Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Adobe Air HIGH 9.3
CVE-2010-2214

Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denia…

Fix: after 10.1.53.64
Fix from $1,950 2010-08-11
Adobe Air HIGH 9.3
CVE-2010-2216

Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denia…

Fix: after 10.1.53.64
Fix from $1,950 2010-08-11
Flash Media Server HIGH 10.0
CVE-2010-2217

Adobe Flash Media Server (FMS) before 3.0.6, and 3.5.x before 3.5.4, allows attackers to execute arbitrary code via unspecified vectors, related to a…

Fix: after 3.0.5
Fix from $1,950 2010-08-11
Adobe Air HIGH 9.3
CVE-2010-0209

Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denia…

Fix: after 10.1.53.64
Fix from $1,950 2010-08-11
Com Joomla Visites HIGH 7.5
CVE-2010-2918EPSS 14%

PHP remote file inclusion vulnerability in core/include/myMailer.class.php in the Visites (com_joomla-visites) component 1.1 RC2 for Joomla! allows r…

No fix yet
Fix from $1,950 2010-07-30
Firefox MEDIUM 6.8
CVE-2010-1215

Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 do not properly implement access to a content object through a SafeJSObjectWrap…

Mitigation only
Fix from $1,600 2010-07-30
Soliddb HIGH 10.0
CVE-2010-2771EPSS 5%

solid.exe in IBM solidDB before 6.5 FP2 allows remote attackers to execute arbitrary code via a long username field in the first handshake packet.

Fix: after 6.5.0.1
Fix from $1,950 2010-07-22
Access HIGH 9.3
CVE-2010-0814EPSS 23%

The Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 and 2007 SP1 and SP2 do not properly interact with the memory-…

Mitigation only
Fix from $1,950 2010-07-15
Access HIGH 9.3
CVE-2010-1881EPSS 20%

The FieldList ActiveX control in the Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 does not properly interact wi…

Mitigation only
Fix from $1,950 2010-07-15
Outlook HIGH 9.3
CVE-2010-0266EPSS 55%

Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_ATTACH_METHOD property value …

Mitigation only
Fix from $1,950 2010-07-15
Com Sef HIGH 7.5
CVE-2010-2681

PHP remote file inclusion vulnerability in the SEF404x (com_sef) component for Joomla! allows remote attackers to execute arbitrary PHP code via a UR…

No fix yet
Fix from $1,950 2010-07-12
Totalcalendar HIGH 7.5
CVE-2009-4928

PHP remote file inclusion vulnerability in config.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary PHP code via a URL in the inc…

No fix yet
Fix from $1,950 2010-07-12
Open Web Analytics MEDIUM 5.1
CVE-2010-2677

PHP remote file inclusion vulnerability in mw_plugin.php in Open Web Analytics (OWA) 1.2.3, when magic_quotes_gpc is disabled and register_globals is…

Patch available
Fix from $1,600 2010-07-08
Cgi Tools Seo Links HIGH 7.5
CVE-2010-2626EPSS 13%

index.pl in Miyabi CGI Tools SEO Links 1.02 allows remote attackers to execute arbitrary commands via shell metacharacters in the fn command. NOTE: s…

No fix yet
Fix from $1,950 2010-07-02
Adapcms MEDIUM 6.8
CVE-2010-2618

PHP remote file inclusion vulnerability in inc/smarty/libs/init.php in AdaptCMS 2.0.0 Beta, when register_globals is enabled, allows remote attackers…

No fix yet
Fix from $1,600 2010-07-02
Acrobat HIGH 9.3
CVE-2010-2205

Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, access uninitialized memory, which allows attackers to execu…

Patch available
Fix from $1,950 2010-06-30
Acrobat HIGH 9.3
CVE-2010-2208

Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, dereference a heap object after this object's deletion, whic…

Patch available
Fix from $1,950 2010-06-30
Nakid Cms MEDIUM 5.1
CVE-2010-2358

PHP remote file inclusion vulnerability in modules/catalog/upload_photo.php in Nakid CMS 0.5.2, when magic_quotes_gpc is disabled and register_global…

No fix yet
Fix from $1,600 2010-06-21
Fusion Middleware MEDIUM 6.0
CVE-2010-1622EPSS 52%

SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary …

No fix yet
Fix from $1,600 2010-06-21
Ezpx Photoblog HIGH 7.5
CVE-2010-2341

PHP remote file inclusion vulnerability in system/application/views/public/commentform.php in EZPX Photoblog 1.2 beta allows remote attackers to exec…

No fix yet
Fix from $1,950 2010-06-18
Np Twitter MEDIUM 6.8
CVE-2010-2314

PHP remote file inclusion vulnerability in nucleus/plugins/NP_Twitter.php in the NP_Twitter Plugin 0.8 and 0.9 for Nucleus, when register_globals is …

No fix yet
Fix from $1,600 2010-06-17
Phpbazar HIGH 7.5
CVE-2010-2315EPSS 6%

PHP remote file inclusion vulnerability in picturelib.php in SmartISoft phpBazar 2.1.1 allows remote attackers to execute arbitrary PHP code via a UR…

No fix yet
Fix from $1,950 2010-06-17
Chrome HIGH 9.3
CVE-2010-2297

rendering/FixedTableLayout.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (applicat…

Fix: 5.0.375.70+
Fix from $1,950 2010-06-15
Flash Player HIGH 9.3
CVE-2010-2161EPSS 7%

Array index error in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execu…

Fix: after 1.5.3.9130
Fix from $1,950 2010-06-15
Flash Player HIGH 9.3
CVE-2010-2163EPSS 7%

Multiple unspecified vulnerabilities in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow…

Fix: after 1.5.3.9130
Fix from $1,950 2010-06-15
Flash Player HIGH 9.3
CVE-2010-2186EPSS 7%

Unspecified vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to ca…

Fix: after 1.5.3.9130
Fix from $1,950 2010-06-15
Safari HIGH 9.3
CVE-2010-1770

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Apple Safari before 4.1 on Mac OS X 10.4, and Google Chrome before 5.0.3…

Fix: 5.0.375.70+
Fix from $1,950 2010-06-11
Safari HIGH 9.3
CVE-2010-1415EPSS 7%

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly handle libxml context…

Fix: after 4.0.5
Fix from $1,950 2010-06-11
Cms S.builder MEDIUM 6.8
CVE-2009-4887

PHP remote file inclusion vulnerability in index.php in CMS S.Builder 3.7 and earlier, when register_globals is enabled, allows remote attackers to e…

Fix: after 3.7
Fix from $1,600 2010-06-11
Wap54gv3 HIGH 10.0
CVE-2010-2261

Linksys WAP54Gv3 firmware 3.04.03 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) data2 and (2)…

Fix: after 3.04.03
Fix from $1,950 2010-06-10