Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 6.8 CVE-2012-4143 Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, allows user-assisted remote attackers to trick users into… Opera Browser after 12.00 Fix from $1,6002012-08-06 HIGH 9.3 CVE-2012-1661EPSS 24% ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assisted remo… Arcmap after 10.0.2.3200 Fix from $1,9502012-07-12 MEDIUM 6.5 CVE-2012-1037 PHP remote file inclusion vulnerability in front/popup.php in GLPI 0.78 through 0.80.61 allows remote authenticated users to execute arbitrary PHP co… Glpi Mitigation only Fix from $1,6002012-07-12 HIGH 8.3 CVE-2012-2486 The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1.9.0, Cisco TelePresence Immersive Endpoint Devices… Telepresence Multipoint Switch Software after 1.9.0.1 Fix from $1,9502012-07-12 HIGH 8.8 CVE-2012-0175EPSS 26% The Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gol… Windows 2003 Server Mitigation only Fix from $1,9502012-07-10 HIGH 9.3 CVE-2012-2174EPSS 38% The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a crafted notes:// URL. Lotus Notes Mitigation only Fix from $1,9502012-06-20 HIGH 7.8 CVE-2012-3289 VMware Workstation 8.x before 8.0.4, VMware Player 4.x before 4.0.4, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 allow remote attacke… Workstation Mitigation only Fix from $1,9502012-06-14 HIGH 9.3 CVE-2012-1855EPSS 20% Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly handle function pointers, which allows remote attackers to execute arbitra… .net Framework Mitigation only Fix from $1,9502012-06-12 MEDIUM 5.5 CVE-2012-2596 The XPath functionality in unspecified web applications in Siemens WinCC 7.0 SP3 before Update 2 does not properly handle special characters in param… Wincc Mitigation only Fix from $1,6002012-06-08 MEDIUM 6.8 CVE-2011-4458 Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabled, allow… Rt Patch available Fix from $1,6002012-06-04 HIGH 9.3 CVE-2012-0295 The Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to conduct file-… Endpoint Protection Mitigation only Fix from $1,9502012-05-23 HIGH 7.5 CVE-2012-2924 PHP remote file inclusion vulnerability in admin/setup.inc.php in Hypermethod eLearning Server 4G allows remote attackers to execute arbitrary PHP co… Elearning Server No fix yet Fix from $1,9502012-05-21 MEDIUM 5.0 CVE-2011-3285 CRLF injection vulnerability in /+CSCOE+/logon.html on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 through 8.4 all… Adaptive Security Appliance Software Mitigation only Fix from $1,6002012-05-02 HIGH 9.3 CVE-2011-2478 Google SketchUp before 8 does not properly handle edge geometry in SketchUp (aka .SKP) files, which allows remote attackers to execute arbitrary code… Sketchup after 7.1 Fix from $1,9502012-04-17 MEDIUM 5.0 CVE-2011-4882 The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 allows remote attackers to cause a denial of service (application exit) via an uns… Webmi2ads after 2.0.1 Fix from $1,6002012-04-13 HIGH 7.5 CVE-2012-2224 Xunlei Thunder before 7.2.6 allows remote attackers to execute arbitrary code via a crafted file, related to a "DLL injection vulnerability." Thunder Mitigation only Fix from $1,9502012-04-11 HIGH 8.8 CVE-2012-0158 KEVEPSS 100% The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3… Office Patch available Fix from $1,9502012-04-10 MEDIUM 6.8 CVE-2012-1924 Opera before 11.62 allows user-assisted remote attackers to trick users into downloading and executing arbitrary files via a small window for the dow… Opera Browser after 11.61 Fix from $1,6002012-03-28 MEDIUM 6.4 CVE-2012-1919 CRLF injection vulnerability in mime.php in @Mail WebMail Client in AtMail Open-Source before 1.05 allows remote attackers to conduct directory trave… Atmail Open after 1.04 Fix from $1,6002012-03-27 MEDIUM 6.5 CVE-2012-0319 The file-management system in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote authenticated users to execute arbitrary… Movable Type Open Source after 4.37 Fix from $1,6002012-03-03 HIGH 7.5 CVE-2011-4189EPSS 12% The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corru… Groupwise No fix yet Fix from $1,9502012-03-02 HIGH 9.0 CVE-2012-0363 The web interface on Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allows… Small Business Srp520 Series Firmware after 1.01.24 Fix from $1,9502012-02-25 HIGH 7.5 CVE-2012-1205EPSS 25% PHP remote file inclusion vulnerability in relocate-upload.php in Relocate Upload plugin before 0.20 for WordPress allows remote attackers to execute… Relocate Upload after 0.14 Fix from $1,9502012-02-24 MEDIUM 6.8 CVE-2012-0993 Eval injection vulnerability in zp-core/zp-extensions/viewer_size_image.php in ZENphoto 1.4.2, when the viewer_size_image plugin is enabled, allows r… Zenphoto Patch available Fix from $1,6002012-02-21 MEDIUM 6.8 CVE-2011-4614EPSS 6% PHP remote file inclusion vulnerability in Classes/Controller/AbstractController.php in the workspaces system extension in TYPO3 4.5.x before 4.5.9, … TYPO3 Patch available Fix from $1,6002012-02-18 HIGH 7.5 CVE-2012-1199 Multiple PHP remote file inclusion vulnerabilities in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbitrary PHP… Basic Analysis And Security Engine No fix yet Fix from $1,9502012-02-18 HIGH 7.5 CVE-2012-1200 Multiple PHP remote file inclusion vulnerabilities in Nova CMS allow remote attackers to execute arbitrary PHP code via a URL in the (1) fileType par… Nova Cms No fix yet Fix from $1,9502012-02-18 HIGH 7.8 CVE-2012-0014EPSS 28% Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unman… .net Framework Mitigation only Fix from $1,9502012-02-14 HIGH 9.3 CVE-2012-0015EPSS 24% Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly calculate the length of an unspecified buffer, which allows remote attackers to execute … .net Framework Mitigation only Fix from $1,9502012-02-14 HIGH 9.3 CVE-2012-0019EPSS 20% Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitr… Visio Viewer Mitigation only Fix from $1,9502012-02-14