Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.2
CVE-2016-8889
In Bitcoin Knots v0.11.0.ljr20150711 through v0.13.0.knots20160814 (fixed in v0.13.1.knots20161027), the debug console stores sensitive information i…
Bitcoin Knots
Patch available
MEDIUM 6.2
CVE-2016-8871
In Botan 1.11.29 through 1.11.32, RSA decryption with certain padding options had a detectable timing channel which could given sufficient queries be…
Botan
Mitigation only
HIGH 7.5
CVE-2016-7919
Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Admini…
Moodle
No fix yet
HIGH 7.5
CVE-2016-6446
A vulnerability in Web Bridge for Cisco Meeting Server could allow an unauthenticated, remote attacker to retrieve memory from a connected server. Mo…
Meeting Server
Mitigation only
MEDIUM 5.7
CVE-2016-5602
Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, 12.2.1.0.0, and 12.…
Data Integrator
Patch available
MEDIUM 5.9
CVE-2016-5597
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality via vec…
Jdk
Patch available
MEDIUM 5.3
CVE-2016-5575
Unspecified vulnerability in the Oracle Common Applications Calendar component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12…
Common Applications
Patch available
HIGH 7.7
CVE-2016-5565
Unspecified vulnerability in the Oracle Hospitality OPERA 5 Property Services component in Oracle Hospitality Applications 5.4.0.0 through 5.4.3.0, 5…
Hospitality Opera 5 Property Services
Patch available
MEDIUM 5.3
CVE-2016-5524
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect c…
Agile Product Lifecycle Management
Patch available
MEDIUM 5.3
CVE-2016-5510
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect c…
Agile Product Lifecycle Management
Patch available
MEDIUM 5.5
CVE-2016-5505
Unspecified vulnerability in the RDBMS Programmable Interface component in Oracle Database Server 11.2.0.4 and 12.1.0.2 allows local users to affect …
Database Server
Patch available
HIGH 7.5
CVE-2016-5500
Unspecified vulnerability in the Oracle Discoverer component in Oracle Fusion Middleware 11.1.1.7.0 allows remote attackers to affect confidentiality…
Discoverer
Patch available
HIGH 7.5
CVE-2016-5495
Unspecified vulnerability in the Oracle Discoverer component in Oracle Fusion Middleware 11.1.1.7.0 allows remote attackers to affect confidentiality…
Discoverer
Patch available
HIGH 7.7
CVE-2016-3473EPSS 14%
Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 a…
Business Intelligence Publisher
Patch available
MEDIUM 5.3
CVE-2016-1000214
Ruckus Wireless H500 web management interface authentication bypass
Wireless H500
Mitigation only
HIGH 7.8
CVE-2016-0247
IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain sensitive cleartex…
Security Guardium
Patch available
MEDIUM 5.3
CVE-2016-3391EPSS 8%
Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow context-dependent attackers to discover credentials by leveraging access to a memory d…
Edge
Mitigation only
MEDIUM 5.3
CVE-2016-3267EPSS 16%
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to determine the existence of unspecified files via a crafted web …
Edge
Mitigation only
MEDIUM 5.5
CVE-2016-3263EPSS 32%
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows S…
Live Meeting
Mitigation only
MEDIUM 5.5
CVE-2016-3262EPSS 32%
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows S…
Live Meeting
Mitigation only
MEDIUM 5.5
CVE-2016-3209EPSS 54%
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows S…
.net Framework
Mitigation only
MEDIUM 5.0
CVE-2016-0079EPSS 5%
The kernel in Microsoft Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to acc…
Windows 10
No fix yet
MEDIUM 5.5
CVE-2016-0075EPSS 7%
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain …
Windows 10
No fix yet
MEDIUM 5.0
CVE-2016-0073EPSS 5%
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain …
Windows 10
No fix yet
MEDIUM 5.5
CVE-2016-0070EPSS 11%
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows R…
Windows 10
Mitigation only
HIGH 7.8
CVE-2016-3946
SAP Console (aka SAPConsole) 7.30 allows local users to discover SAP Server login credentials by reading the Windows registry, aka SAP Security Note …
Sapconsole
Mitigation only
MEDIUM 5.5
CVE-2016-8100
Intel Integrated Performance Primitives (aka IPP) Cryptography before 9.0.4 makes it easier for local users to discover RSA private keys via a side-c…
Integrated Performance Primitives
after 9.0.3
MEDIUM 5.5
CVE-2016-6689
Binder in the kernel in Android before 2016-10-05 on Nexus devices allows attackers to obtain sensitive information via a crafted application, aka in…
Android
after 7.0
MEDIUM 5.5
CVE-2016-6688
The NVIDIA profiler in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka i…
Android
after 7.0
MEDIUM 5.5
CVE-2016-6687
The NVIDIA profiler in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka i…
Android
after 7.0