Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Websphere Application Server MEDIUM 5.0
CVE-2011-1318

Memory leak in org.apache.jasper.runtime.JspWriterImpl.response in the JavaServer Pages (JSP) component in IBM WebSphere Application Server (WAS) bef…

Fix: after 7.0.0.13
Fix from $1,600 2011-03-08
Websphere Application Server MEDIUM 5.0
CVE-2011-1322

The SOAP with Attachments API for Java (SAAJ) implementation in the Web Services component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6…

Mitigation only
Fix from $1,600 2011-03-08
Websphere Application Server MEDIUM 5.0
CVE-2011-1313

Double free vulnerability in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15 allows remote backend IIOP server…

Patch available
Fix from $1,600 2011-03-08
Websphere Application Server MEDIUM 5.0
CVE-2011-1314

The Service Integration Bus (SIB) messaging engine in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denia…

Fix: after 7.0.0.13
Fix from $1,600 2011-03-08
Websphere Application Server MEDIUM 5.0
CVE-2011-1315

Memory leak in the messaging engine in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (m…

Fix: after 7.0.0.13
Fix from $1,600 2011-03-08
Websphere Application Server MEDIUM 5.0
CVE-2011-1316

The Session Initiation Protocol (SIP) Proxy in the HTTP Transport component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote a…

Fix: after 7.0.0.13
Fix from $1,600 2011-03-08
Itunes HIGH 7.6
CVE-2011-0116

Use-after-free vulnerability in the setOuterText method in the htmlelement library in WebKit, as used in Apple iTunes before 10.2 on Windows, allows …

Fix: after 10.1.2
Fix from $1,950 2011-03-03
Safari HIGH 7.6
CVE-2011-0132

Use-after-free vulnerability in the Runin box functionality in the Cascading Style Sheets (CSS) 2.1 Visual Formatting Model implementation in WebKit,…

Fix: after 10.1.2
Fix from $1,950 2011-03-03
Firefox HIGH 10.0
CVE-2011-0055EPSS 7%

Use-after-free vulnerability in the JSON.stringify method in js3250.dll in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey befor…

Fix: after 2.0.11
Fix from $1,950 2011-03-02
Firefox HIGH 10.0
CVE-2011-0057

Use-after-free vulnerability in the Web Workers implementation in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12,…

Fix: after 2.0.11
Fix from $1,950 2011-03-02
Telepresence Multipoint Switch Software HIGH 7.8
CVE-2011-0390

The XML-RPC implementation on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, 1.6.x, and 1.7.0 allows remote a…

Mitigation only
Fix from $1,950 2011-02-25
Telepresence Recording Server Software HIGH 7.8
CVE-2011-0391

Cisco TelePresence Recording Server devices with software 1.6.x allow remote attackers to cause a denial of service (thread consumption and device ou…

Mitigation only
Fix from $1,950 2011-02-25
Adaptive Security Appliance Software HIGH 7.8
CVE-2011-0393

Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.0 before 7.0(8.12), 7.1 and 7.2 before 7.2(5.2), 8.0 before 8.0(5.21), 8…

Fix: after 8.3
Fix from $1,950 2011-02-25
Adaptive Security Appliance HIGH 7.8
CVE-2011-0394

Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.0 before 7.0(8.11), 7.1 and 7.2 before 7.2(5.1), 8.0 before 8.0(5.19), 8…

Fix: after 8.3
Fix from $1,950 2011-02-25
Adaptive Security Appliance HIGH 7.8
CVE-2011-0395

Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.20), 8.1 before 8.1(2.48), 8.2 before 8.2(3), and 8.3 bef…

Mitigation only
Fix from $1,950 2011-02-25
Telepresence System Software HIGH 7.8
CVE-2011-0377

Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x allow remote attackers to cause a denial of service (service crash) via a malfo…

Mitigation only
Fix from $1,950 2011-02-25
Telepresence Recording Server Software HIGH 7.8
CVE-2011-0388

Cisco TelePresence Recording Server devices with software 1.6.x and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1…

Mitigation only
Fix from $1,950 2011-02-25
Telepresence Multipoint Switch Software HIGH 7.8
CVE-2011-0389

Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allow remote attackers to cause a denial of service …

Mitigation only
Fix from $1,950 2011-02-25
Clamav MEDIUM 6.8
CVE-2011-1003

Double free vulnerability in the vba_read_project_strings function in vba_extract.c in libclamav in ClamAV before 0.97 might allow remote attackers t…

Fix: after 0.96.5
Fix from $1,600 2011-02-23
389 Directory Server MEDIUM 5.0
CVE-2010-4746

Multiple memory leaks in the normalization functionality in 389 Directory Server before 1.2.7.5 allow remote attackers to cause a denial of service (…

Fix: after 1.2.7
Fix from $1,600 2011-02-23
Bind HIGH 7.1
CVE-2011-0414EPSS 14%

ISC BIND 9.7.1 through 9.7.2-P3, when configured as an authoritative server, allows remote attackers to cause a denial of service (deadlock and daemo…

Mitigation only
Fix from $1,950 2011-02-23
Openafs HIGH 7.5
CVE-2011-0430

Double free vulnerability in the Rx server process in OpenAFS 1.4.14, 1.4.12, 1.4.7, and possibly other versions allows remote attackers to cause a d…

Mitigation only
Fix from $1,950 2011-02-19
1000v Virtual Ethernet Module \(vem\) HIGH 7.8
CVE-2011-0355

Cisco Nexus 1000V Virtual Ethernet Module (VEM) 4.0(4) SV1(1) through SV1(3b), as used in VMware ESX 4.0 and 4.1 and ESXi 4.0 and 4.1, does not prope…

Mitigation only
Fix from $1,950 2011-02-17
Excel HIGH 9.3
CVE-2011-0977EPSS 32%

Use-after-free vulnerability in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2004 and 2008 for Mac, and Open XML File Format Con…

Mitigation only
Fix from $1,950 2011-02-10
Tomcat MEDIUM 5.0
CVE-2011-0534EPSS 8%

Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector…

Patch available
Fix from $1,600 2011-02-10
Groupwise HIGH 10.0
CVE-2010-4711EPSS 14%

Double free vulnerability in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allows remote attackers t…

Fix: after 8.0.2
Fix from $1,950 2011-01-31
Tor MEDIUM 5.0
CVE-2011-0492

Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (assertion failure and daemon exit) via bl…

Fix: after 0.2.1.28
Fix from $1,600 2011-01-19
MySQL MEDIUM 5.0
CVE-2010-3833

MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 does not properly propagate type errors, which allows remote attackers to cause a de…

Patch available
Fix from $1,600 2011-01-14
Glibc MEDIUM 5.0
CVE-2010-4052EPSS 51%

Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, al…

Patch available
Fix from $1,600 2011-01-13
Wireshark MEDIUM 5.0
CVE-2011-0445

The ASN.1 BER dissector in Wireshark 1.4.0 through 1.4.2 allows remote attackers to cause a denial of service (assertion failure) via crafted packets…

Mitigation only
Fix from $1,600 2011-01-13