Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Mac Os X MEDIUM 5.0
CVE-2015-5841

The CFNetwork Proxies component in Apple iOS before 9 does not properly handle a Set-Cookie header within a response to an HTTP CONNECT request, whic…

Fix: after 10.10.5
Fix from $1,600 2015-09-18
Groovy CRITICAL 9.8
CVE-2015-3253EPSS 41%

The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause…

Patch available
Fix from $2,300 2015-08-13
Sql Server HIGH 7.1
CVE-2015-1762EPSS 10%

Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014, when transactional replication is configured, does not preven…

Mitigation only
Fix from $1,950 2015-07-14
Libmimedir HIGH 7.5
CVE-2015-3205EPSS 11%

libmimedir allows remote attackers to execute arbitrary code via a VCF file with two NULL bytes at the end of the file, related to "free" function ca…

No fix yet
Fix from $1,950 2015-06-16
Lighttpd HIGH 7.5
CVE-2015-3200EPSS 10%

mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon cha…

Fix: after 15.07
Fix from $1,950 2015-06-09
Realmd MEDIUM 5.0
CVE-2015-2704

realmd allows remote attackers to inject arbitrary configurations in to sssd.conf and smb.conf via a newline character in an LDAP response.

Fix: after 15.2
Fix from $1,600 2015-05-18
Owncloud Server MEDIUM 6.0
CVE-2015-3013

ownCloud Server before 5.0.19, 6.x before 6.0.7, and 7.x before 7.0.5 allows remote authenticated users to bypass the file blacklist and upload arbit…

Fix: 5.0.19 / 6.0.7+
Fix from $1,600 2015-05-08
Debian Linux HIGH 7.5
CVE-2015-1592EPSS 75%

Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::thaw funct…

Fix: 5.2.12 / 6.0.7+
Fix from $1,950 2015-02-19
Ektron Content Management System MEDIUM 6.8
CVE-2015-0931

Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1, when the Saxon XSLT parser is used, allows remote attackers to e…

Mitigation only
Fix from $1,600 2015-02-14
Central Authentication Service HIGH 7.5
CVE-2015-1169

Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote attackers to conduct LDAP injection attacks via a crafted username, as …

Fix: after 3.5.2
Fix from $1,950 2015-02-10
Encryption Management Server MEDIUM 5.0
CVE-2014-7287

The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger un…

Fix: after 3.3.2
Fix from $1,600 2015-02-01
Debian Linux HIGH 7.6
CVE-2013-6435EPSS 8%

Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the con…

Fix: after 4.11.1
Fix from $1,950 2014-12-16
Vap2500 Firmware HIGH 10.0
CVE-2014-8423EPSS 62%

Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute arbitrary commands via unknown …

Fix: after 08.41
Fix from $1,950 2014-11-28
Archiva CRITICAL 9.8
CVE-2013-2251 KEVEPSS 100%

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redi…

Fix: 1.3.8+
Fix from $2,300 2013-07-20
Firefox MEDIUM 6.4
CVE-2012-4196

Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before …

Fix: 2.13.2 / 10.0.10+
Fix from $1,600 2012-10-29
Chrome MEDIUM 6.8
CVE-2011-2855

Google Chrome before 14.0.835.163 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a den…

Fix: 5.1 / 5.1.4+
Fix from $1,600 2011-09-19
Chrome MEDIUM 6.8
CVE-2011-2805

Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy and conduct script injection attacks via unspecified vecto…

Fix: 5.0 / 5.1.1+
Fix from $1,600 2011-08-03
Php Recommend HIGH 7.5
CVE-2009-1781

Static code injection vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to inject arbitrary PHP code into p…

Fix: after 1.3
Fix from $1,950 2009-05-22
Opera Browser HIGH 7.5
CVE-2005-3750EPSS 6%

Opera before 8.51 on Linux and Unix systems allows remote attackers to execute arbitrary code via shell metacharacters (backticks) in a URL that anot…

Fix: 8.51+
Fix from $1,950 2005-11-22
Opera Browser HIGH 7.5
CVE-2004-1157

Opera 7.x up to 7.54, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a t…

Fix: after 7.54
Fix from $1,950 2005-01-10
Opera Browser MEDIUM 5.0
CVE-2004-2570

Opera before 7.54 allows remote attackers to modify properties and methods of the location object and execute Javascript to read arbitrary files from…

Fix: 7.54+
Fix from $1,600 2004-12-31