Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.9
CVE-2010-0064
DesktopServices in Apple Mac OS X 10.6 before 10.6.3 preserves file ownership during an authenticated Finder copy, which might allow local users to b…
Mac Os X
Patch available
HIGH 7.2
CVE-2010-0509
SFLServer in OS Services in Apple Mac OS X before 10.6.3 allows local users to gain privileges via vectors related to use of wheel group membership d…
Mac Os X
after 10.6.2
MEDIUM 5.0
CVE-2010-0511
Podcast Producer in Apple Mac OS X 10.6 before 10.6.3 deletes the access restrictions of a Podcast Composer workflow when this workflow is overwritte…
Mac Os X Server
Patch available
HIGH 9.3
CVE-2010-0512
The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account server is used, does not support Login Window ac…
Mac Os X
Patch available
MEDIUM 6.4
CVE-2009-2801
The Application Firewall in Apple Mac OS X 10.5.8 drops unspecified firewall rules after a reboot, which might allow remote attackers to bypass inten…
Mac Os X
Patch available
HIGH 7.5
CVE-2010-0057
AFP Server in Apple Mac OS X before 10.6.3 does not prevent guest use of AFP shares when guest access is disabled, which allows remote attackers to b…
Mac Os X
after 10.6.2
HIGH 7.5
CVE-2009-4762
MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchical ACLs, …
Moinmoin
Patch available
MEDIUM 5.0
CVE-2009-4760
Winn ASP Guestbook 1.01 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to downl…
Asp Guestbook
No fix yet
HIGH 7.5
CVE-2010-1136
The Standard Remember method in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to bypass access restrictions related to "persistent lo…
Tikiwiki Cms\/groupware
Mitigation only
HIGH 7.6
CVE-2010-0168EPSS 12%
The nsDocument::MaybePreLoadImage function in content/base/src/nsDocument.cpp in the image-preloading implementation in Mozilla Firefox 3.6 before 3.…
Firefox
Patch available
MEDIUM 5.0
CVE-2010-1116
LookMer Music Portal stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a da…
Lookmer Muzik Portal
No fix yet
MEDIUM 5.0
CVE-2010-1099
Integer overflow in Apple Safari allows remote attackers to bypass intended port restrictions on outbound TCP connections via a port number outside t…
Safari
Mitigation only
MEDIUM 5.0
CVE-2010-1064
Erolife AjxGaleri VT stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a da…
Erolife Ajxgaleri Vt
No fix yet
MEDIUM 5.0
CVE-2010-1065
Lebisoft Ziyaretci Defteri 7.4 and 7.5 stores sensitive information under the web root with insufficient access control, which allows remote attacker…
Ziyaretci Defteri
No fix yet
MEDIUM 5.0
CVE-2010-1066
AR Web Content Manager (AWCM) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to …
Ar Web Content Manager
No fix yet
MEDIUM 5.0
CVE-2010-1067
E-membres 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database …
E Membres
No fix yet
HIGH 7.1
CVE-2009-3385
The mail component in Mozilla SeaMonkey before 1.1.19 does not properly restrict execution of scriptable plugin content, which allows user-assisted r…
Seamonkey
after 1.1.18
MEDIUM 6.8
CVE-2010-0734
content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an applicat…
Libcurl
Patch available
HIGH 7.5
CVE-2010-0976
Acidcat CMS 3.5.x does not prevent access to install.asp after installation finishes, which might allow remote attackers to restart the installation …
Acidcat Cms
No fix yet
MEDIUM 5.0
CVE-2010-0977
PD PORTAL 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database …
Pd Portal
No fix yet
MEDIUM 5.0
CVE-2010-0978
KMSoft Guestbook (aka GBook) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to d…
Guestbook
No fix yet
MEDIUM 5.0
CVE-2010-0984
Acidcat CMS 3.5.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to down…
Acidcat Cms
after 3.5.3
MEDIUM 5.0
CVE-2010-0965
Jevci Siparis Formu Scripti stores sensitive information under the web root with insufficient access control, which allows remote attackers to downlo…
Jevci Siparis Formu Scripti
No fix yet
MEDIUM 5.0
CVE-2010-0123
The database backup implementation in Employee Timeclock Software 0.99 stores sensitive information under the web root with insufficient access contr…
Employee Timeclock Software
Mitigation only
MEDIUM 5.0
CVE-2010-0962
The FTP proxy server in Apple AirPort Express, AirPort Extreme, and Time Capsule with firmware 7.5 does not restrict the IP address and port specifie…
Airport Express
No fix yet
HIGH 8.5
CVE-2010-0728
smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote authenticated …
Samba
Mitigation only
MEDIUM 5.0
CVE-2010-0939
Visialis ABB Forum 1.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a …
Abb Forum
No fix yet
MEDIUM 6.9
CVE-2010-0393
The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine t…
Cups
Mitigation only
HIGH 8.5
CVE-2010-0571
Unspecified vulnerability in Cisco Digital Media Manager (DMM) 5.0.x and 5.1.x allows remote authenticated users to gain privileges via unknown vecto…
Digital Media Manager
Patch available
MEDIUM 5.0
CVE-2010-0765
fipsForum 2.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database …
Fipsforum
No fix yet