Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
HIGH 7.1
CVE-2013-2811
The (1) Catapult DNP3 I/O driver before 7.2.0.60 and the (2) GE Intelligent Platforms Proficy DNP3 I/O driver before 7.20k, as used in DNPDrv.exe (ak…
Catapult Dnp3 I\/o Driver
after 7.20.56
MEDIUM 5.8
CVE-2013-6174
Multiple open redirect vulnerabilities in xAdmin in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patc…
Document Sciences Xpression
No fix yet
MEDIUM 5.8
CVE-2013-6814
The J2EE Engine in SAP NetWeaver 6.40, 7.02, and earlier allows remote attackers to redirect users to arbitrary web sites, conduct phishing attacks, …
Netweaver
after 7.02
MEDIUM 5.0
CVE-2013-6815
The SHSTI_UPLOAD_XML function in the Application Server for ABAP (AS ABAP) in SAP NetWeaver 7.31 and earlier allows remote attackers to cause a denia…
Netweaver
after 7.31
HIGH 8.8
CVE-2013-6282 KEVEPSS 40%
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, w…
Linux Kernel
3.2.54 / 3.4.12+
HIGH 7.5
CVE-2013-5605
Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly ha…
Network Security Services
Patch available
MEDIUM 6.8
CVE-2013-6686
The SSL VPN implementation in Cisco IOS 15.3(1)T2 and earlier allows remote authenticated users to cause a denial of service (interface queue wedge) …
iOS
after 15.3
MEDIUM 6.9
CVE-2013-6689
Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier allows local users to bypass file permissions, and read, modify, or create arbit…
Unified Communications Manager
after 9.1
MEDIUM 5.0
CVE-2013-3030
The servlet gateway in IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2,…
Cognos Business Intelligence
Mitigation only
MEDIUM 6.8
CVE-2013-3406
The "Files Available for Download" implementation in the Cisco Intelligent Automation for Cloud component in Cisco Services Portal 9.4(1) allows remo…
Service Portal
Mitigation only
HIGH 7.1
CVE-2013-3876EPSS 5%
DirectAccess in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 S…
Windows 7
Mitigation only
MEDIUM 5.7
CVE-2013-4551
Xen 4.2.x and 4.3.x, when nested virtualization is disabled, does not properly check the emulation paths for (1) VMLAUNCH and (2) VMRESUME, which all…
Xen
Mitigation only
MEDIUM 6.4
CVE-2013-6682
The phone-proxy implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier does not properly validate X.509 certificates,…
Adaptive Security Appliance Software
after 9.0.3
MEDIUM 6.1
CVE-2013-6683
The IPv6 implementation in Cisco NX-OS does not properly handle neighbor-table adjacencies, which allows remote attackers to cause a denial of servic…
Nx Os
Mitigation only
MEDIUM 6.8
CVE-2013-6684
The web framework on Cisco Wireless LAN Controller (WLC) devices does not properly validate configuration parameters, which allows remote authenticat…
Wireless Lan Controller
Mitigation only
MEDIUM 5.4
CVE-2013-5560
The IPv6 implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1.3 and earlier, when NAT64 or NAT66 is enabled, does not properly proc…
Adaptive Security Appliance Software
after 9.1
HIGH 7.1
CVE-2013-5568
The auto-update implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier allows remote attackers to cause a denial of s…
Adaptive Security Appliance Software
after 9.0.3
MEDIUM 5.8
CVE-2013-2653
security/MemberLoginForm.php in SilverStripe 3.0.3 supports login using a GET request, which makes it easier for remote attackers to conduct phishing…
Silverstripe
Patch available
MEDIUM 5.0
CVE-2013-3869EPSS 18%
Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8…
Windows 7
Patch available
MEDIUM 6.9
CVE-2013-6122
goodix_tool.c in the Goodix gt915 touchscreen driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for…
Quic Mobile Station Modem Kernel
Patch available
HIGH 9.0
CVE-2013-6618EPSS 11%
jsdm/ajax/port.php in J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1 before 12.1R5, 12.2 before 12.2R3, and 12.3 before 12.3R1 allow…
Junos
after 10.4
HIGH 9.3
CVE-2013-4436
The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, which allows remote attackers t…
Salt
Patch available
MEDIUM 5.0
CVE-2013-5561
The Safe Search enforcement feature in Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security Software does not properly perform filtering…
Adaptive Security Appliance Cx Context Aware Security Software
Mitigation only
MEDIUM 5.2
CVE-2013-4494
Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators …
Debian Linux
after 4.3.4
MEDIUM 5.8
CVE-2013-5431
Open redirect vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.1.1 before IF 15, 6.2.0 before IF 14, 6.2.1, and 6.2.2 before IF 8 and …
Tivoli Federated Identity Manager
Mitigation only
HIGH 7.8
CVE-2013-5543
Cisco IOS XE 3.4 before 3.4.2S and 3.5 before 3.5.1S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) via mal…
Ios Xe
Mitigation only
HIGH 7.8
CVE-2013-5545
The PPTP ALG implementation in Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload…
Ios Xe
Mitigation only
HIGH 7.8
CVE-2013-5546
The TCP reassembly feature in Cisco IOS XE 3.7 before 3.7.3S and 3.8 before 3.8.1S on 1000 ASR devices allows remote attackers to cause a denial of s…
Ios Xe
Mitigation only
HIGH 7.8
CVE-2013-5547
Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) by sending malformed EoGRE pa…
Ios Xe
Mitigation only
HIGH 7.8
CVE-2013-5741
Triangle Research International (aka Tri) Nano-10 PLC devices with firmware r81 and earlier do not properly handle large length values in MODBUS data…
Nano 10 Plc Firmware
Mitigation only