Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Firefox HIGH 7.5
CVE-2012-0454

Use-after-free vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x …

Fix: after 2.7
Fix from $1,950 2012-03-14
Firefox HIGH 9.3
CVE-2012-0457EPSS 7%

Use-after-free vulnerability in the nsSMILTimeValueSpec::ConvertBetweenTimeContainer function in Mozilla Firefox before 3.6.28 and 4.x through 10.0, …

Fix: after 10.0
Fix from $1,950 2012-03-14
Gnutls HIGH 7.5
CVE-2012-1663EPSS 5%

Double free vulnerability in libgnutls in GnuTLS before 3.0.14 allows remote attackers to cause a denial of service (application crash) or possibly h…

Fix: after 3.0.13
Fix from $1,950 2012-03-13
Maximo Asset Management MEDIUM 5.0
CVE-2011-1394

IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Servi…

Mitigation only
Fix from $1,600 2012-03-13
Cyassl MEDIUM 5.0
CVE-2012-1558

yaSSL CyaSSL before 2.0.8 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted X.509 c…

Fix: after 2.0.6
Fix from $1,600 2012-03-12
Safari HIGH 7.6
CVE-2011-3845

Use-after-free vulnerability in Apple Safari 5.1.2, when a plug-in with a blocking function is installed, allows user-assisted remote attackers to ex…

Mitigation only
Fix from $1,950 2012-03-08
Flash Player HIGH 10.0
CVE-2012-0768EPSS 6%

The Matrix3D component in Adobe Flash Player before 10.3.183.16 and 11.x before 11.1.102.63 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111…

Fix: after 11.1.115.6
Fix from $1,950 2012-03-05
Vios HIGH 7.8
CVE-2011-1385

IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.1.x and 2.2.x, allows remote attackers to cause a denial of service (system crash) via an ICMP Echo Reply packe…

Patch available
Fix from $1,950 2012-03-02
Safari HIGH 7.5
CVE-2011-3443

Use-after-free vulnerability in WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of …

Fix: after 5.0.5
Fix from $1,950 2012-03-02
Unity Connection HIGH 7.8
CVE-2012-0367

Cisco Unity Connection before 7.1.5b(Su5), 8.0 and 8.5 before 8.5.1(Su3), and 8.6 before 8.6.2 allows remote attackers to cause a denial of service (…

Fix: after 7.1
Fix from $1,950 2012-03-01
Wireless Lan Controller Software HIGH 7.8
CVE-2012-0368

The administrative management interface on Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.0, 7.1 bef…

Mitigation only
Fix from $1,950 2012-03-01
Wireless Lan Controller Software HIGH 7.8
CVE-2012-0369

Cisco Wireless LAN Controller (WLC) devices with software 6.0 and 7.0 before 7.0.220.0, 7.1 before 7.1.91.0, and 7.2 before 7.2.103.0 allow remote at…

Mitigation only
Fix from $1,950 2012-03-01
Wireless Lan Controller Software HIGH 7.8
CVE-2012-0370

Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.0 and 7.1 before 7.1.91.0, when WebAuth is enabled, a…

Mitigation only
Fix from $1,950 2012-03-01
Unified Communications Manager HIGH 7.8
CVE-2011-4486

Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before 8.0(3a)su3, and 8.5 and 8.6 before 8.6(2a)su1 and…

Mitigation only
Fix from $1,950 2012-03-01
Telepresence System Software HIGH 7.8
CVE-2012-0330

Cisco TelePresence Video Communication Server with software before X7.0.1 allows remote attackers to cause a denial of service (device crash) via a m…

Mitigation only
Fix from $1,950 2012-03-01
Telepresence System Software HIGH 7.5
CVE-2012-0331

Cisco TelePresence Video Communication Server with software before X7.0.1 allows remote attackers to cause a denial of service (device crash) via a c…

Mitigation only
Fix from $1,950 2012-03-01
Cius Software HIGH 7.8
CVE-2012-0359

The Cisco Cius with software before 9.2(1) SR2 allows remote attackers to cause a denial of service (device crash or hang) via malformed network traf…

Fix: after 9.2
Fix from $1,950 2012-03-01
Authoritative Server MEDIUM 5.0
CVE-2012-0206EPSS 5%

common_startup.cc in PowerDNS (aka pdns) Authoritative Server before 2.9.22.5 and 3.x before 3.0.1 allows remote attackers to cause a denial of servi…

Fix: after 2.9.22
Fix from $1,600 2012-02-17
Nx Os HIGH 7.8
CVE-2012-0352

Cisco NX-OS 4.2.x before 4.2(1)SV1(5.1) on Nexus 1000v series switches; 4.x and 5.0.x before 5.0(2)N1(1) on Nexus 5000 series switches; and 4.2.x bef…

Mitigation only
Fix from $1,950 2012-02-16
Firefox HIGH 7.5
CVE-2012-0452

Use-after-free vulnerability in Mozilla Firefox 10.x before 10.0.1, Thunderbird 10.x before 10.0.1, and SeaMonkey 2.7 allows remote attackers to caus…

Mitigation only
Fix from $1,950 2012-02-11
Mac Os X MEDIUM 6.8
CVE-2011-3449

Use-after-free vulnerability in CoreText in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of servi…

Fix: after 10.7.2
Fix from $1,600 2012-02-02
Mac Os X MEDIUM 6.8
CVE-2011-3450

CoreUI in Apple Mac OS X 10.7.x before 10.7.3 does not properly restrict the allocation of stack memory, which allows remote attackers to execute arb…

Mitigation only
Fix from $1,600 2012-02-02
FreeBSD HIGH 7.8
CVE-2011-2393

The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD, NetBSD, and possibly other BSD-based operating systems allows remot…

Mitigation only
Fix from $1,950 2012-02-02
Logsurfer HIGH 7.5
CVE-2011-3626

Double free vulnerability in the prepare_exec function in src/exec.c in Logsurfer 1.5b and earlier, and Logsurfer+ 1.7 and earlier, allows remote att…

Fix: after 1.7
Fix from $1,950 2012-01-27
Dhcp MEDIUM 6.1
CVE-2011-4868

The logging functionality in dhcpd in ISC DHCP before 4.2.3-P2, when using Dynamic DNS (DDNS) and issuing IPv6 addresses, does not properly handle th…

Fix: after 4.2.3
Fix from $1,600 2012-01-15
Codemeter Runtime MEDIUM 5.0
CVE-2011-4057EPSS 5%

Wibu-Systems AG CodeMeter Runtime 4.30c, 4.10b, and possibly other versions before 4.40 allows remote attackers to cause a denial of service (CodeMet…

Fix: after 4.30d
Fix from $1,600 2012-01-13
Tomcat MEDIUM 5.0
CVE-2011-4858EPSS 80%

Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to tri…

No fix yet
Fix from $1,600 2012-01-05
Activemq MEDIUM 5.0
CVE-2011-4905EPSS 9%

Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending ma…

Fix: after 5.5.1
Fix from $1,600 2012-01-05
Dhttpd MEDIUM 5.0
CVE-2009-5110

dhttpd allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.

Mitigation only
Fix from $1,600 2011-12-27
Goahead Webserver MEDIUM 5.0
CVE-2009-5111

GoAhead WebServer allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.

Mitigation only
Fix from $1,600 2011-12-27