Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Compatibility Pack Word Excel Powerpoint HIGH 9.3
CVE-2009-3131EPSS 25%

Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel V…

Mitigation only
Fix from $1,950 2009-11-11
Compatibility Pack Word Excel Powerpoint HIGH 9.3
CVE-2009-3132EPSS 26%

Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel V…

Mitigation only
Fix from $1,950 2009-11-11
Compatibility Pack Word Excel Powerpoint HIGH 9.3
CVE-2009-3133EPSS 25%

Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary…

Mitigation only
Fix from $1,950 2009-11-11
Compatibility Pack Word Excel Powerpoint HIGH 9.3
CVE-2009-3134EPSS 26%

Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel V…

Mitigation only
Fix from $1,950 2009-11-11
Windows 2000 HIGH 9.3
CVE-2009-2514EPSS 47%

win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse font code during construction of…

Mitigation only
Fix from $1,950 2009-11-11
Compatibility Pack Word Excel Powerpoint HIGH 9.3
CVE-2009-3127EPSS 25%

Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, and Office Excel Viewer 2003 SP3 …

Mitigation only
Fix from $1,950 2009-11-11
Compatibility Pack Word Excel Powerpoint HIGH 9.3
CVE-2009-3128EPSS 25%

Microsoft Office Excel 2002 SP3 and 2003 SP3, and Office Excel Viewer 2003 SP3, does not properly parse the Excel file format, which allows remote at…

Mitigation only
Fix from $1,950 2009-11-11
Blender HIGH 9.3
CVE-2009-3850EPSS 9%

Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrary code via a .blend file that contains Python statements in the onLoa…

No fix yet
Fix from $1,950 2009-11-06
TYPO3 HIGH 8.5
CVE-2009-3631

The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2, when the DAM extension or …

Fix: after 4.0.12
Fix from $1,950 2009-11-02
Com Booklibrary HIGH 7.5
CVE-2009-3817

PHP remote file inclusion vulnerability in doc/releasenote.php in the BookLibrary (com_booklibrary) component 1.0 for Joomla! allows remote attackers…

No fix yet
Fix from $1,950 2009-10-28
Com Ajaxchat HIGH 7.5
CVE-2009-3822

PHP remote file inclusion vulnerability in Fiji Web Design Ajax Chat (com_ajaxchat) component 1.0 for Joomla! allows remote attackers to execute arbi…

No fix yet
Fix from $1,950 2009-10-28
Runcms MEDIUM 6.5
CVE-2009-3814

Static code injection vulnerability in RunCMS 2M1 allows remote authenticated administrators to execute arbitrary PHP code via the "Filter/Banning" f…

No fix yet
Fix from $1,600 2009-10-27
Xencenterweb HIGH 7.5
CVE-2009-3760

Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote a…

No fix yet
Fix from $1,950 2009-10-22
Achievo HIGH 7.5
CVE-2009-3705EPSS 10%

PHP remote file inclusion vulnerability in debugger.php in Achievo before 1.4.0 allows remote attackers to execute arbitrary PHP code via a URL in th…

Fix: after 1.3.4
Fix from $1,950 2009-10-16
Windows 2000 HIGH 9.3
CVE-2009-2497EPSS 23%

The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle in…

Mitigation only
Fix from $1,950 2009-10-14
Windows 2003 Server HIGH 9.3
CVE-2009-2503EPSS 22%

GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office Sys…

Mitigation only
Fix from $1,950 2009-10-14
Windows 2000 HIGH 9.3
CVE-2009-2525EPSS 23%

Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does …

Mitigation only
Fix from $1,950 2009-10-14
Windows 2003 Server HIGH 9.3
CVE-2009-2528EPSS 20%

GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute ar…

Mitigation only
Fix from $1,950 2009-10-14
Windows 2000 HIGH 9.3
CVE-2009-0091EPSS 26%

Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows rem…

Mitigation only
Fix from $1,950 2009-10-14
Windows 2000 HIGH 9.3
CVE-2009-0555EPSS 27%

Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does …

Patch available
Fix from $1,950 2009-10-14
Efront MEDIUM 6.8
CVE-2009-3660

PHP remote file inclusion vulnerability in libraries/database.php in Efront 3.5.4 and earlier, when register_globals is enabled, allows remote attack…

Fix: after 3.5.4
Fix from $1,600 2009-10-11
Phpgenealogy HIGH 7.5
CVE-2009-3541

PHP remote file inclusion vulnerability in CoupleDB.php in PHPGenealogy 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the Da…

No fix yet
Fix from $1,950 2009-10-02
Installation Manager HIGH 9.3
CVE-2009-3518EPSS 5%

Argument injection vulnerability in the iim: URI handler in IBMIM.exe in IBM Installation Manager 1.3.2 and earlier, as used in IBM Rational Robot an…

Fix: after 1.3.2
Fix from $1,950 2009-10-01
Justvisual HIGH 7.5
CVE-2009-3511

Multiple PHP remote file inclusion vulnerabilities in justVisual 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the fs_jVroot …

No fix yet
Fix from $1,950 2009-10-01
Loggix Project HIGH 7.5
CVE-2009-3492

Multiple PHP remote file inclusion vulnerabilities in Loggix Project 9.4.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL…

Fix: after 9.4.5
Fix from $1,950 2009-09-30
Fireftp MEDIUM 6.0
CVE-2009-3478

Argument injection vulnerability in (1) src/content/js/connection/sftp.js and (2) src/content/js/connection/controlSocket.js.in in FireFTP Extension …

Patch available
Fix from $1,600 2009-09-29
Maxcms MEDIUM 6.8
CVE-2009-3424

Multiple PHP remote file inclusion vulnerabilities in MaxCMS 3.11.20b, when register_globals is enabled, allow remote attackers to execute arbitrary …

No fix yet
Fix from $1,600 2009-09-25
Maxcms MEDIUM 6.8
CVE-2009-3426

PHP remote file inclusion vulnerability in includes/file_manager/special.php in MaxCMS 3.11.20b allows remote attackers to execute arbitrary PHP code…

No fix yet
Fix from $1,600 2009-09-25
Sznews HIGH 7.5
CVE-2009-3362

PHP remote file inclusion vulnerability in printnews.php3 in SZNews 2.7 allows remote attackers to execute arbitrary PHP code via a URL in the id par…

No fix yet
Fix from $1,950 2009-09-24
Aurora HIGH 7.5
CVE-2009-3365

PHP remote file inclusion vulnerability in add-ons/modules/sysmanager/plugins/install.plugin.php in Aurora CMS 1.0.2 allows remote attackers to execu…

No fix yet
Fix from $1,950 2009-09-24