Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Safari HIGH 7.5
CVE-2014-4466

WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a de…

Fix: after 12.1
Fix from $1,950 2014-12-10
Debian Linux MEDIUM 5.0
CVE-2014-8601EPSS 69%

PowerDNS Recursor before 3.6.2 does not limit delegation chaining, which allows remote attackers to cause a denial of service ("performance degradati…

Fix: after 3.6.1
Fix from $1,600 2014-12-10
phpMyAdmin MEDIUM 5.0
CVE-2014-9218EPSS 11%

libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to cause a den…

Patch available
Fix from $1,600 2014-12-08
Scada MEDIUM 5.0
CVE-2014-5429

DNP Master Driver 3.02 and earlier in Elipse SCADA 2.29 build 141 and earlier, E3 1.0 through 4.6, and Elipse Power 1.0 through 4.6 allows remote att…

Fix: after 4.6
Fix from $1,600 2014-12-06
Seil Plus Firmware HIGH 7.8
CVE-2014-7256

The (1) PPP Access Concentrator (PPPAC) and (2) Dial-Up Networking Internet Initiative Japan Inc. SEIL series routers SEIL/x86 Fuji 1.00 through 3.22…

Fix: after 4.61
Fix from $1,950 2014-12-05
Debian Linux MEDIUM 6.8
CVE-2014-8104

OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server c…

Mitigation only
Fix from $1,600 2014-12-03
Linux Kernel MEDIUM 5.0
CVE-2014-7841EPSS 5%

The sctp_process_param function in net/sctp/sm_make_chunk.c in the SCTP implementation in the Linux kernel before 3.17.4, when ASCONF is used, allows…

Fix: after 3.17.3
Fix from $1,600 2014-11-30
Linux Kernel MEDIUM 5.0
CVE-2014-3688EPSS 6%

The SCTP implementation in the Linux kernel before 3.17.4 allows remote attackers to cause a denial of service (memory consumption) by triggering a l…

Fix: after 3.17.3
Fix from $1,600 2014-11-30
Ios Xr MEDIUM 5.0
CVE-2014-8004

Cisco IOS XR allows remote attackers to cause a denial of service (LISP process reload) by establishing many LISP TCP sessions, aka Bug ID CSCuq90378.

Mitigation only
Fix from $1,600 2014-11-25
Asterisk MEDIUM 5.0
CVE-2014-8414

ConfBridge in Asterisk 11.x before 11.14.1 and Certified Asterisk 11.6 before 11.6-cert8 does not properly handle state changes, which allows remote …

Fix: after 11.14.0
Fix from $1,600 2014-11-24
Moodle MEDIUM 5.0
CVE-2014-7847

iplookup/index.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote attackers to cause a denial…

Fix: after 2.4.11
Fix from $1,600 2014-11-24
Wireshark MEDIUM 5.0
CVE-2014-8714

The dissect_write_structured_field function in epan/dissectors/packet-tn5250.c in the TN5250 dissector in Wireshark 1.10.x before 1.10.11 and 1.12.x …

Mitigation only
Fix from $1,600 2014-11-23
Wireshark MEDIUM 5.0
CVE-2014-8712

The build_expert_data function in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.10.x before 1.10.11 and 1.12.x before 1.12.2…

Mitigation only
Fix from $1,600 2014-11-23
Deep Freeze HIGH 7.2
CVE-2014-2382

The DfDiskLo.sys driver in Faronics Deep Freeze Standard and Enterprise 8.10 and earlier allows local administrators to cause a denial of service (cr…

Fix: after 8.10
Fix from $1,950 2014-11-20
Chrome HIGH 7.5
CVE-2014-7907

Multiple use-after-free vulnerabilities in modules/screen_orientation/ScreenOrientationController.cpp in Blink, as used in Google Chrome before 39.0.…

Fix: after 39.0.2171.45
Fix from $1,950 2014-11-19
Chrome HIGH 7.5
CVE-2014-7906

Use-after-free vulnerability in the Pepper plugins in Google Chrome before 39.0.2171.65 allows remote attackers to cause a denial of service or possi…

Fix: after 39.0.2171.45
Fix from $1,950 2014-11-19
Chrome HIGH 7.5
CVE-2014-7900

Use-after-free vulnerability in the CPDF_Parser::IsLinearizedFile function in fpdfapi/fpdf_parser/fpdf_parser_parser.cpp in PDFium, as used in Google…

Fix: after 39.0.2171.45
Fix from $1,950 2014-11-19
Iphone Os MEDIUM 5.8
CVE-2014-4462

WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (…

Fix: after 8.1
Fix from $1,600 2014-11-18
Safari MEDIUM 5.4
CVE-2014-4452

WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (…

Fix: 6.2.1 / 7.0.2+
Fix from $1,600 2014-11-18
Mumble MEDIUM 5.0
CVE-2014-3755

The QSvg module in Qt, as used in the Mumble client 1.2.x before 1.2.6, allows remote attackers to cause a denial of service (hang and resource consu…

Fix: after 1.2.5
Fix from $1,600 2014-11-16
iOS MEDIUM 6.1
CVE-2014-7997

The DHCP implementation in Cisco IOS on Aironet access points does not properly handle error conditions with short leases and unsuccessful lease-rene…

Mitigation only
Fix from $1,600 2014-11-15
Enterprise Linux Desktop HIGH 9.4
CVE-2014-8567

The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request …

Fix: 0.8.1+
Fix from $1,950 2014-11-14
Katello MEDIUM 5.0
CVE-2014-3712

Katello allows remote attackers to cause a denial of service (memory consumption) via the (1) mode parameter in the setup_utils function in content_s…

No fix yet
Fix from $1,600 2014-11-03
Cxf MEDIUM 5.0
CVE-2014-3584EPSS 7%

The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service …

Fix: after 2.6.10
Fix from $1,600 2014-10-30
iOS MEDIUM 5.0
CVE-2014-3293

Cisco IOS 15.4(3)S0b on ASR901 devices makes incorrect decisions to use the CPU for IPv4 packet processing, which allows remote attackers to cause a …

Mitigation only
Fix from $1,600 2014-10-28
FreeBSD MEDIUM 5.0
CVE-2014-3711

namei in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (memory exhaustion) via vectors that trigger a sandboxed p…

Patch available
Fix from $1,600 2014-10-27
iOS MEDIUM 6.1
CVE-2014-3409

The Ethernet Connectivity Fault Management (CFM) handling feature in Cisco IOS 12.2(33)SRE9a and earlier and IOS XE 3.13S and earlier allows remote a…

Fix: after 12.2
Fix from $1,600 2014-10-25
Calender Base HIGH 7.8
CVE-2014-8325

The Calendar Base (cal) extension before 1.5.9 and 1.6.x before 1.6.1 for TYPO3 allows remote attackers to cause a denial of service (resource consum…

Fix: after 1.5.8
Fix from $1,950 2014-10-22
Ioserver MEDIUM 5.0
CVE-2014-5425

IOServer before Beta2112.exe allows remote attackers to cause a denial of service (out-of-bounds read and master entry consumption) via a null DNP3 h…

Fix: after 1.0.20.0
Fix from $1,600 2014-10-19
Expressway Software HIGH 7.8
CVE-2014-3368

Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.2 allow remote attackers to cause a denial of service (device r…

Mitigation only
Fix from $1,950 2014-10-19