Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Opera Browser MEDIUM 6.8
CVE-2012-4143

Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, allows user-assisted remote attackers to trick users into…

Fix: after 12.00
Fix from $1,600 2012-08-06
Arcmap HIGH 9.3
CVE-2012-1661EPSS 24%

ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assisted remo…

Fix: after 10.0.2.3200
Fix from $1,950 2012-07-12
Glpi MEDIUM 6.5
CVE-2012-1037

PHP remote file inclusion vulnerability in front/popup.php in GLPI 0.78 through 0.80.61 allows remote authenticated users to execute arbitrary PHP co…

Mitigation only
Fix from $1,600 2012-07-12
Telepresence Multipoint Switch Software HIGH 8.3
CVE-2012-2486

The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1.9.0, Cisco TelePresence Immersive Endpoint Devices…

Fix: after 1.9.0.1
Fix from $1,950 2012-07-12
Windows 2003 Server HIGH 8.8
CVE-2012-0175EPSS 26%

The Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gol…

Mitigation only
Fix from $1,950 2012-07-10
Lotus Notes HIGH 9.3
CVE-2012-2174EPSS 38%

The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a crafted notes:// URL.

Mitigation only
Fix from $1,950 2012-06-20
Workstation HIGH 7.8
CVE-2012-3289

VMware Workstation 8.x before 8.0.4, VMware Player 4.x before 4.0.4, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 allow remote attacke…

Mitigation only
Fix from $1,950 2012-06-14
.net Framework HIGH 9.3
CVE-2012-1855EPSS 20%

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly handle function pointers, which allows remote attackers to execute arbitra…

Mitigation only
Fix from $1,950 2012-06-12
Wincc MEDIUM 5.5
CVE-2012-2596

The XPath functionality in unspecified web applications in Siemens WinCC 7.0 SP3 before Update 2 does not properly handle special characters in param…

Mitigation only
Fix from $1,600 2012-06-08
Rt MEDIUM 6.8
CVE-2011-4458

Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabled, allow…

Patch available
Fix from $1,600 2012-06-04
Endpoint Protection HIGH 9.3
CVE-2012-0295

The Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to conduct file-…

Mitigation only
Fix from $1,950 2012-05-23
Elearning Server HIGH 7.5
CVE-2012-2924

PHP remote file inclusion vulnerability in admin/setup.inc.php in Hypermethod eLearning Server 4G allows remote attackers to execute arbitrary PHP co…

No fix yet
Fix from $1,950 2012-05-21
Adaptive Security Appliance Software MEDIUM 5.0
CVE-2011-3285

CRLF injection vulnerability in /+CSCOE+/logon.html on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 through 8.4 all…

Mitigation only
Fix from $1,600 2012-05-02
Sketchup HIGH 9.3
CVE-2011-2478

Google SketchUp before 8 does not properly handle edge geometry in SketchUp (aka .SKP) files, which allows remote attackers to execute arbitrary code…

Fix: after 7.1
Fix from $1,950 2012-04-17
Webmi2ads MEDIUM 5.0
CVE-2011-4882

The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 allows remote attackers to cause a denial of service (application exit) via an uns…

Fix: after 2.0.1
Fix from $1,600 2012-04-13
Thunder HIGH 7.5
CVE-2012-2224

Xunlei Thunder before 7.2.6 allows remote attackers to execute arbitrary code via a crafted file, related to a "DLL injection vulnerability."

Mitigation only
Fix from $1,950 2012-04-11
Office HIGH 8.8
CVE-2012-0158 KEVEPSS 100%

The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3…

Patch available
Fix from $1,950 2012-04-10
Opera Browser MEDIUM 6.8
CVE-2012-1924

Opera before 11.62 allows user-assisted remote attackers to trick users into downloading and executing arbitrary files via a small window for the dow…

Fix: after 11.61
Fix from $1,600 2012-03-28
Atmail Open MEDIUM 6.4
CVE-2012-1919

CRLF injection vulnerability in mime.php in @Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to conduct directory trave…

Fix: after 1.04
Fix from $1,600 2012-03-27
Movable Type Open Source MEDIUM 6.5
CVE-2012-0319

The file-management system in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote authenticated users to execute arbitrary…

Fix: after 4.37
Fix from $1,600 2012-03-03
Groupwise HIGH 7.5
CVE-2011-4189EPSS 12%

The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corru…

No fix yet
Fix from $1,950 2012-03-02
Small Business Srp520 Series Firmware HIGH 9.0
CVE-2012-0363

The web interface on Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allows…

Fix: after 1.01.24
Fix from $1,950 2012-02-25
Relocate Upload HIGH 7.5
CVE-2012-1205EPSS 25%

PHP remote file inclusion vulnerability in relocate-upload.php in Relocate Upload plugin before 0.20 for WordPress allows remote attackers to execute…

Fix: after 0.14
Fix from $1,950 2012-02-24
Zenphoto MEDIUM 6.8
CVE-2012-0993

Eval injection vulnerability in zp-core/zp-extensions/viewer_size_image.php in ZENphoto 1.4.2, when the viewer_size_image plugin is enabled, allows r…

Patch available
Fix from $1,600 2012-02-21
TYPO3 MEDIUM 6.8
CVE-2011-4614EPSS 6%

PHP remote file inclusion vulnerability in Classes/Controller/AbstractController.php in the workspaces system extension in TYPO3 4.5.x before 4.5.9, …

Patch available
Fix from $1,600 2012-02-18
Basic Analysis And Security Engine HIGH 7.5
CVE-2012-1199

Multiple PHP remote file inclusion vulnerabilities in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbitrary PHP…

No fix yet
Fix from $1,950 2012-02-18
Nova Cms HIGH 7.5
CVE-2012-1200

Multiple PHP remote file inclusion vulnerabilities in Nova CMS allow remote attackers to execute arbitrary PHP code via a URL in the (1) fileType par…

No fix yet
Fix from $1,950 2012-02-18
.net Framework HIGH 7.8
CVE-2012-0014EPSS 28%

Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unman…

Mitigation only
Fix from $1,950 2012-02-14
.net Framework HIGH 9.3
CVE-2012-0015EPSS 24%

Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly calculate the length of an unspecified buffer, which allows remote attackers to execute …

Mitigation only
Fix from $1,950 2012-02-14
Visio Viewer HIGH 9.3
CVE-2012-0019EPSS 20%

Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2012-02-14