Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
MEDIUM 5.0
CVE-2012-4482
The Ubercart SecureTrading Payment Method module 6.x for Drupal does not properly verify payment notification information, which allows remote attack…
Ubercart Securetrading Payment Method Module
Mitigation only
MEDIUM 5.0
CVE-2012-2972
The (1) server and (2) agent components in CA ARCserve Backup r12.5, r15, and r16 on Windows do not properly validate RPC requests, which allows remo…
No fix yet
MEDIUM 5.8
CVE-2012-5356
The apt-add-repository tool in Ubuntu Software Properties 0.75.x before 0.75.10.3, 0.80.x before 0.80.9.2, 0.81.x before 0.81.13.5, 0.82.x before 0.8…
Ubuntu Software Properties
Mitigation only
MEDIUM 5.1
CVE-2012-4463
Midnight Commander (mc) 4.8.5 does not properly handle the (1) MC_EXT_SELECTED or (2) MC_EXT_ONLYTAGGED environment variables when multiple files are…
Midnight Commander
Mitigation only
MEDIUM 5.0
CVE-2012-3436
OpenTTD 0.6.0 through 1.2.1 does not properly validate requests to clear a water tile, which allows remote attackers to cause a denial of service (NU…
Openttd
No fix yet
MEDIUM 5.8
CVE-2012-5321EPSS 14%
tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frames and conduct phishing attack…
Tikiwiki Cms\/groupware
No fix yet
MEDIUM 5.8
CVE-2012-4824
Open redirect vulnerability in servlet/traveler in IBM Lotus Notes Traveler 8.5.3 before 8.5.3.3 Interim Fix 1 allows remote attackers to redirect us…
Lotus Notes Traveler
No fix yet
MEDIUM 5.0
CVE-2011-4911
Joomla! before 1.5.12 does not perform a JEXEC check in unspecified files, which allows remote attackers to obtain the installation path via unspecif…
Joomla\!
after 1.5.11
MEDIUM 5.8
CVE-2012-3314
IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1, 6.2.0, 6.2.1, and 6.2.2 allow rem…
Tivoli Federated Identity Manager
Patch available
MEDIUM 5.8
CVE-2012-5234
Open redirect vulnerability in index.php in ocPortal before 7.1.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishi…
Ocportal
after 7.1.5
HIGH 7.5
CVE-2012-2240
scripts/dscverify.pl in devscripts before 2.12.3 allows remote attackers to execute arbitrary commands via unspecified vectors related to "arguments …
Devscripts
after 2.12.2
MEDIUM 5.0
CVE-2012-2241
scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete arbitrary files via a crafted (1) .dsc or (2) .changes file, probably r…
Devscripts
after 2.12.2
MEDIUM 6.8
CVE-2012-2242
scripts/dget.pl in devscripts before 2.10.73 allows remote attackers to execute arbitrary commands via a crafted (1) .dsc or (2) .changes file, relat…
Devscripts
after 2.10.72
HIGH 7.8
CVE-2012-5049
APIFTP Server in Optimalog Optima PLC 1.5.2 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.
Optima Plc
after 1.5.2
HIGH 7.8
CVE-2012-4623
The DHCPv6 server in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x, 3.1.xS before 3.1.4S, 3.1.xSG and 3.2.xSG befo…
Ios Xe
Mitigation only
HIGH 7.8
CVE-2012-3949
The SIP implementation in Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su5, 8.x before 8.5(1)su4, and 8.6 before 8.6(2a)su1;…
Unified Communications Manager
Mitigation only
HIGH 7.1
CVE-2012-4617
The BGP implementation in Cisco IOS 15.2, IOS XE 3.5.xS before 3.5.2S, and IOS XR 4.1.0 through 4.2.2 allows remote attackers to cause a denial of se…
iOS
Mitigation only
MEDIUM 5.0
CVE-2012-2877
The extension system in Google Chrome before 22.0.1229.79 does not properly handle modal dialogs, which allows remote attackers to cause a denial of …
Chrome
after 22.0.1229.78
MEDIUM 6.8
CVE-2012-2882
FFmpeg, as used in Google Chrome before 22.0.1229.79, does not properly handle OGG containers, which allows remote attackers to cause a denial of ser…
Chrome
after 22.0.1229.78
HIGH 9.3
CVE-2012-4655
The WebLaunch feature in Cisco Secure Desktop before 3.6.6020 does not properly validate binaries that are received by the downloader process, which …
Secure Desktop
Mitigation only
MEDIUM 6.8
CVE-2012-3719
Mail in Apple Mac OS X before 10.7.5 does not properly handle embedded web plugins, which allows remote attackers to execute arbitrary plugin code vi…
Mac Os X
after 10.7.4
MEDIUM 6.1
CVE-2012-4999EPSS 7%
Mercury MR804 Router 8.0 3.8.1 Build 101220 Rel.53006nB allows remote attackers to cause a denial of service (service hang) via a crafted string in H…
Mr804 Firmware
No fix yet
MEDIUM 6.8
CVE-2011-4962
code/sitefeatures/PageCommentInterface.php in SilverStripe 2.4.x before 2.4.6 might allow remote attackers to execute arbitrary code via a crafted co…
Silverstripe
Patch available
MEDIUM 5.0
CVE-2012-4001
The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger…
Mod Pagespeed
after 0.10.22.4
MEDIUM 5.0
CVE-2012-4922
The tor_timegm function in common/util.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.22-rc, does not properly validate time values, which allows…
Tor
after 0.2.2.38
MEDIUM 6.0
CVE-2012-3572
Open Source Competency Center (OSCC) MyMeeting 3.0.1 and earlier, and MyMesyuarat 09b-1, does not properly verify uploaded documents, which allows re…
Mymesyuarat
after 3.0.1
MEDIUM 6.0
CVE-2012-2981
Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary Perl code via a crafted file associated with the type (aka monitor ty…
Webmin
after 1.590
MEDIUM 5.8
CVE-2012-3540
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbit…
Horizon
Patch available
HIGH 8.5
CVE-2010-4818EPSS 5%
The GLX extension in X.Org xserver 1.7.7 allows remote authenticated users to cause a denial of service (server crash) and possibly execute arbitrary…
X.org
Patch available
MEDIUM 5.0
CVE-2012-1608
The t3lib_div::RemoveXSS API method in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to…
TYPO3
Mitigation only