Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Chrome HIGH 10.0
CVE-2014-3177

Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google V8, which allows remote attac…

Fix: after 37.0.2062.93
Fix from $1,950 2014-08-27
Cacti HIGH 7.5
CVE-2014-5261EPSS 11%

The graph settings script (graph_settings.php) in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary commands via shell metacharac…

Fix: after 0.8.8b
Fix from $1,950 2014-08-22
Websphere Application Server MEDIUM 6.5
CVE-2014-4767

IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.3 does not properly use the Liberty Repository for feature installation, wh…

Mitigation only
Fix from $1,600 2014-08-22
Open Source Security Information Management HIGH 10.0
CVE-2014-5158

The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to exe…

Fix: after 4.5
Fix from $1,950 2014-08-21
Open Source Security Information Management HIGH 10.0
CVE-2014-5210EPSS 15%

The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (…

Fix: after 4.6.1
Fix from $1,950 2014-08-21
Sphider MEDIUM 6.5
CVE-2014-5194

Static code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbitrary PHP code into settings/…

No fix yet
Fix from $1,600 2014-08-07
Splunk HIGH 9.0
CVE-2013-7394

The "runshellscript echo.sh" script in Splunk before 5.0.5 allows remote authenticated users to execute arbitrary commands via a crafted string. NOT…

Fix: after 5.0.4
Fix from $1,950 2014-08-07
Opensuse MEDIUM 6.8
CVE-2014-3429

IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary c…

Patch available
Fix from $1,600 2014-08-07
Reportbug MEDIUM 6.8
CVE-2014-0479

reportbug before 6.4.4+deb7u1 and 6.5.x before 6.5.0+nmu1 allows remote attackers to execute arbitrary commands via vectors related to compare_versio…

Fix: after 6.5.0
Fix from $1,600 2014-08-06
Ubuntu Linux HIGH 7.9
CVE-2014-3560EPSS 56%

NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code via unspec…

Mitigation only
Fix from $1,950 2014-08-06
Status2k MEDIUM 6.5
CVE-2014-5090

admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the Location …

No fix yet
Fix from $1,600 2014-08-06
Moodle MEDIUM 6.0
CVE-2014-3545

Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote authenticated users to execu…

Patch available
Fix from $1,600 2014-07-29
Moodle HIGH 7.5
CVE-2014-3541

The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remot…

Patch available
Fix from $1,950 2014-07-29
Trixbox HIGH 7.5
CVE-2014-5112EPSS 9%

maint/modules/home/index.php in Fonality trixbox allows remote attackers to execute arbitrary commands via shell metacharacters in the lang parameter.

No fix yet
Fix from $1,950 2014-07-28
Firefox HIGH 9.3
CVE-2014-1556

Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to execute arbitrary code via crafted W…

Fix: after 30.0
Fix from $1,950 2014-07-23
Firefox HIGH 9.3
CVE-2014-1557

The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, does no…

Fix: after 30.0
Fix from $1,950 2014-07-23
Jboss Enterprise Application Platform MEDIUM 6.8
CVE-2014-3518

jmx-remoting.sar in JBoss Remoting, as used in Red Hat JBoss Enterprise Application Platform (JEAP) 5.2.0, Red Hat JBoss BRMS 5.3.1, Red Hat JBoss Po…

Mitigation only
Fix from $1,600 2014-07-22
Fuelphp HIGH 7.5
CVE-2014-1999

The auto-format feature in the Request_Curl class in FuelPHP 1.1 through 1.7.1 allows remote attackers to execute arbitrary code via a crafted respon…

Mitigation only
Fix from $1,950 2014-07-20
Timthumb MEDIUM 6.8
CVE-2014-4663EPSS 10%

TimThumb 2.8.13 and WordThumb 1.07, when Webshot (aka Webshots) is enabled, allows remote attackers to execute arbitrary commands via shell metachara…

No fix yet
Fix from $1,600 2014-07-15
Windows 7 HIGH 9.3
CVE-2014-1824EPSS 19%

Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold a…

Patch available
Fix from $1,950 2014-07-08
Jboss Enterprise Application Platform MEDIUM 6.8
CVE-2014-0248

org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Ente…

Mitigation only
Fix from $1,600 2014-07-07
Security Manager HIGH 7.5
CVE-2014-0602

Directory traversal vulnerability in the DumpToFile method in the NQMcsVarSet ActiveX control in NetIQ Security Manager through 6.5.4 allows remote a…

Fix: after 6.5.4
Fix from $1,950 2014-07-07
Yiiframework HIGH 7.5
CVE-2014-4672

The CDetailView widget in Yii PHP Framework 1.1.14 allows remote attackers to execute arbitrary PHP scripts via vectors related to the value property.

Mitigation only
Fix from $1,950 2014-07-03
Marketing Platform MEDIUM 6.0
CVE-2013-6309

IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to hijack sessions, and consequently read records, modify records, or conduct…

Mitigation only
Fix from $1,600 2014-06-28
Openpages Grc Platform MEDIUM 5.0
CVE-2014-3011

IBM OpenPages GRC Platform 6.1.0.1 before IF4 allows remote attackers to conduct link injection attacks via unspecified vectors.

No fix yet
Fix from $1,600 2014-06-27
Openshift HIGH 10.0
CVE-2014-3496EPSS 5%

cartridge_repository.rb in OpenShift Origin and Enterprise 1.2.8 through 2.1.1 allows remote attackers to execute arbitrary commands via shell metach…

Patch available
Fix from $1,950 2014-06-20
Open Source Security Information Management HIGH 10.0
CVE-2014-4151EPSS 7%

The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitrary code via a craft…

Fix: after 4.7.0
Fix from $1,950 2014-06-18
Open Source Security Information Management HIGH 10.0
CVE-2014-4152EPSS 6%

The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task request, rel…

Fix: after 4.7.0
Fix from $1,950 2014-06-18
Open Source Security Information Management HIGH 10.0
CVE-2014-3804EPSS 72%

The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) update_system_in…

Fix: after 4.6.1
Fix from $1,950 2014-06-13
Open Source Security Information Management HIGH 10.0
CVE-2014-3805EPSS 13%

The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_license, (2)…

Fix: after 4.6.1
Fix from $1,950 2014-06-13