Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 10.0 CVE-2011-4249 Array index error in the RV30 codec in RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via unspecified vector… Realplayer after 14.0.7 Fix from $1,9502011-11-24 MEDIUM 5.0 CVE-2011-4311 ResourceSpace before 4.2.2833 does not properly validate access keys, which allows remote attackers to bypass intended resource restrictions via unsp… Resourcespace after 4.2.2816 Fix from $1,6002011-11-19 MEDIUM 5.0 CVE-2011-3646 phpmyadmin.css.php in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to obtain sensitive information via an array-typed js_frame parameter to … phpMyAdmin Patch available Fix from $1,6002011-11-17 MEDIUM 5.0 CVE-2011-2772 The get_dataroot_image_path function in lib/file.php in Mahara before 1.4.1 does not properly validate uploaded image files, which allows remote atta… Mahara after 1.4.0 Fix from $1,6002011-11-15 HIGH 9.3 CVE-2011-3647 The JSSubScriptLoader in Mozilla Firefox before 3.6.24 and Thunderbird before 3.1.6 does not properly handle XPCNativeWrappers during calls to the lo… Firefox after 3.6.23 Fix from $1,9502011-11-09 HIGH 7.5 CVE-2011-3880 Google Chrome before 15.0.874.102 does not prevent use of an unspecified special character as a delimiter in HTTP headers, which has unknown impact a… Chrome 15.0.874.102+ Fix from $1,9502011-10-25 MEDIUM 6.8 CVE-2011-3884 Google Chrome before 15.0.874.102 does not properly address timing issues during DOM traversal, which allows remote attackers to cause a denial of se… Chrome 15.0.874.102+ Fix from $1,6002011-10-25 MEDIUM 6.8 CVE-2011-3886 Google V8, as used in Google Chrome before 15.0.874.102, allows remote attackers to cause a denial of service or possibly have unspecified other impa… V8 Mitigation only Fix from $1,6002011-10-25 HIGH 7.5 CVE-2011-2057 The cat6000-dot1x component in Cisco IOS 12.2 before 12.2(33)SXI7 does not properly handle (1) a loop between a dot1x enabled port and an open-authen… iOS 12.2+ Fix from $1,9502011-10-22 HIGH 7.5 CVE-2011-2058 The cat6000-dot1x component in Cisco IOS 12.2 before 12.2(33)SXI7 does not properly handle an external loop between a pair of dot1x enabled ports, wh… iOS 12.2+ Fix from $1,9502011-10-22 MEDIUM 6.8 CVE-2011-4063 chan_sip.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.7.1 and 10.x before 10.0.0-rc1 does not properly initialize variables d… Open Source Mitigation only Fix from $1,6002011-10-21 HIGH 7.8 CVE-2011-4151 The krb5_db2_lockout_audit function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4, when the db2 (aka Berkeley D… Kerberos 5 Mitigation only Fix from $1,9502011-10-20 HIGH 7.8 CVE-2011-1527 The kdb_ldap plugin in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 through 1.9.1, when the LDAP back end is used, allows remot… Kerberos 5 Mitigation only Fix from $1,9502011-10-20 HIGH 7.8 CVE-2011-1528 The krb5_ldap_lockout_audit function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4 and 1.9 through 1.9.1, when … Kerberos 5 Mitigation only Fix from $1,9502011-10-20 HIGH 7.8 CVE-2011-1529 The lookup_lockout_policy function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4 and 1.9 through 1.9.1, when th… Kerberos 5 Mitigation only Fix from $1,9502011-10-20 MEDIUM 5.0 CVE-2011-4138 The verify_exists functionality in the URLField implementation in Django before 1.2.7 and 1.3.x before 1.3.1 originally tests a URL's validity throug… Django after 1.2.6 Fix from $1,6002011-10-19 MEDIUM 5.0 CVE-2011-4139 Django before 1.2.7 and 1.3.x before 1.3.1 uses a request's HTTP Host header to construct a full URL in certain circumstances, which allows remote at… Django after 1.2.6 Fix from $1,6002011-10-19 MEDIUM 5.8 CVE-2011-4136 django.contrib.sessions in Django before 1.2.7 and 1.3.x before 1.3.1, when session data is stored in the cache, uses the root namespace for both ses… Django after 1.2.6 Fix from $1,6002011-10-19 MEDIUM 6.8 CVE-2011-3227 libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a nonstandard extension in a Certificate Revocation … Mac Os X after 10.7.1 Fix from $1,6002011-10-14 MEDIUM 5.0 CVE-2011-2012EPSS 17% Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remo… Forefront Unified Access Gateway Mitigation only Fix from $1,6002011-10-12 MEDIUM 5.0 CVE-2011-2007EPSS 24% Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service o… Host Integration Server Mitigation only Fix from $1,6002011-10-12 MEDIUM 5.0 CVE-2011-2008EPSS 21% Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service o… Host Integration Server Mitigation only Fix from $1,6002011-10-12 MEDIUM 5.8 CVE-2010-4900 Open redirect vulnerability in c.php in CMS WebManager-Pro 8.1 and earlier allows remote attackers to redirect users to arbitrary web sites and condu… Cms Webmanager Pro after 8.1 Fix from $1,6002011-10-08 MEDIUM 5.0 CVE-2011-3368EPSS 91% The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with u… HTTP Server Patch available Fix from $1,6002011-10-05 MEDIUM 6.8 CVE-2011-2861 Google Chrome before 14.0.835.163 does not properly handle strings in PDF documents, which allows remote attackers to have an unspecified impact via … Chrome 14.0.835.163+ Fix from $1,6002011-09-19 HIGH 7.5 CVE-2011-2838 Google Chrome before 14.0.835.163 does not properly consider the MIME type during the loading of a plug-in, which has unspecified impact and remote a… Chrome 14.0.835.163+ Fix from $1,9502011-09-19 MEDIUM 6.8 CVE-2011-2841 Google Chrome before 14.0.835.163 does not properly perform garbage collection during the processing of PDF documents, which allows remote attackers … Chrome 14.0.835.163+ Fix from $1,6002011-09-19 HIGH 7.5 CVE-2011-2842 The installer in Google Chrome before 14.0.835.163 on Mac OS X does not properly handle lock files, which has unspecified impact and attack vectors. Chrome 14.0.835.163+ Fix from $1,9502011-09-19 HIGH 10.0 CVE-2011-3496EPSS 14% service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) BF, (… Scadapro after 4.0.0 Fix from $1,9502011-09-16 HIGH 9.3 CVE-2011-3211 The server in Bcfg2 1.1.2 and earlier, and 1.2 prerelease, allows remote attackers to execute arbitrary commands via shell metacharacters in data rec… Bcfg2 after 1.1.2 Fix from $1,9502011-09-16