Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Visio Viewer HIGH 9.3
CVE-2012-0020EPSS 20%

Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2012-02-14
Visio Viewer HIGH 9.3
CVE-2012-0136EPSS 20%

Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2012-02-14
Visio Viewer HIGH 9.3
CVE-2012-0137EPSS 20%

Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2012-02-14
Visio Viewer HIGH 9.3
CVE-2012-0138EPSS 20%

Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2012-02-14
Realplayer HIGH 9.3
CVE-2012-0928

The ATRAC codec in RealNetworks RealPlayer 11.x and 14.x through 14.0.7, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer 12.x before 12.0.0.1703 …

Mitigation only
Fix from $1,950 2012-02-08
Realplayer HIGH 9.3
CVE-2012-0922

rvrender.dll in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute…

Mitigation only
Fix from $1,950 2012-02-08
Realplayer HIGH 9.3
CVE-2012-0923

The RV20 codec in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, does not properly handle the fra…

Mitigation only
Fix from $1,950 2012-02-08
Realplayer HIGH 9.3
CVE-2012-0924

RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code …

Mitigation only
Fix from $1,950 2012-02-08
Realplayer HIGH 9.3
CVE-2012-0925

Unspecified vulnerability in the RV40 codec in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, all…

Mitigation only
Fix from $1,950 2012-02-08
Realplayer HIGH 9.3
CVE-2012-0926

The RV10 codec in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, does not properly handle height …

Mitigation only
Fix from $1,950 2012-02-08
Realplayer HIGH 9.3
CVE-2012-0927

Unspecified vulnerability in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attacke…

Mitigation only
Fix from $1,950 2012-02-08
Webaccess HIGH 10.0
CVE-2011-4041EPSS 18%

webvrpcs.exe in Advantech/BroadWin WebAccess allows remote attackers to execute arbitrary code or obtain a security-code value via a long string in a…

Mitigation only
Fix from $1,950 2012-02-06
Wincc Flexible MEDIUM 5.0
CVE-2011-4512

CRLF injection vulnerability in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before…

Mitigation only
Fix from $1,600 2012-02-03
Data Protector Media Operations HIGH 10.0
CVE-2011-4791EPSS 9%

DBServer.exe in HP Data Protector Media Operations 6.11 and earlier allows remote attackers to execute arbitrary code via a crafted request containin…

Fix: after 6.11
Fix from $1,950 2012-02-03
Support Incident Tracker HIGH 7.5
CVE-2011-4337

Static code injection vulnerability in translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to inject arbit…

No fix yet
Fix from $1,950 2012-01-29
Support Incident Tracker MEDIUM 6.5
CVE-2011-3832

Eval injection vulnerability in config.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated administrators to execute arbitrar…

No fix yet
Fix from $1,600 2012-01-29
Theme Tuner Plugin HIGH 7.5
CVE-2012-0934EPSS 8%

PHP remote file inclusion vulnerability in ajax/savetag.php in the Theme Tuner plugin for WordPress before 0.8 allows remote attackers to execute arb…

Fix: after 0.7
Fix from $1,950 2012-01-29
Digital Media Manager HIGH 9.0
CVE-2012-0329

Cisco Digital Media Manager 5.2.2 and earlier, and 5.2.3, allows remote authenticated users to execute arbitrary code via vectors involving a URL and…

Fix: after 5.2.2
Fix from $1,950 2012-01-19
Whmcompletesolution HIGH 7.5
CVE-2011-5061

functions.php in WHMCompleteSolution (WHMCS) 4.0.x through 5.0.x allows remote attackers to trigger arbitrary code execution in the Smarty templating…

Patch available
Fix from $1,950 2012-01-14
Whmcompletesolution MEDIUM 5.0
CVE-2012-0693

submitticket.php in WHMCompleteSolution (WHMCS) 5.03 allows remote attackers to inject arbitrary code into a subject field via crafted ticket data, a…

Mitigation only
Fix from $1,600 2012-01-14
Cascade Datahub MEDIUM 5.8
CVE-2012-0310

CRLF injection vulnerability in Cogent DataHub 7.1.2 and earlier, Cascade DataHub 6.4.20 and earlier, and OPC DataHub 6.4.20 and earlier allows remot…

Fix: after 7.1.2
Fix from $1,600 2012-01-13
Easy Printer Care Software HIGH 9.3
CVE-2011-4787

A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to download an arbitrary progra…

Fix: after 2.5
Fix from $1,950 2012-01-12
Easy Printer Care Software HIGH 9.3
CVE-2011-4786EPSS 41%

A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to download an arbitrary progra…

Fix: after 2.5
Fix from $1,950 2012-01-12
Struts CRITICAL 9.8
CVE-2012-0391 KEVEPSS 76%

The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling fo…

Fix: 2.2.3.1+
Fix from $2,300 2012-01-08
Struts MEDIUM 6.8
CVE-2012-0394EPSS 75%

The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary command…

Fix: after 2.3.17
Fix from $1,600 2012-01-08
Phpids HIGH 7.5
CVE-2011-5021

PHPIDS before 0.7 does not properly implement Regular Expression Denial of Service (ReDoS) filters, which allows remote attackers to bypass rulesets …

Fix: after 0.6.5
Fix from $1,950 2011-12-29
Rpm HIGH 9.3
CVE-2011-3378EPSS 6%

RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbit…

Fix: after 4.9.1.1
Fix from $1,950 2011-12-24
Bb Flashback HIGH 9.3
CVE-2011-1388

The Blueberry FlashBack ActiveX control in BB FlashBack Recorder.dll in Blueberry BB FlashBack, as used in IBM Rational Rhapsody before 7.6.1 and oth…

Patch available
Fix from $1,950 2011-12-23
Bb Flashback HIGH 9.3
CVE-2011-1391

The Blueberry FlashBack ActiveX control in BB FlashBack Recorder.dll in Blueberry BB FlashBack, as used in IBM Rational Rhapsody before 7.6.1 and oth…

Patch available
Fix from $1,950 2011-12-23
Bb Flashback HIGH 9.3
CVE-2011-1392

The Blueberry FlashBack ActiveX control in BB FlashBack Recorder.dll in Blueberry BB FlashBack, as used in IBM Rational Rhapsody before 7.6.1 and oth…

Patch available
Fix from $1,950 2011-12-23