Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Acrobat Reader HIGH 9.3
CVE-2011-2442

Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allow attackers to execute arbitrary code via unspecified vectors…

Patch available
Fix from $1,950 2011-09-15
Office HIGH 9.3
CVE-2011-1982EPSS 28%

Microsoft Office 2007 SP2, and 2010 Gold and SP1, does not initialize an unspecified object pointer during the opening of Word documents, which allow…

Mitigation only
Fix from $1,950 2011-09-15
Excel HIGH 9.3
CVE-2011-1989EPSS 21%

Microsoft Excel 2003 SP3 and 2007 SP2; Excel in Office 2007 SP2; Excel 2010 Gold and SP1; Excel in Office 2010 Gold and SP1; Office 2004, 2008, and 2…

Mitigation only
Fix from $1,950 2011-09-15
Vpnc HIGH 7.5
CVE-2011-2660

The modify_resolvconf_suse script in the vpnc package before 0.5.1-55.10.1 in SUSE Linux Enterprise Desktop 11 SP1 might allow remote attackers to ex…

Fix: after 0.5.1
Fix from $1,950 2011-09-06
Linux Kernel MEDIUM 5.7
CVE-2011-2723

The skb_gro_header_slow function in include/linux/netdevice.h in the Linux kernel before 2.6.39.4, when Generic Receive Offload (GRO) is enabled, res…

Fix: 2.6.39.4+
Fix from $1,600 2011-09-06
Cloud Manager HIGH 9.3
CVE-2011-2654

The RPC implementation in the server in Novell Cloud Manager 1.1.2 before Patch 3 does not properly initialize objects, which allows remote attackers…

Fix: after 1.1.2
Fix from $1,950 2011-09-06
Lifesize Room Appliance Software HIGH 7.5
CVE-2011-2763EPSS 36%

The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) and 4.7.18 allows remote attackers to execute arbitrary commands via a modified re…

No fix yet
Fix from $1,950 2011-09-02
System Config Printer MEDIUM 5.1
CVE-2011-2899

pysmb.py in system-config-printer 0.6.x and 0.7.x, as used in foomatic-gui and possibly other products, allows remote SMB servers to execute arbitrar…

Patch available
Fix from $1,600 2011-08-31
Iphone Os HIGH 7.5
CVE-2011-0228EPSS 6%

The Data Security component in Apple iOS before 4.2.10 and 4.3.x before 4.3.5 does not check the basicConstraints parameter during validation of X.50…

Fix: after 4.2.9
Fix from $1,950 2011-08-29
Rails MEDIUM 5.0
CVE-2011-2929

The template selection functionality in actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.10 and 3.1.x before 3.1.0.r…

Patch available
Fix from $1,600 2011-08-29
Pidgin HIGH 9.3
CVE-2011-3185

gtkutils.c in Pidgin before 2.10.0 on Windows allows user-assisted remote attackers to execute arbitrary programs via a file: URL in a message.

Fix: after 2.9.0
Fix from $1,950 2011-08-29
Chrome HIGH 10.0
CVE-2011-2822

Google Chrome before 13.0.782.215 on Windows does not properly parse URLs located on the command line, which has unspecified impact and attack vector…

Fix: 13.0.782.215+
Fix from $1,950 2011-08-29
Chrome HIGH 7.5
CVE-2011-2839

The PDF implementation in Google Chrome before 13.0.782.215 on Linux does not properly use the memset library function, which allows remote attackers…

Fix: 13.0.782.215+
Fix from $1,950 2011-08-29
Kiwi HIGH 7.5
CVE-2011-2649

Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to execute arbitrary commands via shell metacharacters in an unspecifie…

Fix: after 3.74.1
Fix from $1,950 2011-08-23
Ubuntu Linux HIGH 7.8
CVE-2011-2748EPSS 39%

The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial o…

Patch available
Fix from $1,950 2011-08-15
Debian Linux HIGH 7.8
CVE-2011-2749EPSS 39%

The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial o…

Patch available
Fix from $1,950 2011-08-15
Tivoli Federated Identity Manager MEDIUM 5.0
CVE-2008-7299

IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2 uses an incomplete SAML 1.x browser-artifact, which allows remote OpenID providers …

Mitigation only
Fix from $1,600 2011-08-12
Proliant Sl Advanced Power Manager HIGH 7.8
CVE-2011-2405

The HP ProLiant SL Advanced Power Manager (SL-APM) with firmware before 1.20 does not properly validate users, which allows remote attackers to cause…

Fix: after 1.11
Fix from $1,950 2011-08-11
Visio HIGH 9.3
CVE-2011-1979EPSS 22%

Microsoft Visio 2003 SP3 and 2007 SP2 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execut…

Mitigation only
Fix from $1,950 2011-08-10
WordPress MEDIUM 5.8
CVE-2011-3127

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rendering for (1) admin or (2) login pages inside a frame in a third-party HTML doc…

Patch available
Fix from $1,600 2011-08-10
Visio HIGH 9.3
CVE-2011-1972EPSS 22%

Microsoft Visio 2003 SP3, 2007 SP2, and 2010 Gold and SP1 does not properly validate objects in memory during Visio file parsing, which allows remote…

Mitigation only
Fix from $1,950 2011-08-10
Uuplayer Activex Control HIGH 9.3
CVE-2011-2590

The Play method in the UUPlayer ActiveX control 6.0.0.1 in UUSee 2010 6.11.0609.2 allows remote attackers to execute arbitrary programs via a UNC sha…

Mitigation only
Fix from $1,950 2011-08-09
Ioquake3 Engine HIGH 10.0
CVE-2011-3012EPSS 8%

The ioQuake3 engine, as used in World of Padman 1.2 and earlier, Tremulous 1.1.0, and ioUrbanTerror 2007-12-20, does not check for dangerous file ext…

Fix: after 1.2
Fix from $1,950 2011-08-09
Bugzilla MEDIUM 5.0
CVE-2011-2978

Bugzilla 2.16rc1 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1…

Patch available
Fix from $1,600 2011-08-09
Ruby MEDIUM 5.0
CVE-2011-2705

The SecureRandom.random_bytes function in lib/securerandom.rb in Ruby before 1.8.7-p352 and 1.9.x before 1.9.2-p290 relies on PID values for initiali…

Fix: after 1.8.7-334
Fix from $1,600 2011-08-05
Ioquake3 Engine HIGH 7.5
CVE-2011-1412

sys/sys_unix.c in the ioQuake3 engine on Unix and Linux, as used in World of Padman 1.5.x before 1.5.1.1 and OpenArena 0.8.x-15 and 0.8.x-16, allows …

Patch available
Fix from $1,950 2011-08-04
Ioquake3 Engine HIGH 10.0
CVE-2011-2764EPSS 9%

The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, Op…

Fix: after 1.36
Fix from $1,950 2011-08-04
Chrome MEDIUM 6.8
CVE-2011-2802

Google V8, as used in Google Chrome before 13.0.782.107, does not properly perform const lookups, which allows remote attackers to cause a denial of …

Fix: 13.0.782.107+
Fix from $1,600 2011-08-03
Chrome MEDIUM 6.8
CVE-2011-2358

Google Chrome before 13.0.782.107 does not ensure that extension installations are confirmed by a browser dialog, which makes it easier for remote at…

Fix: 13.0.782.107+
Fix from $1,600 2011-08-03
Chrome MEDIUM 6.8
CVE-2011-2359

Google Chrome before 13.0.782.107 does not properly track line boxes during rendering, which allows remote attackers to cause a denial of service or …

Fix: 5.0 / 5.1.1+
Fix from $1,600 2011-08-03