Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Safari MEDIUM 6.8
CVE-2015-1069

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a de…

Fix: after 12.1
Fix from $1,600 2015-03-18
Safari MEDIUM 6.8
CVE-2015-1068

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a de…

Fix: after 12.1
Fix from $1,600 2015-03-18
Rational Requirements Composer HIGH 7.8
CVE-2015-0132

The XML parser in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 and Rational Requirements Composer 2.x and 3.x befor…

Patch available
Fix from $1,950 2015-03-18
Office HIGH 9.3
CVE-2015-0086EPSS 13%

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 Gold and SP1, Word 2013 RT Gold and SP1, Word Viewer, Office Compatibility Pack SP…

Mitigation only
Fix from $1,950 2015-03-11
Vbscript HIGH 9.3
CVE-2015-0032EPSS 22%

vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 8 through 11 and other products, allows remote attackers to execut…

Mitigation only
Fix from $1,950 2015-03-11
Debian Linux HIGH 7.1
CVE-2014-9472

The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a denial of se…

Mitigation only
Fix from $1,950 2015-03-09
Ubuntu Linux HIGH 7.5
CVE-2015-1228

The RenderCounter::updateCounter function in core/rendering/RenderCounter.cpp in Blink, as used in Google Chrome before 41.0.2272.76, does not force …

Fix: after 40.0.2214.115
Fix from $1,950 2015-03-09
Chrome HIGH 7.5
CVE-2015-1227

The DragImage::create function in platform/DragImage.cpp in Blink, as used in Google Chrome before 41.0.2272.76, does not initialize memory for image…

Fix: after 40.0.2214.115
Fix from $1,950 2015-03-09
Seil X86 Fuji Firmware HIGH 7.1
CVE-2015-0887

npppd in the PPP Access Concentrator (PPPAC) on SEIL SEIL/x86 Fuji routers 1.00 through 3.30, SEIL/X1 routers 3.50 through 4.70, SEIL/X2 routers 3.50…

Mitigation only
Fix from $1,950 2015-02-28
Debian Linux MEDIUM 5.0
CVE-2015-0885

checkpw 1.02 and earlier allows remote attackers to cause a denial of service (infinite loop) via a -- (dash dash) in a username.

Fix: after 1.02
Fix from $1,600 2015-02-28
Ubuntu Linux MEDIUM 5.0
CVE-2015-0830

The WebGL implementation in Mozilla Firefox before 36.0 does not properly allocate memory for copying an unspecified string to a shader's compilation…

Fix: after 35.0.1
Fix from $1,600 2015-02-25
Ubuntu Linux HIGH 7.8
CVE-2014-9402EPSS 8%

The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Service Switch configuration is…

Fix: after 2.20
Fix from $1,950 2015-02-24
Fedora MEDIUM 5.0
CVE-2014-9465

senddocument.php in Zarafa WebApp before 2.0 beta 3 and WebAccess in Zarafa Collaboration Platform (ZCP) 7.x before 7.1.12 beta 1 and 7.2.x before 7.…

Fix: after 2.0
Fix from $1,600 2015-02-19
Sequence Kinetics MEDIUM 5.0
CVE-2014-6303

The Monitoring Administration pages in PNMsoft Sequence Kinetics before 7.7 do not properly detect recursion during entity expansion, which allows re…

Fix: after 7.5
Fix from $1,600 2015-02-19
Bind MEDIUM 5.4
CVE-2015-1349EPSS 22%

named in ISC BIND 9.7.0 through 9.9.6 before 9.9.6-P2 and 9.10.x before 9.10.1-P2, when DNSSEC validation and the managed-keys feature are enabled, a…

Mitigation only
Fix from $1,600 2015-02-19
Asr 5000 Series Software MEDIUM 5.0
CVE-2015-0617

Cisco ASR 5500 System Architecture Evolution (SAE) Gateway devices allow remote attackers to cause a denial of service (CPU consumption and SNMP outa…

Mitigation only
Fix from $1,600 2015-02-18
iOS HIGH 7.1
CVE-2015-0593

The Zone-Based Firewall implementation in Cisco IOS 12.4(122)T and earlier does not properly manage session-object structures, which allows remote at…

Mitigation only
Fix from $1,950 2015-02-13
Adaptive Security Appliance Software MEDIUM 5.0
CVE-2015-0619

Memory leak in the embedded web server in the WebVPN subsystem in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to cause a…

Mitigation only
Fix from $1,600 2015-02-12
iOS HIGH 7.8
CVE-2015-0592

The Zone-Based Firewall implementation in Cisco IOS 15.4(2)T3 and earlier allows remote attackers to cause a denial of service (device reload) via cr…

Fix: after 15.4
Fix from $1,950 2015-02-12
Web Applications HIGH 9.3
CVE-2015-0064EPSS 30%

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Automation Services in SharePoint Server 2010, Web Applications 2010 SP2, Word Viewer, …

No fix yet
Fix from $1,950 2015-02-11
Word HIGH 9.3
CVE-2015-0065EPSS 30%

Microsoft Word 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office docum…

No fix yet
Fix from $1,950 2015-02-11
Office Compatibility Pack HIGH 9.3
CVE-2015-0063EPSS 16%

Microsoft Excel 2007 SP3; the proofing tools in Office 2010 SP2; Excel 2010 SP2; Excel 2013 Gold, SP1, and RT; Excel Viewer; and Office Compatibility…

Patch available
Fix from $1,950 2015-02-11
Debian Linux MEDIUM 5.0
CVE-2015-1381

Multiple unspecified vulnerabilities in pcrs.c in Privoxy before 3.0.23 allow remote attackers to cause a denial of service (segmentation fault or me…

Fix: after 3.0.22
Fix from $1,600 2015-02-03
Remote Service Manager HIGH 7.8
CVE-2014-7266

Algorithmic complexity vulnerability in Cybozu Remote Service Manager through 2.3.0 and 3.x through 3.1.2 allows remote attackers to cause a denial o…

Patch available
Fix from $1,950 2015-02-01
Mac Os X MEDIUM 6.8
CVE-2014-8816

CoreGraphics in Apple OS X before 10.10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and applica…

Fix: after 10.9.5
Fix from $1,600 2015-01-30
iOS HIGH 7.8
CVE-2015-0586

The Network-Based Application Recognition (NBAR) protocol implementation in Cisco IOS 15.3(100)M and earlier on Cisco 2900 Integrated Services Router…

Fix: after 15.3
Fix from $1,950 2015-01-28
Enterprise Linux Desktop Supplementary HIGH 7.5
CVE-2014-7942

The Fonts implementation in Google Chrome before 40.0.2214.91 does not initialize memory for a data structure, which allows remote attackers to cause…

Fix: after 40.0.2214.85
Fix from $1,950 2015-01-22
Chrome HIGH 7.5
CVE-2014-7940

The collator implementation in i18n/ucol.cpp in International Components for Unicode (ICU) 52 through SVN revision 293126, as used in Google Chrome b…

Fix: after 52.1
Fix from $1,950 2015-01-22
File MEDIUM 5.0
CVE-2014-9621

The ELF parser in file 5.16 through 5.21 allows remote attackers to cause a denial of service via a long string.

Patch available
Fix from $1,600 2015-01-21
File MEDIUM 5.0
CVE-2014-9620

The ELF parser in file 5.08 through 5.21 allows remote attackers to cause a denial of service via a large number of notes.

Patch available
Fix from $1,600 2015-01-21