Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Moodle MEDIUM 5.0
CVE-2011-4203

CRLF injection vulnerability in calendar/set.php in the Calendar component in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, 2.1.x before 2.1.3, and…

No fix yet
Fix from $1,600 2011-12-22
Pmwiki HIGH 7.5
CVE-2011-4453EPSS 52%

The PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitrary code via PHP sequences in …

Patch available
Fix from $1,950 2011-12-22
Ajax File And Image Manager HIGH 7.5
CVE-2011-4825EPSS 39%

Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6…

Fix: after 1.4.1
Fix from $1,950 2011-12-15
V Cms HIGH 7.5
CVE-2011-4828EPSS 65%

Unrestricted file upload vulnerability in includes/inline_image_upload.php in AutoSec Tools V-CMS 1.0 allows remote attackers to execute arbitrary co…

No fix yet
Fix from $1,950 2011-12-15
Publisher HIGH 9.3
CVE-2011-1508EPSS 14%

Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, does not properly manage memory allocations for function pointers, which allows user-assisted rem…

Mitigation only
Fix from $1,950 2011-12-14
Excel HIGH 9.3
CVE-2011-3403EPSS 21%

Microsoft Excel 2003 SP3 and Office 2004 for Mac do not properly handle objects in memory, which allows remote attackers to execute arbitrary code vi…

Mitigation only
Fix from $1,950 2011-12-14
Publisher HIGH 9.3
CVE-2011-3411EPSS 27%

Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect handling of valu…

Mitigation only
Fix from $1,950 2011-12-14
Publisher HIGH 9.3
CVE-2011-3412EPSS 26%

Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages inc…

Mitigation only
Fix from $1,950 2011-12-14
Office HIGH 9.3
CVE-2011-3413EPSS 20%

Microsoft PowerPoint 2007 SP2; Office 2008 for Mac; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; and PowerPoint V…

Mitigation only
Fix from $1,950 2011-12-14
Restorepoint HIGH 9.3
CVE-2011-4201

remote_support.cgi in the Tadasoft Restorepoint 3.2 evaluation image allows remote attackers to execute arbitrary commands via shell metacharacters i…

Mitigation only
Fix from $1,950 2011-12-13
Prestashop MEDIUM 5.0
CVE-2011-4545

CRLF injection vulnerability in admin/displayImage.php in Prestashop 1.4.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTT…

No fix yet
Fix from $1,600 2011-12-02
Tivoli Netcool\/reporter HIGH 7.5
CVE-2011-4668

IBM Tivoli Netcool/Reporter 2.2 before 2.2.0.8 allows remote attackers to execute arbitrary code via vectors related to an unspecified CGI program us…

Mitigation only
Fix from $1,950 2011-12-02
Wp Postratings MEDIUM 6.0
CVE-2011-4646

SQL injection vulnerability in wp-postratings.php in the WP-PostRatings plugin 1.50, 1.61, and probably other versions before 1.62 for WordPress allo…

Patch available
Fix from $1,600 2011-11-30
Dvr Remote Activex Control HIGH 9.3
CVE-2011-3828

DVRemoteAx.ax 2.1.0.39 in the DVR Remote ActiveX control allows remote attackers to execute arbitrary code via a crafted DVRobot.dll file in a manife…

Mitigation only
Fix from $1,950 2011-11-26
Realplayer HIGH 10.0
CVE-2011-4256

The RV30 codec in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 does not initialize an unspecified index value, which a…

Fix: after 14.0.7
Fix from $1,950 2011-11-24
Realplayer HIGH 9.3
CVE-2011-4257

The Cook codec in RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via crafted channel data.

Fix: after 14.0.7
Fix from $1,950 2011-11-24
Realplayer HIGH 9.3
CVE-2011-4258

RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted length of an MLTI chunk in an IVR file.

Fix: after 14.0.7
Fix from $1,950 2011-11-24
Realplayer HIGH 9.3
CVE-2011-4260

RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a malformed header in an MP4 file.

Fix: after 14.0.7
Fix from $1,950 2011-11-24
Realplayer HIGH 9.3
CVE-2011-4247

RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted QCELP stream.

Fix: after 14.0.7
Fix from $1,950 2011-11-24
Realplayer HIGH 9.3
CVE-2011-4248

RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a malformed AAC file.

Fix: after 14.0.7
Fix from $1,950 2011-11-24
Realplayer HIGH 9.3
CVE-2011-4251

RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted sample size in a RealAudio file.

Fix: after 14.0.7
Fix from $1,950 2011-11-24
Realplayer HIGH 9.3
CVE-2011-4252

The RV10 codec in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code via a…

Fix: after 14.0.7
Fix from $1,950 2011-11-24
Realplayer HIGH 10.0
CVE-2011-4254

RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted RTSP SETUP request.

Fix: after 14.0.7
Fix from $1,950 2011-11-24
Kace K2000 Systems Deployment Appliance HIGH 9.3
CVE-2011-4047

The Dell KACE K2000 System Deployment Appliance allows remote attackers to execute arbitrary commands by leveraging database write access.

Mitigation only
Fix from $1,950 2011-11-12
Firefox HIGH 9.3
CVE-2011-3655

Mozilla Firefox 4.x through 7.0 and Thunderbird 5.0 through 7.0 perform access control without checking for use of the NoWaiverWrapper wrapper, which…

Mitigation only
Fix from $1,950 2011-11-09
Simple Contact Form HIGH 7.5
CVE-2010-5038

PHP remote file inclusion vulnerability in contact/contact.php in Groone's Simple Contact Form allows remote attackers to execute arbitrary PHP code …

No fix yet
Fix from $1,950 2011-11-02
Np Gallery Plugin MEDIUM 6.8
CVE-2010-5040

PHP remote file inclusion vulnerability in nucleus/plugins/NP_gallery.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execut…

No fix yet
Fix from $1,600 2011-11-02
Ardeacore Php Framework HIGH 7.5
CVE-2010-4998

PHP remote file inclusion vulnerability in ardeaCore/lib/core/ardeaInit.php in ardeaCore PHP Framework 2.2 allows remote attackers to execute arbitra…

No fix yet
Fix from $1,950 2011-11-02
Phpldapadmin HIGH 7.5
CVE-2011-4075EPSS 52%

The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby par…

Patch available
Fix from $1,950 2011-11-02
Family Connections Who Is Chatting HIGH 7.5
CVE-2010-4988

PHP remote file inclusion vulnerability in mod_chatting/themes/default/header.php in Family Connections Who is Chatting 2.2.3 allows remote attackers…

No fix yet
Fix from $1,950 2011-11-01