Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.1 CVE-2013-2811 The (1) Catapult DNP3 I/O driver before 7.2.0.60 and the (2) GE Intelligent Platforms Proficy DNP3 I/O driver before 7.20k, as used in DNPDrv.exe (ak… Catapult Dnp3 I\/o Driver after 7.20.56 Fix from $1,9502013-11-22 MEDIUM 5.8 CVE-2013-6174 Multiple open redirect vulnerabilities in xAdmin in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patc… Document Sciences Xpression No fix yet Fix from $1,6002013-11-21 MEDIUM 5.8 CVE-2013-6814 The J2EE Engine in SAP NetWeaver 6.40, 7.02, and earlier allows remote attackers to redirect users to arbitrary web sites, conduct phishing attacks, … Netweaver after 7.02 Fix from $1,6002013-11-20 MEDIUM 5.0 CVE-2013-6815 The SHSTI_UPLOAD_XML function in the Application Server for ABAP (AS ABAP) in SAP NetWeaver 7.31 and earlier allows remote attackers to cause a denia… Netweaver after 7.31 Fix from $1,6002013-11-20 HIGH 8.8 CVE-2013-6282 KEVEPSS 40% The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, w… Linux Kernel 3.2.54 / 3.4.12+ Fix from $1,9502013-11-20 HIGH 7.5 CVE-2013-5605 Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly ha… Network Security Services Patch available Fix from $1,9502013-11-18 MEDIUM 6.8 CVE-2013-6686 The SSL VPN implementation in Cisco IOS 15.3(1)T2 and earlier allows remote authenticated users to cause a denial of service (interface queue wedge) … iOS after 15.3 Fix from $1,6002013-11-18 MEDIUM 6.9 CVE-2013-6689 Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier allows local users to bypass file permissions, and read, modify, or create arbit… Unified Communications Manager after 9.1 Fix from $1,6002013-11-18 MEDIUM 5.0 CVE-2013-3030 The servlet gateway in IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2,… Cognos Business Intelligence Mitigation only Fix from $1,6002013-11-18 MEDIUM 6.8 CVE-2013-3406 The "Files Available for Download" implementation in the Cisco Intelligent Automation for Cloud component in Cisco Services Portal 9.4(1) allows remo… Service Portal Mitigation only Fix from $1,6002013-11-18 HIGH 7.1 CVE-2013-3876EPSS 5% DirectAccess in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 S… Windows 7 Mitigation only Fix from $1,9502013-11-18 MEDIUM 5.7 CVE-2013-4551 Xen 4.2.x and 4.3.x, when nested virtualization is disabled, does not properly check the emulation paths for (1) VMLAUNCH and (2) VMRESUME, which all… Xen Mitigation only Fix from $1,6002013-11-18 MEDIUM 6.4 CVE-2013-6682 The phone-proxy implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier does not properly validate X.509 certificates,… Adaptive Security Appliance Software after 9.0.3 Fix from $1,6002013-11-13 MEDIUM 6.1 CVE-2013-6683 The IPv6 implementation in Cisco NX-OS does not properly handle neighbor-table adjacencies, which allows remote attackers to cause a denial of servic… Nx Os Mitigation only Fix from $1,6002013-11-13 MEDIUM 6.8 CVE-2013-6684 The web framework on Cisco Wireless LAN Controller (WLC) devices does not properly validate configuration parameters, which allows remote authenticat… Wireless Lan Controller Mitigation only Fix from $1,6002013-11-13 MEDIUM 5.4 CVE-2013-5560 The IPv6 implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1.3 and earlier, when NAT64 or NAT66 is enabled, does not properly proc… Adaptive Security Appliance Software after 9.1 Fix from $1,6002013-11-13 HIGH 7.1 CVE-2013-5568 The auto-update implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier allows remote attackers to cause a denial of s… Adaptive Security Appliance Software after 9.0.3 Fix from $1,9502013-11-13 MEDIUM 5.8 CVE-2013-2653 security/MemberLoginForm.php in SilverStripe 3.0.3 supports login using a GET request, which makes it easier for remote attackers to conduct phishing… Silverstripe Patch available Fix from $1,6002013-11-13 MEDIUM 5.0 CVE-2013-3869EPSS 18% Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8… Windows 7 Patch available Fix from $1,6002013-11-13 MEDIUM 6.9 CVE-2013-6122 goodix_tool.c in the Goodix gt915 touchscreen driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for… Quic Mobile Station Modem Kernel Patch available Fix from $1,6002013-11-12 HIGH 9.0 CVE-2013-6618EPSS 11% jsdm/ajax/port.php in J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1 before 12.1R5, 12.2 before 12.2R3, and 12.3 before 12.3R1 allow… Junos after 10.4 Fix from $1,9502013-11-05 HIGH 9.3 CVE-2013-4436 The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, which allows remote attackers t… Salt Patch available Fix from $1,9502013-11-05 MEDIUM 5.0 CVE-2013-5561 The Safe Search enforcement feature in Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security Software does not properly perform filtering… Adaptive Security Appliance Cx Context Aware Security Software Mitigation only Fix from $1,6002013-11-04 MEDIUM 5.2 CVE-2013-4494 Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators … Debian Linux after 4.3.4 Fix from $1,6002013-11-02 MEDIUM 5.8 CVE-2013-5431 Open redirect vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.1.1 before IF 15, 6.2.0 before IF 14, 6.2.1, and 6.2.2 before IF 8 and … Tivoli Federated Identity Manager Mitigation only Fix from $1,6002013-11-01 HIGH 7.8 CVE-2013-5543 Cisco IOS XE 3.4 before 3.4.2S and 3.5 before 3.5.1S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) via mal… Ios Xe Mitigation only Fix from $1,9502013-10-31 HIGH 7.8 CVE-2013-5545 The PPTP ALG implementation in Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload… Ios Xe Mitigation only Fix from $1,9502013-10-31 HIGH 7.8 CVE-2013-5546 The TCP reassembly feature in Cisco IOS XE 3.7 before 3.7.3S and 3.8 before 3.8.1S on 1000 ASR devices allows remote attackers to cause a denial of s… Ios Xe Mitigation only Fix from $1,9502013-10-31 HIGH 7.8 CVE-2013-5547 Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) by sending malformed EoGRE pa… Ios Xe Mitigation only Fix from $1,9502013-10-31 HIGH 7.8 CVE-2013-5741 Triangle Research International (aka Tri) Nano-10 PLC devices with firmware r81 and earlier do not properly handle large length values in MODBUS data… Nano 10 Plc Firmware Mitigation only Fix from $1,9502013-10-29