Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2013-7329
The CGI::Application module before 4.50_50 and 4.50_51 for Perl, when run modes are not specified, allows remote attackers to obtain sensitive inform…
Cgi Application Module
after 4.50
MEDIUM 5.0
CVE-2013-6496
Red Hat Conga 0.12.2 allows remote attackers to obtain sensitive information via a crafted request to the (1) homebase, (2) cluster, (3) storage, (4)…
Conga
Mitigation only
MEDIUM 5.0
CVE-2014-3398
The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to obtain potentially sensitive software-versi…
Adaptive Security Appliance Software
Mitigation only
MEDIUM 5.0
CVE-2014-4765
IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5 through 7.5.0.6, Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for…
Change And Configuration Management Database
Patch available
MEDIUM 5.0
CVE-2012-5492
uid_catalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to obtain metadata about hidden objects via a crafted URL.
Plone
after 4.2.2
MEDIUM 5.0
CVE-2012-5497
membership_tool.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to enumerate user account names via a crafted URL.
Plone
after 4.2.2
MEDIUM 5.0
CVE-2012-5505
atat.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read private data structures via a request for a view without a name.
Plone
after 4.2.2
MEDIUM 5.0
CVE-2014-3103
The Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not set the secure flag for th…
Rational Clearcase
Patch available
MEDIUM 5.0
CVE-2014-3105
The OSLC integration feature in the Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 pro…
Rational Clearcase
Patch available
MEDIUM 5.0
CVE-2014-5320
The Bump application for Android does not properly handle implicit intents, which allows attackers to obtain sensitive owner-name information via a c…
Bump
Mitigation only
MEDIUM 5.0
CVE-2014-4361
The Home & Lock Screen subsystem in Apple iOS before 8 does not properly restrict the private API for app prominence, which allows attackers to deter…
Iphone Os
after 7.1.2
MEDIUM 5.0
CVE-2014-4362
The Sandbox Profiles implementation in Apple iOS before 8 does not properly restrict the third-party app sandbox profile, which allows attackers to o…
Iphone Os
after 7.1.2
MEDIUM 5.0
CVE-2014-2377
Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to discover full pathnames via an app…
Integraxor
after 4.1.4392
MEDIUM 5.0
CVE-2014-2009EPSS 7%
The mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to obtain credentials, the installation path, and other sensitive informa…
Mpay24
after 1.5.1
MEDIUM 5.0
CVE-2014-3092
IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, a…
Rational Doors Next Generation
Patch available
MEDIUM 5.0
CVE-2014-0909
The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4.x before 8.1.4.4 does not set the secure flag for the session c…
Rational License Key Server
Patch available
MEDIUM 5.0
CVE-2014-4862EPSS 17%
The Netmaster CBW700N cable modem with software 81.447.392110.729.024 has an SNMP community of public, which allows remote attackers to obtain sensit…
Cbw700 Software
Mitigation only
MEDIUM 5.0
CVE-2014-4863EPSS 16%
The Arris Touchstone DG950A cable modem with software 7.10.131 has an SNMP community of public, which allows remote attackers to obtain sensitive pas…
Touchstone Dg950a Software
No fix yet
MEDIUM 5.0
CVE-2014-5377EPSS 57%
ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct…
Device Expert
after 5.9
MEDIUM 5.0
CVE-2014-5137
Innovative Interfaces Sierra Library Services Platform 1.2_3 provides different responses for login request depending on whether the user account exi…
Sierra
Mitigation only
MEDIUM 5.0
CVE-2014-5128
Innovative Interfaces Encore Discovery Solution 4.3 places a session token in the URI, which might allow remote attackers to obtain sensitive informa…
Encore Discovery Solution
No fix yet
MEDIUM 5.0
CVE-2014-3351
Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly consider whether a session is a problematic NULL session, which all…
Cloud Portal
Mitigation only
HIGH 7.8
CVE-2014-0600
FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via t…
Groupwise
Mitigation only
MEDIUM 5.0
CVE-2014-3562
Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by se…
Directory Server
Mitigation only
MEDIUM 6.3
CVE-2014-2521
EMC Documentum Content Server before 6.7 SP2 P16 and 7.x before 7.1 P07 allows remote authenticated users to read sensitive object metadata via an RP…
Documentum Content Server
after 6.7
MEDIUM 5.0
CVE-2014-4615
The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014…
Openstack
after 0.5.0
MEDIUM 5.0
CVE-2014-3341
The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests dependin…
Nx Os
after 7.0
MEDIUM 6.3
CVE-2014-3081
prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to read arbi…
Global Console Manager 16 Firmware
after 1.20.0.22575
MEDIUM 5.0
CVE-2014-4746
IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF13 and 8.5.0 through CF01 provides different error codes for firewall-traversal requests depending on whe…
Websphere Portal
Patch available
MEDIUM 5.0
CVE-2014-3076
IBM Business Process Manager (BPM) 8.5 through 8.5.5 allows remote attackers to obtain potentially sensitive information by visiting an unspecified J…
Business Process Manager
Patch available