Vulnerability index

Browse CVEs

7,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Bitcoin Qt MEDIUM 5.0
CVE-2013-2272

The penny-flooding protection mechanism in the CTxMemPool::accept method in bitcoind and Bitcoin-Qt before 0.4.9rc1, 0.5.x before 0.5.8rc1, 0.6.0 bef…

Fix: after 0.4.8
Fix from $1,600 2013-03-12
Bitcoin Qt MEDIUM 5.0
CVE-2013-2273

bitcoind and Bitcoin-Qt before 0.4.9rc1, 0.5.x before 0.5.8rc1, 0.6.0 before 0.6.0.11rc1, 0.6.1 through 0.6.5 before 0.6.5rc1, and 0.7.x before 0.7.3…

Fix: after 0.4.8
Fix from $1,600 2013-03-12
Chrome MEDIUM 5.0
CVE-2013-0909

The XSS Auditor in Google Chrome before 25.0.1364.152 allows remote attackers to obtain sensitive HTTP Referer information via unspecified vectors.

Fix: after 25.0.1364.126
Fix from $1,600 2013-03-05
Bugzilla MEDIUM 5.0
CVE-2013-0786

The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x before 3.6.13 and 3.7.x and 4.0.x before 4.0.10 generates different error mess…

Fix: after 3.6.12
Fix from $1,600 2013-02-24
Digilibe MEDIUM 5.0
CVE-2013-1402EPSS 6%

DigiLIBE 3.4 and possibly other versions sends a redirect but does not exit, which allows remote attackers to obtain sensitive configuration informat…

No fix yet
Fix from $1,600 2013-02-14
Joomla\! MEDIUM 5.0
CVE-2013-1454

Joomla! 3.0.x through 3.0.2 allows attackers to obtain sensitive information via unspecified vectors related to "Coding errors."

No fix yet
Fix from $1,600 2013-02-13
Joomla\! MEDIUM 5.0
CVE-2013-1455

Joomla! 3.0.x through 3.0.2 allows attackers to obtain sensitive information via unspecified vectors related to an "Undefined variable."

Mitigation only
Fix from $1,600 2013-02-13
Flash Player MEDIUM 5.0
CVE-2013-0637EPSS 6%

Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10…

Fix: 3.6.0.597 / 3.6.0.599+
Fix from $1,600 2013-02-12
Android HIGH 7.1
CVE-2011-1350

The PowerVR SGX driver in Android before 2.3.6 allows attackers to obtain potentially sensitive information from kernel stack memory via an applicati…

Fix: after 2.3.5
Fix from $1,950 2013-02-05
Moodle MEDIUM 5.0
CVE-2012-6104

blog/rsslib.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allows remote attackers to obtain sensitive information from…

Mitigation only
Fix from $1,600 2013-01-27
Moodle MEDIUM 5.0
CVE-2012-6105

blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 continues to provide a blog RSS feed af…

Mitigation only
Fix from $1,600 2013-01-27
Controllogix Controllers MEDIUM 5.0
CVE-2012-6441EPSS 47%

An information exposure of confidential information results when the device receives a specially crafted CIP packet to Port 2222/TCP, Port 2222/UDP, …

Fix: after 1400
Fix from $1,600 2013-01-24
Organizer MEDIUM 5.0
CVE-2012-6512

The Organizer plugin 1.2.1 for WordPress allows remote attackers to obtain the installation path via unspecified vectors to (1) plugin_hook.php, (2) …

Fix: after 1.2.1
Fix from $1,600 2013-01-24
Efront MEDIUM 5.0
CVE-2012-6515

eFront 3.6.10, 3.6.11 build 15059, and earlier allows remote attackers to obtain sensitive information via invalid courses_ID parameter in the lesson…

No fix yet
Fix from $1,600 2013-01-24
Drupal MEDIUM 5.0
CVE-2012-5652

Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result.

Patch available
Fix from $1,600 2013-01-03
Opera Browser MEDIUM 5.0
CVE-2012-6469

Opera before 12.11 allows remote attackers to determine the existence of arbitrary local files via vectors involving web script in an error page.

Fix: after 12.10
Fix from $1,600 2013-01-02
Wp Php Widget MEDIUM 5.0
CVE-2013-0721

wp-php-widget.php in the WP PHP widget plugin 1.0.2 for WordPress allows remote attackers to obtain sensitive information via a direct request, which…

Mitigation only
Fix from $1,600 2013-01-02
Opera Browser MEDIUM 5.0
CVE-2012-6466

Opera before 12.10 does not properly handle incorrect size data in a WebP image, which allows remote attackers to obtain potentially sensitive inform…

Fix: after 12.10
Fix from $1,600 2013-01-02
Rational Clearquest MEDIUM 5.0
CVE-2012-5765

The Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows remote attackers to obtain sensitive …

Mitigation only
Fix from $1,600 2012-12-20
Helpbox MEDIUM 5.0
CVE-2012-4976

selectawasset.asp in Layton Helpbox 4.4.0 allows remote attackers to discover ODBC database credentials via an element=sys_asset_id request, which is…

Mitigation only
Fix from $1,600 2012-12-12
1.1.2 MEDIUM 5.0
CVE-2012-6313EPSS 8%

simple-gmail-login.php in the Simple Gmail Login plugin before 1.1.4 for WordPress allows remote attackers to obtain sensitive information via a requ…

Mitigation only
Fix from $1,600 2012-12-11
Springsource Spring Security MEDIUM 5.0
CVE-2012-5055

DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password…

Fix: after 2.0.6
Fix from $1,600 2012-12-05
Wireshark MEDIUM 5.0
CVE-2012-6052

Wireshark 1.8.x before 1.8.4 allows remote attackers to obtain sensitive hostname information by reading pcap-ng files.

Mitigation only
Fix from $1,600 2012-12-05
Password Policy MEDIUM 5.0
CVE-2012-5552

The Password policy module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to obtain password hashes by sniffing…

Patch available
Fix from $1,600 2012-12-03
Webform Civicrm MEDIUM 5.0
CVE-2012-5554

The default configuration for the Webform CiviCRM Integration module 7.x-3.x before 7.x-3.2 has "Enforce Permissions" disabled, which allows remote a…

Patch available
Fix from $1,600 2012-12-03
MariaDB MEDIUM 5.0
CVE-2012-5615EPSS 15%

Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different er…

Mitigation only
Fix from $1,600 2012-12-03
Quick.cart MEDIUM 5.0
CVE-2012-6049

Open Solution Quick.Cart 5.0 allows remote attackers to obtain sensitive information via (1) a long string or (2) invalid characters in a cookie, whi…

Mitigation only
Fix from $1,600 2012-11-27
Resteasy MEDIUM 5.0
CVE-2011-5245

The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external …

Fix: after 2.3.1
Fix from $1,600 2012-11-23
Resteasy MEDIUM 5.0
CVE-2012-0818

RESTEasy before 2.3.1 allows remote attackers to read arbitrary files via an external entity reference in a DOM document, aka an XML external entity …

Fix: after 2.3.0
Fix from $1,600 2012-11-23
Seditio MEDIUM 5.0
CVE-2012-5915

Neocrome Seditio build 161 and earlier allows remote attackers to obtain sensitive information via direct request to (1) view.php, (2) plugins/contac…

Mitigation only
Fix from $1,600 2012-11-17