Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 5.0 CVE-2013-4932 Multiple array index errors in epan/dissectors/packet-gsm_a_common.c in the GSM A Common dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before … Wireshark Patch available Fix from $1,6002013-07-30 MEDIUM 5.8 CVE-2013-2248EPSS 95% Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and cond… Struts Mitigation only Fix from $1,6002013-07-20 HIGH 7.8 CVE-2013-1943 The KVM subsystem in the Linux kernel before 3.0 does not check whether kernel addresses are specified during allocation of memory slots for use in a… Linux Kernel 3.0+ Fix from $1,9502013-07-16 MEDIUM 6.8 CVE-2013-3400 The license-installation module in Cisco NX-OS on Nexus 1000V devices allows local users to execute arbitrary commands via crafted "install license" … Nx Os Mitigation only Fix from $1,6002013-07-10 HIGH 7.5 CVE-2013-2871 Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service or possibly have unspecified o… Chrome after 28.0.1500.70 Fix from $1,9502013-07-10 HIGH 7.5 CVE-2013-1362EPSS 66% Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary s… Opensuse after 2.13 Fix from $1,9502013-07-09 MEDIUM 5.0 CVE-2013-2116 The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over… Gnutls Mitigation only Fix from $1,6002013-07-03 MEDIUM 5.8 CVE-2013-3925 Atlassian Crowd 2.5.x before 2.5.4, 2.6.x before 2.6.3, 2.3.8, and 2.4.9 allows remote attackers to read arbitrary files and send HTTP requests to in… Crowd No fix yet Fix from $1,6002013-07-01 MEDIUM 5.0 CVE-2013-4098 ServerAdmin/ErrorViewer.jsp in DS3 Authentication Server allow remote attackers to inject arbitrary error-page text via the message parameter. Authentication Server No fix yet Fix from $1,6002013-06-28 MEDIUM 6.5 CVE-2013-4095EPSS 6% plain/actionsets.html in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated user… Securesphere No fix yet Fix from $1,6002013-06-28 HIGH 9.0 CVE-2013-4096EPSS 9% ServerAdmin/TestTelnetConnection.jsp in DS3 Authentication Server allows remote authenticated users to execute arbitrary commands via shell metachara… Authentication Server No fix yet Fix from $1,9502013-06-28 MEDIUM 6.5 CVE-2013-4094EPSS 6% The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated… Securesphere No fix yet Fix from $1,6002013-06-28 MEDIUM 6.8 CVE-2013-4660EPSS 17% The JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, which allows remote attackers to … Js Yaml after 2.0.4 Fix from $1,6002013-06-28 HIGH 7.8 CVE-2013-3382 The Next-Generation Firewall (aka NGFW, formerly CX Context-Aware Security) module 9.x before 9.1.1.9 and 9.1.2.x before 9.1.2.12 for Cisco Adaptive … Adaptive Security Appliance Mitigation only Fix from $1,9502013-06-26 MEDIUM 5.0 CVE-2013-3393 The Precision Video Engine component in Cisco Jabber for Windows and Cisco Virtualization Experience Media Engine allows remote attackers to cause a … Jabber Mitigation only Fix from $1,6002013-06-26 HIGH 7.5 CVE-2013-1694 The PreserveWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.… Firefox after 21.0 Fix from $1,9502013-06-26 MEDIUM 5.0 CVE-2013-4615EPSS 16% The Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers allow remote attackers to cause a denial of service (device h… Mg3100 Printer Mitigation only Fix from $1,6002013-06-21 MEDIUM 5.0 CVE-2013-0551 The Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in… Tivoli Monitoring Mitigation only Fix from $1,6002013-06-21 HIGH 7.1 CVE-2013-3035 The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allows remote attackers to cause a denial of serv… Aix Mitigation only Fix from $1,9502013-06-21 HIGH 7.8 CVE-2013-3378 Cisco TelePresence TC Software before 6.1 and TE Software before 4.1.3 allow remote attackers to cause a denial of service (temporary device hang) vi… Telepresence Tc Software after 6.0.1 Fix from $1,9502013-06-21 HIGH 7.8 CVE-2013-4632 The Huawei Access Router (AR) before V200R002SPC003 allows remote attackers to cause a denial of service (device reset) via a crafted field in a DHCP… Access Router Mitigation only Fix from $1,9502013-06-20 MEDIUM 5.4 CVE-2013-1203 Cisco ASA CX Context-Aware Security Software allows remote attackers to cause a denial of service (device reload) via crafted TCP packets that appear… Asa Cx Context Aware Security Software Mitigation only Fix from $1,6002013-06-18 MEDIUM 6.5 CVE-2012-6567 REDCap before 4.14.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the logic of a custom rule. Redcap after 4.13.18 Fix from $1,6002013-06-17 MEDIUM 5.8 CVE-2013-1093 Open redirect vulnerability in the fwdToURL function in the ZCC login page in zcc-framework.jar in Novell ZENworks Configuration Management (ZCM) 11.… Zenworks Configuration Management Mitigation only Fix from $1,6002013-06-17 MEDIUM 6.8 CVE-2013-1985 Integer overflow in X.org libXinerama 1.1.2 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vecto… Libxinerama after 1.1.2 Fix from $1,6002013-06-15 HIGH 7.1 CVE-2013-2783 The DNP3 driver in IOServer drivers 1.0.19.0 allows remote attackers to cause a denial of service (infinite loop) or obtain unspecified control via c… Ioserver Patch available Fix from $1,9502013-06-14 HIGH 10.0 CVE-2013-3573 HP Insight Diagnostics 9.4.0.4710 allows remote attackers to conduct unspecified injection attacks via unknown vectors. Insight Diagnostics No fix yet Fix from $1,9502013-06-14 HIGH 7.8 CVE-2013-3574 Absolute path traversal vulnerability in hpdiags/frontend2/commands/saveCompareConfig.php in HP Insight Diagnostics 9.4.0.4710 allows remote attacker… Insight Diagnostics Mitigation only Fix from $1,9502013-06-14 MEDIUM 5.0 CVE-2013-3575 hpdiags/frontend2/help/pageview.php in HP Insight Diagnostics 9.4.0.4710 does not properly restrict PHP include or require statements, which allows r… Insight Diagnostics Mitigation only Fix from $1,6002013-06-14 MEDIUM 5.0 CVE-2013-4078 epan/dissectors/packet-rdp.c in the RDP dissector in Wireshark 1.8.x before 1.8.8 does not validate return values during checks for data availability… Wireshark Mitigation only Fix from $1,6002013-06-09