Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Privoxy MEDIUM 5.0
CVE-2015-1030

Memory leak in the rfc2553_connect_to function in jbsocket.c in Privoxy before 3.0.22 allows remote attackers to cause a denial of service (memory co…

Fix: after 3.0.21
Fix from $1,600 2015-01-20
Raven Ruby MEDIUM 5.0
CVE-2014-9490

The numtok function in lib/raven/okjson.rb in the raven-ruby gem before 0.12.2 for Ruby allows remote attackers to cause a denial of service via a la…

Fix: after 0.12.1
Fix from $1,600 2015-01-20
Sas Raid Module Firmware HIGH 7.8
CVE-2014-3018

IBM BladeCenter SAS Connectivity Module (aka NSSM) and SAS RAID Module (aka RSSM) before 1.3.3.006 allow remote attackers to cause a denial of servic…

Fix: after 1.3.3.004
Fix from $1,950 2015-01-17
Multilink Ml810 Firmware HIGH 7.8
CVE-2014-5418

GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmwar…

Fix: after 5.2.0
Fix from $1,950 2015-01-17
Django MEDIUM 5.0
CVE-2015-0221

The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which a…

Fix: after 1.4.17
Fix from $1,600 2015-01-16
Unified Communications Domain Manager MEDIUM 5.0
CVE-2015-0591

Cisco Unified Communications Domain Manager (UCDM) 10 allows remote attackers to cause a denial of service (daemon hang and GUI outage) via a flood o…

Mitigation only
Fix from $1,600 2015-01-15
Telepresence Video Communication Server MEDIUM 5.0
CVE-2015-0579

Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway allow remote attackers to cause a denial of service (memory and CPU consumpt…

Mitigation only
Fix from $1,600 2015-01-14
Adaptive Security Appliance Software MEDIUM 5.7
CVE-2015-0578

Cisco Adaptive Security Appliance (ASA) Software, when a DHCPv6 relay is configured, allows remote attackers to cause a denial of service (device rel…

Mitigation only
Fix from $1,600 2015-01-14
Unified Communications Domain Manager MEDIUM 5.0
CVE-2014-8020

Cisco Unified Communication Domain Manager Platform Software allows remote attackers to cause a denial of service (CPU consumption, and performance d…

Mitigation only
Fix from $1,600 2015-01-10
Sterling B2b Integrator MEDIUM 5.0
CVE-2014-6199

The HTTP Server Adapter in IBM Sterling B2B Integrator 5.1 and 5.2.x and Sterling File Gateway 2.1 and 2.2 allows remote attackers to cause a denial …

Mitigation only
Fix from $1,600 2015-01-10
Fedora MEDIUM 5.0
CVE-2014-9527EPSS 8%

HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denial of service (infinite loop and deadlock) via a crafted PPT file.

Fix: after 3.11
Fix from $1,600 2015-01-06
Linux Kernel HIGH 7.8
CVE-2014-9428EPSS 5%

The batadv_frag_merge_packets function in net/batman-adv/fragmentation.c in the B.A.T.M.A.N. implementation in the Linux kernel through 3.18.1 uses a…

Fix: 3.14.30 / 3.16.35+
Fix from $1,950 2015-01-02
Symfony MEDIUM 5.0
CVE-2013-5958

The Security component in Symfony 2.0.x before 2.0.25, 2.1.x before 2.1.13, 2.2.x before 2.2.9, and 2.3.x before 2.3.6 allows remote attackers to cau…

Mitigation only
Fix from $1,600 2014-12-27
Enterprise Linux Desktop HIGH 7.2
CVE-2014-7300

GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests,…

Patch available
Fix from $1,950 2014-12-25
Ironport Email Security Appliances MEDIUM 5.0
CVE-2014-8016

The Cisco IronPort Email Security Appliance (ESA) allows remote attackers to cause a denial of service (CPU consumption) via long Subject headers in …

Mitigation only
Fix from $1,600 2014-12-19
FreeBSD MEDIUM 5.0
CVE-2014-8117EPSS 6%

softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or cra…

Fix: after 5.20
Fix from $1,600 2014-12-17
FreeBSD MEDIUM 5.0
CVE-2014-8116

The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large number of …

Patch available
Fix from $1,600 2014-12-17
Zenoss Core MEDIUM 5.0
CVE-2014-6259

Zenoss Core through 5 Beta 3 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (…

Fix: after 5.0.0
Fix from $1,600 2014-12-15
Zenoss Core MEDIUM 5.0
CVE-2014-6258

An unspecified endpoint in Zenoss Core through 5 Beta 3 allows remote attackers to cause a denial of service (CPU consumption) by triggering an arbit…

Fix: after 5.0.0
Fix from $1,600 2014-12-15
FreeBSD MEDIUM 5.0
CVE-2014-7250

The TCP stack in 4.3BSD Net/2, as used in FreeBSD 5.4, NetBSD possibly 2.0, and OpenBSD possibly 3.6, does not properly implement the session timer, …

Mitigation only
Fix from $1,600 2014-12-12
Bind HIGH 7.8
CVE-2014-8500EPSS 58%

ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cau…

Patch available
Fix from $1,950 2014-12-11
Vbscript HIGH 9.3
CVE-2014-6363EPSS 28%

vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 6 through 11 and other products, allows remote attackers to execut…

No fix yet
Fix from $1,950 2014-12-11
Safari MEDIUM 6.8
CVE-2014-4475

WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a de…

Fix: after 12.1
Fix from $1,600 2014-12-10
Safari MEDIUM 6.8
CVE-2014-4474

WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a de…

Fix: after 12.1
Fix from $1,600 2014-12-10
Safari MEDIUM 6.8
CVE-2014-4473

WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a de…

Fix: after 12.1
Fix from $1,600 2014-12-10
Safari MEDIUM 6.8
CVE-2014-4472

WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a de…

Fix: after 12.1
Fix from $1,600 2014-12-10
Safari MEDIUM 6.8
CVE-2014-4471

WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a de…

Fix: after 12.1
Fix from $1,600 2014-12-10
Safari MEDIUM 6.8
CVE-2014-4470

WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a de…

Fix: after 12.1
Fix from $1,600 2014-12-10
Safari MEDIUM 6.8
CVE-2014-4469

WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a de…

Fix: after 12.1
Fix from $1,600 2014-12-10
Safari MEDIUM 6.8
CVE-2014-4468

WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a de…

Fix: after 12.1
Fix from $1,600 2014-12-10