Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2010-3902
OpenConnect before 2.26 places the webvpn cookie value in the debugging output, which might allow remote attackers to obtain sensitive information by…
Openconnect
after 2.25
MEDIUM 5.0
CVE-2010-3192
Certain run-time memory protection mechanisms in the GNU C Library (aka glibc or libc6) print argv[0] and backtrace information, which might allow co…
Glibc
2.26+
MEDIUM 5.5
CVE-2010-2538
Integer overflow in the btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 might allow local users to obtain sensitive …
Linux Kernel
2.6.35+
HIGH 8.1
CVE-2010-2943EPSS 17%
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote a…
Linux Kernel
2.6.35+
MEDIUM 6.9
CVE-2010-3280
The CCAgent option 9.0.8.4 and earlier in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition relie…
Ccagent
after 8.0
MEDIUM 5.5
CVE-2010-3078
The xfs_ioc_fsgetxattr function in fs/xfs/linux-2.6/xfs_ioctl.c in the Linux kernel before 2.6.36-rc4 does not initialize a certain structure member,…
Linux Kernel
after 2.6.35.4
MEDIUM 5.0
CVE-2010-3417
Google Chrome before 6.0.472.59 does not prompt the user before granting access to the extension history, which allows attackers to obtain potentiall…
Chrome
6.0.472.59+
MEDIUM 5.0
CVE-2010-1800
CFNetwork in Apple Mac OS X 10.6.3 and 10.6.4 supports anonymous SSL and TLS connections, which allows man-in-the-middle attackers to redirect a conn…
Cfnetwork
Patch available
MEDIUM 5.0
CVE-2010-3118
The autosuggest feature in the Omnibox implementation in Google Chrome before 5.0.375.127 does not anticipate entry of passwords, which might allow r…
Chrome
5.0.375.127+
MEDIUM 5.0
CVE-2010-2758
Bugzilla 2.17.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 generates different error messages depending on whethe…
Bugzilla
Mitigation only
MEDIUM 5.0
CVE-2010-2989
nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to obtain sensitive information via a request to the…
Web Server Plugin
Mitigation only
HIGH 7.1
CVE-2010-2982
Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 allows remote attackers to discover a group password via a series of SNMP requests,…
Unified Wireless Network Solution Software
Mitigation only
MEDIUM 5.0
CVE-2010-2791EPSS 8%
mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a respon…
HTTP Server
Mitigation only
MEDIUM 5.0
CVE-2010-2754
dom/base/nsJSEnvironment.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, an…
Firefox
after 2.0.5
MEDIUM 5.0
CVE-2009-4961
Lanai Core 0.6 allows remote attackers to obtain configuration information via a direct request to info.php, which calls the phpinfo function.
Lanai Core
No fix yet
MEDIUM 5.0
CVE-2010-2859
news.php in SimpNews 2.47.3 and earlier allows remote attackers to obtain sensitive information via an invalid lang parameter, which reveals the inst…
Simpnews
after 2.47.03
MEDIUM 5.0
CVE-2009-4951
Unspecified vulnerability in the ClickStream Analyzer [output] (alternet_csa_out) extension 0.3.0 and earlier for TYPO3 allows remote attackers to ob…
Alternet Csa Out
after 0.3.0
MEDIUM 5.0
CVE-2009-4943
index.php in AdPeeps 8.5d1 allows remote attackers to obtain sensitive information via (1) a view_adrates action with an invalid uid parameter, which…
Adpeeps
Mitigation only
MEDIUM 5.0
CVE-2010-2333EPSS 60%
LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a…
Litespeed Web Server
Patch available
MEDIUM 5.0
CVE-2010-2336
index.php in Yamamah Photo Gallery 1.00 allows remote attackers to obtain the source code of executable files within the web document root via the do…
Yamamah
Patch available
MEDIUM 5.0
CVE-2010-2323
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS might allow attackers to obtain sensitive information by reading the default_creat…
Websphere Application Server
after 7.0.0.10
MEDIUM 5.0
CVE-2010-2068EPSS 16%
mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in cer…
HTTP Server
Patch available
MEDIUM 5.0
CVE-2010-2263EPSS 72%
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrar…
Nginx
0.7.66+
MEDIUM 5.0
CVE-2009-4844
ToutVirtual VirtualIQ Pro 3.2 build 7882 does not restrict access to the /status URI on port 9080, which allows remote attackers to obtain sensitive …
Virtualiq
Mitigation only
MEDIUM 5.0
CVE-2009-4812
Wolfram Research webMathematica allows remote attackers to obtain sensitive information via a direct request to the MSP script, which reveals the ins…
Webmathematica
No fix yet
MEDIUM 5.0
CVE-2010-0025EPSS 21%
The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2000 SP3, d…
Windows 2000
Patch available
MEDIUM 5.0
CVE-2010-1138
The virtual networking stack in VMware Workstation 7.0 before 7.0.1 build 227600, VMware Workstation 6.5.x before 6.5.4 build 246459 on Windows, VMwa…
Workstation
Patch available
MEDIUM 5.0
CVE-2010-1310
Opera 10.50 allows remote attackers to obtain sensitive information via crafted XSLT constructs, which cause Opera to return cached contents of other…
Opera Browser
Mitigation only
HIGH 10.0
CVE-2010-1230
Google Chrome before 4.1.249.1036 does not have the expected behavior for attempts to delete Web SQL Databases and clear the Strict Transport Securit…
Chrome
4.1.249.1036+
MEDIUM 6.5
CVE-2010-0488EPSS 29%
Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypas…
Internet Explorer
Patch available