Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Acrobat Reader HIGH 10.0
CVE-2014-0528

Double free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X allows attackers to execute arb…

Mitigation only
Fix from $1,950 2014-05-14
Chrome HIGH 7.5
CVE-2014-1740

Multiple use-after-free vulnerabilities in net/websockets/websocket_job.cc in the WebSockets implementation in Google Chrome before 34.0.1847.137 all…

Fix: after 34.0.1847.136
Fix from $1,950 2014-05-14
Security Access Manager For Web Software HIGH 7.1
CVE-2014-0963

The Reverse Proxy feature in IBM Global Security Kit (aka GSKit) in IBM Security Access Manager (ISAM) for Web 7.0 before 7.0.0-ISS-SAM-IF0006 and 8.…

Patch available
Fix from $1,950 2014-05-08
Netty MEDIUM 5.0
CVE-2014-0193

WebSocket08FrameDecoder in Netty 3.6.x before 3.6.9, 3.7.x before 3.7.1, 3.8.x before 3.8.2, 3.9.x before 3.9.1, and 4.0.x before 4.0.19 allows remot…

Patch available
Fix from $1,600 2014-05-06
Ruby MEDIUM 5.8
CVE-2014-2734EPSS 5%

The openssl extension in Ruby 2.x does not properly maintain the state of process memory after a file is reopened, which allows remote attackers to s…

No fix yet
Fix from $1,600 2014-04-24
Ubuntu Linux HIGH 10.0
CVE-2014-0474

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x befor…

Fix: after 1.4.10
Fix from $1,950 2014-04-23
iOS MEDIUM 6.8
CVE-2012-5036

Cisco IOS before 12.2(50)SY1 allows remote authenticated users to cause a denial of service (memory consumption) via a sequence of VTY management ses…

Mitigation only
Fix from $1,600 2014-04-23
Adaptive Security Appliance Software MEDIUM 5.0
CVE-2014-2154

Memory leak in the SIP inspection engine in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to cause a denial of service (me…

Mitigation only
Fix from $1,600 2014-04-23
iOS MEDIUM 5.0
CVE-2012-0360

Memory leak in Cisco IOS before 15.1(1)SY, when IKEv2 debugging is enabled, allows remote attackers to cause a denial of service (memory consumption)…

Mitigation only
Fix from $1,600 2014-04-23
Screenos HIGH 7.8
CVE-2014-2842

Juniper ScreenOS 6.3 and earlier allows remote attackers to cause a denial of service (crash and restart or failover) via a malformed SSL/TLS packet.

Fix: after 6.3.0
Fix from $1,950 2014-04-15
Chrome HIGH 7.5
CVE-2014-1727

Use-after-free vulnerability in content/renderer/renderer_webcolorchooser_impl.h in Google Chrome before 34.0.1847.116 allows remote attackers to cau…

Fix: after 34.0.1847.115
Fix from $1,950 2014-04-09
Chrome HIGH 7.5
CVE-2014-1724

Use-after-free vulnerability in Free(b)soft Laboratory Speech Dispatcher 0.7.1, as used in Google Chrome before 34.0.1847.116, allows remote attacker…

Fix: after 34.0.1847.115
Fix from $1,950 2014-04-09
Chrome HIGH 7.5
CVE-2014-1720

Use-after-free vulnerability in the HTMLBodyElement::insertedInto function in core/html/HTMLBodyElement.cpp in Blink, as used in Google Chrome before…

Fix: after 34.0.1847.115
Fix from $1,950 2014-04-09
Chrome HIGH 7.5
CVE-2014-1722

Use-after-free vulnerability in the RenderBlock::addChildIgnoringAnonymousColumnBlocks function in core/rendering/RenderBlock.cpp in Blink, as used i…

Fix: after 34.0.1847.115
Fix from $1,950 2014-04-09
Chrome HIGH 7.5
CVE-2014-1719

Use-after-free vulnerability in the WebSharedWorkerStub::OnTerminateWorkerContext function in content/worker/websharedworker_stub.cc in the Web Worke…

Fix: after 34.0.1847.115
Fix from $1,950 2014-04-09
Znc Msvc MEDIUM 5.0
CVE-2012-0033

The CBounceDCCMod::OnPrivCTCP function in bouncedcc.cpp in the bouncedcc module in ZNC 0.200 and 0.202 allows remote attackers to cause a denial of s…

Patch available
Fix from $1,600 2014-04-08
Office MEDIUM 5.0
CVE-2014-2730EPSS 12%

The XML parser in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013, and Office for Mac 2011, does not properly detect recursion during entity ex…

Mitigation only
Fix from $1,600 2014-04-05
Vm Virtualbox MEDIUM 6.9
CVE-2014-0983EPSS 8%

Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/server_dispatch.py in Oracle V…

No fix yet
Fix from $1,600 2014-03-31
iOS MEDIUM 6.1
CVE-2014-2131

The packet driver in Cisco IOS allows remote attackers to cause a denial of service (device reload) via a series of (1) Virtual Switching Systems (VS…

Mitigation only
Fix from $1,600 2014-03-29
Simatic S7 Cpu 1200 Firmware MEDIUM 6.1
CVE-2014-2252

Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via cra…

Fix: after 3.0.2
Fix from $1,600 2014-03-24
Simatic S7 Cpu 1200 Firmware HIGH 7.8
CVE-2014-2254

Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via cra…

Fix: after 3.0.2
Fix from $1,950 2014-03-24
Simatic S7 Cpu 1200 Firmware HIGH 7.8
CVE-2014-2256

Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via cra…

Fix: after 3.0.2
Fix from $1,950 2014-03-24
Simatic S7 Cpu 1200 Firmware HIGH 7.8
CVE-2014-2258

Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via cra…

Fix: after 3.0.2
Fix from $1,950 2014-03-24
iOS HIGH 7.1
CVE-2014-2124

Cisco IOS 15.1(2)SY3 and earlier, when used with Supervisor Engine 2T (aka Sup2T) on Catalyst 6500 devices, allows remote attackers to cause a denial…

Fix: after 15.1
Fix from $1,950 2014-03-21
Unified Threat Management Software HIGH 7.8
CVE-2014-2537

Memory leak in the TCP stack in the kernel in Sophos UTM before 9.109 allows remote attackers to cause a denial of service (memory consumption) via u…

Fix: after 9.108
Fix from $1,950 2014-03-18
Chrome HIGH 7.5
CVE-2014-1700

Use-after-free vulnerability in modules/speech/SpeechSynthesis.cpp in Blink, as used in Google Chrome before 33.0.1750.149, allows remote attackers t…

Fix: after 33.0.1750.146
Fix from $1,950 2014-03-16
Chrome HIGH 7.5
CVE-2014-1702

Use-after-free vulnerability in the DatabaseThread::cleanupDatabaseThread function in modules/webdatabase/DatabaseThread.cpp in the web database impl…

Fix: after 33.0.1750.146
Fix from $1,950 2014-03-16
Chrome HIGH 7.5
CVE-2014-1703

Use-after-free vulnerability in the WebSocketDispatcherHost::SendOrDrop function in content/browser/renderer_host/websocket_dispatcher_host.cc in the…

Fix: after 33.0.1750.146
Fix from $1,950 2014-03-16
Wireless Lan Controller Software HIGH 7.8
CVE-2014-0701

Cisco Wireless LAN Controller (WLC) devices 7.0 before 7.0.250.0, 7.2, 7.3, and 7.4 before 7.4.110.0 do not properly deallocate memory, which allows …

Mitigation only
Fix from $1,950 2014-03-06
Wireless Lan Controller Software HIGH 7.1
CVE-2014-0704

The IGMP implementation on Cisco Wireless LAN Controller (WLC) devices 4.x, 5.x, 6.x, 7.0 before 7.0.250.0, 7.1, 7.2, and 7.3, when IGMPv3 Snooping i…

Mitigation only
Fix from $1,950 2014-03-06