Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2011-1416
The Research In Motion (RIM) BlackBerry Torch 9800 with firmware 6.0.0.246 allows attackers to read the contents of memory locations via unknown vect…
Blackberry Torch 9800 Firmware
Mitigation only
MEDIUM 5.0
CVE-2011-1190
The Web Workers implementation in Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors,…
Chrome
5.0 / 5.0.6+
MEDIUM 5.0
CVE-2011-1187
Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak…
Chrome
2.9 / 10.0.648.127+
MEDIUM 5.0
CVE-2011-1103
The WebReporting module in F-Secure Policy Manager 7.x, 8.00 before hotfix 2, 8.1x before hotfix 3 on Windows and hotfix 2 on Linux, and 9.00 before …
Policy Manager
Patch available
HIGH 10.0
CVE-2011-0376
The TFTP implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x, 1.6.0, and 1.6.1 allows remote attackers to obtain …
Telepresence System Software
Mitigation only
MEDIUM 5.0
CVE-2011-0776
The sandbox implementation in Google Chrome before 9.0.597.84 on Mac OS X might allow remote attackers to obtain potentially sensitive information ab…
Chrome
9.0.597.84+
MEDIUM 5.0
CVE-2011-0774
PivotX before 2.2.2 allows remote attackers to obtain sensitive information via a direct request to (1) includes/ping.php and (2) includes/spamping.p…
Pivotx
Patch available
MEDIUM 5.0
CVE-2011-0775
pivotx/modules/module_image.php in PivotX 2.2.2 allows remote attackers to obtain sensitive information via a non-existent file in the image paramete…
Pivotx
Mitigation only
MEDIUM 5.3
CVE-2011-0737
Adobe ColdFusion 9.0.1 CHF1 and earlier allows remote attackers to obtain sensitive information via an id=- query to a .cfm file, which reveals the i…
Coldfusion
after 9.0.1
MEDIUM 5.3
CVE-2011-0736
Adobe ColdFusion 9.0.1 CHF1 and earlier, when a web application is configured to use a DBMS, allows remote attackers to obtain potentially sensitive …
Coldfusion
after 9.0.1
MEDIUM 5.0
CVE-2011-0679
IBM WebSphere Portal 6.0.1.1 through 7.0.0.0, as used in IBM Lotus Web Content Management (WCM) and IBM Lotus Quickr for WebSphere Portal, allows rem…
Websphere Portal
No fix yet
MEDIUM 5.0
CVE-2010-0214
The administrative interface on the PolyVision RoomWizard with firmware 3.2.3 places the Sync Connector Active Directory (AD) credentials in a web fo…
Roomwizard Firmware
No fix yet
MEDIUM 5.0
CVE-2010-4225
Unspecified vulnerability in the mod_mono module for XSP in Mono 2.8.x before 2.8.2 allows remote attackers to obtain the source code for .aspx (ASP.…
Mono
Mitigation only
MEDIUM 5.0
CVE-2010-4349EPSS 9%
admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to obtain sensitive information via an invalid db_type parameter, which…
Mantisbt
after 1.2.3
MEDIUM 5.0
CVE-2010-4625
MyBB (aka MyBulletinBoard) before 1.4.12 does not properly handle a configuration with a visible forum that contains hidden threads, which allows rem…
Mybb
after 1.4.11
MEDIUM 5.0
CVE-2010-4608
Habari 0.6.5 allows remote attackers to obtain sensitive information via a direct request to (1) header.php and (2) comments_items.php in system/admi…
Habari
No fix yet
MEDIUM 5.0
CVE-2010-4611
Html-edit CMS 3.1.8 allows remote attackers to obtain sensitive information via a direct request to (1) pages.php and (2) menu.php in includes/core_f…
Html Edit Cms
No fix yet
MEDIUM 5.0
CVE-2010-4600
Dojo Toolkit, as used in the Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1, allows remote attackers to read…
Dojo Toolkit
Mitigation only
MEDIUM 5.0
CVE-2010-4112
HP Insight Management Agents before 8.6 allows remote attackers to obtain sensitive information via an unspecified request that triggers disclosure o…
Insight Management Agents
after 8.5
MEDIUM 5.0
CVE-2010-4580
Opera before 11.00 does not clear WAP WML form fields after manual navigation to a new web site, which allows remote attackers to obtain sensitive in…
Opera Browser
after 11.00
MEDIUM 5.0
CVE-2010-3860
IcedTea 1.7.x before 1.7.6, 1.8.x before 1.8.3, and 1.9.x before 1.9.2, as based on OpenJDK 6, declares multiple sensitive variables as public, which…
Icedtea
after 1.9.1
MEDIUM 5.0
CVE-2010-2639
IBM WebSphere Commerce Enterprise 7.0 before 7.0.0.2 allows remote attackers to read messages intended for other recipients via vectors involving acc…
Websphere Commerce
Mitigation only
MEDIUM 5.0
CVE-2010-4403
The Register Plus plugin 3.5.1 and earlier for WordPress allows remote attackers to obtain sensitive information via a direct request to (1) dash_wid…
Register Plus
after 3.5.1
MEDIUM 5.0
CVE-2010-4401EPSS 6%
languages.inc.php in DynPG CMS 4.2.0 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation pat…
Dynpg
Patch available
MEDIUM 5.0
CVE-2008-7268
The phpinfo function in SiteEngine 5.x allows remote attackers to obtain system information by setting the action parameter to php_info in misc.php.
Siteengine
No fix yet
MEDIUM 5.0
CVE-2010-4354
The remote-access IPSec VPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices, PIX Security Appliances 500 series device…
Asa 5500
Mitigation only
MEDIUM 5.0
CVE-2010-3978
Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validating request…
Spree
Patch available
MEDIUM 5.0
CVE-2010-3764
The Old Charts implementation in Bugzilla 2.12 through 3.2.8, 3.4.8, 3.6.2, 3.7.3, and 4.1 creates graph files with predictable names in graphs/, whi…
Bugzilla
Patch available
MEDIUM 5.0
CVE-2010-3979
Dswsbobje in SAP BusinessObjects Enterprise XI 3.2 generates different error messages depending on whether the Login field corresponds to a valid use…
Businessobjects
No fix yet
MEDIUM 5.0
CVE-2010-3982
SAP BusinessObjects Enterprise XI 3.2 allows remote attackers to trigger TCP connections to arbitrary intranet hosts on any port, and obtain potentia…
Businessobjects
No fix yet