Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Show And Share MEDIUM 6.5
CVE-2011-2585

Cisco Show and Share 5(2), 5.2(1), and 5.2(2) before 5.2(2.1) allows remote authenticated users to upload and execute arbitrary code by leveraging vi…

Fix: after 5.2
Fix from $1,600 2011-10-20
Ciscoworks Common Services HIGH 9.0
CVE-2011-3310EPSS 15%

The Home Page component in Cisco CiscoWorks Common Services before 4.1 on Windows, as used in CiscoWorks LAN Management Solution, Cisco Security Mana…

Fix: after 4.0.1
Fix from $1,950 2011-10-20
Dcs 2121 Firmware HIGH 9.0
CVE-2010-4964

recorder_test.cgi on the D-Link DCS-2121 camera with firmware 1.04 allows remote attackers to execute arbitrary commands via shell metacharacters in …

No fix yet
Fix from $1,950 2011-10-16
Iphone Os MEDIUM 6.8
CVE-2011-3260

Buffer overflow in OfficeImport in Apple iOS before 5 allows remote attackers to execute arbitrary code or cause a denial of service (application cra…

Mitigation only
Fix from $1,600 2011-10-14
Iphone Os MEDIUM 6.8
CVE-2011-3261

Double free vulnerability in OfficeImport in Apple iOS before 5 allows remote attackers to execute arbitrary code or cause a denial of service (appli…

Mitigation only
Fix from $1,600 2011-10-14
Mac Os X MEDIUM 6.8
CVE-2011-3228

QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and appli…

Fix: after 10.7.1
Fix from $1,600 2011-10-14
Safari MEDIUM 6.8
CVE-2011-3229

Directory traversal vulnerability in Apple Safari before 5.1.1 allows remote attackers to execute arbitrary JavaScript code, in a Safari Extensions c…

Fix: after 5.1
Fix from $1,600 2011-10-14
Safari MEDIUM 6.8
CVE-2011-3231

The SSL implementation in Apple Safari before 5.1.1 on Mac OS X before 10.7 accesses uninitialized memory during the processing of X.509 certificates…

Fix: after 5.1
Fix from $1,600 2011-10-14
Mac Os X MEDIUM 6.8
CVE-2011-3221

QuickTime in Apple Mac OS X before 10.7.2 does not properly handle the atom hierarchy in movie files, which allows remote attackers to execute arbitr…

Fix: after 10.7.1
Fix from $1,600 2011-10-14
Mac Os X MEDIUM 6.8
CVE-2011-0224

CoreMedia in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a c…

Fix: after 10.6.8
Fix from $1,600 2011-10-14
Forefront Unified Access Gateway HIGH 9.3
CVE-2011-1969EPSS 17%

Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 provides the MicrosoftClient.jar file containing a signed Jav…

Mitigation only
Fix from $1,950 2011-10-12
Saurus Cms HIGH 7.5
CVE-2010-4943

Multiple PHP remote file inclusion vulnerabilities in Saurus CMS 4.7.0 allow remote attackers to execute arbitrary PHP code via a URL in the class_pa…

No fix yet
Fix from $1,950 2011-10-09
Php Free Photo Gallery HIGH 7.5
CVE-2010-4948

PHP remote file inclusion vulnerability in libs/adodb/adodb.inc.php in PHP Free Photo Gallery script allows remote attackers to execute arbitrary PHP…

No fix yet
Fix from $1,950 2011-10-09
Mailform HIGH 7.5
CVE-2010-4939

PHP remote file inclusion vulnerability in index.php in MailForm 1.2 allows remote attackers to execute arbitrary PHP code via a URL in the theme par…

No fix yet
Fix from $1,950 2011-10-09
Clearbudget HIGH 7.5
CVE-2010-4924

PHP remote file inclusion vulnerability in logic/controller.class.php in clearBudget 0.9.8 allows remote attackers to execute arbitrary PHP code via …

No fix yet
Fix from $1,950 2011-10-09
Php Classifieds HIGH 7.5
CVE-2010-4914

PHP remote file inclusion vulnerability in tools/phpmailer/class.phpmailer.php in PHP Classifieds 7.3 allows remote attackers to execute arbitrary PH…

No fix yet
Fix from $1,950 2011-10-08
Com Magazine HIGH 7.5
CVE-2010-4918

PHP remote file inclusion vulnerability in iJoomla Magazine (com_magazine) component 3.0.1 for Joomla! allows remote attackers to execute arbitrary P…

No fix yet
Fix from $1,950 2011-10-08
Dompdf HIGH 7.5
CVE-2010-4879EPSS 5%

PHP remote file inclusion vulnerability in dompdf.php in dompdf 0.6.0 beta1 allows remote attackers to execute arbitrary PHP code via a URL in the in…

No fix yet
Fix from $1,950 2011-10-07
Gaestebuch HIGH 7.5
CVE-2010-4884EPSS 6%

PHP remote file inclusion vulnerability in guestbook/gbook.php in Gaestebuch 1.2 allows remote attackers to execute arbitrary PHP code via a URL in t…

No fix yet
Fix from $1,950 2011-10-07
Kontakt Formular HIGH 7.5
CVE-2010-4878

PHP remote file inclusion vulnerability in formmailer.php in Kontakt Formular 1.1 allows remote attackers to execute arbitrary PHP code via a URL in …

No fix yet
Fix from $1,950 2011-10-07
Allwebmenus Plugin HIGH 7.5
CVE-2011-3981EPSS 10%

PHP remote file inclusion vulnerability in actions.php in the Allwebmenus plugin 1.1.3 for WordPress allows remote attackers to execute arbitrary PHP…

Patch available
Fix from $1,950 2011-10-04
Im Manager HIGH 7.5
CVE-2011-0554

The management console in Symantec IM Manager before 8.4.18 allows remote attackers to execute arbitrary code via unspecified vectors, related to a "…

Fix: after 8.4.17
Fix from $1,950 2011-10-02
Ffmpeg HIGH 9.3
CVE-2011-3504EPSS 6%

The Matroska format decoder in FFmpeg before 0.8.3 does not properly allocate memory, which allows remote attackers to execute arbitrary code via a c…

Fix: after 0.8.0
Fix from $1,950 2011-09-29
Firefox HIGH 9.3
CVE-2011-3232EPSS 5%

YARR, as used in Mozilla Firefox before 7.0, Thunderbird before 7.0, and SeaMonkey before 2.4, allows remote attackers to cause a denial of service (…

Fix: after 6.0.2
Fix from $1,950 2011-09-29
Palm Pre Webos HIGH 7.1
CVE-2009-5097

Palm Pre WebOS 1.1 and earlier processes JavaScript in email messages, which allows remote attackers to execute arbitrary JavaScript, as demonstrated…

Fix: after 1.1.0
Fix from $1,950 2011-09-13
Gbook MEDIUM 6.8
CVE-2009-5095

PHP remote file inclusion vulnerability in index_inc.php in ea gBook 0.1 and 0.1.4 allows remote attackers to execute arbitrary PHP code via a URL in…

No fix yet
Fix from $1,600 2011-09-12
Firefox HIGH 10.0
CVE-2011-0084

The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5; Thunderbird 3.x before 3.1.12 and other version…

Fix: after 3.6.19
Fix from $1,950 2011-08-18
Firefox HIGH 10.0
CVE-2011-2378EPSS 6%

The appendChild function in Mozilla Firefox before 3.6.20, Thunderbird 3.x before 3.1.12, SeaMonkey 2.x, and possibly other products does not properl…

Fix: after 3.6.19
Fix from $1,950 2011-08-18
Firefox HIGH 10.0
CVE-2011-2984

Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly handle the dropping of a t…

Fix: after 3.6.19
Fix from $1,950 2011-08-18
Easy Printer Care Software HIGH 7.5
CVE-2011-2404EPSS 74%

A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to download an arbitrary progra…

Fix: after 2.5
Fix from $1,950 2011-08-11