Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Chrome HIGH 7.5
CVE-2013-0912

WebKit in Google Chrome before 25.0.1364.160 allows remote attackers to execute arbitrary code via vectors that leverage "type confusion."

Mitigation only
Fix from $1,950 2013-03-11
Acrobat Reader HIGH 7.5
CVE-2013-2549EPSS 6%

Unspecified vulnerability in Adobe Reader 11.0.02 allows remote attackers to execute arbitrary code via vectors related to a "break into the sandbox,…

Mitigation only
Fix from $1,950 2013-03-11
Stunnel MEDIUM 6.6
CVE-2013-1762

stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, whic…

Fix: after 4.54
Fix from $1,600 2013-03-08
Cognos Business Intelligence MEDIUM 5.0
CVE-2012-4840

IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote attackers to conduct XP…

Mitigation only
Fix from $1,600 2013-03-05
Codesys Gateway Server HIGH 10.0
CVE-2012-4707

3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors that trigger an out-of-bounds memory access.

Fix: after 2.3.9.19
Fix from $1,950 2013-02-24
Enterprise Buildings Integrator MEDIUM 6.8
CVE-2013-0108EPSS 27%

An ActiveX control in HscRemoteDeploy.dll in Honeywell Enterprise Buildings Integrator (EBI) R310, R400.2, R410.1, and R410.2; SymmetrE R310, R410.1,…

Mitigation only
Fix from $1,600 2013-02-24
Groupwise HIGH 9.3
CVE-2012-0439EPSS 39%

An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute ar…

Mitigation only
Fix from $1,950 2013-02-24
Opera Browser HIGH 9.3
CVE-2013-1637

Opera before 12.13 allows remote attackers to execute arbitrary code via vectors involving DOM events.

Fix: after 12.12
Fix from $1,950 2013-02-08
Opera Browser HIGH 9.3
CVE-2013-1638EPSS 8%

Opera before 12.13 allows remote attackers to execute arbitrary code via crafted clipPaths in an SVG document.

Fix: after 12.12
Fix from $1,950 2013-02-08
Firefox HIGH 9.3
CVE-2013-0758EPSS 73%

Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 a…

Fix: 2.15 / 10.0.12+
Fix from $1,950 2013-01-13
Firefox HIGH 9.3
CVE-2013-0745

The AutoWrapperChanger class in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 1…

Fix: 2.15 / 17.0.2+
Fix from $1,950 2013-01-13
Acrobat HIGH 10.0
CVE-2013-0614EPSS 6%

Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code via unspecified vecto…

Mitigation only
Fix from $1,950 2013-01-10
Acrobat HIGH 10.0
CVE-2013-0618EPSS 6%

Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code via unspecified vecto…

Mitigation only
Fix from $1,950 2013-01-10
Acrobat HIGH 10.0
CVE-2013-0607EPSS 6%

Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code via unspecified vecto…

Mitigation only
Fix from $1,950 2013-01-10
Acrobat HIGH 10.0
CVE-2013-0608EPSS 6%

Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code via unspecified vecto…

Mitigation only
Fix from $1,950 2013-01-10
Xml Core Services HIGH 9.3
CVE-2013-0007EPSS 32%

Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary cod…

Mitigation only
Fix from $1,950 2013-01-09
Perl HIGH 7.5
CVE-2012-6329EPSS 62%

The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly handle backslashes and fully qual…

Fix: after 5.16.2
Fix from $1,950 2013-01-04
Opera Browser HIGH 9.3
CVE-2012-6465

Opera before 12.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed SVG image.

Fix: after 12.10
Fix from $1,950 2013-01-02
Privileged User Manager HIGH 10.0
CVE-2012-5932EPSS 63%

Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 allo…

Mitigation only
Fix from $1,950 2012-12-24
Realplayer HIGH 9.3
CVE-2012-5690

RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allow remote attackers to execute arbitrary code via a RealAudio file t…

Fix: after 16.0.0
Fix from $1,950 2012-12-19
Chrome HIGH 10.0
CVE-2012-5142

Google Chrome before 23.0.1271.97 does not properly handle history navigation, which allows remote attackers to execute arbitrary code or cause a den…

Fix: after 23.0.1271.96
Fix from $1,950 2012-12-12
Windows 2003 Server HIGH 9.3
CVE-2012-2556EPSS 21%

The OpenType Font (OTF) driver in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Se…

Mitigation only
Fix from $1,950 2012-12-12
Xcom Data Transport HIGH 10.0
CVE-2012-5973

CA XCOM Data Transport r11.0 and r11.5 on UNIX and Linux allows remote attackers to execute arbitrary commands via a crafted request.

Mitigation only
Fix from $1,950 2012-12-10
Simplenews Scheduler MEDIUM 6.0
CVE-2012-5537

The Simplenews Scheduler module 6.x-2.x before 6.x-2.4 for Drupal allows remote authenticated users with the "send scheduled newsletters" permission …

Patch available
Fix from $1,600 2012-12-03
Php Enter HIGH 10.0
CVE-2012-6046

Static code injection vulnerability in admin/banners.php in PHP Enter allows remote attackers to inject arbitrary PHP code into horad.php via the cod…

Mitigation only
Fix from $1,950 2012-11-27
Firefox HIGH 7.5
CVE-2012-5836

Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allow remote attackers to execute arbitrary code or cause a denial of…

Fix: 2.14 / 17.0+
Fix from $1,950 2012-11-21
Firefox MEDIUM 6.8
CVE-2012-5837

The Web Developer Toolbar in Mozilla Firefox before 17.0 executes script with chrome privileges, which allows user-assisted remote attackers to condu…

Fix: after 16.0.2
Fix from $1,600 2012-11-21
Empirecms MEDIUM 6.8
CVE-2012-5777

Eval injection vulnerability in the ReplaceListVars function in the template parser in e/class/connect.php in EmpireCMS 6.6 allows user-assisted remo…

No fix yet
Fix from $1,600 2012-11-16
Rt MEDIUM 5.0
CVE-2012-4884

Argument injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to create arbitrary files…

Mitigation only
Fix from $1,600 2012-11-11
Unclassified HIGH 7.5
CVE-2012-2971

The server in CA ARCserve Backup r12.5, r15, and r16 on Windows does not properly process RPC requests, which allows remote attackers to execute arbi…

No fix yet
Fix from $1,950 2012-10-20