Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Cobbler HIGH 8.5
CVE-2010-2235

template_api.py in Cobbler before 2.0.7, as used in Red Hat Network Satellite Server and other products, does not disable the ability of the Cheetah …

Fix: after 2.0.4
Fix from $1,950 2010-12-09
Movie Decoder HIGH 9.3
CVE-2010-4294EPSS 6%

The frame decompression functionality in the VMnc media codec in VMware Movie Decoder before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548, VM…

Fix: after 6.5.5
Fix from $1,950 2010-12-06
Pandora Fms HIGH 7.5
CVE-2010-4281EPSS 10%

Incomplete blacklist vulnerability in the safe_url_extraclean function in ajax.php in Pandora FMS before 3.1.1 allows remote attackers to execute arb…

Fix: after 3.1
Fix from $1,950 2010-12-02
Pandora Fms HIGH 7.5
CVE-2010-4283EPSS 9%

PHP remote file inclusion vulnerability in extras/pandora_diag.php in Pandora FMS before 3.1.1 allows remote attackers to execute arbitrary PHP code …

Fix: after 3.1
Fix from $1,950 2010-12-02
Awstats HIGH 7.5
CVE-2010-4367EPSS 28%

awstats.cgi in AWStats before 7.0 accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted…

Fix: after 6.95
Fix from $1,950 2010-12-02
Awstats HIGH 7.5
CVE-2010-4368

awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands vi…

Fix: after 6.95
Fix from $1,950 2010-12-02
Vtiger Crm MEDIUM 6.0
CVE-2010-3909

Incomplete blacklist vulnerability in config.template.php in vtiger CRM before 5.2.1 allows remote authenticated users to execute arbitrary code by u…

Fix: after 5.2.0
Fix from $1,600 2010-11-26
Unified Videoconferencing System 5110 Firmware HIGH 8.5
CVE-2010-3037

goform/websXMLAdminRequestCgi.cgi in Cisco Unified Videoconferencing (UVC) System 5110 and 5115, and possibly Unified Videoconferencing System 3545 a…

Mitigation only
Fix from $1,950 2010-11-22
Safari HIGH 9.3
CVE-2010-3808

WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of…

Fix: after 5.0.2
Fix from $1,950 2010-11-22
Safari HIGH 9.3
CVE-2010-3809

WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of…

Fix: after 5.0.2
Fix from $1,950 2010-11-22
Safari HIGH 9.3
CVE-2010-3819

WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of…

Fix: after 5.0.2
Fix from $1,950 2010-11-22
Tomboy MEDIUM 6.9
CVE-2010-4005

The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1.5.2 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows…

Fix: after 1.5.2
Fix from $1,600 2010-11-06
Realplayer HIGH 9.3
CVE-2010-3749EPSS 26%

The browser-plugin implementation in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1 allows remote attackers to arguments…

No fix yet
Fix from $1,950 2010-10-19
.net Framework HIGH 9.3
CVE-2010-3228EPSS 19%

The JIT compiler in Microsoft .NET Framework 4.0 on 64-bit platforms does not properly perform optimizations, which allows remote attackers to execut…

Mitigation only
Fix from $1,950 2010-10-13
Windows Media Player HIGH 9.3
CVE-2010-2745EPSS 24%

Microsoft Windows Media Player (WMP) 9 through 12 does not properly deallocate objects during a browser reload action, which allows user-assisted rem…

Mitigation only
Fix from $1,950 2010-10-13
Office HIGH 9.3
CVE-2010-2747EPSS 21%

Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle an uninitialized pointer during parsing of a Word document, which allows remot…

Mitigation only
Fix from $1,950 2010-10-13
Office HIGH 9.3
CVE-2010-2748EPSS 19%

Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly check an unspecified boundary during parsing of a Word document, which allows remote …

Mitigation only
Fix from $1,950 2010-10-13
Office HIGH 9.3
CVE-2010-2750EPSS 20%

Array index error in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Word document th…

Mitigation only
Fix from $1,950 2010-10-13
Office HIGH 9.3
CVE-2010-3215EPSS 20%

Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle unspecified return values during parsing of a Word document, which allows remo…

Mitigation only
Fix from $1,950 2010-10-13
Office HIGH 9.3
CVE-2010-3216EPSS 20%

Microsoft Word 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a crafted Word document containing bookmarks tha…

Mitigation only
Fix from $1,950 2010-10-13
Word HIGH 9.3
CVE-2010-3218EPSS 23%

Heap-based buffer overflow in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via malformed records in a Word document, aka…

Mitigation only
Fix from $1,950 2010-10-13
Word HIGH 9.3
CVE-2010-3219EPSS 20%

Array index vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a crafted Word document that triggers memo…

Mitigation only
Fix from $1,950 2010-10-13
Office HIGH 9.3
CVE-2010-3220EPSS 19%

Unspecified vulnerability in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Word doc…

Mitigation only
Fix from $1,950 2010-10-13
Office HIGH 9.3
CVE-2010-3221EPSS 19%

Microsoft Word 2002 SP3 and 2003 SP3, Office 2004 for Mac, and Word Viewer do not properly handle a malformed record during parsing of a Word documen…

Mitigation only
Fix from $1,950 2010-10-13
Mednafen HIGH 10.0
CVE-2010-3085

The network-play implementation in Mednafen before 0.8.D might allow remote servers to execute arbitrary code via unspecified vectors, related to "st…

Fix: after 0.8.c
Fix from $1,950 2010-10-12
Pidgin Knotify MEDIUM 5.1
CVE-2010-3088

The notify function in pidgin-knotify.c in the pidgin-knotify plugin 0.2.1 and earlier for Pidgin allows remote attackers to execute arbitrary comman…

Fix: after 0.2.1
Fix from $1,600 2010-10-08
Acrobat HIGH 9.3
CVE-2010-3625EPSS 8%

Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allow attackers to execute arbitrary code via unspecified vect…

Patch available
Fix from $1,950 2010-10-06
Tivoli Storage Manager Fastback HIGH 10.0
CVE-2010-3758EPSS 7%

Multiple stack-based buffer overflows in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.…

Mitigation only
Fix from $1,950 2010-10-05
Tivoli Storage Manager Fastback HIGH 10.0
CVE-2010-3759

FastBackMount.exe in the Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 writes a cert…

Mitigation only
Fix from $1,950 2010-10-05
Tivoli Storage Manager Fastback HIGH 10.0
CVE-2010-3761

Unspecified vulnerability in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to…

Mitigation only
Fix from $1,950 2010-10-05