Vulnerability index

Browse CVEs

7,769 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Advantech Webaccess MEDIUM 5.0
CVE-2012-0236

Advantech/BroadWin WebAccess 7.0 and earlier allows remote attackers to obtain sensitive information via a direct request to a URL. NOTE: the vendor…

Fix: after 6.0
Fix from $1,600 2012-02-21
R2\/extreme MEDIUM 5.0
CVE-2012-1223

RabidHamster R2/Extreme 1.65 and earlier uses a small search space of values for the PIN number, which allows remote attackers to obtain the PIN numb…

Fix: after 1.65
Fix from $1,600 2012-02-21
Linux Kernel MEDIUM 5.0
CVE-2010-4563

The Linux kernel, when using IPv6, allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a…

Mitigation only
Fix from $1,600 2012-02-02
Firefox MEDIUM 5.0
CVE-2012-0447

Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize data for image/vnd.microsoft.icon i…

Fix: after 2.7
Fix from $1,600 2012-02-01
Firefox MEDIUM 5.0
CVE-2011-3670

Mozilla Firefox before 3.6.26 and 4.x through 6.0, Thunderbird before 3.1.18 and 5.0 through 6.0, and SeaMonkey before 2.4 do not properly enforce th…

Fix: after 3.6.25
Fix from $1,600 2012-02-01
Samba MEDIUM 5.0
CVE-2012-0817

Memory leak in smbd in Samba 3.6.x before 3.6.3 allows remote attackers to cause a denial of service (memory and CPU consumption) by making many conn…

Patch available
Fix from $1,600 2012-01-30
WordPress MEDIUM 5.0
CVE-2011-4898EPSS 10%

wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbna…

Fix: after 3.3.1
Fix from $1,600 2012-01-30
Envision MEDIUM 5.0
CVE-2011-4143

EMC RSA enVision 4.0 before SP4 P5 and 4.1 before P3 allows remote attackers to obtain sensitive information about environment variables in the web s…

Mitigation only
Fix from $1,600 2012-01-27
Kaixin001 MEDIUM 6.4
CVE-2011-4866

The Kaixin001 (com.kaixin001.activity) application 1.3.1 and 1.3.3 for Android does not properly protect data, which allows remote attackers to read …

Mitigation only
Fix from $1,600 2012-01-25
Mitalk Messenger MEDIUM 6.4
CVE-2011-4697

The Xiaomi MiTalk Messenger (com.xiaomi.channel) application before 2.1.320 for Android does not properly protect data, which allows remote attackers…

Fix: after 2.1.310
Fix from $1,600 2012-01-25
Easy Filter MEDIUM 6.4
CVE-2011-4698

The AndroidAppTools Easy Filter (com.phoneblocker.android) application 1.1 and 1.2 for Android does not properly protect data, which allows remote at…

Mitigation only
Fix from $1,600 2012-01-25
Twidroyd Legacy MEDIUM 6.4
CVE-2011-4699

The Ubermedia Twidroyd Legacy (com.twidroydlegacy) application 4.3.11 for Android does not properly protect data, which allows remote attackers to re…

Mitigation only
Fix from $1,600 2012-01-25
Tomcat MEDIUM 5.0
CVE-2011-3375EPSS 7%

Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request object…

Mitigation only
Fix from $1,600 2012-01-19
Hp Chaisoe HIGH 7.8
CVE-2011-4785

Directory traversal vulnerability in the HP-ChaiSOE/1.0 web server on the HP LaserJet P3015 printer with firmware before 07.080.3, LaserJet 4650 prin…

Mitigation only
Fix from $1,950 2012-01-10
Debian Linux MEDIUM 5.0
CVE-2011-4360

MediaWiki before 1.17.1 allows remote attackers to obtain the page titles of all restricted pages via a series of requests involving the (1) curid or…

Fix: 1.17.1+
Fix from $1,600 2012-01-08
Parallels Plesk Small Business Panel MEDIUM 5.0
CVE-2011-4766

The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 allows remote attackers to obtain ASP source code via a dire…

Mitigation only
Fix from $1,600 2011-12-16
Parallels Plesk Small Business Panel MEDIUM 5.0
CVE-2011-4767

The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 has web pages containing e-mail addresses that are not inten…

Mitigation only
Fix from $1,600 2011-12-16
Smarterstats MEDIUM 5.0
CVE-2011-4751

SmarterTools SmarterStats 6.2.4100 generates web pages containing external links in response to GET requests with query strings for frmGettingStarted…

Mitigation only
Fix from $1,600 2011-12-16
Parallels Plesk Small Business Panel MEDIUM 5.0
CVE-2011-4756

Parallels Plesk Small Business Panel 10.2.0 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote …

Mitigation only
Fix from $1,600 2011-12-16
Parallels Plesk Small Business Panel MEDIUM 5.0
CVE-2011-4759

Parallels Plesk Small Business Panel 10.2.0 generates web pages containing external links in response to GET requests with query strings for client@1…

Mitigation only
Fix from $1,600 2011-12-16
Parallels Plesk Small Business Panel MEDIUM 5.0
CVE-2011-4760

Parallels Plesk Small Business Panel 10.2.0 has web pages containing e-mail addresses that are not intended for correspondence about the local applic…

Mitigation only
Fix from $1,600 2011-12-16
Parallels Plesk Panel MEDIUM 5.0
CVE-2011-4737

The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 includes a submitted password within an HTTP response body, which allows remote a…

Mitigation only
Fix from $1,600 2011-12-16
Parallels Plesk Panel MEDIUM 5.0
CVE-2011-4738

The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which mak…

Mitigation only
Fix from $1,600 2011-12-16
Parallels Plesk Panel MEDIUM 5.0
CVE-2011-4741

The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 includes a database connection string within a web page, which allows remote atta…

Mitigation only
Fix from $1,600 2011-12-16
Parallels Plesk Panel MEDIUM 5.0
CVE-2011-4742

The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 has web pages containing e-mail addresses that are not intended for correspondenc…

Mitigation only
Fix from $1,600 2011-12-16
Parallels Plesk Panel MEDIUM 5.0
CVE-2011-4748

The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 has web pages containing e-mail addresses that are not intended for correspond…

Mitigation only
Fix from $1,600 2011-12-16
Parallels Plesk Panel MEDIUM 5.0
CVE-2011-4731

The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 includes an RFC 1918 IP address within a web page, which allows re…

Mitigation only
Fix from $1,600 2011-12-16
Parallels Plesk Panel MEDIUM 5.0
CVE-2011-4728

The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not set the secure flag for a cookie in an https session, whi…

Mitigation only
Fix from $1,600 2011-12-16
Asterisk MEDIUM 5.0
CVE-2011-4597

The SIP over UDP implementation in Asterisk Open Source 1.4.x before 1.4.43, 1.6.x before 1.6.2.21, and 1.8.x before 1.8.7.2 uses different port numb…

Mitigation only
Fix from $1,600 2011-12-15
Blackberry Tablet Os HIGH 7.2
CVE-2011-0291

The BlackBerry PlayBook service on the Research In Motion (RIM) BlackBerry PlayBook tablet with software before 1.0.8.6067 allows local users to gain…

Mitigation only
Fix from $1,950 2011-12-08