Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
HTTP Server MEDIUM 5.0
CVE-2007-6750EPSS 71%

The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by…

Fix: after 2.2.14
Fix from $1,600 2011-12-27
Firefox HIGH 7.5
CVE-2011-3661

YARR, as used in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6, allows remote attackers to cause a denial of…

Fix: after 2.5
Fix from $1,950 2011-12-21
Firefox HIGH 7.5
CVE-2011-3665

Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to cause a denial of service (applicati…

Fix: after 2.5
Fix from $1,950 2011-12-21
Firefox HIGH 7.5
CVE-2011-3658EPSS 70%

The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly interact with DOMAttrModified event handlers, whi…

Mitigation only
Fix from $1,950 2011-12-21
Unbound HIGH 7.8
CVE-2011-4869

validator/val_nsec3.c in Unbound before 1.4.13p2 does not properly perform proof processing for NSEC3-signed zones, which allows remote DNS servers t…

Fix: after 1.4.12
Fix from $1,950 2011-12-20
Unbound MEDIUM 5.0
CVE-2011-4528

Unbound before 1.4.13p2 attempts to free unallocated memory during processing of duplicate CNAME records in a signed zone, which allows remote DNS se…

Fix: after 1.4.13
Fix from $1,600 2011-12-20
Office HIGH 9.3
CVE-2011-1983EPSS 22%

Use-after-free vulnerability in Microsoft Office 2007 SP2 and SP3, Office 2010 Gold and SP1, and Office for Mac 2011 allows remote attackers to execu…

Mitigation only
Fix from $1,950 2011-12-14
Mit Kerberos MEDIUM 6.8
CVE-2011-1530

The process_tgs_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 through 1.9.2 allows remote authen…

Patch available
Fix from $1,600 2011-12-08
Opera Browser MEDIUM 5.0
CVE-2011-4687

Opera before 11.60 allows remote attackers to cause a denial of service (CPU and memory consumption) via unspecified content on a web page, as demons…

Fix: after 11.60
Fix from $1,600 2011-12-07
Proftpd HIGH 9.0
CVE-2011-4130EPSS 13%

Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute arbitrary code via vectors inv…

Fix: after 1.3.3
Fix from $1,950 2011-12-06
Squid MEDIUM 5.0
CVE-2011-4096EPSS 37%

The idnsGrokReply function in Squid before 3.1.16 does not properly free memory, which allows remote attackers to cause a denial of service (daemon a…

Fix: after 3.1.15
Fix from $1,600 2011-11-17
Iphone Os HIGH 7.2
CVE-2011-3442

The kernel in Apple iOS before 5.0.1 does not ensure the validity of flag combinations for an mmap system call, which allows local users to execute a…

Mitigation only
Fix from $1,950 2011-11-11
Csworks MEDIUM 5.0
CVE-2011-3996

The LiveData Service in CSWorks before 2.0.4115.1 allows remote attackers to cause a denial of service (service crash) via crafted TCP packets.

Fix: after 2.0.4115.0
Fix from $1,600 2011-11-03
Webmail MEDIUM 5.0
CVE-2011-4078

include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP 5.3.7 or 5.3.8 is used, allows remote attackers to trigger a GET request for an a…

Fix: after 0.5.4
Fix from $1,600 2011-11-03
Slimpdf Reader HIGH 9.3
CVE-2011-4218

Investintech.com SlimPDF Reader does not prevent faulting-instruction data from affecting write operations, which allows remote attackers to cause a …

Mitigation only
Fix from $1,950 2011-11-01
Slimpdf Reader HIGH 9.3
CVE-2011-4219

Investintech.com SlimPDF Reader does not prevent faulting-address data from affecting branch selection, which allows remote attackers to cause a deni…

Mitigation only
Fix from $1,950 2011-11-01
Unified Communications Manager HIGH 7.8
CVE-2011-0941

Memory leak in Cisco Unified Communications Manager (CUCM) 6.x before 6.1(5)su2, 7.x before 7.1(5b)su3, 8.x before 8.0(3a)su1, and 8.5 before 8.5(1),…

Mitigation only
Fix from $1,950 2011-11-01
Video Surveillance 2421 HIGH 7.8
CVE-2011-3318

Cisco Video Surveillance 2421 and 2500 series cameras with software 1.1.x and 2.x before 2.4.0 and Video Surveillance 2600 series cameras with softwa…

Fix: after 4.2.0
Fix from $1,950 2011-10-27
Django MEDIUM 5.0
CVE-2011-4137

The verify_exists functionality in the URLField implementation in Django before 1.2.7 and 1.3.x before 1.3.1 relies on Python libraries that attempt …

Fix: after 1.2.6
Fix from $1,600 2011-10-19
Apple Tv MEDIUM 5.0
CVE-2011-3259

The kernel in Apple iOS before 5 and Apple TV before 4.4 does not properly recover memory allocated for incomplete TCP connections, which allows remo…

Mitigation only
Fix from $1,600 2011-10-14
Iphone Os MEDIUM 5.0
CVE-2011-3432

The UIKit Alerts component in Apple iOS before 5 allows remote attackers to cause a denial of service (device hang) via a long tel: URL that triggers…

Mitigation only
Fix from $1,600 2011-10-14
Windows 2003 Server HIGH 7.2
CVE-2011-2011

Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2…

Mitigation only
Fix from $1,950 2011-10-12
Quagga MEDIUM 5.0
CVE-2011-3324

The ospf6_lsa_is_changed function in ospf6_lsa.c in the OSPFv3 implementation in ospf6d in Quagga before 0.99.19 allows remote attackers to cause a d…

Fix: after 0.99.18
Fix from $1,600 2011-10-10
Quagga MEDIUM 5.0
CVE-2011-3325

ospf_packet.c in ospfd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) via (1) a 0x0a type field in an I…

Fix: after 0.99.18
Fix from $1,600 2011-10-10
Quagga MEDIUM 5.0
CVE-2011-3326

The ospf_flood function in ospf_flood.c in ospfd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) via an …

Fix: after 0.99.18
Fix from $1,600 2011-10-10
Jabber Extensible Communications Platform HIGH 7.8
CVE-2011-3287

Cisco Jabber Extensible Communications Platform (aka Jabber XCP) 2.x through 5.4.x before 5.4.0.27581 and 5.8.x before 5.8.1.27561 does not properly …

Fix: after 5.8
Fix from $1,950 2011-10-06
Firewall Services Module Software HIGH 7.8
CVE-2011-3296

Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7), when IPv6 is used, allow…

Mitigation only
Fix from $1,950 2011-10-06
Adaptive Security Appliance Software HIGH 7.8
CVE-2011-3299

Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 be…

Mitigation only
Fix from $1,950 2011-10-06
Adaptive Security Appliance Software HIGH 7.8
CVE-2011-3300

Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 be…

Mitigation only
Fix from $1,950 2011-10-06
Adaptive Security Appliance Software HIGH 7.8
CVE-2011-3301

Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 be…

Mitigation only
Fix from $1,950 2011-10-06