Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2012-3838
Gekko before 1.2.0 allows remote attackers to obtain the installation path via a direct request to (1) admin/templates/babygekko/index.php or (2) tem…
Baby Gekko
after 1.1.5
MEDIUM 5.0
CVE-2012-3829
Joomla! 2.5.3 allows remote attackers to obtain the installation path via the Host HTTP Header.
Joomla\!
No fix yet
MEDIUM 5.0
CVE-2012-2815
Google Chrome before 20.0.1132.43 allows remote attackers to obtain potentially sensitive information from a fragment identifier by leveraging access…
Chrome
after 20.0.1132.42
MEDIUM 5.0
CVE-2012-3798
The Janrain Capture module 6.x-1.0 and 7.x-1.0 for Drupal, when creating a local user account, allows attackers to obtain part of the initial input u…
Janrain Capture
Patch available
MEDIUM 5.0
CVE-2012-3796EPSS 11%
Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to obtain sens…
Pro Server Ex
after 3.1.00
MEDIUM 6.0
CVE-2011-2707
The ptrace_setxregs function in arch/xtensa/kernel/ptrace.c in the Linux kernel before 3.1 does not validate user-space pointers, which allows local …
Linux Kernel
3.1+
MEDIUM 5.5
CVE-2011-2898
net/packet/af_packet.c in the Linux kernel before 2.6.39.3 does not properly restrict user-space access to certain packet data structures associated …
Linux Kernel
2.6.39.3+
MEDIUM 5.0
CVE-2012-2922
The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] pa…
Drupal
after 7.14
MEDIUM 5.0
CVE-2012-1249
The iLunascape application 1.0.4.0 and earlier for Android does not properly implement the WebView class, which allows remote attackers to obtain sen…
Ilunascape Android
after 1.0.4.0
MEDIUM 5.0
CVE-2012-0651
The directory server in Directory Service in Apple Mac OS X 10.6.8 allows remote attackers to obtain sensitive information from process memory via a …
Mac Os X
Mitigation only
MEDIUM 5.0
CVE-2011-4232
The web server in Cisco Unified MeetingPlace 6.1 and 8.5 produces different responses for directory queries depending on whether the directory exists…
Unified Meetingplace
Mitigation only
MEDIUM 6.8
CVE-2012-0731
IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not prevent service-account impersonation, which allows remote authenticated users to…
Rational Appscan
Mitigation only
MEDIUM 5.0
CVE-2012-1243
The TwitRocker2 application before 1.0.23 for Android does not properly implement the WebView class, which allows remote attackers to obtain sensitiv…
Twitrocker2 Android
Mitigation only
MEDIUM 5.0
CVE-2012-0130
HP Onboard Administrator (OA) before 3.50 allows remote attackers to obtain sensitive information via unspecified vectors.
Onboard Administrator
after 3.32
MEDIUM 5.0
CVE-2012-1670EPSS 8%
admin/index.php in PHP Grade Book before 1.9.5 BETA allows remote attackers to read the database via a SaveSQL action.
Php Grade Book
after 1.9.4
MEDIUM 5.0
CVE-2012-1926
Opera before 11.62 allows remote attackers to bypass the Same Origin Policy via the (1) history.pushState and (2) history.replaceState functions in c…
Opera Browser
after 11.61
MEDIUM 5.0
CVE-2012-1920
@Mail WebMail Client in AtMail Open-Source 1.04 and earlier allows remote attackers to obtain configuration information via a direct request to insta…
Atmail Open
after 1.04
MEDIUM 5.0
CVE-2012-1837
The (1) webreports, (2) post/create-role, and (3) post/update-role programs in IBM Tivoli Endpoint Manager (TEM) before 8.2 do not include the HTTPOn…
Tivoli Endpoint Manager
after 8.1
MEDIUM 5.0
CVE-2012-0328
Janetter before 3.3.0.0 (aka 3.3.0) allows remote attackers to obtain session information for twitter.com web sites via unspecified vectors.
Janetter
after 3.2.1.1
MEDIUM 5.0
CVE-2012-1464
Dashboard Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the installation path via a request with a trailing "?" …
Netdecision
after 4.5.1
MEDIUM 5.0
CVE-2012-1466
The Traffic Grapher Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the source code of NtDecision script files wit…
Netdecision
after 4.5.1
MEDIUM 5.0
CVE-2012-1786
The Media Upload form in the Video Embed & Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to obtain the installation pat…
Video Embed \& Thumbnail Generator
after 1.1
MEDIUM 5.0
CVE-2009-5112EPSS 5%
wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to obtain the installation path via a crafted request.
Webglimpse
after 2.18.7
MEDIUM 5.0
CVE-2012-0456
The SVG Filters implementation in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5…
Firefox
after 10.0
MEDIUM 5.0
CVE-2012-0687
TIBCO ActiveMatrix Runtime Platform in Service Grid and Service Bus 2.x before 2.3.2 and BusinessWorks Service Engine before 5.8.2; TIBCO ActiveMatri…
Activematrix Service Bus
after 5.9.2
MEDIUM 5.0
CVE-2012-0689
The server in TIBCO ActiveMatrix Platform in TIBCO Silver Fabric ActiveMatrix Service Grid Distribution 3.1.3, Service Grid and Service Bus 3.x befor…
Activematrix Bpm
Mitigation only
MEDIUM 5.0
CVE-2012-0690
TIBCO Spotfire Web Application, Web Player Application, Automation Services Application, and Analytics Client Application in Spotfire Analytics Serve…
Spotfire Analytics Server
after 4.0.1
MEDIUM 5.0
CVE-2012-0640
WebKit in Apple Safari before 5.1.4 does not properly implement "From third parties and advertisers" cookie blocking, which makes it easier for remot…
Safari
after 5.1.3
MEDIUM 5.0
CVE-2012-0647
WebKit in Apple Safari before 5.1.4 does not properly handle redirects in conjunction with HTTP authentication, which might allow remote web servers …
Safari
after 5.1.3
MEDIUM 5.0
CVE-2012-0316
The Cookpad 1.5.16 and earlier and Cookpad Noseru 1.1.1 and earlier applications for Android do not properly implement the WebView class, which allow…
Android Activities
after 1.5.16