db2 (aka Berkeley D…

Mitigation only
Fix from $1,950 2011-10-20
Kerberos 5 HIGH 7.8
CVE-2011-1527

The kdb_ldap plugin in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 through 1.9.1, when the LDAP back end is used, allows remot…

Mitigation only
Fix from $1,950 2011-10-20
Kerberos 5 HIGH 7.8
CVE-2011-1528

The krb5_ldap_lockout_audit function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4 and 1.9 through 1.9.1, when …

Mitigation only
Fix from $1,950 2011-10-20
Kerberos 5 HIGH 7.8
CVE-2011-1529

The lookup_lockout_policy function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4 and 1.9 through 1.9.1, when th…

Mitigation only
Fix from $1,950 2011-10-20
Django MEDIUM 5.0
CVE-2011-4138

The verify_exists functionality in the URLField implementation in Django before 1.2.7 and 1.3.x before 1.3.1 originally tests a URL's validity throug…

Fix: after 1.2.6
Fix from $1,600 2011-10-19
Django MEDIUM 5.0
CVE-2011-4139

Django before 1.2.7 and 1.3.x before 1.3.1 uses a request's HTTP Host header to construct a full URL in certain circumstances, which allows remote at…

Fix: after 1.2.6
Fix from $1,600 2011-10-19
Django MEDIUM 5.8
CVE-2011-4136

django.contrib.sessions in Django before 1.2.7 and 1.3.x before 1.3.1, when session data is stored in the cache, uses the root namespace for both ses…

Fix: after 1.2.6
Fix from $1,600 2011-10-19
Mac Os X MEDIUM 6.8
CVE-2011-3227

libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a nonstandard extension in a Certificate Revocation …

Fix: after 10.7.1
Fix from $1,600 2011-10-14
Forefront Unified Access Gateway MEDIUM 5.0
CVE-2011-2012EPSS 17%

Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remo…

Mitigation only
Fix from $1,600 2011-10-12
Host Integration Server MEDIUM 5.0
CVE-2011-2007EPSS 24%

Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service o…

Mitigation only
Fix from $1,600 2011-10-12
Host Integration Server MEDIUM 5.0
CVE-2011-2008EPSS 21%

Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service o…

Mitigation only
Fix from $1,600 2011-10-12
Cms Webmanager Pro MEDIUM 5.8
CVE-2010-4900

Open redirect vulnerability in c.php in CMS WebManager-Pro 8.1 and earlier allows remote attackers to redirect users to arbitrary web sites and condu…

Fix: after 8.1
Fix from $1,600 2011-10-08
HTTP Server MEDIUM 5.0
CVE-2011-3368EPSS 91%

The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with u…

Patch available
Fix from $1,600 2011-10-05
Chrome MEDIUM 6.8
CVE-2011-2861

Google Chrome before 14.0.835.163 does not properly handle strings in PDF documents, which allows remote attackers to have an unspecified impact via …

Fix: 14.0.835.163+
Fix from $1,600 2011-09-19
Chrome HIGH 7.5
CVE-2011-2838

Google Chrome before 14.0.835.163 does not properly consider the MIME type during the loading of a plug-in, which has unspecified impact and remote a…

Fix: 14.0.835.163+
Fix from $1,950 2011-09-19
Chrome MEDIUM 6.8
CVE-2011-2841

Google Chrome before 14.0.835.163 does not properly perform garbage collection during the processing of PDF documents, which allows remote attackers …

Fix: 14.0.835.163+
Fix from $1,600 2011-09-19
Chrome HIGH 7.5
CVE-2011-2842

The installer in Google Chrome before 14.0.835.163 on Mac OS X does not properly handle lock files, which has unspecified impact and attack vectors.

Fix: 14.0.835.163+
Fix from $1,950 2011-09-19
Scadapro HIGH 10.0
CVE-2011-3496EPSS 14%

service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) BF, (…

Fix: after 4.0.0
Fix from $1,950 2011-09-16
Bcfg2 HIGH 9.3
CVE-2011-3211

The server in Bcfg2 1.1.2 and earlier, and 1.2 prerelease, allows remote attackers to execute arbitrary commands via shell metacharacters in data rec…

Fix: after 1.1.2
Fix from $1,950 2011-09-16