Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 10.0 CVE-2015-0301EPSS 5% Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 1… Adobe Air Sdk And Compiler after 15.0.0.356 Fix from $1,9502015-01-13 MEDIUM 5.0 CVE-2015-0582 The High Availability (HA) subsystem in Cisco NX-OS on MDS 9000 devices allows remote attackers to cause a denial of service via crafted traffic, aka… Nx Os Mitigation only Fix from $1,6002015-01-10 MEDIUM 5.0 CVE-2015-0563 epan/dissectors/packet-smtp.c in the SMTP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 uses an incorrect length value for ce… Wireshark Mitigation only Fix from $1,6002015-01-10 MEDIUM 5.0 CVE-2015-0561EPSS 6% asn1/lpp/lpp.cnf in the LPP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 does not validate a certain index value, which allo… Wireshark Mitigation only Fix from $1,6002015-01-10 MEDIUM 5.0 CVE-2014-8036 The outlookpa component in Cisco WebEx Meetings Server does not properly validate API input, which allows remote attackers to modify a meeting's invi… Webex Meetings Server Mitigation only Fix from $1,6002015-01-10 HIGH 7.5 CVE-2014-9509 The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, when config.prefixLocalAnchors… TYPO3 No fix yet Fix from $1,9502015-01-04 MEDIUM 5.0 CVE-2011-4720 Hillstone HS TFTP Server 1.3.2 allows remote attackers to cause a denial of service (daemon crash) via a long filename in a (1) RRQ or (2) WRQ operat… Hs Tftp Server No fix yet Fix from $1,6002014-12-28 HIGH 7.2 CVE-2014-0748 apinit on Cray devices with CLE before 4.2.UP02 and 5.x before 5.1.UP00 does not use alpsauth data to validate the UID in a launch message, which all… Cray Linux Environment after 4.2 Fix from $1,9502014-12-27 HIGH 7.5 CVE-2011-1798 rendering/svg/RenderSVGText.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 does not properly perform a cast of an unspecified variable … Chrome after 11.0.696.64 Fix from $1,9502014-12-26 HIGH 7.5 CVE-2011-1793 rendering/svg/RenderSVGResourceFilter.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of servi… Chrome after 11.0.696.65 Fix from $1,9502014-12-26 MEDIUM 5.0 CVE-2014-3971 The CmdAuthenticate::_authenticateX509 function in db/commands/authentication_commands.cpp in mongod in MongoDB 2.6.x before 2.6.2 allows remote atta… MongoDB Patch available Fix from $1,6002014-12-25 HIGH 7.5 CVE-2004-2771EPSS 7% The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands… Linux after 12.5 Fix from $1,9502014-12-24 MEDIUM 5.4 CVE-2014-7994 Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote attackers to execute arbitrary commands by leveraging knowledge of a… Meraki Mr Firmware after 2014-09-24 Fix from $1,6002014-12-24 HIGH 7.5 CVE-2014-9378 Ettercap 0.8.1 does not validate certain return values, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitr… Ettercap Patch available Fix from $1,9502014-12-19 MEDIUM 6.8 CVE-2014-7241 The TSUTAYA application 5.3 and earlier for Android allows remote attackers to execute arbitrary Java methods via a crafted HTML document. Tsutaya after 5.3 Fix from $1,6002014-12-19 HIGH 10.0 CVE-2014-9371EPSS 19% The NativeAppServlet in ManageEngine Desktop Central MSP before 90075 allows remote attackers to execute arbitrary code via a crafted JSON object. Manageengine Desktop Central after 9.0 Fix from $1,9502014-12-16 MEDIUM 6.4 CVE-2014-9358 Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via … Docker after 1.3.2 Fix from $1,6002014-12-16 HIGH 7.5 CVE-2014-6052EPSS 7% The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibVNCServer 0.9.9 and earlier does not check certain malloc return values, which a… Debian Linux after 0.9.9 Fix from $1,9502014-12-15 HIGH 7.5 CVE-2014-7840 The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers to execute arbitrary code via… Enterprise Linux Desktop after 2.1.3 Fix from $1,9502014-12-12 HIGH 7.5 CVE-2014-4323 The mdp_lut_hw_update function in drivers/video/msm/mdp.c in the MDP display driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (… Linux Kernel after 3.16.1 Fix from $1,9502014-12-12 MEDIUM 6.8 CVE-2014-1594 Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 might allow remote attackers to execute… Firefox after 33.0 Fix from $1,6002014-12-11 MEDIUM 6.8 CVE-2014-1587 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and… Firefox after 33.0 Fix from $1,6002014-12-11 MEDIUM 5.4 CVE-2014-8680EPSS 9% The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial of service (assertion failure and named exit) via… Bind Mitigation only Fix from $1,6002014-12-11 MEDIUM 6.5 CVE-2014-8010 The web framework in Cisco Unified Communications Domain Manager 8 allows remote authenticated administrators to execute arbitrary OS commands via cr… Unified Communications Domain Manager Mitigation only Fix from $1,6002014-12-10 HIGH 7.2 CVE-2014-8003 Cisco Integrated Management Controller in Cisco Unified Computing System 2.2(2c)A and earlier allows local users to obtain shell access via a crafted… Unified Computing System after 2.2 Fix from $1,9502014-12-10 MEDIUM 5.0 CVE-2014-4465 WebKit in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1 allows remote attackers to bypass the Same Origin Policy via crafted Casc… Safari after 8.1.2 Fix from $1,6002014-12-10 MEDIUM 6.4 CVE-2014-9351 engine/server/server.cpp in Teeworlds 0.6.x before 0.6.3 allows remote attackers to read memory and cause a denial of service (crash) via unspecified… Teeworlds Patch available Fix from $1,6002014-12-09 MEDIUM 6.8 CVE-2014-9268 The AdView.AdViewer.1 ActiveX control in Autodesk Design Review (ADR) before 2013 Hotfix 1 allows remote attackers to execute arbitrary code via a cr… Design Review after 2013 Fix from $1,6002014-12-08 MEDIUM 5.0 CVE-2014-9130EPSS 13% scanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to cause a denial… Libyaml Patch available Fix from $1,6002014-12-08 MEDIUM 5.0 CVE-2012-6656 iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via … Debian Linux after 2.16 Fix from $1,6002014-12-05