Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
MEDIUM 5.0 CVE-2015-5841 The CFNetwork Proxies component in Apple iOS before 9 does not properly handle a Set-Cookie header within a response to an HTTP CONNECT request, whic… Mac Os X after 10.10.5 Fix from $1,6002015-09-18 CRITICAL 9.8 CVE-2015-3253EPSS 41% The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause… Groovy Patch available Fix from $2,3002015-08-13 HIGH 7.1 CVE-2015-1762EPSS 10% Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014, when transactional replication is configured, does not preven… Sql Server Mitigation only Fix from $1,9502015-07-14 HIGH 7.5 CVE-2015-3205EPSS 11% libmimedir allows remote attackers to execute arbitrary code via a VCF file with two NULL bytes at the end of the file, related to "free" function ca… Libmimedir No fix yet Fix from $1,9502015-06-16 HIGH 7.5 CVE-2015-3200EPSS 10% mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon cha… Lighttpd after 15.07 Fix from $1,9502015-06-09 MEDIUM 5.0 CVE-2015-2704 realmd allows remote attackers to inject arbitrary configurations in to sssd.conf and smb.conf via a newline character in an LDAP response. Realmd after 15.2 Fix from $1,6002015-05-18 MEDIUM 6.0 CVE-2015-3013 ownCloud Server before 5.0.19, 6.x before 6.0.7, and 7.x before 7.0.5 allows remote authenticated users to bypass the file blacklist and upload arbit… Owncloud Server 5.0.19 / 6.0.7+ Fix from $1,6002015-05-08 HIGH 7.5 CVE-2015-1592EPSS 75% Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::thaw funct… Debian Linux 5.2.12 / 6.0.7+ Fix from $1,9502015-02-19 MEDIUM 6.8 CVE-2015-0931 Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1, when the Saxon XSLT parser is used, allows remote attackers to e… Ektron Content Management System Mitigation only Fix from $1,6002015-02-14 HIGH 7.5 CVE-2015-1169 Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote attackers to conduct LDAP injection attacks via a crafted username, as … Central Authentication Service after 3.5.2 Fix from $1,9502015-02-10 MEDIUM 5.0 CVE-2014-7287 The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger un… Encryption Management Server after 3.3.2 Fix from $1,6002015-02-01 HIGH 7.6 CVE-2013-6435EPSS 8% Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the con… Debian Linux after 4.11.1 Fix from $1,9502014-12-16 HIGH 10.0 CVE-2014-8423EPSS 62% Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute arbitrary commands via unknown … Vap2500 Firmware after 08.41 Fix from $1,9502014-11-28 CRITICAL 9.8 CVE-2013-2251 KEVEPSS 100% Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redi… Archiva 1.3.8+ Fix from $2,3002013-07-20 MEDIUM 6.4 CVE-2012-4196 Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before … Firefox 2.13.2 / 10.0.10+ Fix from $1,6002012-10-29 MEDIUM 6.8 CVE-2011-2855 Google Chrome before 14.0.835.163 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a den… Chrome 5.1 / 5.1.4+ Fix from $1,6002011-09-19 MEDIUM 6.8 CVE-2011-2805 Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy and conduct script injection attacks via unspecified vecto… Chrome 5.0 / 5.1.1+ Fix from $1,6002011-08-03 HIGH 7.5 CVE-2009-1781 Static code injection vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to inject arbitrary PHP code into p… Php Recommend after 1.3 Fix from $1,9502009-05-22 HIGH 7.5 CVE-2005-3750EPSS 6% Opera before 8.51 on Linux and Unix systems allows remote attackers to execute arbitrary code via shell metacharacters (backticks) in a URL that anot… Opera Browser 8.51+ Fix from $1,9502005-11-22 HIGH 7.5 CVE-2004-1157 Opera 7.x up to 7.54, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a t… Opera Browser after 7.54 Fix from $1,9502005-01-10 MEDIUM 5.0 CVE-2004-2570 Opera before 7.54 allows remote attackers to modify properties and methods of the location object and execute Javascript to read arbitrary files from… Opera Browser 7.54+ Fix from $1,6002004-12-31