Vulnerability index

Browse CVEs

1,649 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux Desktop HIGH 8.8
CVE-2013-0643 KEVEPSS 11%

The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x be…

Fix: 10.3.183.67 / 11.2.202.273+
Fix from $1,950 2013-02-27
Enterprise Linux Desktop HIGH 7.8
CVE-2013-0641 KEVEPSS 32%

Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute arbitrar…

Fix: 9.5.4 / 10.1.6+
Fix from $1,950 2013-02-14
Enterprise Linux Desktop HIGH 7.8
CVE-2013-0640 KEVEPSS 87%

Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a de…

Fix: 9.5.4 / 10.1.6+
Fix from $1,950 2013-02-14
Openjdk MEDIUM 5.3
CVE-2013-0431 KEVEPSS 90%

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted …

Mitigation only
Fix from $1,600 2013-01-31
Coldfusion CRITICAL 9.8
CVE-2013-0632 KEVEPSS 94%

administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code …

Mitigation only
Fix from $2,300 2013-01-17
Ubuntu Linux CRITICAL 9.8
CVE-2013-0422 KEVEPSS 98%

Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantia…

Mitigation only
Fix from $2,300 2013-01-10
Coldfusion HIGH 7.5
CVE-2013-0631 KEVEPSS 66%

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2 allows attackers to obtain sensitive information via unspecified vectors, as exploited in the wild in January …

Mitigation only
Fix from $1,950 2013-01-09
Coldfusion HIGH 7.5
CVE-2013-0629 KEVEPSS 66%

Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified vect…

Mitigation only
Fix from $1,950 2013-01-09
Coldfusion CRITICAL 9.8
CVE-2013-0625 KEVEPSS 94%

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbi…

Mitigation only
Fix from $2,300 2013-01-09
Internet Explorer HIGH 8.8
CVE-2012-4792 KEVEPSS 79%

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that…

Patch available
Fix from $1,950 2012-12-30
Office Compatibility Pack HIGH 7.8
CVE-2012-2539 KEVEPSS 53%

Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remot…

Patch available
Fix from $1,950 2012-12-12
Fusion Middleware CRITICAL 9.1
CVE-2012-3152 KEVEPSS 99%

Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attack…

Patch available
Fix from $2,300 2012-10-16
Jre CRITICAL 9.8
CVE-2012-5076 KEVEPSS 91%

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect …

Patch available
Fix from $2,300 2012-10-16
Flash Player HIGH 8.8
CVE-2012-5054 KEVEPSS 21%

Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbit…

Fix: 11.4.402.265+
Fix from $1,950 2012-09-24
Internet Explorer HIGH 8.1
CVE-2012-4969 KEVEPSS 82%

Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to exec…

Patch available
Fix from $1,950 2012-09-18
Enterprise Linux Desktop CRITICAL 9.8
CVE-2012-4681 KEVEPSS 99%

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute a…

Mitigation only
Fix from $2,300 2012-08-28
Enterprise Linux Desktop HIGH 7.8
CVE-2012-1535 KEVEPSS 70%

Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers …

Fix: 11.2.202.238 / 11.3.300.271+
Fix from $1,950 2012-08-15
Commerce Server HIGH 8.8
CVE-2012-1856 KEVEPSS 62%

The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and…

Patch available
Fix from $1,950 2012-08-15
Office HIGH 7.8
CVE-2012-1854 KEVEPSS 21%

Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for App…

Mitigation only
Fix from $1,950 2012-07-10
Icedtea6 CRITICAL 9.8
CVE-2012-1723 KEVEPSS 94%

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update…

Fix: 1.10.8 / 1.11.3+
Fix from $2,300 2012-06-16
Xml Core Services HIGH 8.8
CVE-2012-1889 KEVEPSS 84%

Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code o…

Patch available
Fix from $1,950 2012-06-13
Enterprise Linux Desktop HIGH 7.5
CVE-2012-2034 KEVEPSS 8%

Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux;…

Fix: after 11.2.202.235
Fix from $1,950 2012-06-09
Debian Linux CRITICAL 9.8
CVE-2012-0507 KEVEPSS 98%

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 …

Mitigation only
Fix from $2,300 2012-06-07
PHP CRITICAL 9.8
CVE-2012-1823 KEVEPSS 100%

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query string…

Fix: 5.3.12 / 5.4.2+
Fix from $2,300 2012-05-11
Fusion Middleware CRITICAL 9.8
CVE-2012-1710 KEVEPSS 12%

Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect …

Patch available
Fix from $2,300 2012-05-03
Office HIGH 8.8
CVE-2012-0158 KEVEPSS 100%

The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3…

Patch available
Fix from $1,950 2012-04-10
Windows 7 HIGH 7.8
CVE-2012-0151 KEVEPSS 84%

The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008…

Patch available
Fix from $1,950 2012-04-10
Flash Player MEDIUM 6.1
CVE-2012-0767 KEVEPSS 7%

Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solari…

Fix: 10.3.183.15 / 11.1.102.62+
Fix from $1,600 2012-02-16
Flash Player HIGH 8.1
CVE-2012-0754 KEVEPSS 92%

Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x;…

Fix: 10.3.183.15 / 11.1.102.62+
Fix from $1,950 2012-02-16
Struts CRITICAL 9.8
CVE-2012-0391 KEVEPSS 76%

The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling fo…

Fix: 2.2.3.1+
Fix from $2,300 2012-01-08