Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2019-17210 A denial-of-service issue was discovered in the MQTT library in Arm Mbed OS 2017-11-02. The function readMQTTLenString() is called by the function MQ… Mbed Mqtt Mitigation only Fix from $1,9502019-11-04 HIGH 7.8 CVE-2005-4890 There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to… Shadow after 4.1.5 Fix from $1,9502019-11-04 CRITICAL 9.8 CVE-2013-2259 Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview Cryptocat 2.0.22+ Fix from $2,3002019-11-04 CRITICAL 9.8 CVE-2013-4103EPSS 7% Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input Cryptocat 2.0.22+ Fix from $2,3002019-11-04 HIGH 7.5 CVE-2013-4100 Cryptocat before 2.0.22 has Remote Denial of Service via username Cryptocat 2.0.22+ Fix from $1,9502019-11-04 MEDIUM 5.3 CVE-2013-4101 Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weakness Cryptocat 2.0.22+ Fix from $1,6002019-11-04 HIGH 7.3 CVE-2013-0165 cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp. Openshift Mitigation only Fix from $1,9502019-11-01 MEDIUM 5.5 CVE-2013-0178 Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm. Redis 2.6.0+ Fix from $1,6002019-11-01 MEDIUM 5.5 CVE-2013-0180 Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds. Redis Patch available Fix from $1,6002019-11-01 HIGH 7.5 CVE-2013-2227EPSS 13% GLPI 0.83.7 has Local File Inclusion in common.tabs.php. Debian Linux No fix yet Fix from $1,9502019-11-01 MEDIUM 5.5 CVE-2013-3718 evince is missing a check on number of pages which can lead to a segmentation fault Debian Linux Patch available Fix from $1,6002019-11-01 HIGH 8.1 CVE-2013-4751 php-symfony2-Validator has loss of information during serialization Symfony 2.0.24 / 2.1.12+ Fix from $1,9502019-11-01 HIGH 7.5 CVE-2019-18228 Honeywell equIP series IP cameras Multiple equIP Series Cameras, A vulnerability exists in the affected products where a specially crafted HTTP packe… H2w2pc1m Firmware Mitigation only Fix from $1,9502019-10-31 MEDIUM 6.5 CVE-2012-6123 Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack." Debian Linux 4.8.0+ Fix from $1,6002019-10-31 CRITICAL 9.8 CVE-2012-6125 Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions. Chicken 4.8.0+ Fix from $2,3002019-10-31 CRITICAL 9.8 CVE-2013-1910 yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Tro… Debian Linux Mitigation only Fix from $2,3002019-10-31 MEDIUM 6.5 CVE-2010-2490 Mumble: murmur-server has DoS due to malformed client query Debian Linux Patch available Fix from $1,6002019-10-31 CRITICAL 9.8 CVE-2010-0748 Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr a… Debian Linux 1.92+ Fix from $2,3002019-10-30 HIGH 7.8 CVE-2010-2061 rpcbind 0.2.0 does not properly validate (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr, which can be created by an attacker before the daemon is star… Rpcbind Mitigation only Fix from $1,9502019-10-29 HIGH 7.5 CVE-2010-1678 Mapserver 5.2, 5.4 and 5.6 before 5.6.5-2 improperly validates symbol index values during Mapfile parsing. Mapserver 5.6.5.-2+ Fix from $1,9502019-10-29 CRITICAL 9.8 CVE-2012-0694EPSS 67% SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code. Sugarcrm after 6.3.1 Fix from $2,3002019-10-29 MEDIUM 5.5 CVE-2010-3373 paxtest handles temporary files insecurely Debian Linux No fix yet Fix from $1,6002019-10-29 CRITICAL 9.8 CVE-2010-3375 qtparted has insecure library loading which may allow arbitrary code execution Qtparted Mitigation only Fix from $2,3002019-10-29 MEDIUM 5.5 CVE-2010-3293 mailscanner can allow local users to prevent virus signatures from being updated Mailscanner 4.79.11-2+ Fix from $1,6002019-10-28 CRITICAL 9.8 CVE-2010-4239EPSS 13% Tiki Wiki CMS Groupware 5.2 has Local File Inclusion Tikiwiki Cms\/groupware No fix yet Fix from $2,3002019-10-28 CRITICAL 9.8 CVE-2002-2444 Snoopy before 2.0.0 has a security hole in exec cURL Snoopy Patch available Fix from $2,3002019-10-28 MEDIUM 6.5 CVE-2019-3982 Nessus versions 8.6.0 and earlier were found to contain a Denial of Service vulnerability due to improper validation of specific imported scan types.… Nessus after 8.6.0 Fix from $1,6002019-10-23 HIGH 7.5 CVE-2014-2304 A vulnerability in version 0.90 of the Open Floodlight SDN controller software could result in a denial of service attack and crashing of the control… Open Sdn Controller No fix yet Fix from $1,9502019-10-23 HIGH 7.5 CVE-2013-7333 A vulnerability in version 0.90 of the Open Floodlight SDN controller software could allow an attacker with access to the OpenFlow control network to… Open Sdn Controller No fix yet Fix from $1,9502019-10-23 HIGH 7.5 CVE-2019-12290 GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it p… Libidn2 2.2.0+ Fix from $1,9502019-10-22