Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
HIGH 10.0
CVE-2011-4249
Array index error in the RV30 codec in RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via unspecified vector…
Realplayer
after 14.0.7
MEDIUM 5.0
CVE-2011-4311
ResourceSpace before 4.2.2833 does not properly validate access keys, which allows remote attackers to bypass intended resource restrictions via unsp…
Resourcespace
after 4.2.2816
MEDIUM 5.0
CVE-2011-3646
phpmyadmin.css.php in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to obtain sensitive information via an array-typed js_frame parameter to …
phpMyAdmin
Patch available
MEDIUM 5.0
CVE-2011-2772
The get_dataroot_image_path function in lib/file.php in Mahara before 1.4.1 does not properly validate uploaded image files, which allows remote atta…
Mahara
after 1.4.0
HIGH 9.3
CVE-2011-3647
The JSSubScriptLoader in Mozilla Firefox before 3.6.24 and Thunderbird before 3.1.6 does not properly handle XPCNativeWrappers during calls to the lo…
Firefox
after 3.6.23
HIGH 7.5
CVE-2011-3880
Google Chrome before 15.0.874.102 does not prevent use of an unspecified special character as a delimiter in HTTP headers, which has unknown impact a…
Chrome
15.0.874.102+
MEDIUM 6.8
CVE-2011-3884
Google Chrome before 15.0.874.102 does not properly address timing issues during DOM traversal, which allows remote attackers to cause a denial of se…
Chrome
15.0.874.102+
MEDIUM 6.8
CVE-2011-3886
Google V8, as used in Google Chrome before 15.0.874.102, allows remote attackers to cause a denial of service or possibly have unspecified other impa…
V8
Mitigation only
HIGH 7.5
CVE-2011-2057
The cat6000-dot1x component in Cisco IOS 12.2 before 12.2(33)SXI7 does not properly handle (1) a loop between a dot1x enabled port and an open-authen…
iOS
12.2+
HIGH 7.5
CVE-2011-2058
The cat6000-dot1x component in Cisco IOS 12.2 before 12.2(33)SXI7 does not properly handle an external loop between a pair of dot1x enabled ports, wh…
iOS
12.2+
MEDIUM 6.8
CVE-2011-4063
chan_sip.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.7.1 and 10.x before 10.0.0-rc1 does not properly initialize variables d…
Open Source
Mitigation only
HIGH 7.8
CVE-2011-4151
The krb5_db2_lockout_audit function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4, when the db2 (aka Berkeley D…
Kerberos 5
Mitigation only
HIGH 7.8
CVE-2011-1527
The kdb_ldap plugin in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 through 1.9.1, when the LDAP back end is used, allows remot…
Kerberos 5
Mitigation only
HIGH 7.8
CVE-2011-1528
The krb5_ldap_lockout_audit function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4 and 1.9 through 1.9.1, when …
Kerberos 5
Mitigation only
HIGH 7.8
CVE-2011-1529
The lookup_lockout_policy function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4 and 1.9 through 1.9.1, when th…
Kerberos 5
Mitigation only
MEDIUM 5.0
CVE-2011-4138
The verify_exists functionality in the URLField implementation in Django before 1.2.7 and 1.3.x before 1.3.1 originally tests a URL's validity throug…
Django
after 1.2.6
MEDIUM 5.0
CVE-2011-4139
Django before 1.2.7 and 1.3.x before 1.3.1 uses a request's HTTP Host header to construct a full URL in certain circumstances, which allows remote at…
Django
after 1.2.6
MEDIUM 5.8
CVE-2011-4136
django.contrib.sessions in Django before 1.2.7 and 1.3.x before 1.3.1, when session data is stored in the cache, uses the root namespace for both ses…
Django
after 1.2.6
MEDIUM 6.8
CVE-2011-3227
libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a nonstandard extension in a Certificate Revocation …
Mac Os X
after 10.7.1
MEDIUM 5.0
CVE-2011-2012EPSS 17%
Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remo…
Forefront Unified Access Gateway
Mitigation only
MEDIUM 5.0
CVE-2011-2007EPSS 24%
Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service o…
Host Integration Server
Mitigation only
MEDIUM 5.0
CVE-2011-2008EPSS 21%
Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service o…
Host Integration Server
Mitigation only
MEDIUM 5.8
CVE-2010-4900
Open redirect vulnerability in c.php in CMS WebManager-Pro 8.1 and earlier allows remote attackers to redirect users to arbitrary web sites and condu…
Cms Webmanager Pro
after 8.1
MEDIUM 5.0
CVE-2011-3368EPSS 91%
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with u…
HTTP Server
Patch available
MEDIUM 6.8
CVE-2011-2861
Google Chrome before 14.0.835.163 does not properly handle strings in PDF documents, which allows remote attackers to have an unspecified impact via …
Chrome
14.0.835.163+
HIGH 7.5
CVE-2011-2838
Google Chrome before 14.0.835.163 does not properly consider the MIME type during the loading of a plug-in, which has unspecified impact and remote a…
Chrome
14.0.835.163+
MEDIUM 6.8
CVE-2011-2841
Google Chrome before 14.0.835.163 does not properly perform garbage collection during the processing of PDF documents, which allows remote attackers …
Chrome
14.0.835.163+
HIGH 7.5
CVE-2011-2842
The installer in Google Chrome before 14.0.835.163 on Mac OS X does not properly handle lock files, which has unspecified impact and attack vectors.
Chrome
14.0.835.163+
HIGH 10.0
CVE-2011-3496EPSS 14%
service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) BF, (…
Scadapro
after 4.0.0
HIGH 9.3
CVE-2011-3211
The server in Bcfg2 1.1.2 and earlier, and 1.2 prerelease, allows remote attackers to execute arbitrary commands via shell metacharacters in data rec…
Bcfg2
after 1.1.2