Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Excel HIGH 9.3
CVE-2010-0257EPSS 19%

Microsoft Office Excel 2002 SP3 does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted …

Mitigation only
Fix from $1,950 2010-03-10
Excel HIGH 9.3
CVE-2010-0260EPSS 23%

Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel…

Mitigation only
Fix from $1,950 2010-03-10
Excel HIGH 9.3
CVE-2010-0262EPSS 21%

Microsoft Office Excel 2007 SP1 and SP2 and Office 2004 for Mac do not properly parse the Excel file format, which allows remote attackers to execute…

Mitigation only
Fix from $1,950 2010-03-10
Excel HIGH 9.3
CVE-2010-0263EPSS 26%

Microsoft Office Excel 2007 SP1 and SP2; Office 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; Office Compati…

Mitigation only
Fix from $1,950 2010-03-10
Excel HIGH 9.3
CVE-2010-0264EPSS 21%

Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format…

Mitigation only
Fix from $1,950 2010-03-10
Minicwb HIGH 7.5
CVE-2009-4693

Multiple PHP remote file inclusion vulnerabilities in GraFX MiniCWB 2.3.0 allow remote attackers to execute arbitrary PHP code via a URL in the LANG …

No fix yet
Fix from $1,950 2010-03-10
Duo Usb HIGH 9.3
CVE-2010-0103EPSS 27%

UsbCharger.dll in the Energizer DUO USB battery charger software contains a backdoor that is implemented through the Arucer.dll file in the %WINDIR%\…

No fix yet
Fix from $1,950 2010-03-10
Download Protect HIGH 7.5
CVE-2009-4666

Multiple PHP remote file inclusion vulnerabilities in Webradev Download Protect 1.0 allow remote attackers to execute arbitrary PHP code via a URL in…

No fix yet
Fix from $1,950 2010-03-05
Windows 2000 HIGH 7.6
CVE-2010-0483EPSS 86%

vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, a…

No fix yet
Fix from $1,950 2010-03-03
Wikyblog HIGH 7.5
CVE-2010-0755

PHP remote file inclusion vulnerability in include/WBmap.php in WikyBlog 1.7.3 rc2 allows remote attackers to execute arbitrary PHP code via a URL in…

No fix yet
Fix from $1,950 2010-02-27
Katalog Stron Hurricane MEDIUM 6.8
CVE-2010-0678

PHP remote file inclusion vulnerability in includes/moderation.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, when register_globals is e…

No fix yet
Fix from $1,600 2010-02-22
Firefox HIGH 10.0
CVE-2009-1571EPSS 6%

Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonke…

Mitigation only
Fix from $1,950 2010-02-22
Secure File Transfer Appliance HIGH 9.0
CVE-2009-4646

Static code injection vulnerability in the administrative web interface in Accellion Secure File Transfer Appliance allows remote authenticated admin…

No fix yet
Fix from $1,950 2010-02-19
Chrome HIGH 9.3
CVE-2010-0647

WebKit before r53525, as used in Google Chrome before 4.0.249.89, allows remote attackers to execute arbitrary code in the Chrome sandbox via a malfo…

Fix: after 4.0.249.78
Fix from $1,950 2010-02-18
Openoffice HIGH 9.3
CVE-2009-3302EPSS 12%

filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execut…

Fix: 3.2.0+
Fix from $1,950 2010-02-16
Panda Activescan HIGH 9.3
CVE-2009-3735EPSS 6%

The ActiveScan Installer ActiveX control in as2stubie.dll before 1.3.3.0 in PandaActiveScan Installer 2.0 in Panda ActiveScan downloads software in a…

Mitigation only
Fix from $1,950 2010-02-11
Office HIGH 9.3
CVE-2010-0031EPSS 21%

Array index error in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Office 2004 for Mac, allows remote attackers to execute arb…

Mitigation only
Fix from $1,950 2010-02-10
Powerpoint HIGH 9.3
CVE-2010-0032EPSS 21%

Use-after-free vulnerability in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Pow…

Mitigation only
Fix from $1,950 2010-02-10
Windows 2000 HIGH 9.3
CVE-2010-0252EPSS 29%

The Microsoft Data Analyzer ActiveX control (aka the Office Excel ActiveX control for Data Analysis) in max3activex.dll in Microsoft Windows 2000 SP4…

Mitigation only
Fix from $1,950 2010-02-10
Windows 2000 HIGH 9.0
CVE-2010-0020EPSS 32%

The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1,…

Mitigation only
Fix from $1,950 2010-02-10
Ffmpeg HIGH 9.3
CVE-2009-4635EPSS 8%

FFmpeg 0.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted MOV container with improperly order…

No fix yet
Fix from $1,950 2010-02-10
Systemtap HIGH 10.0
CVE-2009-4273EPSS 18%

stap-server in SystemTap before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in stap command-line arguments in …

Fix: after 1.0
Fix from $1,950 2010-01-26
Internet Explorer HIGH 9.3
CVE-2010-0027EPSS 34%

The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP…

Mitigation only
Fix from $1,950 2010-01-22
Bits Video Script HIGH 7.5
CVE-2010-0367

Multiple PHP remote file inclusion vulnerabilities in BitScripts Bits Video Script 2.05 Gold Beta, and possibly 2.04, allow remote attackers to execu…

No fix yet
Fix from $1,950 2010-01-21
Moa Gallery HIGH 7.5
CVE-2009-4614

Multiple PHP remote file inclusion vulnerabilities in Moa Gallery 1.2.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in…

Fix: after 1.2.0
Fix from $1,950 2010-01-18
Drunken\ HIGH 7.5
CVE-2009-4622

PHP remote file inclusion vulnerability in admin/admin_news_bot.php in Drunken:Golem Gaming Portal 0.5.1 alpha 2 allows remote attackers to execute a…

No fix yet
Fix from $1,950 2010-01-18
Advanced Comment System HIGH 7.5
CVE-2009-4623EPSS 10%

Multiple PHP remote file inclusion vulnerabilities in Advanced Comment System 1.0 allow remote attackers to execute arbitrary PHP code via a URL in t…

No fix yet
Fix from $1,950 2010-01-18
Thttpd CRITICAL 9.8
CVE-2009-4491EPSS 13%

thttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, o…

No fix yet
Fix from $2,300 2010-01-13
Acrobat HIGH 10.0
CVE-2009-3954EPSS 9%

The 3D implementation in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow attackers to execute arbitr…

Fix: after 9.2
Fix from $1,950 2010-01-13
Com Mamboleto HIGH 7.5
CVE-2009-4604

PHP remote file inclusion vulnerability in mamboleto.php in the Fernando Soares Mamboleto (com_mamboleto) component 2.0 RC3 for Joomla! allows remote…

No fix yet
Fix from $1,950 2010-01-12