Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 6.8 CVE-2015-1782 The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact vi… Debian Linux after 1.4.3 Fix from $1,6002015-03-13 HIGH 7.8 CVE-2015-0652 The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X8.2 and Cis… Expressway Software Mitigation only Fix from $1,9502015-03-13 HIGH 7.8 CVE-2015-0523 EMC RSA Certificate Manager (RCM) before 6.9 build 558 and RSA Registration Manager (RRM) before 6.9 build 558 allow remote attackers to cause an Adm… Rsa Certificate Manager after 6.8 Fix from $1,9502015-03-12 MEDIUM 5.0 CVE-2015-2187 The dissect_atn_cpdlc_heur function in asn1/atn-cpdlc/packet-atn-cpdlc-template.c in the ATN-CPDLC dissector in Wireshark 1.12.x before 1.12.4 does n… Wireshark Mitigation only Fix from $1,6002015-03-08 MEDIUM 5.0 CVE-2015-0228EPSS 19% The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a de… HTTP Server after 2.4.12 Fix from $1,6002015-03-08 HIGH 7.5 CVE-2015-2177EPSS 35% Siemens SIMATIC S7-300 CPU devices allow remote attackers to cause a denial of service (defect-mode transition) via crafted packets on (1) TCP port 1… Simatic S7 300 Cpu Firmware No fix yet Fix from $1,9502015-03-07 HIGH 7.8 CVE-2014-9369 Siemens SPC controllers SPC4000, SPC5000, and SPC6000 before 3.6.0 allow remote attackers to cause a denial of service (device restart) via crafted p… Spc5000 Firmware after 3.5.9 Fix from $1,9502015-03-07 HIGH 7.5 CVE-2015-1483 Symantec NetBackup OpsCenter 7.6.0.2 through 7.6.1 on Linux and UNIX allows remote attackers to execute arbitrary JavaScript code via unspecified vec… Netbackup Opscenter Mitigation only Fix from $1,9502015-03-06 MEDIUM 5.0 CVE-2015-0657 Cisco IOS XR allows remote attackers to cause a denial of service (RSVP process reload) via a malformed RSVP packet, aka Bug ID CSCur69192. Ios Xr Mitigation only Fix from $1,6002015-03-06 MEDIUM 5.0 CVE-2014-8160EPSS 5% net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables … Linux Kernel 3.18+ Fix from $1,6002015-03-02 MEDIUM 6.8 CVE-2015-0633 The Integrated Management Controller (IMC) in Cisco Unified Computing System (UCS) 1.4(7h) and earlier on C-Series servers allows remote attackers to… Unified Computing System Mitigation only Fix from $1,6002015-02-26 HIGH 7.8 CVE-2015-2055 Zhone GPON 2520 with firmware R4.0.2.566b allows remote attackers to cause a denial of service via a long string in the oldpassword parameter. Gpon 2520 Firmware No fix yet Fix from $1,9502015-02-23 HIGH 7.2 CVE-2015-0584 The image-upgrade implementation on Cisco Desktop Collaboration Experience (aka Collaboration Desk Experience or DX) DX650 endpoints allows local use… Desktop Collaboration Experience Dx650 Mitigation only Fix from $1,9502015-02-20 MEDIUM 6.5 CVE-2015-1604 Unrestricted file upload vulnerability in asys/site/files.php in Adminsystems CMS before 4.0.2 allows remote authenticated users to execute arbitrary… Adminsystems Cms after 4.0.0 Fix from $1,6002015-02-19 MEDIUM 5.0 CVE-2012-6687EPSS 6% FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial of service (segmentation fault and crash) via a large number of connec… Fcgi Mitigation only Fix from $1,6002015-02-19 HIGH 7.1 CVE-2015-0622 The Wireless Intrusion Detection (aka WIDS) functionality on Cisco Wireless LAN Controller (WLC) devices allows remote attackers to cause a denial of… Wireless Lan Controller Mitigation only Fix from $1,9502015-02-19 MEDIUM 5.0 CVE-2015-0600 The mobility extension on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to cause a denial of service (logoff… Unified Ip Phones 9900 Series Firmware after 9.4 Fix from $1,6002015-02-07 HIGH 9.0 CVE-2015-0589 The administrative web interface in Cisco WebEx Meetings Server 1.0 through 1.5 allows remote authenticated users to execute arbitrary OS commands wi… Webex Meetings Server Mitigation only Fix from $1,9502015-02-07 MEDIUM 5.0 CVE-2015-0604 The web framework on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to upload files to arbitrary locations on… Unified Ip Phones 9971 Firmware Mitigation only Fix from $1,6002015-02-07 MEDIUM 5.0 CVE-2015-1382 parsers.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to an HTTP time … Debian Linux after 3.0.22 Fix from $1,6002015-02-03 MEDIUM 5.0 CVE-2015-1380 jcc.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (abort) via a crafted chunk-encoded body. Privoxy after 3.0.22 Fix from $1,6002015-02-03 MEDIUM 6.8 CVE-2015-1049 The web server on Siemens SCALANCE X-200IRT switches with firmware before 5.2.0 allows remote attackers to hijack sessions via unspecified vectors. Scalance X 200 Series Firmware after 5.1.1 Fix from $1,6002015-02-02 MEDIUM 5.0 CVE-2015-0597 The Forgot Password feature in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to enumerate administrative accounts via c… Webex Meetings Server after 1.5 Fix from $1,6002015-02-02 HIGH 10.0 CVE-2014-8836 The Bluetooth driver in Apple OS X before 10.10.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (ar… Mac Os X after 10.10.1 Fix from $1,9502015-01-30 HIGH 7.2 CVE-2014-8825 The kernel in Apple OS X before 10.10.2 does not properly perform identitysvc validation of certain directory-service functionality, which allows loc… Mac Os X after 10.10.1 Fix from $1,9502015-01-30 HIGH 10.0 CVE-2014-8824 The kernel in Apple OS X before 10.10.2 does not properly validate IODataQueue object metadata fields, which allows attackers to execute arbitrary co… Mac Os X after 10.10.1 Fix from $1,9502015-01-30 MEDIUM 6.8 CVE-2014-4494 Springboard in Apple iOS before 8.1.3 does not properly validate signatures when determining whether to solicit an app trust decision from the user, … Iphone Os after 8.1.2 Fix from $1,6002015-01-30 HIGH 7.5 CVE-2015-1371EPSS 8% Unrestricted file upload vulnerability in ferretCMS 1.0.4-alpha allows remote administrators to execute arbitrary code by uploading a file with an ex… Ferretcms No fix yet Fix from $1,9502015-01-27 MEDIUM 6.8 CVE-2014-8479 The FTP server on Siemens SCALANCE X-300 switches with firmware before 4.0 and SCALANCE X 408 switches with firmware before 4.0 allows remote authent… Scalance X 408 Firmware after 3.9.3 Fix from $1,6002015-01-21 MEDIUM 6.8 CVE-2014-9598EPSS 6% The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial… Vlc Media Player Mitigation only Fix from $1,6002015-01-21