Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Libvirt MEDIUM 5.0
CVE-2013-2218EPSS 8%

Double free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_netcf.c in libvirt 1.0.6 allows remote attackers t…

Patch available
Fix from $1,600 2013-09-30
iOS HIGH 7.8
CVE-2013-5473

Memory leak in Cisco IOS 12.2, 15.1, and 15.2; IOS XE 3.4.2S through 3.4.5S; and IOS XE 3.6.xS before 3.6.1S allows remote attackers to cause a denia…

Mitigation only
Fix from $1,950 2013-09-27
Linux Kernel MEDIUM 6.9
CVE-2013-4343

Use-after-free vulnerability in drivers/net/tun.c in the Linux kernel through 3.11.1 allows local users to gain privileges by leveraging the CAP_NET_…

Fix: 3.10.16 / 3.11.5+
Fix from $1,600 2013-09-25
Fosuserbundle MEDIUM 5.0
CVE-2013-5750

The login form in the FriendsOfSymfony FOSUserBundle bundle before 1.3.3 for Symfony allows remote attackers to cause a denial of service (CPU consum…

Fix: after 1.3.2
Fix from $1,600 2013-09-25
Nx Os MEDIUM 5.4
CVE-2013-1121

The regex engine in the BGP implementation in Cisco NX-OS, when a complex regular expression is configured for inbound routes, allows remote attacker…

Mitigation only
Fix from $1,600 2013-09-19
Firefox HIGH 9.3
CVE-2013-1722EPSS 6%

Use-after-free vulnerability in the nsAnimationManager::BuildAnimations function in the Animation Manager in Mozilla Firefox before 24.0, Firefox ESR…

Fix: after 23.0.1
Fix from $1,950 2013-09-18
Firefox HIGH 9.3
CVE-2013-1724EPSS 6%

Use-after-free vulnerability in the mozilla::dom::HTMLFormElement::IsDefaultSubmitElement function in Mozilla Firefox before 24.0, Thunderbird before…

Fix: after 23.0.1
Fix from $1,950 2013-09-18
Firefox HIGH 9.3
CVE-2013-1738EPSS 6%

Use-after-free vulnerability in the JS_GetGlobalForScopeChain function in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before …

Fix: after 23.0.1
Fix from $1,950 2013-09-18
Outlook HIGH 9.3
CVE-2013-3870EPSS 19%

Double free vulnerability in Microsoft Outlook 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to execute arbitrary code by including many nest…

No fix yet
Fix from $1,950 2013-09-11
Debian Linux MEDIUM 6.8
CVE-2013-4232EPSS 5%

Use-after-free vulnerability in the t2p_readwrite_pdf_image function in tools/tiff2pdf.c in libtiff 4.0.3 allows remote attackers to cause a denial o…

Patch available
Fix from $1,600 2013-09-10
Xen HIGH 7.4
CVE-2013-1432

Xen 4.1.x and 4.2.x, when the XSA-45 patch is in place, does not properly maintain references on pages stored for deferred cleanup, which allows loca…

Patch available
Fix from $1,950 2013-08-28
Enterprise Virtualization HIGH 7.2
CVE-2013-2176

Unquoted Windows search path vulnerability in the Red Hat Enterprise Virtualization Application Provisioning Tool (RHEV-APT) in the rhev-guest-tools-…

Mitigation only
Fix from $1,950 2013-08-28
Prime Central For Hosted Collaboration Solution Assurance HIGH 7.8
CVE-2013-3387

Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.x before 9.2(1) allows remote attackers to cause a denial of service …

Mitigation only
Fix from $1,950 2013-08-25
Prime Central For Hosted Collaboration Solution Assurance HIGH 7.8
CVE-2013-3388

Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.x before 9.2(1) allows remote attackers to cause a denial of service …

Mitigation only
Fix from $1,950 2013-08-25
Prime Central For Hosted Collaboration Solution Assurance HIGH 7.8
CVE-2013-3389

Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.x before 9.2(1) allows remote attackers to cause a denial of service …

Mitigation only
Fix from $1,950 2013-08-25
Prime Central For Hosted Collaboration Solution Assurance HIGH 7.8
CVE-2013-3390

Memory leak in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.x before 9.2(1) allows remote attackers to cause a den…

Mitigation only
Fix from $1,950 2013-08-25
Unified Communications Manager HIGH 7.8
CVE-2013-3459

Cisco Unified Communications Manager (Unified CM) 7.1(x) before 7.1(5b)su6a does not properly handle errors, which allows remote attackers to cause a…

Mitigation only
Fix from $1,950 2013-08-25
Unified Communications Manager HIGH 7.8
CVE-2013-3460

Memory leak in Cisco Unified Communications Manager (Unified CM) 8.5(x) before 8.5(1)su6, 8.6(x) before 8.6(2a)su3, and 9.x before 9.1(1) allows remo…

Mitigation only
Fix from $1,950 2013-08-25
Unified Communications Manager HIGH 7.1
CVE-2013-3461

Cisco Unified Communications Manager (Unified CM) 8.5(x) and 8.6(x) before 8.6(2a)su3 and 9.x before 9.1(1) does not properly restrict the rate of SI…

Mitigation only
Fix from $1,950 2013-08-25
Unified Communications Manager HIGH 7.8
CVE-2013-3453

Memory leak in Cisco Unified Communications Manager IM and Presence Service before 8.6(5)SU1 and 9.x before 9.1(2), and Cisco Unified Presence, allow…

Fix: after 8.6
Fix from $1,950 2013-08-22
Pi Interface MEDIUM 5.0
CVE-2013-2800

The OSIsoft PI Interface for IEEE C37.118 before 1.0.6.158 allows remote attackers to cause a denial of service (memory consumption or memory corrupt…

Fix: after 1.0.5.101
Fix from $1,600 2013-08-22
Chrome HIGH 7.5
CVE-2013-2902

Use-after-free vulnerability in the XSLT ProcessingInstruction implementation in Blink, as used in Google Chrome before 29.0.1547.57, allows remote a…

Fix: after 29.0.1547.56
Fix from $1,950 2013-08-21
Chrome HIGH 7.5
CVE-2013-2903

Use-after-free vulnerability in the HTMLMediaElement::didMoveToNewDocument function in core/html/HTMLMediaElement.cpp in Blink, as used in Google Chr…

Fix: after 29.0.1547.56
Fix from $1,950 2013-08-21
Chrome HIGH 7.5
CVE-2013-2904

Use-after-free vulnerability in the Document::finishedParsing function in core/dom/Document.cpp in Blink, as used in Google Chrome before 29.0.1547.5…

Fix: after 29.0.1547.56
Fix from $1,950 2013-08-21
Ubuntu Linux MEDIUM 5.0
CVE-2013-4130

The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_channel.c in SPICE before 0.12.4 do not properly p…

Fix: after 0.12.3
Fix from $1,600 2013-08-20
Cxf MEDIUM 5.0
CVE-2013-2160EPSS 32%

The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to cause a denial of s…

Patch available
Fix from $1,600 2013-08-19
Ubuntu Linux HIGH 7.5
CVE-2013-2126

Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to ca…

Fix: after 0.15.1
Fix from $1,950 2013-08-14
Sterling B2b Integrator MEDIUM 5.0
CVE-2013-0494

IBM Sterling B2B Integrator 5.0 and 5.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted HTTP (1) Rang…

Mitigation only
Fix from $1,600 2013-08-09
Firefox HIGH 9.3
CVE-2013-1704

Use-after-free vulnerability in the nsINode::GetParentNode function in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allows remote attackers …

Fix: after 22.0
Fix from $1,950 2013-08-07
Bitcoin Qt MEDIUM 6.4
CVE-2013-3220

bitcoind and Bitcoin-Qt before 0.4.9rc2, 0.5.x before 0.5.8rc2, 0.6.x before 0.6.5rc2, and 0.7.x before 0.7.3rc2, and wxBitcoin, do not properly cons…

Fix: after 0.4.9
Fix from $1,600 2013-08-02