Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Expressway Software HIGH 7.1
CVE-2014-3369

The SIP IX implementation in Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allows remote attackers to cau…

Mitigation only
Fix from $1,950 2014-10-19
Telepresence Video Communication Server Software HIGH 7.1
CVE-2014-3370

Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allow remote attackers to cause a denial of service (device…

Mitigation only
Fix from $1,950 2014-10-19
Telepresence Mcu Software HIGH 7.8
CVE-2014-3397

The network stack in Cisco TelePresence MCU Software before 4.3(2.30) allows remote attackers to cause a denial of service (memory consumption) via c…

Fix: after 4.3
Fix from $1,950 2014-10-19
Openshift MEDIUM 5.0
CVE-2014-3661

Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to cause a denial of service (thread consumption) via vectors related to a CLI ha…

Fix: after 3.1
Fix from $1,600 2014-10-16
.net Framework HIGH 10.0
CVE-2014-4121EPSS 19%

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly parse internationalized resource identifiers, which allows r…

Mitigation only
Fix from $1,950 2014-10-15
Junos E HIGH 7.8
CVE-2014-6377

Juniper JunosE before 13.3.3p0-1, 14.x before 14.3.2, and 15.x before 15.1.0, when DEBUG severity icmpTraffic logging is enabled, allows remote attac…

Fix: after 13.3.2
Fix from $1,950 2014-10-14
Junos HIGH 7.8
CVE-2014-6378

Juniper Junos 11.4 before R12-S4, 12.1X44 before D35, 12.1X45 before D30, 12.1X46 before D25, 12.1X47 before D10, 12.2 before R9, 12.2X50 before D70,…

Mitigation only
Fix from $1,950 2014-10-14
E5332 Firmware MEDIUM 6.8
CVE-2014-5328

Buffer overflow in the Webserver component on the Huawei E5332 router before 21.344.27.00.1080 allows remote authenticated users to cause a denial of…

Mitigation only
Fix from $1,600 2014-10-12
E5332 Firmware MEDIUM 6.8
CVE-2014-5327

Buffer overflow in the Webserver component on the Huawei E5332 router before 21.344.27.00.1080 allows remote authenticated users to cause a denial of…

Fix: after 21.344.19.00.1080
Fix from $1,600 2014-10-12
Asa HIGH 7.8
CVE-2014-3383

The IKE implementation in the VPN component in Cisco ASA Software 9.1 before 9.1(5.1) allows remote attackers to cause a denial of service (device re…

Mitigation only
Fix from $1,950 2014-10-10
Asa HIGH 7.8
CVE-2014-3384

The IKEv2 implementation in Cisco ASA Software 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) allows remote…

Mitigation only
Fix from $1,950 2014-10-10
Asa HIGH 7.8
CVE-2014-3386

The GPRS Tunneling Protocol (GTP) inspection engine in Cisco ASA Software 8.2 before 8.2(5.51), 8.4 before 8.4(7.15), 8.7 before 8.7(1.13), 9.0 befor…

Mitigation only
Fix from $1,950 2014-10-10
Asa HIGH 7.8
CVE-2014-3387

The SunRPC inspection engine in Cisco ASA Software 7.2 before 7.2(5.14), 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.5 before…

Mitigation only
Fix from $1,950 2014-10-10
Asa HIGH 7.8
CVE-2014-3388

The DNS inspection engine in Cisco ASA Software 9.0 before 9.0(4.13), 9.1 before 9.1(5.7), and 9.2 before 9.2(2) allows remote attackers to cause a d…

Mitigation only
Fix from $1,950 2014-10-10
Chrome MEDIUM 5.0
CVE-2014-3195

Google V8, as used in Google Chrome before 38.0.2125.101, does not properly track JavaScript heap-memory allocations as allocations of uninitialized …

Fix: after 38.0.2125.7
Fix from $1,600 2014-10-08
Enterprise Linux Desktop Supplementary MEDIUM 5.0
CVE-2014-3199

The wrap function in bindings/core/v8/custom/V8EventCustom.cpp in the V8 bindings in Blink, as used in Google Chrome before 38.0.2125.101, has an err…

Fix: after 38.0.2125.7
Fix from $1,600 2014-10-08
Ubuntu Linux MEDIUM 5.0
CVE-2014-7204

jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted Java…

Patch available
Fix from $1,600 2014-10-07
Suricata MEDIUM 5.0
CVE-2014-6603

The SSHParseBanner function in SSH parser (app-layer-ssh.c) in Suricata before 2.0.4 allows remote attackers to bypass SSH rules, cause a denial of s…

Fix: after 2.0.3-2
Fix from $1,600 2014-10-07
Ubuntu Linux MEDIUM 5.0
CVE-2014-3565

snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows remote attackers to cause a denial of service (snmptrapd crash) via …

Fix: after 5.7.0
Fix from $1,600 2014-10-07
Libvirt MEDIUM 5.0
CVE-2014-3657

The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remo…

Fix: after 1.2.8
Fix from $1,600 2014-10-06
Ab Micrologix Controller HIGH 7.1
CVE-2014-5410

The DNP3 feature on Rockwell Automation Allen-Bradley MicroLogix 1400 1766-Lxxxxx A FRN controllers 7 and earlier and 1400 1766-Lxxxxx B FRN controll…

Mitigation only
Fix from $1,950 2014-10-03
Xen HIGH 8.3
CVE-2014-7188

The hvm_msr_read_intercept function in arch/x86/hvm/hvm.c in Xen 4.1 through 4.4.x uses an improper MSR range for x2APIC emulation, which allows loca…

Patch available
Fix from $1,950 2014-10-02
Tl Wdr4300 Firmware MEDIUM 5.0
CVE-2014-4728

The web server in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to cause a deni…

Fix: after 130617
Fix from $1,600 2014-09-30
Plone MEDIUM 5.0
CVE-2012-5496

kupu_spellcheck.py in Kupu in Plone before 4.0 allows remote attackers to cause a denial of service (ZServer thread lock) via a crafted URL.

Fix: after 3.3.5
Fix from $1,600 2014-09-30
Plone MEDIUM 5.0
CVE-2012-5499

python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to cause a denial of service (memory consumption) via a large v…

Fix: after 4.2.2
Fix from $1,600 2014-09-30
Plone MEDIUM 5.0
CVE-2012-5506

python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to cause a denial of service (infinite loop) via an RSS feed re…

Fix: after 4.2.2
Fix from $1,600 2014-09-30
Linux Kernel HIGH 7.8
CVE-2014-6417EPSS 5%

net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly consider the possibility of kmalloc failure, which allows rem…

Fix: 3.4.105 / 3.10.55+
Fix from $1,950 2014-09-28
Linux Kernel HIGH 7.1
CVE-2014-6418

net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly validate auth replies, which allows remote attackers to cause…

Fix: 3.2.64 / 3.4.105+
Fix from $1,950 2014-09-28
Enterprise Linux Desktop HIGH 7.8
CVE-2014-7145

The SMB2_tcon function in fs/cifs/smb2pdu.c in the Linux kernel before 3.16.3 allows remote CIFS servers to cause a denial of service (NULL pointer d…

Fix: 3.10.55 / 3.12.29+
Fix from $1,950 2014-09-28
iOS HIGH 7.8
CVE-2014-3359

Memory leak in Cisco IOS 15.1 through 15.4 and IOS XE 3.4.xS, 3.5.xS, 3.6.xS, and 3.7.xS before 3.7.6S; 3.8.xS, 3.9.xS, and 3.10.xS before 3.10.1S; a…

Mitigation only
Fix from $1,950 2014-09-25