Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Unity Connection MEDIUM 5.0
CVE-2013-1129

Memory leak in Cisco Unity Connection 9.x allows remote attackers to cause a denial of service (memory consumption and process crash) by sending many…

Mitigation only
Fix from $1,600 2013-02-19
Linux Kernel MEDIUM 5.2
CVE-2013-0217

Memory leak in drivers/net/xen-netback/netback.c in the Xen netback functionality in the Linux kernel before 3.7.8 allows guest OS users to cause a d…

Fix: after 3.7.8
Fix from $1,600 2013-02-18
iOS MEDIUM 5.4
CVE-2013-1100

The HTTP server in Cisco IOS on Catalyst switches does not properly handle TCP socket events, which allows remote attackers to cause a denial of serv…

Mitigation only
Fix from $1,600 2013-02-13
Zend Framework MEDIUM 5.0
CVE-2012-6532

(1) Zend_Dom, (2) Zend_Feed, (3) Zend_Soap, and (4) Zend_XmlRpc in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 allow remote attackers …

Mitigation only
Fix from $1,600 2013-02-13
Flash Player HIGH 10.0
CVE-2013-1374EPSS 9%

Use-after-free vulnerability in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.…

Fix: 3.6.0.597 / 3.6.0.599+
Fix from $1,950 2013-02-12
Flash Player HIGH 10.0
CVE-2013-0644EPSS 9%

Use-after-free vulnerability in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.…

Fix: 3.6.0.597 / 3.6.0.599+
Fix from $1,950 2013-02-12
Flash Player HIGH 10.0
CVE-2013-0649EPSS 9%

Use-after-free vulnerability in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.…

Fix: 3.6.0.597 / 3.6.0.599+
Fix from $1,950 2013-02-12
Controllogix Controllers HIGH 7.5
CVE-2012-6435EPSS 33%

When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or P…

Fix: after 1400
Fix from $1,950 2013-01-24
Chrome HIGH 7.5
CVE-2013-0839

Use-after-free vulnerability in Google Chrome before 24.0.1312.56 allows remote attackers to cause a denial of service or possibly have unspecified o…

Fix: after 24.0.1312.55
Fix from $1,950 2013-01-24
Enterprise Linux MEDIUM 5.0
CVE-2012-2124

functions/imap_general.php in SquirrelMail, as used in Red Hat Enterprise Linux (RHEL) 4 and 5, does not properly handle 8-bit characters in password…

Mitigation only
Fix from $1,600 2013-01-18
Adaptive Security Appliance Software HIGH 7.8
CVE-2012-5419

Cisco Adaptive Security Appliance (ASA) software 8.7.1 and 8.7.1.1 for the Cisco ASA 1000V Cloud Firewall allows remote attackers to cause a denial o…

Mitigation only
Fix from $1,950 2013-01-17
Chrome HIGH 7.5
CVE-2013-0832

Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified o…

Fix: after 24.0.1312.51
Fix from $1,950 2013-01-15
Chrome MEDIUM 6.8
CVE-2013-0836

Google V8 before 3.14.5.3, as used in Google Chrome before 24.0.1312.52, does not properly implement garbage collection, which allows remote attacker…

Fix: after 24.0.1312.51
Fix from $1,600 2013-01-15
Chrome HIGH 7.5
CVE-2012-5147

Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified o…

Fix: after 24.0.1312.51
Fix from $1,950 2013-01-15
Chrome HIGH 7.5
CVE-2012-5150

Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified o…

Fix: after 24.0.1312.51
Fix from $1,950 2013-01-15
Chrome MEDIUM 6.8
CVE-2012-5156

Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified o…

Fix: after 24.0.1312.51
Fix from $1,600 2013-01-15
Chrome MEDIUM 6.8
CVE-2013-0828

The PDF functionality in Google Chrome before 24.0.1312.52 does not properly perform a cast of an unspecified variable during processing of the root …

Fix: after 24.0.1312.51
Fix from $1,600 2013-01-15
Acrobat HIGH 10.0
CVE-2013-0602EPSS 8%

Use-after-free vulnerability in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arb…

Patch available
Fix from $1,950 2013-01-10
Tor MEDIUM 5.0
CVE-2012-5573

The connection_edge_process_relay_cell function in or/relay.c in Tor before 0.2.3.25 maintains circuits even if an unexpected SENDME cell arrives, wh…

Fix: after 0.2.3.24
Fix from $1,600 2013-01-01
Libxml2 MEDIUM 5.0
CVE-2012-0841

libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent atta…

Fix: after 6.1.4
Fix from $1,600 2012-12-21
Libunity Webapps HIGH 7.5
CVE-2012-4551

Use-after-free vulnerability in libunity-webapps before 2.4.1 allows remote attackers to cause a denial of service (memory corruption and crash) and …

Fix: after 2.4.0
Fix from $1,950 2012-11-30
Libssh MEDIUM 6.8
CVE-2012-4559EPSS 5%

Multiple double free vulnerabilities in the (1) agent_sign_data function in agent.c, (2) channel_request function in channels.c, (3) ssh_userauth_pub…

Fix: after 0.5.2
Fix from $1,600 2012-11-30
Libssh HIGH 7.5
CVE-2012-6063

Double free vulnerability in the sftp_mkdir function in sftp.c in libssh before 0.5.3 allows remote attackers to cause a denial of service (crash) an…

Fix: after 0.5.2
Fix from $1,950 2012-11-30
HTTP Server MEDIUM 5.0
CVE-2012-4557EPSS 17%

The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-pr…

Patch available
Fix from $1,600 2012-11-30
Tivoli Endpoint Manager MEDIUM 5.0
CVE-2012-4841

Unspecified vulnerability in Tivoli Endpoint Manager for Remote Control Broker 8.2 before 8.2.1-TIV-TEMRC821-IF0002 allows remote attackers to cause …

Patch available
Fix from $1,600 2012-11-29
Chrome HIGH 7.5
CVE-2012-5135

Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service or possibly have unspecified o…

Fix: after 23.0.1271.89
Fix from $1,950 2012-11-28
Greenbrowser MEDIUM 6.8
CVE-2012-6041

Double free vulnerability in GreenBrowser before 6.0.1002, when the keyword search bar (F6) is activated, allows remote attackers to execute arbitrar…

Fix: after 6.0.1001
Fix from $1,600 2012-11-26
Ar Web Content Manager MEDIUM 5.0
CVE-2012-2438

ar web content manager (AWCM) 2.2 does not restrict the number of comment records that can be submitted through HTTP requests, which allows remote at…

No fix yet
Fix from $1,600 2012-11-26
Lighttpd MEDIUM 5.0
CVE-2012-5533EPSS 12%

The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via…

Patch available
Fix from $1,600 2012-11-24
Excel HIGH 9.3
CVE-2012-1887EPSS 25%

Use-after-free vulnerability in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1, and Office 2008 and 2011 for Mac, allows remote attackers t…

Mitigation only
Fix from $1,950 2012-11-14