Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Opera Browser MEDIUM 5.0
CVE-2010-1989

Opera 9.52 executes a mail application in situations where an IMG element has a SRC attribute that is a redirect to a mailto: URL, which allows remot…

No fix yet
Fix from $1,600 2010-05-20
Firefox MEDIUM 5.0
CVE-2010-1990

Mozilla Firefox 3.6.x, 3.5.x, 3.0.19, and earlier, and SeaMonkey, executes a mail application in situations where an IFRAME element has a mailto: URL…

Fix: after 3.0.19
Fix from $1,600 2010-05-20
Ie MEDIUM 5.0
CVE-2010-1991EPSS 11%

Microsoft Internet Explorer 6.0.2900.2180, 7, and 8.0.7600.16385 executes a mail application in situations where an IFRAME element has a mailto: URL …

No fix yet
Fix from $1,600 2010-05-20
Chrome MEDIUM 5.0
CVE-2010-1992

Google Chrome 1.0.154.48 executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remot…

No fix yet
Fix from $1,600 2010-05-20
Opera Browser MEDIUM 5.0
CVE-2010-1993

Opera 9.52 does not properly handle an IFRAME element with a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of ser…

No fix yet
Fix from $1,600 2010-05-20
Websphere Application Server MEDIUM 5.0
CVE-2010-0775

Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 allows remote a…

Mitigation only
Fix from $1,600 2010-05-17
Pgw 2200 Softswitch HIGH 7.8
CVE-2010-1565

Unspecified vulnerability in the SIP implementation on the Cisco PGW 2200 Softswitch with software 9.7(3)S before 9.7(3)S9 and 9.7(3)P before 9.7(3)P…

Patch available
Fix from $1,950 2010-05-14
Safari HIGH 7.6
CVE-2010-1939EPSS 15%

Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using window.open to create a popu…

Patch available
Fix from $1,950 2010-05-13
Opera Browser HIGH 9.3
CVE-2010-1728EPSS 7%

Opera before 10.53 on Windows and Mac OS X does not properly handle a series of document modifications that occur asynchronously, which allows remote…

Fix: after 10.52
Fix from $1,950 2010-05-06
Advanced Management Module MEDIUM 5.0
CVE-2010-1460

The IBM BladeCenter with Advanced Management Module (AMM) firmware before bpet50g does not properly perform interrupt sharing for USB and iSCSI, whic…

Fix: after 2.50
Fix from $1,600 2010-04-16
Windows 2000 HIGH 7.2
CVE-2010-0236

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not properly allocate memory for the destination key a…

Mitigation only
Fix from $1,950 2010-04-14
Windows 7 HIGH 10.0
CVE-2010-0269EPSS 28%

The SMB client in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 …

Mitigation only
Fix from $1,950 2010-04-14
Windows 7 HIGH 10.0
CVE-2010-0476EPSS 34%

The SMB client in Microsoft Windows Server 2003 SP2, Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2 allows remote SMB servers and man…

Mitigation only
Fix from $1,950 2010-04-14
Linux Kernel HIGH 7.8
CVE-2010-1086

The ULE decapsulation functionality in drivers/media/dvb/dvb-core/dvb_net.c in dvb-core in Linux kernel 2.6.33 and earlier allows attackers to cause …

Fix: after 2.6.33
Fix from $1,950 2010-04-06
Firefox HIGH 9.3
CVE-2010-0175EPSS 7%

Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.9, Thunderbird before 3.0.4,…

Fix: after 3.0.17
Fix from $1,950 2010-04-05
Firefox HIGH 9.3
CVE-2010-0176EPSS 5%

Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 do not properly manag…

Fix: after 3.5.7
Fix from $1,950 2010-04-05
Firefox HIGH 9.3
CVE-2010-0177EPSS 7%

Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, frees the contents of the window.navigator.plu…

Fix: after 3.0.17
Fix from $1,950 2010-04-05
Chrome HIGH 10.0
CVE-2010-1229

The sandbox infrastructure in Google Chrome before 4.1.249.1036 does not properly use pointers, which has unspecified impact and attack vectors.

Fix: after 4.1.249.1035
Fix from $1,950 2010-04-01
Chrome MEDIUM 5.0
CVE-2010-1232

Google Chrome before 4.1.249.1036 allows remote attackers to cause a denial of service (memory error) or possibly have unspecified other impact via a…

Fix: after 4.1.249.1035
Fix from $1,600 2010-04-01
Internet Explorer HIGH 9.3
CVE-2010-0491EPSS 29%

Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 allows remote attackers to execute arbitrary code by changing unsp…

Patch available
Fix from $1,950 2010-03-31
Linux Kernel HIGH 7.1
CVE-2010-1188

Use-after-free vulnerability in net/ipv4/tcp_input.c in the Linux kernel 2.6 before 2.6.20, when IPV6_RECVPKTINFO is set on a listening socket, allow…

Patch available
Fix from $1,950 2010-03-31
Mac Os X Server MEDIUM 6.5
CVE-2010-0503

Use-after-free vulnerability in iChat Server in Apple Mac OS X Server 10.5.8 allows remote authenticated users to execute arbitrary code or cause a d…

Fix: after 10.6.2
Fix from $1,600 2010-03-30
Safari HIGH 10.0
CVE-2010-1119EPSS 19%

Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Safari before 4.1 on Mac OS X 10.4, and …

Fix: after 4.0.5
Fix from $1,950 2010-03-25
Firefox HIGH 9.3
CVE-2010-0164EPSS 6%

Use-after-free vulnerability in the imgContainer::InternalAddFrameHelper function in src/imgContainer.cpp in libpr0n in Mozilla Firefox 3.6 before 3.…

No fix yet
Fix from $1,950 2010-03-25
iOS HIGH 7.1
CVE-2010-0577

Cisco IOS 12.2 through 12.4, when certain PMTUD, SNAT, or window-size configurations are used, allows remote attackers to cause a denial of service (…

Patch available
Fix from $1,950 2010-03-25
iOS HIGH 7.8
CVE-2010-0583

Memory leak in the H.323 implementation in Cisco IOS 12.1 through 12.4, and 15.0M before 15.0(1)M1, allows remote attackers to cause a denial of serv…

Patch available
Fix from $1,950 2010-03-25
Safari MEDIUM 5.0
CVE-2010-1029EPSS 10%

Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Safari on iPhone OS and iPhone O…

No fix yet
Fix from $1,600 2010-03-19
Linux Kernel HIGH 7.8
CVE-2010-0008

The sctp_rcv_ootb function in the SCTP implementation in the Linux kernel before 2.6.23 allows remote attackers to cause a denial of service (infinit…

Fix: after 2.6.22.19
Fix from $1,950 2010-03-19
Unbound MEDIUM 5.0
CVE-2010-0969

Unbound before 1.4.3 does not properly align structures on 64-bit platforms, which allows remote attackers to cause a denial of service (daemon crash…

Fix: after 1.4.2
Fix from $1,600 2010-03-16
Safari HIGH 9.3
CVE-2010-0049EPSS 11%

Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (a…

Fix: after 4.0.4
Fix from $1,950 2010-03-15