Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 7.5 CVE-2013-0912 WebKit in Google Chrome before 25.0.1364.160 allows remote attackers to execute arbitrary code via vectors that leverage "type confusion." Chrome Mitigation only Fix from $1,9502013-03-11 HIGH 7.5 CVE-2013-2549EPSS 6% Unspecified vulnerability in Adobe Reader 11.0.02 allows remote attackers to execute arbitrary code via vectors related to a "break into the sandbox,… Acrobat Reader Mitigation only Fix from $1,9502013-03-11 MEDIUM 6.6 CVE-2013-1762 stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, whic… Stunnel after 4.54 Fix from $1,6002013-03-08 MEDIUM 5.0 CVE-2012-4840 IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote attackers to conduct XP… Cognos Business Intelligence Mitigation only Fix from $1,6002013-03-05 HIGH 10.0 CVE-2012-4707 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors that trigger an out-of-bounds memory access. Codesys Gateway Server after 2.3.9.19 Fix from $1,9502013-02-24 MEDIUM 6.8 CVE-2013-0108EPSS 27% An ActiveX control in HscRemoteDeploy.dll in Honeywell Enterprise Buildings Integrator (EBI) R310, R400.2, R410.1, and R410.2; SymmetrE R310, R410.1,… Enterprise Buildings Integrator Mitigation only Fix from $1,6002013-02-24 HIGH 9.3 CVE-2012-0439EPSS 39% An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute ar… Groupwise Mitigation only Fix from $1,9502013-02-24 HIGH 9.3 CVE-2013-1637 Opera before 12.13 allows remote attackers to execute arbitrary code via vectors involving DOM events. Opera Browser after 12.12 Fix from $1,9502013-02-08 HIGH 9.3 CVE-2013-1638EPSS 8% Opera before 12.13 allows remote attackers to execute arbitrary code via crafted clipPaths in an SVG document. Opera Browser after 12.12 Fix from $1,9502013-02-08 HIGH 9.3 CVE-2013-0758EPSS 73% Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 a… Firefox 2.15 / 10.0.12+ Fix from $1,9502013-01-13 HIGH 9.3 CVE-2013-0745 The AutoWrapperChanger class in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 1… Firefox 2.15 / 17.0.2+ Fix from $1,9502013-01-13 HIGH 10.0 CVE-2013-0614EPSS 6% Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code via unspecified vecto… Acrobat Mitigation only Fix from $1,9502013-01-10 HIGH 10.0 CVE-2013-0618EPSS 6% Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code via unspecified vecto… Acrobat Mitigation only Fix from $1,9502013-01-10 HIGH 10.0 CVE-2013-0607EPSS 6% Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code via unspecified vecto… Acrobat Mitigation only Fix from $1,9502013-01-10 HIGH 10.0 CVE-2013-0608EPSS 6% Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code via unspecified vecto… Acrobat Mitigation only Fix from $1,9502013-01-10 HIGH 9.3 CVE-2013-0007EPSS 32% Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary cod… Xml Core Services Mitigation only Fix from $1,9502013-01-09 HIGH 7.5 CVE-2012-6329EPSS 62% The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly handle backslashes and fully qual… Perl after 5.16.2 Fix from $1,9502013-01-04 HIGH 9.3 CVE-2012-6465 Opera before 12.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed SVG image. Opera Browser after 12.10 Fix from $1,9502013-01-02 HIGH 10.0 CVE-2012-5932EPSS 63% Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 allo… Privileged User Manager Mitigation only Fix from $1,9502012-12-24 HIGH 9.3 CVE-2012-5690 RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allow remote attackers to execute arbitrary code via a RealAudio file t… Realplayer after 16.0.0 Fix from $1,9502012-12-19 HIGH 10.0 CVE-2012-5142 Google Chrome before 23.0.1271.97 does not properly handle history navigation, which allows remote attackers to execute arbitrary code or cause a den… Chrome after 23.0.1271.96 Fix from $1,9502012-12-12 HIGH 9.3 CVE-2012-2556EPSS 21% The OpenType Font (OTF) driver in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Se… Windows 2003 Server Mitigation only Fix from $1,9502012-12-12 HIGH 10.0 CVE-2012-5973 CA XCOM Data Transport r11.0 and r11.5 on UNIX and Linux allows remote attackers to execute arbitrary commands via a crafted request. Xcom Data Transport Mitigation only Fix from $1,9502012-12-10 MEDIUM 6.0 CVE-2012-5537 The Simplenews Scheduler module 6.x-2.x before 6.x-2.4 for Drupal allows remote authenticated users with the "send scheduled newsletters" permission … Simplenews Scheduler Patch available Fix from $1,6002012-12-03 HIGH 10.0 CVE-2012-6046 Static code injection vulnerability in admin/banners.php in PHP Enter allows remote attackers to inject arbitrary PHP code into horad.php via the cod… Php Enter Mitigation only Fix from $1,9502012-11-27 HIGH 7.5 CVE-2012-5836 Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allow remote attackers to execute arbitrary code or cause a denial of… Firefox 2.14 / 17.0+ Fix from $1,9502012-11-21 MEDIUM 6.8 CVE-2012-5837 The Web Developer Toolbar in Mozilla Firefox before 17.0 executes script with chrome privileges, which allows user-assisted remote attackers to condu… Firefox after 16.0.2 Fix from $1,6002012-11-21 MEDIUM 6.8 CVE-2012-5777 Eval injection vulnerability in the ReplaceListVars function in the template parser in e/class/connect.php in EmpireCMS 6.6 allows user-assisted remo… Empirecms No fix yet Fix from $1,6002012-11-16 MEDIUM 5.0 CVE-2012-4884 Argument injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to create arbitrary files… Rt Mitigation only Fix from $1,6002012-11-11 HIGH 7.5 CVE-2012-2971 The server in CA ARCserve Backup r12.5, r15, and r16 on Windows does not properly process RPC requests, which allows remote attackers to execute arbi… No fix yet Fix from $1,9502012-10-20