Vulnerability index

Browse CVEs

1,648 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2014-9163 KEVEPSS 20% Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425 o… Flash Player 11.2.202.425 / 13.0.0.259+ Fix from $1,9502014-12-10 HIGH 8.8 CVE-2014-8439 KEVEPSS 20% Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.… Flash Player 15.0.0.302+ Fix from $1,9502014-11-25 HIGH 8.8 CVE-2014-6324 KEVEPSS 87% The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1… Windows 7 Patch available Fix from $1,9502014-11-18 HIGH 8.8 CVE-2014-6332 KEVEPSS 95% OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.… Windows 7 Patch available Fix from $1,9502014-11-11 HIGH 7.8 CVE-2014-4077 KEVEPSS 48% Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka I… Office 2007 Ime Patch available Fix from $1,9502014-11-11 HIGH 7.8 CVE-2014-6352 KEVEPSS 78% Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows … Windows 7 Patch available Fix from $1,9502014-10-22 HIGH 8.8 CVE-2014-4148 KEVEPSS 60% win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Win… Windows 7 Patch available Fix from $1,9502014-10-15 HIGH 8.8 CVE-2014-4123 KEVEPSS 47% Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privi… Internet Explorer Patch available Fix from $1,9502014-10-15 HIGH 7.8 CVE-2014-4114 KEVEPSS 82% Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows … Windows 7 Patch available Fix from $1,9502014-10-15 HIGH 7.8 CVE-2014-4113 KEVEPSS 87% win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Win… Windows 7 Patch available Fix from $1,9502014-10-15 CRITICAL 9.8 CVE-2014-6287 KEVEPSS 99% The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to exe… Http File Server 2.3c+ Fix from $2,3002014-10-07 HIGH 8.8 CVE-2014-6278 KEVEPSS 100% GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to… Bash Patch available Fix from $1,9502014-09-30 CRITICAL 9.8 CVE-2014-7169 KEVEPSS 100% GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which… Linux Patch available Fix from $2,3002014-09-25 CRITICAL 9.8 CVE-2014-6271 KEVEPSS 100% GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to e… Linux Patch available Fix from $2,3002014-09-24 HIGH 7.8 CVE-2014-4404 KEVEPSS 49% Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged cont… Iphone Os 7.0 / 8.0+ Fix from $1,9502014-09-18 HIGH 8.4 CVE-2013-2597 KEV Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualco… Android Msm Mitigation only Fix from $1,9502014-08-31 HIGH 8.8 CVE-2014-2817 KEVEPSS 26% Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privi… Internet Explorer Patch available Fix from $1,9502014-08-12 CRITICAL 9.8 CVE-2014-0546 KEVEPSS 22% Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and consequ… Acrobat 10.1.11 / 11.0.08+ Fix from $2,3002014-08-12 HIGH 8.1 CVE-2014-3120 KEVEPSS 89% The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions … Elasticsearch 1.2.0+ Fix from $1,9502014-07-28 MEDIUM 6.5 CVE-2013-3993 KEVEPSS 5% IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted d… Infosphere Biginsights 2.1.0.3+ Fix from $1,6002014-07-07 HIGH 7.8 CVE-2014-3153 KEVEPSS 37% The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which … Linux Kernel 3.2.60 / 3.4.92+ Fix from $1,9502014-06-07 HIGH 8.8 CVE-2014-1812 KEVEPSS 65% The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Window… Windows 7 Patch available Fix from $1,9502014-05-14 MEDIUM 5.5 CVE-2014-0196 KEVEPSS 22% The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST"… Linux Kernel 3.2.59 / 3.4.91+ Fix from $1,6002014-05-07 HIGH 7.5 CVE-2014-0130 KEVEPSS 54% Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18,… Subscription Asset Manager 3.2.18 / 4.0.5+ Fix from $1,9502014-05-07 CRITICAL 9.8 CVE-2014-1776 KEVEPSS 88% Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of servi… Internet Explorer Patch available Fix from $2,3002014-04-27 CRITICAL 9.8 CVE-2014-0780 KEVEPSS 75% Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwor… Web Studio Patch available Fix from $2,3002014-04-25 HIGH 7.5 CVE-2014-0160 KEVEPSS 100% The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attac… OpenSSL 1.0.1g+ Fix from $1,9502014-04-07 HIGH 7.8 CVE-2014-1761 KEVEPSS 77% Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automat… Office Patch available Fix from $1,9502014-03-25 MEDIUM 6.1 CVE-2014-2120 KEVEPSS 19% Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inje… Adaptive Security Appliance Software Mitigation only Fix from $1,6002014-03-19 MEDIUM 6.5 CVE-2013-7331 KEVEPSS 58% The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC … Internet Explorer Patch available Fix from $1,6002014-02-26