Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2009-2669
A certain debugging component in IBM AIX 5.3 and 6.1 does not properly handle the (1) _LIB_INIT_DBG and (2) _LIB_INIT_DBG_FILE environment variables,…
Aix
Patch available
MEDIUM 5.0
CVE-2008-6886
RSA EnVision 3.5.0, 3.5.1, 3.5.2, and 3.7.0 does not properly restrict access to unspecified user profile functionality, which allows remote attacker…
Envision
Patch available
HIGH 9.3
CVE-2009-1863EPSS 6%
Unspecified vulnerability in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a …
Air
after 10.0.22.87
MEDIUM 5.0
CVE-2009-2648
FlashDen Guestbook allows remote attackers to obtain configuration information via a direct request to amfphp/phpinfo.php, which calls the phpinfo fu…
Guestbook
No fix yet
HIGH 8.8
CVE-2009-2493EPSS 38%
The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and…
Visual C\+\+
Patch available
MEDIUM 5.0
CVE-2009-2602
R2 Newsletter Lite, Pro, and Stats stores sensitive information under the web root with insufficient access control, which allows remote attackers to…
R2 Newsletter Lite
No fix yet
MEDIUM 5.0
CVE-2009-2606
ASP Football Pool 2.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the…
Asp Football Pool
No fix yet
MEDIUM 5.0
CVE-2008-6870
Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information via a direct request to (1) c…
Educate Server
No fix yet
MEDIUM 5.0
CVE-2008-6871
Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers to obtain unspecified sensitiv…
Educate Server
No fix yet
MEDIUM 5.0
CVE-2008-6869EPSS 6%
Oramon Oracle Database Monitoring Tool 2.0.1 stores sensitive information under the web root with insufficient access control, which allows remote at…
Oramon
No fix yet
MEDIUM 6.5
CVE-2009-2574
index.php in MiniTwitter 0.2 beta allows remote authenticated users to modify certain options of arbitrary accounts via an opt action.
Minitwitter
No fix yet
HIGH 7.5
CVE-2009-2558
system/message.php in Admin News Tools 2.5 does not properly restrict access, which allows remote attackers to post news messages via a direct reques…
Admin News Tools
No fix yet
HIGH 7.2
CVE-2009-2564EPSS 6%
NOS Microsystems getPlus Download Manager, as used in Adobe Reader 1.6.2.36 and possibly other versions, Corel getPlus Download Manager before 1.5.0.…
Getplus Download Manager
No fix yet
MEDIUM 6.9
CVE-2009-2482
The pam_unix module in OpenPAM in NetBSD 4.0 before 4.0.2 and 5.0 before 5.0.1 allows local users to change the current root password if it is alread…
Netbsd
Mitigation only
HIGH 9.0
CVE-2009-1135EPSS 26%
Microsoft Internet Security and Acceleration (ISA) Server 2006 Gold and SP1, when Radius OTP is enabled, uses the HTTP-Basic authentication method, w…
Isa Server
Mitigation only
HIGH 9.0
CVE-2009-1542EPSS 8%
The Virtual Machine Monitor (VMM) in Microsoft Virtual PC 2004 SP1, 2007, and 2007 SP1, and Microsoft Virtual Server 2005 R2 SP1, does not enforce CP…
Virtual Pc
Mitigation only
HIGH 7.2
CVE-2009-2461
mathtex.cgi in mathTeX, when downloaded before 20090713, does not securely create temporary files, which has unspecified impact and local attack vect…
Mathtex
after 1.02
HIGH 7.5
CVE-2009-2453
Citrix XenApp (formerly Presentation Server) 4.5 Hotfix Rollup Pack 3 does not apply an access policy when it is defined with the Access Gateway Adva…
Presentation Server
Patch available
MEDIUM 5.0
CVE-2009-2443
Siteframe 3.2.3, and other 3.2.x versions, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which cal…
Siteframe Cms
Patch available
MEDIUM 5.0
CVE-2009-2432
WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to wp-settings.php, which reveals…
WordPress
after 2.7.1
MEDIUM 6.5
CVE-2009-2393
admin/index.php in Virtuenetz Virtue Online Test Generator does not require administrative privileges, which allows remote authenticated users to hav…
Virtue Online Test Generator
No fix yet
MEDIUM 6.5
CVE-2009-2371
Advanced Forum 6.x before 6.x-1.1, a module for Drupal, does not prevent users from modifying user signatures after the associated comment format has…
Advanced Forum
Patch available
HIGH 9.0
CVE-2009-2344EPSS 9%
The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authenticated users to gain privileges …
3d Sensor
after 4.8.1
MEDIUM 6.4
CVE-2009-0904
The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XM…
Websphere Application Server
Mitigation only
HIGH 7.5
CVE-2008-6844
The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1, and 4.0.1, allows remote at…
Ez Publish
after 3.5.6
HIGH 7.5
CVE-2009-2306
The ARD-9808 DVR card security camera stores sensitive information under the web root with insufficient access control, which allows remote attackers…
Ard 9808 Software
No fix yet
MEDIUM 6.8
CVE-2009-2291
Unspecified vulnerability in LoginToboggan 6.x-1.x before 6.x-1.5, a module for Drupal, when "Allow users to login using their e-mail address" is ena…
Logintoboggan
Patch available
HIGH 7.5
CVE-2009-2293
Optimum Web Design Tutorial Share 3.5.0 and earlier allows remote attackers to bypass authentication and obtain administrative access by setting the …
Tutorial Share
after 3.5.0
MEDIUM 5.8
CVE-2009-1888
The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, whe…
Debian Linux
3.2.13 / 3.3.6+
MEDIUM 5.0
CVE-2009-2160
TorrentTrader Classic 1.09 allows remote attackers to (1) obtain configuration information via a direct request to phpinfo.php, which calls the phpin…
Torrenttrader Classic
No fix yet