Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Unified Communications Domain Manager Platform MEDIUM 5.0
CVE-2014-3380

Cisco Unified Communications Domain Manager Platform Software 4.4(.3) and earlier allows remote attackers to cause a denial of service (CPU consumpti…

Mitigation only
Fix from $1,600 2014-09-24
Rational Clearcase MEDIUM 5.0
CVE-2014-3104

IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 allows remote attackers to cause a denial of service (me…

Patch available
Fix from $1,600 2014-09-23
Wireshark MEDIUM 5.0
CVE-2014-6423

The tvb_raw_text_add function in epan/dissectors/packet-megaco.c in the MEGACO dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 …

Mitigation only
Fix from $1,600 2014-09-20
Wireshark MEDIUM 5.0
CVE-2014-6426

The dissect_hip_tlv function in epan/dissectors/packet-hip.c in the HIP dissector in Wireshark 1.12.x before 1.12.1 does not properly handle a NULL t…

Mitigation only
Fix from $1,600 2014-09-20
Wireshark MEDIUM 5.0
CVE-2014-6432

The SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file parser in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 does…

Mitigation only
Fix from $1,600 2014-09-20
Acrobat Reader HIGH 10.0
CVE-2014-0560EPSS 7%

Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allows attackers to execute …

Patch available
Fix from $1,950 2014-09-17
Telepresence System Software HIGH 7.8
CVE-2014-3362

Memory leak in Cisco TelePresence System Edge MXP Series Software F9.3.3 and earlier allows remote attackers to cause a denial of service (management…

Mitigation only
Fix from $1,950 2014-09-12
.net Framework MEDIUM 5.0
CVE-2014-4072EPSS 31%

Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly use a hash table for request data, which a…

Mitigation only
Fix from $1,600 2014-09-10
Ios Xr HIGH 7.1
CVE-2014-3353

Cisco IOS XR 4.3(.2) and earlier, as used in Cisco Carrier Routing System (CRS), allows remote attackers to cause a denial of service (CPU consumptio…

Fix: after 4.3.2
Fix from $1,950 2014-09-04
iOS MEDIUM 5.4
CVE-2014-3347

Cisco IOS 15.1(4)M2 on Cisco 1800 ISR devices, when the ISDN Basic Rate Interface is enabled, allows remote attackers to cause a denial of service (d…

Mitigation only
Fix from $1,600 2014-08-28
WordPress MEDIUM 5.0
CVE-2014-5265

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations with…

Fix: after 3.9.1
Fix from $1,600 2014-08-18
WordPress MEDIUM 5.0
CVE-2014-5266EPSS 24%

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of ele…

Fix: after 3.9.1
Fix from $1,600 2014-08-18
Sql Server MEDIUM 6.8
CVE-2014-4061EPSS 26%

Microsoft SQL Server 2008 SP3, 2008 R2 SP2, and 2012 SP1 does not properly control use of stack memory for processing of T-SQL batch commands, which …

Mitigation only
Fix from $1,600 2014-08-12
Windows 7 HIGH 7.5
CVE-2014-0316EPSS 11%

Memory leak in the Local RPC (LRPC) server implementation in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Ser…

Patch available
Fix from $1,950 2014-08-12
HTTP Server MEDIUM 5.0
CVE-2014-3523EPSS 16%

Memory leak in the winnt_accept function in server/mpm/winnt/child.c in the WinNT MPM in the Apache HTTP Server 2.4.x before 2.4.10 on Windows, when …

Patch available
Fix from $1,600 2014-07-20
HTTP Server MEDIUM 5.0
CVE-2014-0231EPSS 44%

The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of ser…

Fix: 2.2.29 / 2.4.10+
Fix from $1,600 2014-07-20
Cloudforms 3.0 Management Engine MEDIUM 5.0
CVE-2014-0180

The wait_for_task function in app/controllers/application_controller.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allows remo…

Fix: after 5.2.4
Fix from $1,600 2014-07-07
PHP MEDIUM 5.0
CVE-2014-3538EPSS 12%

file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service…

Fix: 5.4.32 / 5.5.16+
Fix from $1,600 2014-07-03
Iphone Os MEDIUM 6.8
CVE-2014-1354

CoreGraphics in Apple iOS before 7.1.2 does not properly restrict allocation of stack memory for processing of XBM images, which allows remote attack…

Fix: after 7.1.1
Fix from $1,600 2014-07-01
Ios Xr HIGH 7.1
CVE-2014-2176

Cisco IOS XR 4.1.2 through 5.1.1 on ASR 9000 devices, when a Trident-based line card is used, allows remote attackers to cause a denial of service (N…

Mitigation only
Fix from $1,950 2014-06-14
Windows 7 MEDIUM 5.0
CVE-2014-1811EPSS 18%

The TCP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012…

Patch available
Fix from $1,600 2014-06-11
Mambo Cms MEDIUM 5.0
CVE-2013-2564

Mambo CMS 4.6.5 allows remote attackers to cause a denial of service (memory and bandwidth consumption) by uploading a crafted file.

No fix yet
Fix from $1,600 2014-06-09
Websphere Portal MEDIUM 5.0
CVE-2014-0949

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote atta…

Patch available
Fix from $1,600 2014-05-22
Chrome HIGH 7.5
CVE-2014-1743

Use-after-free vulnerability in the StyleElement::removedFromDocument function in core/dom/StyleElement.cpp in Blink, as used in Google Chrome before…

Fix: after 35.0.1916.113
Fix from $1,950 2014-05-21
Chrome HIGH 7.1
CVE-2014-1745

Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a de…

Fix: after 35.0.1916.113
Fix from $1,950 2014-05-21
Unrealircd MEDIUM 5.0
CVE-2013-6413

Use-after-free vulnerability in UnrealIRCd 3.2.10 before 3.2.10.2 allows remote attackers to cause a denial of service (crash) via unspecified vector…

Mitigation only
Fix from $1,600 2014-05-19
Hapi Server Framework MEDIUM 5.0
CVE-2014-3742

The hapi server framework 2.0.x and 2.1.x before 2.2.0 for Node.js allows remote attackers to cause a denial of service (file descriptor consumption …

Mitigation only
Fix from $1,600 2014-05-16
Websphere Application Server HIGH 7.1
CVE-2014-0964

IBM WebSphere Application Server (WAS) 6.1.0.0 through 6.1.0.47 and 6.0.2.0 through 6.0.2.43 allows remote attackers to cause a denial of service via…

Mitigation only
Fix from $1,950 2014-05-16
Chrome HIGH 7.5
CVE-2014-1742

Use-after-free vulnerability in the FrameSelection::updateAppearance function in core/editing/FrameSelection.cpp in Blink, as used in Google Chrome b…

Fix: after 34.0.1847.136
Fix from $1,950 2014-05-14
Acrobat HIGH 10.0
CVE-2014-0527EPSS 13%

Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X allows attackers to execute …

Mitigation only
Fix from $1,950 2014-05-14