Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
MEDIUM 6.4
CVE-2011-5136
showImg.php in EPractize Labs Subscription Manager, possibly 1.0, allows remote attackers to overwrite arbitrary files via the db parameter.
Subscription Manager
No fix yet
MEDIUM 6.0
CVE-2012-3325
IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.5, and 8.5.x Full Profile before 8.5.0.1, whe…
Websphere Application Server
Mitigation only
MEDIUM 6.8
CVE-2012-2104EPSS 5%
cgi-bin/munin-cgi-graph in Munin 2.x writes data to a log file without sanitizing non-printable characters, which might allow user-assisted remote at…
Munin
No fix yet
MEDIUM 5.1
CVE-2012-1177
libgdata before 0.10.2 and 0.11.x before 0.11.1 does not validate SSL certificates, which allows remote attackers to obtain user names and passwords …
Libgdata
after 0.11.0
HIGH 7.2
CVE-2012-3485
Tunnelblick 3.3beta20 and earlier relies on argv[0] to determine the name of an appropriate (1) kernel module pathname or (2) executable file pathnam…
Tunnelblick
after 3.3beta20
HIGH 10.0
CVE-2010-5185
The Antivirus component in Comodo Internet Security before 5.3.174622.1216 does not check whether X.509 certificates in signed executable files have …
Comodo Internet Security
after 5.0.163652.1142
MEDIUM 6.4
CVE-2012-4670
Tigase XMPP Server before 5.1.0 does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spo…
Tigase Xmpp Server
after 5.1.0
MEDIUM 5.8
CVE-2012-4671
psyced before 20120821 does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domain…
Psyced
after 20111122
MEDIUM 5.8
CVE-2012-4672
Apple iChat Server does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains vi…
Ichat Server
Mitigation only
MEDIUM 5.8
CVE-2012-3525
s2s/out.c in jabberd2 2.2.16 and earlier does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP serve…
Jabberd2
after 2.2.16
MEDIUM 5.8
CVE-2012-4669
M-Link R14.6 before R14.6v14 and R15.1 before R15.1v10 does not verify that a request was made for an XMPP Server Dialback response, which allows rem…
M Link
Mitigation only
MEDIUM 5.0
CVE-2008-7312
The Filtering Service in Websense Enterprise 5.2 through 6.3 does not consider the IP address during URL categorization, which makes it easier for re…
Enterprise
Mitigation only
MEDIUM 6.8
CVE-2011-3952
The decode_init function in kmvc.c in libavcodec in FFmpeg before 0.10 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.6, and 0…
Ffmpeg
after 0.9.1
MEDIUM 6.8
CVE-2012-0853
The decodeTonalComponents function in the Actrac3 codec (atrac3.c) in libavcodec in FFmpeg 0.7.x before 0.7.12, and 0.8.x before 0.8.11; and in Libav…
Ffmpeg
No fix yet
HIGH 9.3
CVE-2012-4359
Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 do not validate the return value of the realloc function, which a…
Winlog Pro
after 2.07.17
HIGH 9.3
CVE-2012-4357EPSS 7%
Array index error in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 might allow remote attackers to execute arbi…
Winlog Pro
after 2.07.16
HIGH 9.3
CVE-2012-4358
Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 do not validate the return value of the realloc function, which a…
Winlog Pro
after 2.07.16
HIGH 7.8
CVE-2012-1535 KEVEPSS 70%
Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers …
Enterprise Linux Desktop
11.2.202.238 / 11.3.300.271+
MEDIUM 5.0
CVE-2012-2096
The Fivestar module 6.x-1.x before 6.x-1.20 for Drupal does not properly validate voting data, which allows remote attackers to manipulate voting ave…
Fivestar Module For Drupal
Patch available
MEDIUM 6.4
CVE-2012-2330
The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allo…
Node.js
after 0.6.16
MEDIUM 5.0
CVE-2012-2368
Bytemark Symbiosis before Revision 1322 does not properly validate passwords, which allows remote attackers to gain access to email accounts via an a…
Symbiosis
after 1321
MEDIUM 5.0
CVE-2012-2964
The BreakingPoint Storm appliance before 3.0 requires cleartext credentials for establishing a session from a GUI administrative client, which allows…
Breakingpoint Storm Appliance Ctm
after 2.0
HIGH 7.5
CVE-2012-2965
Caucho Quercus, as distributed in Resin before 4.0.29, does not properly handle unspecified characters in the names of variables, which has unknown i…
Resin
after 4.0.28
HIGH 7.2
CVE-2012-2136
The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before 3.4.5 does not properly validate a certain length value, which allows…
Linux Kernel
3.0.37 / 3.2.23+
MEDIUM 5.0
CVE-2012-2191
IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, does…
Global Security Kit
after 8.0.13
MEDIUM 5.0
CVE-2012-3429
The dns_to_ldap_dn_escape function in src/ldap_convert.c in bind-dyndb-ldap 1.1.0rc1 and earlier does not properly escape distinguished names (DN) fo…
Bind Dyndb Ldap
after 1.1.0
MEDIUM 5.0
CVE-2012-2490
Cisco IP Communicator 8.6 allows man-in-the-middle attackers to modify the Certificate Trust List via unspecified vectors, aka Bug ID CSCtz01471.
Ip Communicator
No fix yet
HIGH 9.3
CVE-2012-1015
The kdc_handle_protected_negotiation function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8.x, 1.9.x before 1.9.5, and 1.10.x…
Kerberos 5
Patch available
MEDIUM 5.0
CVE-2012-1367
The MallocLite implementation in Cisco IOS 12.0, 12.2, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (Route Processor cra…
iOS
No fix yet
MEDIUM 5.0
CVE-2012-3443
The django.forms.ImageField class in the form system in Django before 1.3.2 and 1.4.x before 1.4.1 completely decompresses image data during image va…
Django
after 1.3