Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Networker Module For Microsoft Applications HIGH 9.3
CVE-2012-2290

The client in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375 allows remote attackers to …

Mitigation only
Fix from $1,950 2012-10-18
Word HIGH 9.3
CVE-2012-0182EPSS 68%

Microsoft Word 2007 SP2 and SP3 does not properly handle memory during the parsing of Word documents, which allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2012-10-09
Backwpup HIGH 7.5
CVE-2011-4342EPSS 11%

PHP remote file inclusion vulnerability in wp_xml_export.php in the BackWPup plugin before 1.7.2 for WordPress allows remote attackers to execute arb…

Fix: after 1.7.1
Fix from $1,950 2012-10-08
Webtitan MEDIUM 6.5
CVE-2011-4639

The (1) Traceroute and (2) Ping implementations in tools.php in SpamTitan WebTitan before 3.60 allow remote authenticated users to execute arbitrary …

Fix: after 3.50
Fix from $1,600 2012-10-08
Yvs Image Gallery HIGH 7.5
CVE-2012-5304

Static code injection vulnerability in administration/install.php in YVS Image Gallery allows remote attackers to inject arbitrary PHP code into func…

Mitigation only
Fix from $1,950 2012-10-06
Impresspages Cms HIGH 7.5
CVE-2011-4932

Eval injection vulnerability in ip_cms/modules/standard/content_management/actions.php in ImpressPages CMS 1.0.12 and possibly other versons before 1…

No fix yet
Fix from $1,950 2012-10-06
Sapid Cms HIGH 7.5
CVE-2012-5293

Multiple PHP remote file inclusion vulnerabilities in SAPID CMS 1.2.3 Stable allow remote attackers to execute arbitrary PHP code via a URL in the (1…

No fix yet
Fix from $1,950 2012-10-04
Vbadvanced Cmps HIGH 7.5
CVE-2012-5224

PHP remote file inclusion vulnerability in vb/includes/vba_cmps_include_bottom.php in vBadvanced CMPS 3.2.2 and earlier allows remote attackers to ex…

Fix: after 3.2.2
Fix from $1,950 2012-10-01
Minicms HIGH 7.5
CVE-2012-5231

miniCMS 1.0 and 2.0 allows remote attackers to execute arbitrary PHP code via a crafted (1) pagename or (2) area variable containing an executable ex…

No fix yet
Fix from $1,950 2012-10-01
Vbseo HIGH 7.5
CVE-2012-5223EPSS 41%

The proc_deutf function in includes/functions_vbseocp_abstract.php in vBSEO 3.5.0, 3.5.1, 3.5.2, 3.6.0, and earlier allows remote attackers to insert…

Fix: after 3.6.0
Fix from $1,950 2012-10-01
Gnome Shell MEDIUM 6.8
CVE-2012-4427

The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extensions from extensions.gnome.or…

No fix yet
Fix from $1,600 2012-10-01
Groupware HIGH 7.5
CVE-2012-0209EPSS 72%

Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, cont…

Patch available
Fix from $1,950 2012-09-25
phpMyAdmin HIGH 7.5
CVE-2012-5159EPSS 75%

phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an externally introduced modifica…

Mitigation only
Fix from $1,950 2012-09-25
Fillpdf MEDIUM 6.0
CVE-2012-1625

Eval injection vulnerability in the fillpdf_form_export_decode function in fillpdf.admin.inc in the Fill PDF module 6.x-1.x before 6.x-1.16 and 7.x-1…

Patch available
Fix from $1,600 2012-09-20
Freepbx HIGH 7.5
CVE-2012-4869EPSS 70%

The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attackers to execute arbitrary comma…

Fix: after 2.10
Fix from $1,950 2012-09-06
Winlicense HIGH 9.3
CVE-2012-4864EPSS 6%

Oreans WinLicense 2.1.8.0 allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via …

No fix yet
Fix from $1,950 2012-09-06
Freewebshop MEDIUM 5.0
CVE-2011-5147

Static code injection vulnerability in ajax_save_name.php in the Ajax File Manager module in the tinymce plugin in FreeWebshop 2.2.9 R2 and earlier a…

Fix: after 2.2.9
Fix from $1,600 2012-08-31
Cybozu Live MEDIUM 6.8
CVE-2012-4008

The Cybozu Live application 1.0.4 and earlier for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information…

Fix: after 1.0.4
Fix from $1,600 2012-08-31
Cybozu Live MEDIUM 6.8
CVE-2012-4009

The WebView class in the Cybozu Live application 1.0.4 and earlier for Android allows remote attackers to execute arbitrary JavaScript code, and obta…

Fix: after 1.0.4
Fix from $1,600 2012-08-31
Family Connections Cms MEDIUM 6.8
CVE-2011-5130EPSS 37%

dev/less.php in Family Connections CMS (FCMS) 2.5.0 - 2.7.1, when register_globals is enabled, allows remote attackers to execute arbitrary commands …

No fix yet
Fix from $1,600 2012-08-30
Firefox HIGH 9.3
CVE-2012-3980

The web console in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 allow…

Fix: after 14.0
Fix from $1,950 2012-08-29
Gajim MEDIUM 6.8
CVE-2012-2085

The exec_command function in common/helpers.py in Gajim before 0.15 allows user-assisted remote attackers to execute arbitrary commands via shell met…

Fix: after 0.14.4
Fix from $1,600 2012-08-28
Newscoop MEDIUM 6.8
CVE-2012-1933EPSS 6%

Multiple PHP remote file inclusion vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4 before RC4, when register_globals is enabled, allow remote at…

No fix yet
Fix from $1,600 2012-08-27
Silverstripe MEDIUM 6.0
CVE-2010-5091

The setName function in filesystem/File.php in SilverStripe 2.3.x before 2.3.8 and 2.4.x before 2.4.1 allows remote authenticated users with CMS auth…

Patch available
Fix from $1,600 2012-08-26
Personal Firewall 9 MEDIUM 5.3
CVE-2010-5164

Race condition in KingSoft Personal Firewall 9 Plus 2009.05.07.70 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute d…

Mitigation only
Fix from $1,600 2012-08-25
Premium Security Suite MEDIUM 5.3
CVE-2010-5153

Race condition in Avira Premium Security Suite 10.0.0.536 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous…

Mitigation only
Fix from $1,600 2012-08-25
Kies HIGH 9.3
CVE-2012-2990

The MASetupCaller ActiveX control before 1.4.2012.508 in MASetupCaller.dll in MarkAny ContentSAFER, as distributed in Samsung KIES before 2.3.2.12074…

Fix: after 2.3.2.12074
Fix from $1,950 2012-08-24
Enterprise Linux Desktop HIGH 7.8
CVE-2012-1535 KEVEPSS 70%

Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers …

Fix: 11.2.202.238 / 11.3.300.271+
Fix from $1,950 2012-08-15
Kindle Touch HIGH 10.0
CVE-2012-4249

The Amazon Lab126 com.lab126.system sendEvent implementation on the Kindle Touch before 5.1.2 allows context-dependent attackers to execute arbitrary…

Mitigation only
Fix from $1,950 2012-08-12
Sleipnir Mobile MEDIUM 6.8
CVE-2012-2649

The Sleipnir Mobile application 2.2.0 and earlier and Sleipnir Mobile Black Edition application 2.2.0 and earlier for Android allow remote attackers …

Fix: after 2.2.0
Fix from $1,600 2012-08-08