Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.8 CVE-2010-5077 server/sv_main.c in Quake3 Arena, as used in ioquake3 before r1762, OpenArena, Tremulous, and other products, allows remote attackers to cause a deni… Ioquake3 Engine Mitigation only Fix from $1,9502014-10-27 MEDIUM 5.0 CVE-2014-3955 routed in FreeBSD 8.4 through 10.1-RC2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an RIP request fr… FreeBSD Patch available Fix from $1,6002014-10-27 MEDIUM 6.8 CVE-2011-4953 The set_mgmt_parameters function in item.py in cobbler before 2.2.2 allows context-dependent attackers to execute arbitrary code via vectors related … Cobbler after 2.2.1 Fix from $1,6002014-10-27 MEDIUM 5.0 CVE-2014-0136 The (1) get and (2) log methods in the AgentController in Red Hat CloudForms 3.0 Management Engine (CFME) 5.x allow remote attackers to insert arbitr… Cloudforms 3.0 Management Engine after 5.2.5.3 Fix from $1,6002014-10-27 HIGH 7.5 CVE-2011-4103 emitters.py in Django Piston before 0.2.3 and 0.2.x before 0.2.2.1 does not properly deserialize YAML data, which allows remote attackers to execute … Piston after 0.2.2.0 Fix from $1,9502014-10-27 HIGH 7.5 CVE-2011-4104 The from_yaml method in serializers.py in Django Tastypie before 0.9.10 does not properly deserialize YAML data, which allows remote attackers to exe… Tastypie after 0.9.9 Fix from $1,9502014-10-27 MEDIUM 6.8 CVE-2014-3137 Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to … Bottle Patch available Fix from $1,6002014-10-25 HIGH 7.5 CVE-2014-1927 The shell_quote function in python-gnupg 0.3.5 does not properly quote strings, which allows context-dependent attackers to execute arbitrary code vi… Python Gnupg No fix yet Fix from $1,9502014-10-25 HIGH 7.5 CVE-2014-4840 IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote attacke… Tririga Application Platform Mitigation only Fix from $1,9502014-10-19 MEDIUM 6.5 CVE-2014-4833 IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allows remote authenticated users to gain privileges via invalid input. Qradar Security Information And Event Manager No fix yet Fix from $1,6002014-10-19 MEDIUM 5.0 CVE-2014-3021 IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 does not properly handle HTTP headers, which … Websphere Application Server Mitigation only Fix from $1,6002014-10-19 HIGH 7.8 CVE-2014-4443 Apple OS X before 10.10 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted ASN.1 data. Mac Os X after 10.9.5 Fix from $1,9502014-10-18 MEDIUM 5.0 CVE-2014-4417 Safari in Apple OS X before 10.10 allows remote attackers to cause a denial of service (universal Push Notification outage) via a web site that trigg… Mac Os X after 10.9.5 Fix from $1,6002014-10-18 MEDIUM 6.5 CVE-2014-3573 The oVirt Engine backend module, as used in Red Hat Enterprise Virtualization Manager before 3.4.2, uses an "insecure DocumentBuilderFactory," which … Enterprise Virtualization Manager after 3.4.1 Fix from $1,6002014-10-18 MEDIUM 5.1 CVE-2014-2278 Unrestricted file upload vulnerability in op/op.AddFile2.php in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allows remote attackers to execute … Seeddms after 4.3.3 Fix from $1,6002014-10-17 MEDIUM 6.8 CVE-2014-8755 Panasonic Network Camera View 3 and 4 allows remote attackers to execute arbitrary code via a crafted page, which triggers an invalid pointer derefer… Network Camera View Patch available Fix from $1,6002014-10-17 HIGH 7.1 CVE-2014-8310 The CMS CORBA listener in SAP BusinessObjects BI Edge 4.0 allows remote attackers to cause a denial of service (server shutdown) via crafted OSCAFact… Businessobjects No fix yet Fix from $1,9502014-10-16 MEDIUM 6.8 CVE-2014-3686 wpa_supplicant and hostapd 0.7.2 through 2.2, when running with certain configurations and using wpa_cli or hostapd_cli with action scripts, allows r… Ubuntu Linux Mitigation only Fix from $1,6002014-10-16 HIGH 9.3 CVE-2014-4117EPSS 17% Microsoft Office 2007 SP3, Word 2007 SP3, Office 2010 SP1 and SP2, Word 2010 SP1 and SP2, Office for Mac 2011, Office Compatibility Pack SP3, Word Au… Office Mitigation only Fix from $1,9502014-10-15 MEDIUM 6.8 CVE-2014-3825 The Juniper SRX Series devices with Junos 11.4 before 11.4R12-S4, 12.1X44 before 12.1X44-D40, 12.1X45 before 12.1X45-D30, 12.1X46 before 12.1X46-D25,… Junos Mitigation only Fix from $1,6002014-10-14 MEDIUM 6.8 CVE-2014-3390 The Virtual Network Management Center (VNMC) policy implementation in Cisco ASA Software 8.7 before 8.7(1.14), 9.2 before 9.2(2.8), and 9.3 before 9.… Adaptive Security Appliance Software Mitigation only Fix from $1,6002014-10-10 MEDIUM 6.8 CVE-2014-3391 Untrusted search path vulnerability in Cisco ASA Software 8.x before 8.4(3), 8.5, and 8.7 before 8.7(1.13) allows local users to gain privileges by p… Adaptive Security Appliance Software Mitigation only Fix from $1,6002014-10-10 HIGH 7.2 CVE-2014-4870 /opt/vyatta/bin/sudo-users/vyatta-clear-dhcp-lease.pl on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 does not properly validate param… Vyatta 5400 Vrouter Software Mitigation only Fix from $1,9502014-10-07 HIGH 9.3 CVE-2014-7861 The IOHIDSecurePromptClient function in Apple OS X does not properly validate pointer values, which allows remote attackers to execute arbitrary code… Mac Os X Mitigation only Fix from $1,9502014-10-05 MEDIUM 5.0 CVE-2014-7278 The login page on the ZyXEL SBG-3300 Security Gateway with firmware 1.00(AADY.4)C0 and earlier allows remote attackers to cause a denial of service (… Sbg3300 N Firmware after 1.00 Fix from $1,6002014-10-04 HIGH 7.1 CVE-2014-5410 The DNP3 feature on Rockwell Automation Allen-Bradley MicroLogix 1400 1766-Lxxxxx A FRN controllers 7 and earlier and 1400 1766-Lxxxxx B FRN controll… Ab Micrologix Controller Mitigation only Fix from $1,9502014-10-03 HIGH 7.5 CVE-2014-6290 The News (tt_news) extension before 3.5.2 for TYPO3 allows remote attackers to have unspecified impact via vectors related to an "insecure unserializ… News after 3.5.1 Fix from $1,9502014-10-03 MEDIUM 5.0 CVE-2014-3395 Cisco WebEx Meetings Server (WMS) 2.5 allows remote attackers to trigger the download of arbitrary files via a crafted URL, aka Bug ID CSCup10343. Webex Meetings Server Mitigation only Fix from $1,6002014-09-30 MEDIUM 5.0 CVE-2012-5621 lib/engine/components/opal/opal-call.cpp in ekiga before 4.0.0 allows remote attackers to cause a denial of service (crash) via an OPAL connection wi… Ekiga after 3.9.90 Fix from $1,6002014-09-29 HIGH 7.8 CVE-2014-3354 Cisco IOS 12.0, 12.2, 12.4, 15.0, 15.1, 15.2, and 15.3 and IOS XE 2.x and 3.x before 3.7.4S; 3.2.xSE and 3.3.xSE before 3.3.2SE; 3.3.xSG and 3.4.xSG … iOS Mitigation only Fix from $1,9502014-09-25