Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Blacklist Free MEDIUM 5.8
CVE-2011-4705

The Ming Blacklist Free (vc.software.blacklist) application 1.8.1 and 1.9.2.1 for Android does not properly protect data, which allows remote attacke…

Mitigation only
Fix from $1,600 2012-01-25
Mobilesafe MEDIUM 5.8
CVE-2011-4769

The 360 MobileSafe (com.qihoo360.mobilesafe) application 2.x before 2.3.0 for Android does not properly protect data, which allows remote attackers t…

Mitigation only
Fix from $1,600 2012-01-25
Wallet MEDIUM 5.8
CVE-2011-4770

The QIWI Wallet (ru.mw) application before 1.14.2 for Android does not properly protect data, which allows remote attackers to read or modify financi…

Fix: after 1.14.2
Fix from $1,600 2012-01-25
Scan To Pdf Free MEDIUM 5.8
CVE-2011-4771

The Scan to PDF Free (com.scan.to.pdf.trial) application 2.0.4 for Android does not properly protect data, which allows remote attackers to read or m…

Mitigation only
Fix from $1,600 2012-01-25
Kouxin MEDIUM 5.8
CVE-2011-4772

The 360 KouXin (com.qihoo360.kouxin) application 1.5.3 for Android does not properly protect data, which allows remote attackers to read or modify SM…

Mitigation only
Fix from $1,600 2012-01-25
Anguanjia MEDIUM 5.8
CVE-2011-4773

The AnGuanJia (com.anguanjia.safe) application 2.10.343 for Android does not properly protect data, which allows remote attackers to read or modify S…

Mitigation only
Fix from $1,600 2012-01-25
Qqpimsecure MEDIUM 5.8
CVE-2011-4863

The Tencent QQPimSecure (com.tencent.qqpimsecure) application 3.0.2 for Android does not properly protect data, which allows remote attackers to read…

Mitigation only
Fix from $1,600 2012-01-25
Mobileqq MEDIUM 5.8
CVE-2011-4864

The Tencent MobileQQ (com.tencent.mobileqq) application 2.2 for Android does not properly protect data, which allows remote attackers to read or modi…

Mitigation only
Fix from $1,600 2012-01-25
Microblogpad MEDIUM 5.8
CVE-2011-4865

The Tencent WBlog (com.tencent.WBlog) 3.3.1 and MicroBlogPad 1.4.0 applications for Android do not properly protect data, which allows remote attacke…

Mitigation only
Fix from $1,600 2012-01-25
Qqpphoto MEDIUM 5.8
CVE-2011-4867

The Tencent QQPhoto (com.tencent.qqphoto) application 0.97 for Android does not properly protect data, which allows remote attackers to read or modif…

Mitigation only
Fix from $1,600 2012-01-25
Ubersocial MEDIUM 5.8
CVE-2011-4700

The UberMedia UberSocial (com.twidroid) application 7.x before 7.2.4 for Android does not properly protect data, which allows remote attackers to rea…

Mitigation only
Fix from $1,600 2012-01-25
Callconfirm MEDIUM 5.8
CVE-2011-4701

The CallConfirm (jp.gr.java_conf.ofnhwx.callconfirm) application 2.0.0 for Android does not properly protect data, which allows remote attackers to r…

Mitigation only
Fix from $1,600 2012-01-25
Nimbuzz MEDIUM 5.8
CVE-2011-4702

The Nimbuzz (com.nimbuzz) application 2.0.8 and 2.0.10 for Android does not properly protect data, which allows remote attackers to read or modify a …

Mitigation only
Fix from $1,600 2012-01-25
Limit My Call MEDIUM 5.8
CVE-2011-4703

The Limit My Call (com.limited.call.view) application 2.11 for Android does not properly protect data, which allows remote attackers to read or modif…

Mitigation only
Fix from $1,600 2012-01-25
Telepresence E20 Software HIGH 10.0
CVE-2011-4659

Cisco TelePresence Software before TE 4.1.1 on the Cisco IP Video Phone E20 has a default password for the root account after an upgrade to TE 4.1.0,…

Mitigation only
Fix from $1,950 2012-01-19
Tomcat MEDIUM 5.0
CVE-2011-1184EPSS 9%

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the…

Patch available
Fix from $1,600 2012-01-14
Tomcat MEDIUM 5.0
CVE-2011-5062EPSS 8%

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qo…

Patch available
Fix from $1,600 2012-01-14
Codesys MEDIUM 6.4
CVE-2011-5058

The CmbWebserver.dll module of the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to create arbitrary directories under the we…

No fix yet
Fix from $1,600 2012-01-10
Struts MEDIUM 5.0
CVE-2011-5057EPSS 29%

Apache Struts 2.3.1.2 and earlier, 2.3.19-2.3.23, provides interfaces that do not properly restrict access to collections such as the session and req…

Fix: 2.3.3+
Fix from $1,600 2012-01-08
Struts MEDIUM 6.4
CVE-2012-0393EPSS 37%

The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to c…

Fix: 2.3.1.1+
Fix from $1,600 2012-01-08
Digital Security Audits MEDIUM 6.9
CVE-2011-3337

eEye Audit ID 2499 in eEye Digital Security Audits 2406 through 2423 for eEye Retina Network Security Scanner on HP-UX, IRIX, and Solaris allows loca…

Mitigation only
Fix from $1,600 2012-01-04
Pfsense HIGH 7.5
CVE-2011-4197

etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constraint, whi…

Fix: after 2.0
Fix from $1,950 2012-01-03
Sopcast HIGH 7.2
CVE-2011-5044

SopCast 3.4.7.45585 uses weak permissions (Everyone:Full Control) for Diagnose.exe, which allows local users to execute arbitrary code by replacing D…

No fix yet
Fix from $1,950 2011-12-30
Skyrouter HIGH 10.0
CVE-2011-5010EPSS 65%

apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via shell metacharacters in the PIN…

Mitigation only
Fix from $1,950 2011-12-25
Wuzly HIGH 7.5
CVE-2011-3839

The administration functionality in Wuzly 2.0 allows remote attackers to bypass authentication by setting the dXNlcm5hbWU cookie.

Mitigation only
Fix from $1,950 2011-12-24
Tor MEDIUM 5.8
CVE-2011-2768

Tor before 0.2.2.34, when configured as a client or bridge, sends a TLS certificate chain as part of an outgoing OR connection, which allows remote r…

Fix: after 0.2.2.33
Fix from $1,600 2011-12-23
Firefox MEDIUM 6.8
CVE-2011-3666

Mozilla Firefox before 3.6.25 and Thunderbird before 3.1.17 on Mac OS X do not consider .jar files to be executable files, which allows user-assisted…

Fix: after 3.6.24
Fix from $1,600 2011-12-21
Quantum Ethernet Module 140noe77100 HIGH 10.0
CVE-2011-4861

The modbus_125_handler function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) allows re…

Fix: after 5.0
Fix from $1,950 2011-12-17
Rsa Adaptive Authentication On Premise MEDIUM 6.8
CVE-2011-2741

EMC RSA Adaptive Authentication On-Premise (AAOP) 6.0.2.1 SP1 Patch 2, SP1 Patch 3, SP2, SP2 Patch 1, and SP3 does not properly implement Device Reco…

Mitigation only
Fix from $1,600 2011-12-14
Rsa Adaptive Authentication On Premise MEDIUM 6.8
CVE-2011-2742

EMC RSA Adaptive Authentication On-Premise (AAOP) 6.0.2.1 SP1 Patch 2, SP1 Patch 3, SP2, SP2 Patch 1, and SP3 does not properly perform forensic eval…

Mitigation only
Fix from $1,600 2011-12-14