Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Prosody MEDIUM 5.0
CVE-2011-2532

The json.decode function in util/json.lua in Prosody 0.8.x before 0.8.1 might allow remote attackers to cause a denial of service (infinite loop) via…

Patch available
Fix from $1,600 2011-06-22
Prosody MEDIUM 5.0
CVE-2011-2205

Prosody before 0.8.1 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory a…

Fix: after 0.8.0
Fix from $1,600 2011-06-22
Citadel MEDIUM 5.0
CVE-2011-1756

modules/xmpp/serv_xmpp.c in Citadel 7.86 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cau…

Fix: after 7.86
Fix from $1,600 2011-06-21
Djabberd MEDIUM 5.0
CVE-2011-1757

DJabberd 0.84 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (mem…

Fix: after 0.84
Fix from $1,600 2011-06-21
Luaexpat MEDIUM 5.0
CVE-2011-2188

LuaExpat before 1.2.0 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory …

Fix: after 1.1.0
Fix from $1,600 2011-06-21
Ejabberd MEDIUM 5.0
CVE-2011-1753

expat_erl.c in ejabberd before 2.1.7 and 3.x before 3.0.0-alpha-3, and exmpp before 0.9.7, does not properly detect recursion during entity expansion…

Fix: after 2.1.6
Fix from $1,600 2011-06-21
Jabberd14 MEDIUM 5.0
CVE-2011-1754

jabberd14 1.6.1.1 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service …

Fix: after 1.6.1.1
Fix from $1,600 2011-06-21
Windows 2003 Server HIGH 7.8
CVE-2011-1869EPSS 10%

The Distributed File System (DFS) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Ser…

Mitigation only
Fix from $1,950 2011-06-16
Post Revolution MEDIUM 5.0
CVE-2011-1952

common.php in Post Revolution before 0.8.0c-2 allows remote attackers to cause a denial of service (infinite loop) via malformed HTML markup, as demo…

Fix: after 0.8.0c
Fix from $1,600 2011-06-06
Unbound MEDIUM 5.0
CVE-2009-4008

Unbound before 1.4.4 does not send responses for signed zones after mishandling an unspecified query, which allows remote attackers to cause a denial…

Fix: after 1.4.3
Fix from $1,600 2011-06-02
Fetchmail MEDIUM 5.0
CVE-2011-1947

fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time after issuing a (1) STARTTLS or (2) STLS request, which allows remote servers to…

Mitigation only
Fix from $1,600 2011-06-02
Content Delivery System Engine HIGH 7.8
CVE-2011-1649

The Internet Streamer application in Cisco Content Delivery System (CDS) with software 2.5.7, 2.5.8, and 2.5.9 before build 126 allows remote attacke…

Mitigation only
Fix from $1,950 2011-05-31
Ios Xr HIGH 7.8
CVE-2011-1651

Cisco IOS XR 3.9.x and 4.0.x before 4.0.3 and 4.1.x before 4.1.1, when an SPA interface processor is installed, allows remote attackers to cause a de…

Mitigation only
Fix from $1,950 2011-05-31
Ios Xr HIGH 7.8
CVE-2011-0943

Cisco IOS XR 3.8.3, 3.8.4, and 3.9.1 allows remote attackers to cause a denial of service (NetIO process restart or device reload) via a crafted IPv4…

Mitigation only
Fix from $1,950 2011-05-31
Ios Xr HIGH 7.8
CVE-2011-0949

Cisco IOS XR 3.6.x, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 does not properly remove sshd_lock files from /tmp/, which allows remote attackers to …

Mitigation only
Fix from $1,950 2011-05-31
Viewvc MEDIUM 5.0
CVE-2009-5024

ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumption attac…

Fix: after 1.1.10
Fix from $1,600 2011-05-23
Pure Ftpd MEDIUM 5.8
CVE-2011-1575EPSS 33%

The STARTTLS implementation in ftp_parser.c in Pure-FTPd before 1.0.30 does not properly restrict I/O buffering, which allows man-in-the-middle attac…

Fix: after 1.0.29
Fix from $1,600 2011-05-23
Ffmpeg MEDIUM 6.8
CVE-2011-0723

FFmpeg 0.5.x, as used in MPlayer and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arb…

Mitigation only
Fix from $1,600 2011-05-20
Datacap Taskmaster Capture MEDIUM 5.0
CVE-2011-2144

The eDocument Conversion Actions implementation in IBM Datacap Taskmaster Capture 8.0.1 FP1 and earlier allows remote attackers to cause a denial of …

Fix: after 8.0.1
Fix from $1,600 2011-05-16
Intelligent Management Center HIGH 10.0
CVE-2011-1854EPSS 11%

Use-after-free vulnerability in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to execute arbitrary code via a lo…

Patch available
Fix from $1,950 2011-05-13
Bind MEDIUM 5.0
CVE-2011-1907EPSS 5%

ISC BIND 9.8.x before 9.8.0-P1, when Response Policy Zones (RPZ) RRset replacement is enabled, allows remote attackers to cause a denial of service (…

Mitigation only
Fix from $1,600 2011-05-09
Firefox HIGH 10.0
CVE-2011-0066

Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execut…

Fix: after 2.0.13
Fix from $1,950 2011-05-07
Firefox HIGH 10.0
CVE-2011-0065EPSS 74%

Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execut…

Fix: after 2.0.13
Fix from $1,950 2011-05-07
Linux Kernel MEDIUM 5.7
CVE-2011-0714

Use-after-free vulnerability in a certain Red Hat patch for the RPC server sockets functionality in the Linux kernel 2.6.32 on Red Hat Enterprise Lin…

Mitigation only
Fix from $1,600 2011-05-04
Esx HIGH 7.8
CVE-2011-1785

VMware ESXi 4.0 and 4.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service (socket exhaustion) via unspecified network traffic.

Mitigation only
Fix from $1,950 2011-05-03
Esx MEDIUM 5.0
CVE-2011-1786

lsassd in Likewise Open /Enterprise 5.3 before build 7845, Open 6.0 before build 8325, and Enterprise 6.0 before build 178, as distributed in VMware …

Mitigation only
Fix from $1,600 2011-05-03
Unified Communications Manager HIGH 7.1
CVE-2011-1604

Memory leak in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5b)su3, 8.0 before 8.0(3a)s…

Mitigation only
Fix from $1,950 2011-05-03
Asterisk MEDIUM 5.0
CVE-2011-1507

Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Business Editio…

Patch available
Fix from $1,600 2011-04-27
Tivoli Directory Server MEDIUM 6.8
CVE-2007-6742

The get_filter_list function in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0006 does not properly perform certain sub filter par…

Patch available
Fix from $1,600 2011-04-21
Tivoli Directory Server MEDIUM 5.0
CVE-2008-7288

IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 on AIX allows remote attackers to cause a denial of service (server destabilizat…

Mitigation only
Fix from $1,600 2011-04-21