Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Openswan MEDIUM 6.5
CVE-2010-3308

Buffer overflow in programs/pluto/xauth.c in the client in Openswan 2.6.26 through 2.6.28 might allow remote authenticated gateways to execute arbitr…

Patch available
Fix from $1,600 2010-10-05
Free Simple Cms HIGH 7.5
CVE-2010-3742

Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Free Simple CMS 1.0 allow remote attackers to execute arbitrary PHP…

No fix yet
Fix from $1,950 2010-10-05
Free Simple Cms HIGH 7.5
CVE-2010-3307

Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Free Simple CMS 1.0 and earlier allow remote attackers to execute a…

Mitigation only
Fix from $1,950 2010-10-05
Libavcodec MEDIUM 6.8
CVE-2010-3429

flicvideo.c in libavcodec 0.6 and earlier in FFmpeg, as used in MPlayer and other products, allows remote attackers to execute arbitrary code via a c…

Fix: after 1.0
Fix from $1,600 2010-09-30
Egroupware HIGH 7.5
CVE-2010-3313EPSS 9%

phpgwapi/js/fckeditor/editor/dialog/fck_spellerpages/spellerpages/serverscripts/spellchecker.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibl…

Patch available
Fix from $1,950 2010-09-22
Family Connections Cms HIGH 7.5
CVE-2010-3419

Multiple PHP remote file inclusion vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 2.2.3 allow remote attackers to execute arbitrary PH…

No fix yet
Fix from $1,950 2010-09-16
Firefox HIGH 9.3
CVE-2010-2766EPSS 5%

The normalizeDocument function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonke…

Fix: after 3.5.11
Fix from $1,950 2010-09-09
Linux Kernel HIGH 7.2
CVE-2010-2240

The do_anonymous_page function in mm/memory.c in the Linux kernel before 2.6.27.52, 2.6.32.x before 2.6.32.19, 2.6.34.x before 2.6.34.4, and 2.6.35.x…

Fix: after 2.6.27.51
Fix from $1,950 2010-09-03
Seagull HIGH 7.5
CVE-2010-3209

Multiple PHP remote file inclusion vulnerabilities in Seagull 0.6.7 allow remote attackers to execute arbitrary PHP code via a URL in the includeFile…

No fix yet
Fix from $1,950 2010-09-03
Multi Lingual E Commerce System HIGH 7.5
CVE-2010-3210

Multiple PHP remote file inclusion vulnerabilities in Multi-lingual E-Commerce System 0.2 allow remote attackers to execute arbitrary PHP code via a …

No fix yet
Fix from $1,950 2010-09-03
Textpattern HIGH 7.5
CVE-2010-3205

PHP remote file inclusion vulnerability in index.php in Textpattern CMS 4.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the …

No fix yet
Fix from $1,950 2010-09-03
Diy Cms HIGH 7.5
CVE-2010-3206

Multiple PHP remote file inclusion vulnerabilities in DiY-CMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang para…

No fix yet
Fix from $1,950 2010-09-03
Pecio Cms HIGH 7.5
CVE-2010-3204

Multiple PHP remote file inclusion vulnerabilities in Pecio CMS 2.0.5 allow remote attackers to execute arbitrary PHP code via a URL in the template …

No fix yet
Fix from $1,950 2010-09-03
Internet Security HIGH 9.3
CVE-2010-3189EPSS 39%

The extSetOwner function in the UfProxyBrowserCtrl ActiveX control (UfPBCtrl.dll) in Trend Micro Internet Security Pro 2010 allows remote attackers t…

Patch available
Fix from $1,950 2010-08-31
Realplayer HIGH 9.3
CVE-2010-2996EPSS 7%

Array index error in RealNetworks RealPlayer 11.0 through 11.1 on Windows allows remote attackers to execute arbitrary code via a malformed header in…

Mitigation only
Fix from $1,950 2010-08-30
Lm Starmail Paidmail HIGH 7.5
CVE-2009-4993

PHP remote file inclusion vulnerability in home.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary PHP code via a URL in th…

No fix yet
Fix from $1,950 2010-08-25
Mybackup MEDIUM 6.5
CVE-2009-4977

PHP remote file inclusion vulnerability in index.php in MyBackup 1.4.0 allows remote authenticated users to execute arbitrary PHP code via a URL in t…

No fix yet
Fix from $1,600 2010-08-25
Strongswan HIGH 7.5
CVE-2010-2628

The IKE daemon in strongSwan 4.3.x before 4.3.7 and 4.4.x before 4.4.1 does not properly check the return values of snprintf calls, which allows remo…

Patch available
Fix from $1,950 2010-08-20
Uzbl MEDIUM 6.8
CVE-2010-2809EPSS 7%

The default configuration of the <Button2> binding in Uzbl before 2010.08.05 does not properly use the @SELECTED_URI feature, which allows user-assis…

Fix: after 2010.04.03
Fix from $1,600 2010-08-19
Siebel Option Pack Ie Activex Control HIGH 9.3
CVE-2009-3737

The Oracle Siebel Option Pack for IE ActiveX control does not properly initialize memory that is used by the NewBusObj method, which allows remote at…

Mitigation only
Fix from $1,950 2010-08-17
Opera Browser MEDIUM 6.8
CVE-2010-2576

Opera before 10.61 does not properly suppress clicks on download dialogs that became visible after a recent tab change, which allows remote attackers…

Fix: after 10.60
Fix from $1,600 2010-08-16
Online Plug In For Windows For Xenapp \& Xendesktop HIGH 9.3
CVE-2010-2991EPSS 7%

The IICAClient interface in the ICAClient library in the ICA Client ActiveX Object (aka ICO) component in Citrix Online Plug-in for Windows for XenAp…

Fix: after 12.0
Fix from $1,950 2010-08-11
Xml Core Services HIGH 9.3
CVE-2010-2561EPSS 25%

Microsoft XML Core Services (aka MSXML) 3.0 does not properly handle HTTP responses, which allows remote attackers to execute arbitrary code or cause…

Mitigation only
Fix from $1,950 2010-08-11
Excel HIGH 9.3
CVE-2010-2562EPSS 18%

Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Exce…

Mitigation only
Fix from $1,950 2010-08-11
Windows Movie Maker HIGH 9.3
CVE-2010-2564EPSS 23%

Buffer overflow in Microsoft Windows Movie Maker (WMM) 2.1, 2.6, and 6.0 allows remote attackers to execute arbitrary code or cause a denial of servi…

Mitigation only
Fix from $1,950 2010-08-11
.net Framework HIGH 9.3
CVE-2010-1898EPSS 25%

The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP1, 2.0 SP2, 3.5, 3.5 SP1, and 3.5.1, and Microsoft Silverlight 2 and 3 before 3.0…

Fix: after 3.0.50106.0
Fix from $1,950 2010-08-11
Word HIGH 9.3
CVE-2010-1900EPSS 40%

Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word V…

Mitigation only
Fix from $1,950 2010-08-11
Word HIGH 9.3
CVE-2010-1901EPSS 19%

Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word V…

Mitigation only
Fix from $1,950 2010-08-11
Word HIGH 9.3
CVE-2010-1903EPSS 19%

Microsoft Office Word 2002 SP3 and 2003 SP3, and Office Word Viewer, allows remote attackers to execute arbitrary code or cause a denial of service (…

Mitigation only
Fix from $1,950 2010-08-11
Adobe Air HIGH 9.3
CVE-2010-2213

Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denia…

Fix: after 10.1.53.64
Fix from $1,950 2010-08-11