Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
MEDIUM 6.5
CVE-2014-8789
GleamTech FileVista before 6.1 allows remote authenticated users to create arbitrary files and possibly execute arbitrary code via a crafted path in …
Filevista
after 6.0.9
HIGH 9.3
CVE-2014-7178EPSS 5%
Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP…
Tuleap
after 7.5.99.5
HIGH 7.5
CVE-2014-9093
LibreOffice before 4.3.5 allows remote attackers to cause a denial of service (invalid write operation and crash) and possibly execute arbitrary code…
Fedora
after 4.3.4
MEDIUM 6.4
CVE-2014-7142EPSS 25%
The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (crash) via a crafted (1) I…
Ubuntu Linux
Mitigation only
MEDIUM 5.0
CVE-2014-2037
Openswan 2.6.40 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack ex…
Openswan
Mitigation only
MEDIUM 6.4
CVE-2014-9038
wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct serve…
WordPress
after 3.7.4
HIGH 9.0
CVE-2014-8420EPSS 24%
The ViewPoint web application in Dell SonicWALL Global Management System (GMS) before 7.2 SP2, SonicWALL Analyzer before 7.2 SP2, and SonicWALL UMA b…
Analyzer
Mitigation only
MEDIUM 6.4
CVE-2014-7839
DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which …
Resteasy
Mitigation only
HIGH 7.1
CVE-2014-9030
The do_mmu_update function in arch/x86/mm.c in Xen 3.2.x through 4.4.x does not properly manage page references, which allows remote domains to cause…
Debian Linux
Patch available
MEDIUM 5.0
CVE-2014-8416
Use-after-free vulnerability in the PJSIP channel driver in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1, when using the res_pjsip_…
Asterisk
12.7.1 / 13.0.1+
MEDIUM 5.0
CVE-2014-8415
Race condition in the chan_pjsip channel driver in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1 allows remote attackers to cause a …
Asterisk
12.7.1 / 13.0.1+
MEDIUM 5.0
CVE-2014-9060
The LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not properly restrict the parameters use…
Moodle
after 2.4.11
MEDIUM 5.4
CVE-2014-8594
The do_mmu_update function in arch/x86/mm.c in Xen 4.x through 4.4.x does not properly restrict updates to only PV page tables, which allows remote P…
Debian Linux
Patch available
MEDIUM 5.0
CVE-2014-7899
Google Chrome before 38.0.2125.101 allows remote attackers to spoof the address bar by placing a blob: substring at the beginning of the URL, followe…
Chrome
after 38.0.2125.7
HIGH 7.5
CVE-2014-7146EPSS 51%
The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) description field o…
Mantisbt
Patch available
HIGH 9.3
CVE-2014-4461
The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDataQueue object metadata, which allows attackers t…
Iphone Os
after 10.10.1
MEDIUM 5.0
CVE-2014-7815
The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value.
Debian Linux
Mitigation only
HIGH 9.3
CVE-2014-4149EPSS 21%
Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly perform TypeFilterLevel checks, which allows remote…
.net Framework
Mitigation only
HIGH 7.5
CVE-2014-3673EPSS 7%
The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF…
Linux Kernel
3.2.64 / 3.4.107+
MEDIUM 6.8
CVE-2014-7989
Cisco Unified Computing System on B-Series blade servers allows local users to gain shell privileges via a crafted (1) ping6 or (2) traceroute6 comma…
B200 M3
Mitigation only
MEDIUM 6.8
CVE-2014-7990
Cisco IOS XE 3.5E and earlier on WS-C3850, WS-C3860, and AIR-CT5760 devices does not properly parse the "request system shell" challenge response, wh…
Ios Xe
after 3.5e
MEDIUM 5.0
CVE-2014-2179
The Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote attac…
Rv180 Firmware
after 1.0.5.8
MEDIUM 5.0
CVE-2014-0995EPSS 10%
The Standalone Enqueue Server in SAP Netweaver 7.20, 7.01, and earlier allows remote attackers to cause a denial of service (uncontrolled recursion a…
Netweaver
after 7.01
HIGH 7.5
CVE-2014-8543
libavcodec/mmvideo.c in FFmpeg before 2.4.2 does not consider all lines of HHV Intra blocks during validation of image height, which allows remote at…
Ubuntu Linux
after 2.4.1
HIGH 7.5
CVE-2014-8544
libavcodec/tiff.c in FFmpeg before 2.4.2 does not properly validate bits-per-pixel fields, which allows remote attackers to cause a denial of service…
Ubuntu Linux
after 2.4.1
MEDIUM 5.0
CVE-2013-0336
The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_extop.c in the directory server (dirsrv) in FreeIPA before 3.2.0 allows…
Freeipa
after 3.1.5
MEDIUM 6.8
CVE-2014-0488
APT before 1.0.9 does not "invalidate repository data" when moving from an unauthenticated to authenticated state, which allows remote attackers to h…
Advanced Package Tool
Patch available
HIGH 7.5
CVE-2014-0489
APT before 1.0.9, when the Acquire::GzipIndexes option is enabled, does not validate checksums, which allows remote attackers to execute arbitrary co…
Advanced Package Tool
Patch available
HIGH 7.5
CVE-2014-0490
The apt-get download command in APT before 1.0.9 does not properly validate signatures for packages, which allows remote attackers to execute arbitra…
Advanced Package Tool
after 1.0.8
MEDIUM 5.0
CVE-2013-0334
Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same …
Bundler
1.7.0+