Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 6.4 CVE-2011-5136 showImg.php in EPractize Labs Subscription Manager, possibly 1.0, allows remote attackers to overwrite arbitrary files via the db parameter. Subscription Manager No fix yet Fix from $1,6002012-08-30 MEDIUM 6.0 CVE-2012-3325 IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.5, and 8.5.x Full Profile before 8.5.0.1, whe… Websphere Application Server Mitigation only Fix from $1,6002012-08-30 MEDIUM 6.8 CVE-2012-2104EPSS 5% cgi-bin/munin-cgi-graph in Munin 2.x writes data to a log file without sanitizing non-printable characters, which might allow user-assisted remote at… Munin No fix yet Fix from $1,6002012-08-26 MEDIUM 5.1 CVE-2012-1177 libgdata before 0.10.2 and 0.11.x before 0.11.1 does not validate SSL certificates, which allows remote attackers to obtain user names and passwords … Libgdata after 0.11.0 Fix from $1,6002012-08-26 HIGH 7.2 CVE-2012-3485 Tunnelblick 3.3beta20 and earlier relies on argv[0] to determine the name of an appropriate (1) kernel module pathname or (2) executable file pathnam… Tunnelblick after 3.3beta20 Fix from $1,9502012-08-26 HIGH 10.0 CVE-2010-5185 The Antivirus component in Comodo Internet Security before 5.3.174622.1216 does not check whether X.509 certificates in signed executable files have … Comodo Internet Security after 5.0.163652.1142 Fix from $1,9502012-08-26 MEDIUM 6.4 CVE-2012-4670 Tigase XMPP Server before 5.1.0 does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spo… Tigase Xmpp Server after 5.1.0 Fix from $1,6002012-08-25 MEDIUM 5.8 CVE-2012-4671 psyced before 20120821 does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domain… Psyced after 20111122 Fix from $1,6002012-08-25 MEDIUM 5.8 CVE-2012-4672 Apple iChat Server does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains vi… Ichat Server Mitigation only Fix from $1,6002012-08-25 MEDIUM 5.8 CVE-2012-3525 s2s/out.c in jabberd2 2.2.16 and earlier does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP serve… Jabberd2 after 2.2.16 Fix from $1,6002012-08-25 MEDIUM 5.8 CVE-2012-4669 M-Link R14.6 before R14.6v14 and R15.1 before R15.1v10 does not verify that a request was made for an XMPP Server Dialback response, which allows rem… M Link Mitigation only Fix from $1,6002012-08-25 MEDIUM 5.0 CVE-2008-7312 The Filtering Service in Websense Enterprise 5.2 through 6.3 does not consider the IP address during URL categorization, which makes it easier for re… Enterprise Mitigation only Fix from $1,6002012-08-23 MEDIUM 6.8 CVE-2011-3952 The decode_init function in kmvc.c in libavcodec in FFmpeg before 0.10 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0… Ffmpeg after 0.9.1 Fix from $1,6002012-08-20 MEDIUM 6.8 CVE-2012-0853 The decodeTonalComponents function in the Actrac3 codec (atrac3.c) in libavcodec in FFmpeg 0.7.x before 0.7.12, and 0.8.x before 0.8.11; and in Libav… Ffmpeg No fix yet Fix from $1,6002012-08-20 HIGH 9.3 CVE-2012-4359 Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 do not validate the return value of the realloc function, which a… Winlog Pro after 2.07.17 Fix from $1,9502012-08-19 HIGH 9.3 CVE-2012-4357EPSS 7% Array index error in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 might allow remote attackers to execute arbi… Winlog Pro after 2.07.16 Fix from $1,9502012-08-19 HIGH 9.3 CVE-2012-4358 Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 do not validate the return value of the realloc function, which a… Winlog Pro after 2.07.16 Fix from $1,9502012-08-19 HIGH 7.8 CVE-2012-1535 KEVEPSS 70% Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers … Enterprise Linux Desktop 11.2.202.238 / 11.3.300.271+ Fix from $1,9502012-08-15 MEDIUM 5.0 CVE-2012-2096 The Fivestar module 6.x-1.x before 6.x-1.20 for Drupal does not properly validate voting data, which allows remote attackers to manipulate voting ave… Fivestar Module For Drupal Patch available Fix from $1,6002012-08-14 MEDIUM 6.4 CVE-2012-2330 The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allo… Node.js after 0.6.16 Fix from $1,6002012-08-13 MEDIUM 5.0 CVE-2012-2368 Bytemark Symbiosis before Revision 1322 does not properly validate passwords, which allows remote attackers to gain access to email accounts via an a… Symbiosis after 1321 Fix from $1,6002012-08-13 MEDIUM 5.0 CVE-2012-2964 The BreakingPoint Storm appliance before 3.0 requires cleartext credentials for establishing a session from a GUI administrative client, which allows… Breakingpoint Storm Appliance Ctm after 2.0 Fix from $1,6002012-08-12 HIGH 7.5 CVE-2012-2965 Caucho Quercus, as distributed in Resin before 4.0.29, does not properly handle unspecified characters in the names of variables, which has unknown i… Resin after 4.0.28 Fix from $1,9502012-08-12 HIGH 7.2 CVE-2012-2136 The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before 3.4.5 does not properly validate a certain length value, which allows… Linux Kernel 3.0.37 / 3.2.23+ Fix from $1,9502012-08-09 MEDIUM 5.0 CVE-2012-2191 IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, does… Global Security Kit after 8.0.13 Fix from $1,6002012-08-08 MEDIUM 5.0 CVE-2012-3429 The dns_to_ldap_dn_escape function in src/ldap_convert.c in bind-dyndb-ldap 1.1.0rc1 and earlier does not properly escape distinguished names (DN) fo… Bind Dyndb Ldap after 1.1.0 Fix from $1,6002012-08-07 MEDIUM 5.0 CVE-2012-2490 Cisco IP Communicator 8.6 allows man-in-the-middle attackers to modify the Certificate Trust List via unspecified vectors, aka Bug ID CSCtz01471. Ip Communicator No fix yet Fix from $1,6002012-08-06 HIGH 9.3 CVE-2012-1015 The kdc_handle_protected_negotiation function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8.x, 1.9.x before 1.9.5, and 1.10.x… Kerberos 5 Patch available Fix from $1,9502012-08-06 MEDIUM 5.0 CVE-2012-1367 The MallocLite implementation in Cisco IOS 12.0, 12.2, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (Route Processor cra… iOS No fix yet Fix from $1,6002012-08-06 MEDIUM 5.0 CVE-2012-3443 The django.forms.ImageField class in the form system in Django before 1.3.2 and 1.4.x before 1.4.1 completely decompresses image data during image va… Django after 1.3 Fix from $1,6002012-07-31