Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Chrome HIGH 7.5
CVE-2011-3084

Google Chrome before 19.0.1084.46 does not use a dedicated process for the loading of links found on an internal page, which might allow attackers to…

Fix: after 19.0.1084.45
Fix from $1,950 2012-05-16
Basercms MEDIUM 5.1
CVE-2012-1248

app/config/core.php in baserCMS 1.6.15 and earlier does not properly handle installations in shared-hosting environments, which allows remote attacke…

Fix: after 1.6.15
Fix from $1,600 2012-05-15
Performance Insight HIGH 9.0
CVE-2012-2009

Unspecified vulnerability in HP Performance Insight for Networks 5.3.x, 5.41, 5.41.001, and 5.41.002 allows remote authenticated users to gain privil…

Mitigation only
Fix from $1,950 2012-05-09
Excel HIGH 9.3
CVE-2012-0184EPSS 24%

Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2008 and 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and …

Mitigation only
Fix from $1,950 2012-05-09
Excel HIGH 9.3
CVE-2012-0185EPSS 25%

Heap-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 Gold and SP1, Excel Viewer, and Office Compatibility Pack SP2 and SP3 allows …

Mitigation only
Fix from $1,950 2012-05-09
Excel HIGH 9.3
CVE-2012-1847EPSS 25%

Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2008 and 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and …

Mitigation only
Fix from $1,950 2012-05-09
Database Server HIGH 7.5
CVE-2012-1675EPSS 78%

The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.0.5, as used in Oracle Fusion…

No fix yet
Fix from $1,950 2012-05-08
Aix HIGH 7.2
CVE-2012-0745

The getpwnam function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.1.0.10 through 2.2.1.3 does not properly interact with customer-extended LDAP user filt…

Mitigation only
Fix from $1,950 2012-05-04
Rational Appscan MEDIUM 6.0
CVE-2012-0733

IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1, when Integrated Windows authentication is used, allows remote authenticated users to obta…

Mitigation only
Fix from $1,600 2012-05-03
Ip Communicator MEDIUM 5.0
CVE-2012-0361

The sccp-protocol component in Cisco IP Communicator (CIPC) 7.0 through 8.6 does not limit the rate of SCCP messages to Cisco Unified Communications …

Mitigation only
Fix from $1,600 2012-05-02
Toad For Data Analysts MEDIUM 6.9
CVE-2012-0279

Quest Toad for Data Analysts 3.0.1 uses weak permissions (Everyone: Full Control) for the %COMMONPROGRAMFILES%\Quest Shared directory, which allows l…

Mitigation only
Fix from $1,600 2012-05-01
Paste MEDIUM 5.1
CVE-2012-0878

Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to b…

Fix: after 1.7.5
Fix from $1,600 2012-05-01
Evo 4g Software MEDIUM 6.4
CVE-2012-2217

The HTC IQRD service for Android on the HTC EVO 4G before 4.67.651.3, EVO Design 4G before 2.12.651.5, Shift 4G before 2.77.651.3, EVO 3D before 2.17…

Fix: after 4.54.651.1
Fix from $1,600 2012-05-01
Samba MEDIUM 6.5
CVE-2012-2111

The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.…

Patch available
Fix from $1,600 2012-04-30
Web Gateway MEDIUM 5.0
CVE-2012-2212

McAfee Web Gateway 7.0 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname i…

Mitigation only
Fix from $1,600 2012-04-28
Squid MEDIUM 5.0
CVE-2012-2213EPSS 12%

Squid 3.1.9 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host …

Mitigation only
Fix from $1,600 2012-04-28
Prosafe Fvs318n HIGH 7.5
CVE-2012-2439

The default configuration of the NETGEAR ProSafe FVS318N firewall enables web-based administration on the WAN interface, which allows remote attacker…

Mitigation only
Fix from $1,950 2012-04-28
8840t HIGH 7.5
CVE-2012-2440

The default configuration of the TP-Link 8840T router enables web-based administration on the WAN interface, which allows remote attackers to establi…

Mitigation only
Fix from $1,950 2012-04-28
Firefox HIGH 9.3
CVE-2012-0478

The texImage2D implementation in the WebGL subsystem in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.…

Fix: after 2.9
Fix from $1,950 2012-04-25
WordPress MEDIUM 5.0
CVE-2012-2401

Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain f…

Fix: after 3.3.1
Fix from $1,600 2012-04-21
WordPress MEDIUM 5.5
CVE-2012-2402

wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and deactivate …

Fix: after 3.3.1
Fix from $1,600 2012-04-21
Data Protection Advisor HIGH 7.8
CVE-2012-0406EPSS 9%

The DPA_Utilities.cProcessAuthenticationData function in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a den…

No fix yet
Fix from $1,950 2012-04-20
Workstation HIGH 8.3
CVE-2012-1518

VMware Workstation 8.x before 8.0.2, VMware Player 4.x before 4.0.2, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 …

Mitigation only
Fix from $1,950 2012-04-17
Helix Server MEDIUM 5.0
CVE-2012-2267

master.exe in the SNMP Master Agent in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to cause a denial…

Mitigation only
Fix from $1,600 2012-04-17
Activescriptruby HIGH 7.5
CVE-2012-1241

GRScript18.dll before 1.2.2.0 in ActiveScriptRuby (ASR) before 1.8.7 does not properly restrict interaction with an Internet Explorer ActiveX environ…

Fix: after 1.0.8.8
Fix from $1,950 2012-04-16
360zip HIGH 7.5
CVE-2012-2225

360zip 1.93beta allows remote attackers to execute arbitrary code via vectors related to file browsing and file extraction.

Mitigation only
Fix from $1,950 2012-04-11
Acrobat Reader HIGH 10.0
CVE-2012-0776EPSS 8%

The installer in Adobe Reader 9.x before 9.5.1 and 10.x before 10.1.3 allows attackers to bypass intended access restrictions and execute arbitrary c…

Patch available
Fix from $1,950 2012-04-10
E Studio 167 With Network Printer Kit Firmware HIGH 10.0
CVE-2012-1239

The TopAccess web-based management interface on TOSHIBA TEC e-Studio multi-function peripheral (MFP) devices with firmware 30x through 302, 35x throu…

Mitigation only
Fix from $1,950 2012-04-06
Firepass HIGH 7.2
CVE-2012-2053

The sudoers file in the Linux system configuration in F5 FirePass 6.0.0 through 6.1.0 and 7.0.0 does not require a password for executing commands as…

No fix yet
Fix from $1,950 2012-04-05
Onboard Administrator HIGH 7.6
CVE-2012-0129EPSS 8%

HP Onboard Administrator (OA) before 3.50 allows remote attackers to bypass intended access restrictions and execute arbitrary code via unspecified v…

Fix: after 3.32
Fix from $1,950 2012-04-05