Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2016-5759
The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root.
Suse Linux Enterprise Desktop
Mitigation only
MEDIUM 5.3
CVE-2017-12217
A vulnerability in the General Packet Radio Service (GPRS) Tunneling Protocol ingress packet handler of Cisco ASR 5500 System Architecture Evolution …
Asr 5500 Firmware
Mitigation only
MEDIUM 5.8
CVE-2017-12218
A vulnerability in the malware detection functionality within Advanced Malware Protection (AMP) of Cisco AsyncOS Software for Cisco Email Security Ap…
Asyncos
Mitigation only
MEDIUM 6.4
CVE-2017-12223
A vulnerability in the ROM Monitor (ROMMON) code of Cisco IR800 Integrated Services Router Software could allow an unauthenticated, local attacker to…
Ir800 Integrated Services Router Firmware
Mitigation only
MEDIUM 6.5
CVE-2017-6792
A vulnerability in the batch provisioning feature in Cisco Prime Collaboration Provisioning Tool could allow an authenticated, remote attacker to ove…
Prime Collaboration Provisioning
Mitigation only
MEDIUM 6.7
CVE-2017-6794
A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and…
Meeting Server
Mitigation only
HIGH 8.8
CVE-2017-14169
In the mxf_read_primer_pack function in libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, an integer signedness error might occur when a crafted file, whi…
Debian Linux
Patch available
HIGH 8.8
CVE-2015-0853
svn-workbench 1.6.2 and earlier on a system with xeyes installed allows local users to execute arbitrary commands by using the "Command Shell" menu i…
Svn Workbench
after 1.6.2
MEDIUM 5.3
CVE-2015-5186
Audit before 2.4.4 in Linux does not sanitize escape characters in filenames.
Linux Audit
after 2.4.3
HIGH 7.5
CVE-2017-14098EPSS 47%
In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, or Contact…
Asterisk
Patch available
HIGH 7.5
CVE-2017-12874
The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature valid…
Debian Linux
Patch available
HIGH 7.8
CVE-2017-14105
HiveManager Classic through 8.1r1 allows arbitrary JSP code execution by modifying a backup archive before a restore, because the restore feature doe…
Hivemanager Classic
Patch available
HIGH 7.5
CVE-2017-12869
The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentica…
Debian Linux
after 1.14.13
MEDIUM 5.9
CVE-2017-3898
A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) versions prior to 16.0.3 allo…
Livesafe
after 16.0.2
HIGH 7.5
CVE-2017-0900EPSS 8%
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clie…
Debian Linux
after 2.6.12
HIGH 7.5
CVE-2017-0901EPSS 26%
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on th…
Debian Linux
Patch available
HIGH 7.5
CVE-2017-14063
Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if …
Async Http Client
2.0.35+
MEDIUM 6.5
CVE-2017-9945
In the Siemens 7KM PAC Switched Ethernet PROFINET expansion module (All versions < V2.1.3), a Denial-of-Service condition could be induced by a speci…
7km Pac Switched Ethernet Profinet Expansion Module Firmware
after 2.1.2
HIGH 8.8
CVE-2016-4462
By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that ar…
Ofbiz
Mitigation only
HIGH 7.5
CVE-2017-13767
In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the MSDP dissector could go into an infinite loop. This was addressed in epan/dissectors/pac…
Wireshark
Patch available
MEDIUM 6.1
CVE-2017-1428
IBM Cognos Analytics 11.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web …
Cognos Analytics
Patch available
HIGH 7.5
CVE-2015-5209EPSS 9%
Apache Struts 2.x before 2.3.24.1 allows remote attackers to manipulate Struts internals, alter user sessions, or affect container settings via vecto…
Struts
Mitigation only
HIGH 7.5
CVE-2017-12775
qa-include/qa-install.php in Question2Answer before 1.7.5 allows remote attackers to create multiple user accounts.
Question2answer
after 1.7.4
HIGH 8.8
CVE-2017-10952EPSS 15%
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.2.0.2051. User interaction is requ…
Foxit Reader
No fix yet
MEDIUM 5.5
CVE-2017-13685
The dump_callback function in SQLite 3.20.0 allows remote attackers to cause a denial of service (EXC_BAD_ACCESS and application crash) via a crafted…
SQLite
Mitigation only
HIGH 7.5
CVE-2017-13735
There is a floating point exception in the kodak_radc_load_raw function in dcraw_common.cpp in LibRaw 0.18.2. It will lead to a remote denial of serv…
Libraw
Mitigation only
HIGH 7.5
CVE-2015-0234
Multiple temporary file creation vulnerabilities in pki-core 10.2.0.
Pki Core
Patch available
HIGH 7.5
CVE-2015-1554
kgb-bot 1.33-2 allows remote attackers to cause a denial of service (crash).
Kgb Bot
No fix yet
HIGH 8.8
CVE-2015-1443
The httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30 allows remote attackers to execute arbitrary code.
Fli4l
after 3.10.0
HIGH 7.5
CVE-2017-13709
In FlightGear before version 2017.3.1, Main/logger.cxx in the FGLogger subsystem allows one to overwrite any file via a resource that affects the con…
Flightgear
No fix yet