Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2012-5916
Neocrome Seditio build 161 allows remote attackers to obtain sensitive information via a direct request to (1) docs/new/seditio-createnew-160.sql, (2…
Seditio
No fix yet
MEDIUM 5.0
CVE-2012-5890
The Front End User Registration (sr_feuser_register) extension before 2.6.2 for TYPO3 allows remote attackers to obtain user names and passwords via …
Sr Feuser Register
after 2.6.1
MEDIUM 5.0
CVE-2012-5172
The Asial Monaca Debugger application before 1.4.2 for Android allows remote attackers to obtain sensitive (1) account or (2) session ID information …
Monaca Debugger
after 1.4.1
MEDIUM 5.0
CVE-2012-4197
Bugzilla/Attachment.pm in attachment.cgi in Bugzilla 2.x and 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x…
Bugzilla
Patch available
MEDIUM 5.0
CVE-2012-5884
The User.get method in Bugzilla/WebService/User.pm in Bugzilla 4.3.2 allows remote attackers to obtain sensitive information about the saved searches…
Bugzilla
Mitigation only
MEDIUM 5.0
CVE-2012-1896EPSS 24%
Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly consider trust levels during construction of output data, which allows remote attackers …
.net Framework
Mitigation only
MEDIUM 5.0
CVE-2012-2532EPSS 42%
Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) processes unspecified commands before TLS is enabled for a session, which a…
Ftp Service
Mitigation only
MEDIUM 5.0
CVE-2012-1812
eosfailoverservice.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to obtain sensitive cleartext information via a session on TCP por…
Eoscada
after 11.0.19.1
MEDIUM 5.0
CVE-2012-3749
The extensions APIs in the kernel in Apple iOS before 6.0.1 provide kernel addresses in responses that contain an OSBundleMachOHeaders key, which mak…
Iphone Os
after 6.0
MEDIUM 5.8
CVE-2012-4511
services/flickr/flickr.c in libsocialweb before 0.25.21 automatically connects to Flickr when no Flickr account is set, which might allow remote atta…
Libsocialweb
after 0.25.20
MEDIUM 5.8
CVE-2011-4129
(1) services/twitter/twitter-contact-view.c and (2) services/twitter/twitter-item-view.c in libsocialweb before 0.25.20 automatically connect to Twit…
Libsocialweb
after 0.25.19
MEDIUM 5.0
CVE-2012-3319
IBM Rational Business Developer 8.x before 8.0.1.4 allows remote attackers to obtain potentially sensitive information via a connection to a web serv…
Rational Business Developer
after 8.0.1.3
MEDIUM 5.0
CVE-2012-4429
Vino 2.28, 2.32, 3.4.2, and earlier allows remote attackers to read clipboard activity by listening on TCP port 5900.
Vino
after 3.4.2
MEDIUM 5.8
CVE-2012-3493
The command_give_request_ad function in condor_startd.V6/command.cpp Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 allows remote attackers to obt…
Condor
Mitigation only
MEDIUM 5.0
CVE-2012-2891
The IPC implementation in Google Chrome before 22.0.1229.79 allows attackers to obtain potentially sensitive information about memory addresses via u…
Chrome
after 22.0.1229.78
MEDIUM 5.0
CVE-2012-3724
CFNetwork in Apple iOS before 6 does not properly identify the host portion of a URL, which allows remote attackers to obtain sensitive information b…
Iphone Os
after 5.1.1
MEDIUM 5.0
CVE-2012-4403
theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attack…
Moodle
Patch available
MEDIUM 5.0
CVE-2012-4407
lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files,…
Moodle
Patch available
MEDIUM 5.0
CVE-2012-3094
The VPN downloader in the download_install component in Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495 on Linux accepts arbitrary X.5…
Anyconnect Secure Mobility Client
Mitigation only
MEDIUM 5.0
CVE-2012-1579
The resource loader in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 includes private data such as CSRF tokens in a JavaScript file, which …
Mediawiki
No fix yet
MEDIUM 5.0
CVE-2012-0837
Joomla! 1.7.x before 1.7.5 and 2.5.x before 2.5.1 allows attackers to obtain the installation path via unspecified vectors related to "administrator."
Joomla\!
Patch available
MEDIUM 5.0
CVE-2012-1607
The Command Line Interface (CLI) script in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attacker…
TYPO3
Mitigation only
MEDIUM 5.0
CVE-2012-1614EPSS 9%
Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/…
Coppermine Photo Gallery
after 1.5.18
MEDIUM 5.0
CVE-2012-3972
The format-number functionality in the XSLT implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, T…
Firefox
10.0.7 / 15.0+
MEDIUM 5.0
CVE-2012-3419
Performance Co-Pilot (PCP) before 3.6.5 exports some of the /proc file system, which allows attackers to obtain sensitive information such as proc/pi…
Performance Co Pilot
after 3.6.4
MEDIUM 5.0
CVE-2011-5126
Blue Coat ProxySG 6.1 before SGOS 6.1.5.1 and 6.2 before SGOS 6.2.2.1 writes the secure heap to core images, which allows context-dependent attackers…
Sgos
Mitigation only
MEDIUM 5.0
CVE-2010-5188
SilverStripe 2.3.x before 2.3.6 allows remote attackers to obtain sensitive information via the (1) debug_memory parameter to core/control/Director.p…
Silverstripe
Patch available
MEDIUM 5.0
CVE-2012-4674
PluXml before 5.1.6 allows remote attackers to obtain the installation path via the PHPSESSID.
Pluxml
after 5.1.5
MEDIUM 5.0
CVE-2012-3519
routerlist.c in Tor before 0.2.2.38 uses a different amount of time for relay-list iteration depending on which relay is chosen, which might allow re…
Tor
after 0.2.2.37
MEDIUM 5.0
CVE-2012-4605
The default configuration of the SMTP component in Websense Email Security 6.1 through 7.3 enables weak SSL ciphers in the "SurfControl plc\SuperScou…
Websense Email Security
Mitigation only