Vulnerability index

Browse CVEs

1,648 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Flash Player HIGH 7.8
CVE-2014-9163 KEVEPSS 20%

Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425 o…

Fix: 11.2.202.425 / 13.0.0.259+
Fix from $1,950 2014-12-10
Flash Player HIGH 8.8
CVE-2014-8439 KEVEPSS 20%

Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.…

Fix: 15.0.0.302+
Fix from $1,950 2014-11-25
Windows 7 HIGH 8.8
CVE-2014-6324 KEVEPSS 87%

The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1…

Patch available
Fix from $1,950 2014-11-18
Windows 7 HIGH 8.8
CVE-2014-6332 KEVEPSS 95%

OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.…

Patch available
Fix from $1,950 2014-11-11
Office 2007 Ime HIGH 7.8
CVE-2014-4077 KEVEPSS 48%

Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka I…

Patch available
Fix from $1,950 2014-11-11
Windows 7 HIGH 7.8
CVE-2014-6352 KEVEPSS 78%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows …

Patch available
Fix from $1,950 2014-10-22
Windows 7 HIGH 8.8
CVE-2014-4148 KEVEPSS 60%

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Win…

Patch available
Fix from $1,950 2014-10-15
Internet Explorer HIGH 8.8
CVE-2014-4123 KEVEPSS 47%

Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privi…

Patch available
Fix from $1,950 2014-10-15
Windows 7 HIGH 7.8
CVE-2014-4114 KEVEPSS 82%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows …

Patch available
Fix from $1,950 2014-10-15
Windows 7 HIGH 7.8
CVE-2014-4113 KEVEPSS 87%

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Win…

Patch available
Fix from $1,950 2014-10-15
Http File Server CRITICAL 9.8
CVE-2014-6287 KEVEPSS 99%

The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to exe…

Fix: 2.3c+
Fix from $2,300 2014-10-07
Bash HIGH 8.8
CVE-2014-6278 KEVEPSS 100%

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to…

Patch available
Fix from $1,950 2014-09-30
Linux CRITICAL 9.8
CVE-2014-7169 KEVEPSS 100%

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which…

Patch available
Fix from $2,300 2014-09-25
Linux CRITICAL 9.8
CVE-2014-6271 KEVEPSS 100%

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to e…

Patch available
Fix from $2,300 2014-09-24
Iphone Os HIGH 7.8
CVE-2014-4404 KEVEPSS 49%

Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged cont…

Fix: 7.0 / 8.0+
Fix from $1,950 2014-09-18
Android Msm HIGH 8.4
CVE-2013-2597 KEV

Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualco…

Mitigation only
Fix from $1,950 2014-08-31
Internet Explorer HIGH 8.8
CVE-2014-2817 KEVEPSS 26%

Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privi…

Patch available
Fix from $1,950 2014-08-12
Acrobat CRITICAL 9.8
CVE-2014-0546 KEVEPSS 22%

Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and consequ…

Fix: 10.1.11 / 11.0.08+
Fix from $2,300 2014-08-12
Elasticsearch HIGH 8.1
CVE-2014-3120 KEVEPSS 89%

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions …

Fix: 1.2.0+
Fix from $1,950 2014-07-28
Infosphere Biginsights MEDIUM 6.5
CVE-2013-3993 KEVEPSS 5%

IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted d…

Fix: 2.1.0.3+
Fix from $1,600 2014-07-07
Linux Kernel HIGH 7.8
CVE-2014-3153 KEVEPSS 37%

The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which …

Fix: 3.2.60 / 3.4.92+
Fix from $1,950 2014-06-07
Windows 7 HIGH 8.8
CVE-2014-1812 KEVEPSS 65%

The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Window…

Patch available
Fix from $1,950 2014-05-14
Linux Kernel MEDIUM 5.5
CVE-2014-0196 KEVEPSS 22%

The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST"…

Fix: 3.2.59 / 3.4.91+
Fix from $1,600 2014-05-07
Subscription Asset Manager HIGH 7.5
CVE-2014-0130 KEVEPSS 54%

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18,…

Fix: 3.2.18 / 4.0.5+
Fix from $1,950 2014-05-07
Internet Explorer CRITICAL 9.8
CVE-2014-1776 KEVEPSS 88%

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of servi…

Patch available
Fix from $2,300 2014-04-27
Web Studio CRITICAL 9.8
CVE-2014-0780 KEVEPSS 75%

Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwor…

Patch available
Fix from $2,300 2014-04-25
OpenSSL HIGH 7.5
CVE-2014-0160 KEVEPSS 100%

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attac…

Fix: 1.0.1g+
Fix from $1,950 2014-04-07
Office HIGH 7.8
CVE-2014-1761 KEVEPSS 77%

Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automat…

Patch available
Fix from $1,950 2014-03-25
Adaptive Security Appliance Software MEDIUM 6.1
CVE-2014-2120 KEVEPSS 19%

Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inje…

Mitigation only
Fix from $1,600 2014-03-19
Internet Explorer MEDIUM 6.5
CVE-2013-7331 KEVEPSS 58%

The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC …

Patch available
Fix from $1,600 2014-02-26