Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Saas Endpoint Protection MEDIUM 6.8
CVE-2011-3007

The myCIOScn ActiveX control (myCIOScn.dll) in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to write to arbitrary files …

Fix: after 5.2.1
Fix from $1,600 2011-08-10
Foomatic MEDIUM 6.8
CVE-2011-2964

foomaticrip.c in foomatic-rip in foomatic-filters in Foomatic 4.0.6 allows remote attackers to execute arbitrary code via a crafted *FoomaticRIPComma…

Patch available
Fix from $1,600 2011-07-29
Picasa HIGH 9.3
CVE-2011-2747

Google Picasa before 3.6 Build 105.67 does not properly handle invalid properties in JPEG images, which allows remote attackers to execute arbitrary …

Fix: after 3.6_build_105.65
Fix from $1,950 2011-07-28
Squirrelmail MEDIUM 5.8
CVE-2011-2752

CRLF injection vulnerability in SquirrelMail 1.4.21 and earlier allows remote attackers to modify or add preference values via a \n (newline) charact…

Fix: after 1.4.21
Fix from $1,600 2011-07-17
phpMyAdmin MEDIUM 6.4
CVE-2011-2505EPSS 13%

libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns val…

Patch available
Fix from $1,600 2011-07-14
phpMyAdmin HIGH 7.5
CVE-2011-2506EPSS 10%

setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restrict the presence of comment clo…

Patch available
Fix from $1,950 2011-07-14
phpMyAdmin MEDIUM 6.5
CVE-2011-2507

libraries/server_synchronize.lib.php in the Synchronize implementation in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly q…

Patch available
Fix from $1,600 2011-07-14
Bluetooth Stack HIGH 8.8
CVE-2011-1265EPSS 6%

The Bluetooth Stack 2.1 in Microsoft Windows Vista SP1 and SP2 and Windows 7 Gold and SP1 does not prevent access to objects in memory that (1) were …

Patch available
Fix from $1,950 2011-07-13
Ar Web Content Manager HIGH 7.5
CVE-2010-4810

Multiple PHP remote file inclusion vulnerabilities in AR Web Content Manager (AWCM) 2.1 final allow remote attackers to execute arbitrary PHP code vi…

No fix yet
Fix from $1,950 2011-07-08
Acrobat Reader HIGH 9.3
CVE-2011-2101EPSS 7%

Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X do not properly restrict script, which allows…

Patch available
Fix from $1,950 2011-06-16
Service Center HIGH 7.5
CVE-2011-1863

HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allow remote authenticated users to conduct unspecified script injection attac…

Mitigation only
Fix from $1,950 2011-06-14
Oprofile HIGH 7.2
CVE-2011-1760

utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to conduct eval injection attacks and gain privileges via shell metacharacters …

Fix: after 0.9.6
Fix from $1,950 2011-06-09
Site Survey HIGH 9.3
CVE-2011-2386EPSS 45%

VisiWaveReport.exe in AZO Technologies, Inc. VisiWave Site Survey before 2.1.9 allows user-assisted remote attackers to execute arbitrary code via a …

Fix: after 2.1
Fix from $1,950 2011-06-08
Rvs4000 HIGH 9.0
CVE-2011-1646

The web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N …

Mitigation only
Fix from $1,950 2011-05-31
Mediawiki MEDIUM 6.8
CVE-2010-2789

PHP remote file inclusion vulnerability in MediaWikiParserTest.php in MediaWiki 1.16 beta, when register_globals is enabled, allows remote attackers …

Patch available
Fix from $1,600 2011-04-27
Telepresence Recording Server Software HIGH 9.3
CVE-2011-0386

The XML-RPC implementation on Cisco TelePresence Recording Server devices with software 1.6.x and 1.7.x before 1.7.1 allows remote attackers to overw…

Mitigation only
Fix from $1,950 2011-02-25
Security Agent HIGH 10.0
CVE-2011-0364EPSS 20%

The Management Console (webagent.exe) in Cisco Security Agent 5.1, 5.2, and 6.0 before 6.0.2.145 allows remote attackers to create arbitrary files an…

Mitigation only
Fix from $1,950 2011-02-19
Netbiter Easyconnect Ec150 HIGH 9.0
CVE-2010-4732

cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom …

No fix yet
Fix from $1,950 2011-02-15
Visio HIGH 9.3
CVE-2011-0092EPSS 24%

The LZW stream decompression functionality in ORMELEMS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 allows remote attackers to execute arb…

Mitigation only
Fix from $1,950 2011-02-10
Visio HIGH 9.3
CVE-2011-0093EPSS 20%

ELEMENTS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 does not properly parse structures during the opening of a Visio file, which allows …

Mitigation only
Fix from $1,950 2011-02-10
Im Manager HIGH 8.5
CVE-2010-3719EPSS 13%

Eval injection vulnerability in IMAdminSchedTask.asp in the administrative interface for Symantec IM Manager 8.4.16 and earlier allows remote attacke…

Fix: after 8.4.16
Fix from $1,950 2011-02-02
Simploo Cms MEDIUM 6.0
CVE-2011-0635

Static code injection vulnerability in Simploo CMS 1.7.1 and earlier allows remote authenticated users to inject arbitrary PHP code into config/custo…

Fix: after 1.7.1
Fix from $1,600 2011-01-22
Icq HIGH 9.3
CVE-2011-0487

ICQ 7 does not verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a crafted file that is fetc…

Mitigation only
Fix from $1,950 2011-01-18
Wmi Administrative Tools HIGH 9.3
CVE-2010-3973EPSS 72%

The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in Microsoft Windows XP SP2 and …

Fix: after 1.1
Fix from $1,950 2010-12-23
Wmi Administrative Tools HIGH 9.3
CVE-2010-4588EPSS 33%

The WBEMSingleView.ocx ActiveX control 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier allows remote attackers to execute arbitrary…

Fix: after 1.1
Fix from $1,950 2010-12-23
Phpmyfaq HIGH 7.5
CVE-2010-4558

phpMyFAQ 2.6.11 and 2.6.12, as distributed between December 4th and December 15th 2010, contains an externally introduced modification (Trojan Horse)…

Patch available
Fix from $1,950 2010-12-17
Publisher HIGH 9.3
CVE-2010-3955EPSS 19%

pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3 does not properly perform array indexing, which allows remote attackers…

Mitigation only
Fix from $1,950 2010-12-16
Windows 2003 Server HIGH 9.3
CVE-2010-3956EPSS 8%

The OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2…

Mitigation only
Fix from $1,950 2010-12-16
Windows 2003 Server MEDIUM 6.9
CVE-2010-3959EPSS 14%

The OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2…

Mitigation only
Fix from $1,600 2010-12-16
Publisher HIGH 9.3
CVE-2010-2569EPSS 21%

pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3, 2003 SP3, and 2007 SP2 does not properly handle an unspecified size fi…

Mitigation only
Fix from $1,950 2010-12-16