Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
MEDIUM 5.0
CVE-2013-4282
Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service …
Enterprise Virtualization
Patch available
MEDIUM 5.2
CVE-2013-4416
The Ocaml xenstored implementation (oxenstored) in Xen 4.1.x, 4.2.x, and 4.3.x allows local guest domains to cause a denial of service (domain shutdo…
Xen
Mitigation only
MEDIUM 5.0
CVE-2013-6075
The compare_dn function in utils/identification.c in strongSwan 4.3.3 through 5.1.1 allows (1) remote attackers to cause a denial of service (out-of-…
Strongswan
Patch available
MEDIUM 6.3
CVE-2013-5551
Cisco Adaptive Security Appliance (ASA) Software, when certain same-security-traffic and management-access options are enabled, allows remote authent…
Adaptive Security Appliance Software
Mitigation only
MEDIUM 5.0
CVE-2013-4484
Varnish before 3.0.5 allows remote attackers to cause a denial of service (child-process crash and temporary caching outage) via a GET request with t…
Varnish
after 3.0.4
MEDIUM 6.8
CVE-2013-5596
The cycle collection (CC) implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before …
Firefox
after 24.0.1
HIGH 10.0
CVE-2013-5602EPSS 5%
The Worker::SetEventListener function in the Web workers implementation in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x befo…
Firefox
after 24.0.1
HIGH 9.3
CVE-2013-5604EPSS 6%
The txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1,…
Firefox
after 24.0.1
MEDIUM 6.8
CVE-2010-1159EPSS 7%
Multiple heap-based buffer overflows in Aircrack-ng before 1.1 allow remote attackers to cause a denial of service (crash) and execute arbitrary code…
Linux
after 1.0
MEDIUM 6.8
CVE-2012-6303EPSS 10%
Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in WaveSurfer 1.8.8p4, allows re…
Snack Sound Toolkit
No fix yet
MEDIUM 6.8
CVE-2013-5914
Buffer overflow in the ssl_read_record function in ssl_tls.c in PolarSSL before 1.1.8, when using TLS 1.1, might allow remote attackers to execute ar…
Polarssl
after 1.1.7
MEDIUM 6.8
CVE-2013-5170
Buffer underflow in CoreGraphics in Apple Mac OS X before 10.9 allows remote attackers to execute arbitrary code or cause a denial of service (applic…
Mac Os X
after 10.8.5
HIGH 8.5
CVE-2013-6027
Stack-based buffer overflow in the RuntimeDiagnosticPing function in /bin/webs on D-Link DIR-100 routers might allow remote authenticated administrat…
Dir 100
No fix yet
HIGH 9.3
CVE-2013-6021EPSS 12%
Buffer overflow in WGagent in WatchGuard WSM and Fireware before 11.8 allows remote attackers to execute arbitrary code via a long sessionid value in…
Fireware
after 11.7.4
MEDIUM 5.0
CVE-2013-2254
The deepGetOrCreateNode function in impl/operations/AbstractCreateOperation.java in org.apache.sling.servlets.post.bundle 2.2.0 and 2.3.0 in Apache S…
Org.apache.sling.servlets.post
Patch available
MEDIUM 6.8
CVE-2013-6013
Buffer overflow in the flow daemon (flowd) in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R7-S2, 12.1.X44 before 12.1X44-D15, 12.1X45 before 1…
Junos
after 10.4
HIGH 7.1
CVE-2013-5513
Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(7), 8.5.x before 8.5(1.18), 8.6.x b…
Adaptive Security Appliance Software
Mitigation only
HIGH 7.8
CVE-2013-5515
The Clientless SSL VPN feature in Cisco Adaptive Security Appliance (ASA) Software 8.x before 8.2(5.44), 8.3.x before 8.3(2.39), 8.4.x before 8.4(5.7…
Adaptive Security Appliance Software
Mitigation only
HIGH 7.8
CVE-2013-3415
Cisco Adaptive Security Appliance (ASA) Software 8.4.x before 8.4(3) and 8.6.x before 8.6(1.3) does not properly manage memory upon an AnyConnect SSL…
Adaptive Security Appliance Software
Mitigation only
MEDIUM 6.9
CVE-2012-4709
Invensys Wonderware InTouch HMI 2012 R2 and earlier allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause…
Wonderware Intouch
after 2012
MEDIUM 6.8
CVE-2013-4388
Buffer overflow in the mp4a packetizer (modules/packetizer/mpeg4audio.c) in VideoLAN VLC Media Player before 2.0.8 allows remote attackers to cause a…
Vlc Media Player
after 2.0.7
HIGH 7.2
CVE-2013-6079
Buffer overflow in MostGear Soft Easy LAN Folder Share 3.2.0.100 allows local users to cause a denial of service (application crash) and possibly exe…
Easy Lan Folder Share
No fix yet
MEDIUM 6.1
CVE-2013-4387
net/ipv6/ip6_output.c in the Linux kernel through 3.11.4 does not properly determine the need for UDP Fragmentation Offload (UFO) processing of small…
Linux Kernel
after 3.11.4
MEDIUM 5.1
CVE-2012-4424
Stack-based buffer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-dependent attackers to ca…
Glibc
after 2.17
MEDIUM 6.8
CVE-2013-4237
sysdeps/posix/readdir_r.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allows context-dependent attackers to cause a denial of service …
Glibc
after 2.18
HIGH 7.5
CVE-2013-4385
Buffer overflow in the "read-string!" procedure in the "extras" unit in CHICKEN stable before 4.8.0.5 and development snapshots before 4.8.3 allows r…
Chicken
after 4.8.0.4
HIGH 10.0
CVE-2013-5327
MDBMS.dll in Adobe RoboHelp 10 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Robohelp
Patch available
HIGH 9.3
CVE-2013-3889EPSS 27%
Microsoft Excel 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office for Mac 2011; Excel Viewe…
Excel
Mitigation only
HIGH 9.3
CVE-2013-3890EPSS 20%
Microsoft Excel 2007 SP3, Excel Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office docum…
Excel
Mitigation only
HIGH 9.3
CVE-2013-3891EPSS 19%
Microsoft Word 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Memory Corruption Vulnerability."
Word
Mitigation only