Vulnerability index

Browse CVEs

1,649 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dir 300 Firmware MEDIUM 5.7
CVE-2011-4723 KEV

The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecified vector…

Mitigation only
Fix from $1,600 2011-12-20
Acrobat CRITICAL 9.8
CVE-2011-2462 KEVEPSS 87%

Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9…

Fix: after 10.1.1
Fix from $2,300 2011-12-07
Windows 7 HIGH 8.8
CVE-2011-3402 KEVEPSS 78%

Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows S…

Mitigation only
Fix from $1,950 2011-11-04
Ubuntu Linux CRITICAL 9.8
CVE-2011-3544 KEVEPSS 97%

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrust…

Fix: 1.6.0+
Fix from $2,300 2011-10-19
Windows Server 2003 HIGH 7.8
CVE-2011-2005 KEVEPSS 32%

afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed to…

Patch available
Fix from $1,950 2011-10-12
Forefront Threat Management Gateway CRITICAL 9.8
CVE-2011-1889 KEVEPSS 48%

The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitr…

Patch available
Fix from $2,300 2011-06-16
Android HIGH 7.8
CVE-2011-1823 KEVEPSS 42%

The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local use…

Fix: 2.3.4+
Fix from $1,950 2011-06-09
Chrome HIGH 8.8
CVE-2011-0611 KEVEPSS 94%

Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; an…

Fix: 2.6.19140 / 9.4+
Fix from $1,950 2011-04-13
Chrome HIGH 7.8
CVE-2011-0609 KEVEPSS 67%

Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android;…

Fix: 10.0.648.134+
Fix from $1,950 2011-03-15
Debian Linux HIGH 7.8
CVE-2010-4345 KEVEPSS 18%

Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration …

Fix: after 4.72
Fix from $1,950 2010-12-14
Debian Linux CRITICAL 9.8
CVE-2010-4344 KEVEPSS 72%

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SM…

Fix: 4.70+
Fix from $2,300 2010-12-14
Linux Kernel HIGH 7.8
CVE-2010-3904 KEVEPSS 12%

The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 do…

Fix: 2.6.36+
Fix from $1,950 2010-12-06
Windows 7 HIGH 7.8
CVE-2010-4398 KEVEPSS 9%

Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Window…

Patch available
Fix from $1,950 2010-12-06
Office HIGH 7.8
CVE-2010-3333 KEVEPSS 89%

Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2…

Patch available
Fix from $1,950 2010-11-10
Powerpoint HIGH 7.8
CVE-2010-2572 KEVEPSS 63%

Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document,…

Patch available
Fix from $1,950 2010-11-10
Internet Explorer HIGH 8.1
CVE-2010-3962 KEVEPSS 96%

Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Casc…

Patch available
Fix from $1,950 2010-11-05
Firefox CRITICAL 9.8
CVE-2010-3765 KEVEPSS 83%

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.1…

Mitigation only
Fix from $2,300 2010-10-28
Acrobat HIGH 7.3
CVE-2010-2883 KEVEPSS 82%

Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote a…

Fix: 8.2.5 / 9.4+
Fix from $1,950 2010-09-09
Ios Xr HIGH 7.5
CVE-2010-3035 KEVEPSS 6%

Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to …

Fix: after 3.9.1
Fix from $1,950 2010-08-30
Coldfusion CRITICAL 9.8
CVE-2010-2861 KEVEPSS 100%

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitr…

Fix: after 9.0.1
Fix from $2,300 2010-08-11
Jboss Enterprise Application Platform HIGH 8.8
CVE-2010-1871 KEVEPSS 83%

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Exp…

Mitigation only
Fix from $1,950 2010-08-05
Windows 7 HIGH 7.8
CVE-2010-2568 KEVEPSS 91%

Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote att…

Patch available
Fix from $1,950 2010-07-22
Air HIGH 7.8
CVE-2010-1297 KEVEPSS 82%

Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x …

Fix: 2.0.2.12610 / 8.2.3+
Fix from $1,950 2010-06-08
Jboss Enterprise Application Platform HIGH 7.5
CVE-2010-1428 KEVEPSS 62%

The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 …

Mitigation only
Fix from $1,950 2010-04-28
Jboss Enterprise Application Platform MEDIUM 5.3
CVE-2010-0738 KEVEPSS 79%

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 be…

Mitigation only
Fix from $1,600 2010-04-28
Ubuntu Linux CRITICAL 9.8
CVE-2010-0840 KEVEPSS 96%

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 …

Patch available
Fix from $2,300 2010-04-01
Internet Explorer HIGH 8.8
CVE-2010-0806 KEVEPSS 82%

Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers t…

Patch available
Fix from $1,950 2010-03-10
Acrobat HIGH 7.8
CVE-2010-0188 KEVEPSS 88%

Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (applicatio…

Fix: 8.2.1 / 9.3.1+
Fix from $1,950 2010-02-22
Blazeds MEDIUM 6.5
CVE-2009-3960 KEVEPSS 90%

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex…

Fix: after 3.2
Fix from $1,600 2010-02-15
Windows 2000 HIGH 7.8
CVE-2010-0232 KEVEPSS 29%

The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista …

Patch available
Fix from $1,950 2010-01-21