Vulnerability index

Browse CVEs

1,649 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Internet Explorer MEDIUM 6.5
CVE-2013-7331 KEVEPSS 58%

The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC …

Patch available
Fix from $1,600 2014-02-26
Enterprise Linux Desktop HIGH 8.8
CVE-2014-0502 KEVEPSS 24%

Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.…

Fix: 4.0.0.1628 / 11.2.202.341+
Fix from $1,950 2014-02-21
Internet Explorer HIGH 8.8
CVE-2014-0322 KEVEPSS 85%

Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted …

Patch available
Fix from $1,950 2014-02-14
Chrome CRITICAL 9.8
CVE-2014-0497 KEVEPSS 100%

Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.3…

Fix: 11.2.202.336 / 11.7.700.261+
Fix from $2,300 2014-02-05
Acrobat HIGH 8.8
CVE-2014-0496 KEVEPSS 40%

Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X allows attackers to execu…

Fix: 10.1.9 / 11.0.6+
Fix from $1,950 2014-01-15
Windows 10 1507 MEDIUM 5.5
CVE-2013-3900 KEVEPSS 45%

Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table an…

Patch available
Fix from $1,600 2013-12-11
Windows 2003 Server HIGH 7.8
CVE-2013-5065 KEVEPSS 35%

NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as…

Patch available
Fix from $1,950 2013-11-28
Linux Kernel HIGH 8.8
CVE-2013-6282 KEVEPSS 40%

The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, w…

Fix: 3.2.54 / 3.4.12+
Fix from $1,950 2013-11-20
Dsl 2760u Firmware MEDIUM 5.4
CVE-2013-5223 KEVEPSS 34%

Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web sc…

Fix: 1.12+
Fix from $1,600 2013-11-19
Windows 7 HIGH 8.8
CVE-2013-3918 KEVEPSS 74%

The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2,…

Patch available
Fix from $1,950 2013-11-12
Excel Viewer HIGH 7.8
CVE-2013-3906 KEVEPSS 85%

GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 201…

Patch available
Fix from $1,950 2013-11-06
Internet Explorer HIGH 8.8
CVE-2013-3897 KEVEPSS 77%

Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execut…

Patch available
Fix from $1,950 2013-10-09
Silverlight MEDIUM 5.5
CVE-2013-3896 KEVEPSS 70%

Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, which allows remote attackers t…

Fix: 5.1.20913.0+
Fix from $1,600 2013-10-09
Internet Explorer HIGH 8.8
CVE-2013-3893 KEVEPSS 86%

Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers …

Mitigation only
Fix from $1,950 2013-09-18
Application Lifecycle Management CRITICAL 9.8
CVE-2013-4810 KEVEPSS 79%

HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attac…

Mitigation only
Fix from $2,300 2013-09-16
Acrobat CRITICAL 9.8
CVE-2013-3346 KEVEPSS 79%

Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of…

Fix: 9.5.5 / 10.1.7+
Fix from $2,300 2013-08-30
Archiva CRITICAL 9.8
CVE-2013-2251 KEVEPSS 100%

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redi…

Fix: 1.3.8+
Fix from $2,300 2013-07-20
Internet Explorer HIGH 8.8
CVE-2013-3163 KEVEPSS 71%

Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a cra…

Patch available
Fix from $1,950 2013-07-10
Firefox HIGH 8.8
CVE-2013-1690 KEVEPSS 69%

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle…

Fix: 17.0.7 / 22.0+
Fix from $1,950 2013-06-26
Jre CRITICAL 9.8
CVE-2013-2465 KEVEPSS 99%

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0…

Patch available
Fix from $2,300 2013-06-18
Office HIGH 7.8
CVE-2013-1331 KEVEPSS 82%

Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Off…

Patch available
Fix from $1,950 2013-06-12
Windows 7 HIGH 7.8
CVE-2013-3660 KEVEPSS 40%

The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows V…

Patch available
Fix from $1,950 2013-05-24
Enterprise Linux Desktop CRITICAL 9.8
CVE-2013-2729 KEVEPSS 67%

Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code…

Fix: 9.5.5 / 10.1.7+
Fix from $2,300 2013-05-16
Firefox MEDIUM 6.5
CVE-2013-1675 KEVEPSS 7%

Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initia…

Fix: 17.0.6 / 21.0+
Fix from $1,600 2013-05-16
Linux Kernel HIGH 8.4
CVE-2013-2094 KEVEPSS 48%

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users…

Fix: 3.0.75 / 3.2.45+
Fix from $1,950 2013-05-14
Internet Explorer HIGH 8.8
CVE-2013-1347 KEVEPSS 78%

Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an obj…

Patch available
Fix from $1,950 2013-05-05
Linux Kernel HIGH 7.8
CVE-2013-2596 KEV

Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.…

Fix: 3.0.75 / 3.2.45+
Fix from $1,950 2013-04-13
Silverlight HIGH 7.8
CVE-2013-0074 KEVEPSS 82%

Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows r…

Fix: 5.1.20125.0+
Fix from $1,950 2013-03-13
Internet Explorer HIGH 8.8
CVE-2013-2551 KEVEPSS 74%

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site tha…

Patch available
Fix from $1,950 2013-03-11
Enterprise Linux Desktop HIGH 8.8
CVE-2013-0648 KEVEPSS 11%

Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 o…

Fix: 10.3.183.67 / 11.2.202.273+
Fix from $1,950 2013-02-27