Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 9.3 CVE-2012-0210EPSS 5% debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to obtain system information and execute arbitrary co… Devscripts Mitigation only Fix from $1,9502012-06-16 HIGH 9.3 CVE-2012-0211EPSS 6% debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via a crafted tarball file … Devscripts Mitigation only Fix from $1,9502012-06-16 HIGH 9.3 CVE-2012-0212EPSS 6% debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via shell metacharacters in… Devscripts Mitigation only Fix from $1,9502012-06-16 HIGH 9.3 CVE-2012-3288 VMware Workstation 7.x before 7.1.6 and 8.x before 8.0.4, VMware Player 3.x before 3.1.6 and 4.x before 4.0.4, VMware Fusion 4.x before 4.1.3, VMware… Workstation Mitigation only Fix from $1,9502012-06-14 HIGH 9.3 CVE-2012-3556 Opera before 11.65 does not properly restrict the opening of a pop-up window in response to the first click of a double-click action, which makes it … Opera Browser after 11.62 Fix from $1,9502012-06-14 HIGH 7.2 CVE-2012-1864 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, a… Windows 2003 Server Mitigation only Fix from $1,9502012-06-12 HIGH 7.2 CVE-2012-1865 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, a… Windows 2003 Server Mitigation only Fix from $1,9502012-06-12 HIGH 7.2 CVE-2012-1866 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, a… Windows 2003 Server Mitigation only Fix from $1,9502012-06-12 MEDIUM 5.8 CVE-2012-3003 Open redirect vulnerability in an unspecified web application in Siemens WinCC 7.0 SP3 before Update 2 allows remote attackers to redirect users to a… Wincc Mitigation only Fix from $1,6002012-06-08 HIGH 7.5 CVE-2012-1817 Buffer overflow in Emerson DeltaV and DeltaV Workstations 9.3.1, 10.3.1, 11.3, and 11.3.1 and DeltaV ProEssentials Scientific Graph 5.0.0.6 allows us… Deltav Mitigation only Fix from $1,9502012-06-08 HIGH 8.8 CVE-2012-0247 ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via craf… Debian Linux Patch available Fix from $1,9502012-06-05 MEDIUM 6.8 CVE-2012-0060 RPM before 4.9.1.3 does not properly validate region tags, which allows remote attackers to cause a denial of service (crash) and possibly execute ar… Rpm after 4.9.1.2 Fix from $1,6002012-06-04 MEDIUM 6.8 CVE-2012-0061 The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly validate region tags, which allows user-assisted remote attackers to … Rpm after 4.9.1.2 Fix from $1,6002012-06-04 HIGH 7.8 CVE-2012-2488 Cisco IOS XR before 4.2.1 on ASR 9000 series devices and CRS series devices allows remote attackers to cause a denial of service (packet transmission… Ios Xr after 4.2.0 Fix from $1,9502012-05-31 MEDIUM 6.8 CVE-2010-5099 The fileDenyPattern functionality in the PHP file inclusion protection API in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 d… TYPO3 No fix yet Fix from $1,6002012-05-30 MEDIUM 6.5 CVE-2011-3363 The setup_cifs_sb function in fs/cifs/connect.c in the Linux kernel before 2.6.39 does not properly handle DFS referrals, which allows remote CIFS se… Linux Kernel 2.6.39+ Fix from $1,6002012-05-24 MEDIUM 5.0 CVE-2012-2374 CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote attackers to inject arbitrar… Tornado after 2.2 Fix from $1,6002012-05-23 HIGH 7.6 CVE-2012-2562 The Xelex MobileTrack application 2.3.7 and earlier for Android does not verify the origin of SMS commands, which allows remote attackers to execute … Mobiletrack after 2.3.7 Fix from $1,9502012-05-22 HIGH 10.0 CVE-2012-2321EPSS 6% The loopback plug-in in ConnMan before 0.85 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) host name or (2… Connman after 0.84 Fix from $1,9502012-05-18 HIGH 10.0 CVE-2012-2118 Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service or possibl… X11 Patch available Fix from $1,9502012-05-18 MEDIUM 5.8 CVE-2012-1589 Open redirect vulnerability in the Form API in Drupal 7.x before 7.13 allows remote attackers to redirect users to arbitrary web sites and conduct ph… Drupal Mitigation only Fix from $1,6002012-05-18 MEDIUM 5.5 CVE-2012-1090 The cifs_lookup function in fs/cifs/dir.c in the Linux kernel before 3.2.10 allows local users to cause a denial of service (OOPS) via attempted acce… Linux Kernel 3.2.10+ Fix from $1,6002012-05-17 HIGH 10.0 CVE-2011-3097 The PDF functionality in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other im… Chrome after 19.0.1084.45 Fix from $1,9502012-05-16 HIGH 10.0 CVE-2011-3092 The regex implementation in Google V8, as used in Google Chrome before 19.0.1084.46, allows remote attackers to cause a denial of service (invalid wr… Chrome after 19.0.1084.45 Fix from $1,9502012-05-16 MEDIUM 5.0 CVE-2011-3093 Google Chrome before 19.0.1084.46 does not properly handle glyphs, which allows remote attackers to cause a denial of service (out-of-bounds read) vi… Chrome after 19.0.1084.45 Fix from $1,6002012-05-16 MEDIUM 5.0 CVE-2011-3094 Google Chrome before 19.0.1084.46 does not properly handle Tibetan text, which allows remote attackers to cause a denial of service (out-of-bounds re… Chrome after 19.0.1084.45 Fix from $1,6002012-05-16 HIGH 10.0 CVE-2011-3095 The OGG container in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact… Chrome after 19.0.1084.45 Fix from $1,9502012-05-16 HIGH 9.3 CVE-2012-2611EPSS 45% The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EH… Netweaver No fix yet Fix from $1,9502012-05-15 MEDIUM 5.0 CVE-2012-0676 WebKit in Apple Safari before 5.1.7 does not properly track state information during the processing of form input, which allows remote attackers to f… Safari after 5.1.6 Fix from $1,6002012-05-11 HIGH 9.3 CVE-2012-0018EPSS 25% Microsoft Visio Viewer 2010 Gold and SP1 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary cod… Visio Viewer Mitigation only Fix from $1,9502012-05-09