Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 6.5 CVE-2014-8789 GleamTech FileVista before 6.1 allows remote authenticated users to create arbitrary files and possibly execute arbitrary code via a crafted path in … Filevista after 6.0.9 Fix from $1,6002014-12-02 HIGH 9.3 CVE-2014-7178EPSS 5% Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP… Tuleap after 7.5.99.5 Fix from $1,9502014-11-28 HIGH 7.5 CVE-2014-9093 LibreOffice before 4.3.5 allows remote attackers to cause a denial of service (invalid write operation and crash) and possibly execute arbitrary code… Fedora after 4.3.4 Fix from $1,9502014-11-26 MEDIUM 6.4 CVE-2014-7142EPSS 25% The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (crash) via a crafted (1) I… Ubuntu Linux Mitigation only Fix from $1,6002014-11-26 MEDIUM 5.0 CVE-2014-2037 Openswan 2.6.40 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack ex… Openswan Mitigation only Fix from $1,6002014-11-26 MEDIUM 6.4 CVE-2014-9038 wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct serve… WordPress after 3.7.4 Fix from $1,6002014-11-25 HIGH 9.0 CVE-2014-8420EPSS 24% The ViewPoint web application in Dell SonicWALL Global Management System (GMS) before 7.2 SP2, SonicWALL Analyzer before 7.2 SP2, and SonicWALL UMA b… Analyzer Mitigation only Fix from $1,9502014-11-25 MEDIUM 6.4 CVE-2014-7839 DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which … Resteasy Mitigation only Fix from $1,6002014-11-25 HIGH 7.1 CVE-2014-9030 The do_mmu_update function in arch/x86/mm.c in Xen 3.2.x through 4.4.x does not properly manage page references, which allows remote domains to cause… Debian Linux Patch available Fix from $1,9502014-11-24 MEDIUM 5.0 CVE-2014-8416 Use-after-free vulnerability in the PJSIP channel driver in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1, when using the res_pjsip_… Asterisk 12.7.1 / 13.0.1+ Fix from $1,6002014-11-24 MEDIUM 5.0 CVE-2014-8415 Race condition in the chan_pjsip channel driver in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1 allows remote attackers to cause a … Asterisk 12.7.1 / 13.0.1+ Fix from $1,6002014-11-24 MEDIUM 5.0 CVE-2014-9060 The LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not properly restrict the parameters use… Moodle after 2.4.11 Fix from $1,6002014-11-24 MEDIUM 5.4 CVE-2014-8594 The do_mmu_update function in arch/x86/mm.c in Xen 4.x through 4.4.x does not properly restrict updates to only PV page tables, which allows remote P… Debian Linux Patch available Fix from $1,6002014-11-19 MEDIUM 5.0 CVE-2014-7899 Google Chrome before 38.0.2125.101 allows remote attackers to spoof the address bar by placing a blob: substring at the beginning of the URL, followe… Chrome after 38.0.2125.7 Fix from $1,6002014-11-19 HIGH 7.5 CVE-2014-7146EPSS 51% The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) description field o… Mantisbt Patch available Fix from $1,9502014-11-18 HIGH 9.3 CVE-2014-4461 The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDataQueue object metadata, which allows attackers t… Iphone Os after 10.10.1 Fix from $1,9502014-11-18 MEDIUM 5.0 CVE-2014-7815 The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value. Debian Linux Mitigation only Fix from $1,6002014-11-14 HIGH 9.3 CVE-2014-4149EPSS 21% Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly perform TypeFilterLevel checks, which allows remote… .net Framework Mitigation only Fix from $1,9502014-11-11 HIGH 7.5 CVE-2014-3673EPSS 7% The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF… Linux Kernel 3.2.64 / 3.4.107+ Fix from $1,9502014-11-10 MEDIUM 6.8 CVE-2014-7989 Cisco Unified Computing System on B-Series blade servers allows local users to gain shell privileges via a crafted (1) ping6 or (2) traceroute6 comma… B200 M3 Mitigation only Fix from $1,6002014-11-07 MEDIUM 6.8 CVE-2014-7990 Cisco IOS XE 3.5E and earlier on WS-C3850, WS-C3860, and AIR-CT5760 devices does not properly parse the "request system shell" challenge response, wh… Ios Xe after 3.5e Fix from $1,6002014-11-07 MEDIUM 5.0 CVE-2014-2179 The Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote attac… Rv180 Firmware after 1.0.5.8 Fix from $1,6002014-11-07 MEDIUM 5.0 CVE-2014-0995EPSS 10% The Standalone Enqueue Server in SAP Netweaver 7.20, 7.01, and earlier allows remote attackers to cause a denial of service (uncontrolled recursion a… Netweaver after 7.01 Fix from $1,6002014-11-06 HIGH 7.5 CVE-2014-8543 libavcodec/mmvideo.c in FFmpeg before 2.4.2 does not consider all lines of HHV Intra blocks during validation of image height, which allows remote at… Ubuntu Linux after 2.4.1 Fix from $1,9502014-11-05 HIGH 7.5 CVE-2014-8544 libavcodec/tiff.c in FFmpeg before 2.4.2 does not properly validate bits-per-pixel fields, which allows remote attackers to cause a denial of service… Ubuntu Linux after 2.4.1 Fix from $1,9502014-11-05 MEDIUM 5.0 CVE-2013-0336 The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_extop.c in the directory server (dirsrv) in FreeIPA before 3.2.0 allows… Freeipa after 3.1.5 Fix from $1,6002014-11-03 MEDIUM 6.8 CVE-2014-0488 APT before 1.0.9 does not "invalidate repository data" when moving from an unauthenticated to authenticated state, which allows remote attackers to h… Advanced Package Tool Patch available Fix from $1,6002014-11-03 HIGH 7.5 CVE-2014-0489 APT before 1.0.9, when the Acquire::GzipIndexes option is enabled, does not validate checksums, which allows remote attackers to execute arbitrary co… Advanced Package Tool Patch available Fix from $1,9502014-11-03 HIGH 7.5 CVE-2014-0490 The apt-get download command in APT before 1.0.9 does not properly validate signatures for packages, which allows remote attackers to execute arbitra… Advanced Package Tool after 1.0.8 Fix from $1,9502014-11-03 MEDIUM 5.0 CVE-2013-0334 Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same … Bundler 1.7.0+ Fix from $1,6002014-10-31