Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 6.8 CVE-2011-3007 The myCIOScn ActiveX control (myCIOScn.dll) in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to write to arbitrary files … Saas Endpoint Protection after 5.2.1 Fix from $1,6002011-08-10 MEDIUM 6.8 CVE-2011-2964 foomaticrip.c in foomatic-rip in foomatic-filters in Foomatic 4.0.6 allows remote attackers to execute arbitrary code via a crafted *FoomaticRIPComma… Foomatic Patch available Fix from $1,6002011-07-29 HIGH 9.3 CVE-2011-2747 Google Picasa before 3.6 Build 105.67 does not properly handle invalid properties in JPEG images, which allows remote attackers to execute arbitrary … Picasa after 3.6_build_105.65 Fix from $1,9502011-07-28 MEDIUM 5.8 CVE-2011-2752 CRLF injection vulnerability in SquirrelMail 1.4.21 and earlier allows remote attackers to modify or add preference values via a \n (newline) charact… Squirrelmail after 1.4.21 Fix from $1,6002011-07-17 MEDIUM 6.4 CVE-2011-2505EPSS 13% libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns val… phpMyAdmin Patch available Fix from $1,6002011-07-14 HIGH 7.5 CVE-2011-2506EPSS 10% setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restrict the presence of comment clo… phpMyAdmin Patch available Fix from $1,9502011-07-14 MEDIUM 6.5 CVE-2011-2507 libraries/server_synchronize.lib.php in the Synchronize implementation in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly q… phpMyAdmin Patch available Fix from $1,6002011-07-14 HIGH 8.8 CVE-2011-1265EPSS 6% The Bluetooth Stack 2.1 in Microsoft Windows Vista SP1 and SP2 and Windows 7 Gold and SP1 does not prevent access to objects in memory that (1) were … Bluetooth Stack Patch available Fix from $1,9502011-07-13 HIGH 7.5 CVE-2010-4810 Multiple PHP remote file inclusion vulnerabilities in AR Web Content Manager (AWCM) 2.1 final allow remote attackers to execute arbitrary PHP code vi… Ar Web Content Manager No fix yet Fix from $1,9502011-07-08 HIGH 9.3 CVE-2011-2101EPSS 7% Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X do not properly restrict script, which allows… Acrobat Reader Patch available Fix from $1,9502011-06-16 HIGH 7.5 CVE-2011-1863 HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allow remote authenticated users to conduct unspecified script injection attac… Service Center Mitigation only Fix from $1,9502011-06-14 HIGH 7.2 CVE-2011-1760 utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to conduct eval injection attacks and gain privileges via shell metacharacters … Oprofile after 0.9.6 Fix from $1,9502011-06-09 HIGH 9.3 CVE-2011-2386EPSS 45% VisiWaveReport.exe in AZO Technologies, Inc. VisiWave Site Survey before 2.1.9 allows user-assisted remote attackers to execute arbitrary code via a … Site Survey after 2.1 Fix from $1,9502011-06-08 HIGH 9.0 CVE-2011-1646 The web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N … Rvs4000 Mitigation only Fix from $1,9502011-05-31 MEDIUM 6.8 CVE-2010-2789 PHP remote file inclusion vulnerability in MediaWikiParserTest.php in MediaWiki 1.16 beta, when register_globals is enabled, allows remote attackers … Mediawiki Patch available Fix from $1,6002011-04-27 HIGH 9.3 CVE-2011-0386 The XML-RPC implementation on Cisco TelePresence Recording Server devices with software 1.6.x and 1.7.x before 1.7.1 allows remote attackers to overw… Telepresence Recording Server Software Mitigation only Fix from $1,9502011-02-25 HIGH 10.0 CVE-2011-0364EPSS 20% The Management Console (webagent.exe) in Cisco Security Agent 5.1, 5.2, and 6.0 before 6.0.2.145 allows remote attackers to create arbitrary files an… Security Agent Mitigation only Fix from $1,9502011-02-19 HIGH 9.0 CVE-2010-4732 cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom … Netbiter Easyconnect Ec150 No fix yet Fix from $1,9502011-02-15 HIGH 9.3 CVE-2011-0092EPSS 24% The LZW stream decompression functionality in ORMELEMS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 allows remote attackers to execute arb… Visio Mitigation only Fix from $1,9502011-02-10 HIGH 9.3 CVE-2011-0093EPSS 20% ELEMENTS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 does not properly parse structures during the opening of a Visio file, which allows … Visio Mitigation only Fix from $1,9502011-02-10 HIGH 8.5 CVE-2010-3719EPSS 13% Eval injection vulnerability in IMAdminSchedTask.asp in the administrative interface for Symantec IM Manager 8.4.16 and earlier allows remote attacke… Im Manager after 8.4.16 Fix from $1,9502011-02-02 MEDIUM 6.0 CVE-2011-0635 Static code injection vulnerability in Simploo CMS 1.7.1 and earlier allows remote authenticated users to inject arbitrary PHP code into config/custo… Simploo Cms after 1.7.1 Fix from $1,6002011-01-22 HIGH 9.3 CVE-2011-0487 ICQ 7 does not verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a crafted file that is fetc… Icq Mitigation only Fix from $1,9502011-01-18 HIGH 9.3 CVE-2010-3973EPSS 72% The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in Microsoft Windows XP SP2 and … Wmi Administrative Tools after 1.1 Fix from $1,9502010-12-23 HIGH 9.3 CVE-2010-4588EPSS 33% The WBEMSingleView.ocx ActiveX control 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier allows remote attackers to execute arbitrary… Wmi Administrative Tools after 1.1 Fix from $1,9502010-12-23 HIGH 7.5 CVE-2010-4558 phpMyFAQ 2.6.11 and 2.6.12, as distributed between December 4th and December 15th 2010, contains an externally introduced modification (Trojan Horse)… Phpmyfaq Patch available Fix from $1,9502010-12-17 HIGH 9.3 CVE-2010-3955EPSS 19% pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3 does not properly perform array indexing, which allows remote attackers… Publisher Mitigation only Fix from $1,9502010-12-16 HIGH 9.3 CVE-2010-3956EPSS 8% The OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2… Windows 2003 Server Mitigation only Fix from $1,9502010-12-16 MEDIUM 6.9 CVE-2010-3959EPSS 14% The OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2… Windows 2003 Server Mitigation only Fix from $1,6002010-12-16 HIGH 9.3 CVE-2010-2569EPSS 21% pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3, 2003 SP3, and 2007 SP2 does not properly handle an unspecified size fi… Publisher Mitigation only Fix from $1,9502010-12-16