Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 5.0 CVE-2012-5703 The vSphere API in VMware ESXi 4.1 and ESX 4.1 allows remote attackers to cause a denial of service (host daemon crash) via an invalid value in a (1)… Esx Mitigation only Fix from $1,6002012-11-20 MEDIUM 5.0 CVE-2011-4612 icecast before 2.3.3 allows remote attackers to inject control characters such as newlines into the error loc (error.log) via a crafted URL. Icecast after 2.3.2 Fix from $1,6002012-11-20 MEDIUM 6.4 CVE-2012-4520 The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arb… Django Patch available Fix from $1,6002012-11-18 HIGH 7.5 CVE-2012-4945 Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to execute arbitrary commands via unspecified vectors, related to a … Fleetcommander after 4.0 Fix from $1,9502012-11-18 MEDIUM 5.0 CVE-2012-2733EPSS 9% java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not… Tomcat Mitigation only Fix from $1,6002012-11-16 HIGH 7.5 CVE-2012-4850 IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1, when JAX-RS is used, does not properly validate requests, which allows remote at… Websphere Application Server Mitigation only Fix from $1,9502012-11-14 HIGH 7.8 CVE-2012-2619EPSS 13% The Broadcom BCM4325 and BCM4329 Wi-Fi chips, as used in certain Acer, Apple, Asus, Ford, HTC, Kyocera, LG, Malata, Motorola, Nokia, Pantech, Samsung… Bcm4325 after 6.0.2 Fix from $1,9502012-11-14 HIGH 9.3 CVE-2012-4776EPSS 25% The Web Proxy Auto-Discovery (WPAD) functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not validate configuration data th… .net Framework Mitigation only Fix from $1,9502012-11-14 MEDIUM 5.0 CVE-2012-5424 Cisco Secure Access Control System (ACS) 5.x before 5.2 Patch 11 and 5.3 before 5.3 Patch 7, when a certain configuration involving TACACS+ and LDAP … Secure Access Control Server Mitigation only Fix from $1,6002012-11-07 HIGH 7.5 CVE-2012-5118 Google Chrome before 23.0.1271.64 on Mac OS X does not properly validate an integer value during the handling of GPU command buffers, which allows re… Chrome after 23.0.1271.62 Fix from $1,9502012-11-07 MEDIUM 5.8 CVE-2011-5241 Services_Twitter 0.6.3 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of th… Services Twitter Mitigation only Fix from $1,6002012-11-06 MEDIUM 5.8 CVE-2011-5242 tmhOAuth before 0.61 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the … Tmhoauth after 0.60 Fix from $1,6002012-11-06 MEDIUM 5.8 CVE-2011-5243 TwitterOAuth does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 ce… Twitteroauth Mitigation only Fix from $1,6002012-11-06 MEDIUM 5.8 CVE-2011-5236 Moneris eSelectPlus 2.03 PHP API does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName f… Eselect Plus Mitigation only Fix from $1,6002012-11-06 MEDIUM 5.8 CVE-2011-5237 PayPal WPS ToolKit does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.… Wps Toolkit Mitigation only Fix from $1,6002012-11-06 MEDIUM 5.8 CVE-2011-5238 google-checkout-php-sample-code before 1.3.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subj… Checkout Php after 1.3.1 Fix from $1,6002012-11-06 MEDIUM 5.8 CVE-2011-5239 CiviCRM 4.0.5 and 4.1.1 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of t… Civicrm Mitigation only Fix from $1,6002012-11-06 MEDIUM 5.8 CVE-2011-5240 Magento 1.5 and 1.6.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the… Magento Mitigation only Fix from $1,6002012-11-06 MEDIUM 5.8 CVE-2012-5801 The PayPal module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName fi… Ebay No fix yet Fix from $1,6002012-11-04 MEDIUM 5.8 CVE-2012-5802 The PayPal module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName fiel… Paypal No fix yet Fix from $1,6002012-11-04 MEDIUM 5.8 CVE-2012-5803 The Authorize.Net module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNa… Authorize.net Module No fix yet Fix from $1,6002012-11-04 MEDIUM 5.8 CVE-2012-5804 The CyberSource module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName… Cybersource No fix yet Fix from $1,6002012-11-04 MEDIUM 5.8 CVE-2012-5805 The PayPal IPN functionality in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectA… Instant Payment Notification No fix yet Fix from $1,6002012-11-04 MEDIUM 5.8 CVE-2012-5806 The PayPal Payments Pro module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjec… Payments Pro No fix yet Fix from $1,6002012-11-04 MEDIUM 5.8 CVE-2012-5807 The Authorize.Net eCheck module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subje… Authorize.net Echeck Module No fix yet Fix from $1,6002012-11-04 MEDIUM 5.8 CVE-2012-5808 The LinkPoint module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName f… Linkpoint No fix yet Fix from $1,6002012-11-04 MEDIUM 5.8 CVE-2012-5812 The ACRA library for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field… Acra Library No fix yet Fix from $1,6002012-11-04 MEDIUM 5.8 CVE-2012-5813 The Android_Pusher library for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAlt… Android Pusher No fix yet Fix from $1,6002012-11-04 MEDIUM 5.8 CVE-2012-5814 Weberknecht, as used in GitHub Gaug.es and other products, does not verify that the server hostname matches a domain name in the subject's Common Nam… Gaug.es No fix yet Fix from $1,6002012-11-04 MEDIUM 5.8 CVE-2012-5815 The Rackspace app 2.1.5 for iOS does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName fi… Rackspace No fix yet Fix from $1,6002012-11-04