Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.8
CVE-2007-4174EPSS 6%
Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify…
Tor
after 0.1.2.15
HIGH 7.2
CVE-2007-3532
NVIDIA drivers (nvidia-drivers) before 1.0.7185, 1.0.9639, and 100.14.11, as used in Gentoo Linux and possibly other distributions, creates /dev/nvid…
Video Driver
after 100.14.11
MEDIUM 5.3
CVE-2007-3968
index.php in dirLIST before 0.1.1 allows remote attackers to list the contents of an excluded folder via a modified URL containing the folder name.
Dirlist Php
after 0.1.1
MEDIUM 5.0
CVE-2007-3804
The AntiVirus engine in the HTTP-ALG in Clavister CorePlus before 8.81.00 and 8.80.03 might allow remote attackers to bypass scanning via small files.
Clavister Coreplus
after 8.81.00
HIGH 10.0
CVE-2007-3500
Xeweb XEForum allows remote attackers to gain privileges via a modified xeforum cookie.
Xeforum
No fix yet
HIGH 10.0
CVE-2007-3455
cgiChkMasterPwd.exe before 8.0.0.142 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to bypass the password requirement and g…
Officescan
Patch available
MEDIUM 6.8
CVE-2007-3285
Mozilla Firefox before 2.0.0.5, when run on Windows, allows remote attackers to bypass file type checks and possibly execute programs via a (1) file:…
Firefox
after 2.0.0.4
MEDIUM 6.9
CVE-2007-3278
PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows re…
PostgreSQL
7.3.21 / 7.4.19+
HIGH 7.5
CVE-2007-3242
The Menu Manager Mod for (1) web-app.net WebAPP (aka WebAPP NE) 0.9.9.3.3 through 0.9.9.8, and (2) web-app.org WebAPP before 0.9.9.6, allows remote a…
Webapp
Mitigation only
HIGH 9.3
CVE-2007-3186
Apple Safari Beta 3.0.1 for Windows allows remote attackers to execute arbitrary commands via shell metacharacters in a URI in the SRC of an IFRAME, …
Safari
Mitigation only
HIGH 9.3
CVE-2007-2279EPSS 6%
The Scheduler Service (VxSchedService.exe) in Symantec Storage Foundation for Windows 5.0 allows remote attackers to bypass authentication and execut…
Veritas Storage Foundation
Patch available
HIGH 10.0
CVE-2007-2985
Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's username, which can be used t…
Pheap
No fix yet
HIGH 7.5
CVE-2007-2975
The admin console in Ignite Realtime Openfire 3.3.0 and earlier (formerly Wildfire) does not properly specify a filter mapping in web.xml, which allo…
Openfire
after 3.3.0
MEDIUM 5.0
CVE-2007-2944
WabCMS 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via…
Wabcms
Mitigation only
HIGH 10.0
CVE-2007-2815EPSS 73%
The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configur…
Internet Information Services
Mitigation only
HIGH 10.0
CVE-2007-2435
Sun Java Web Start in JDK and JRE 5.0 Update 10 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, allows remote attackers to perfo…
Java Enterprise System
after 5.0
MEDIUM 6.0
CVE-2007-2138
Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4…
PostgreSQL
7.3.19 / 7.4.17+
HIGH 7.2
CVE-2007-0729
Apple File Protocol (AFP) Client in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment before executing commands, which all…
Mac Os X
Patch available
MEDIUM 6.8
CVE-2007-2108EPSS 22%
Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 on Windows allows remote attackers …
Windows
Mitigation only
HIGH 7.2
CVE-2007-1206
The Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0; 2000 SP4; XP SP2; Server 2003, 2003 SP1, and 2003 SP2; and Windows V…
Windows 2000
Mitigation only
HIGH 9.0
CVE-2007-1309
Novell Access Management 3 SSLVPN Server allows remote authenticated users to bypass VPN restrictions by making policy.txt read-only, disconnecting, …
Access Manager
Patch available
MEDIUM 5.0
CVE-2006-7114
P-News 2.0 stores db/user.txt under the web document root with insufficient access control, which allows remote attackers to obtain sensitive informa…
P News
after 2.0
HIGH 7.5
CVE-2007-1261
Unspecified vulnerability in the reports system in OpenBiblio before 0.6.0 allows attackers to gain privileges via unspecified vectors.
Openbiblio
after 0.5.2
MEDIUM 6.6
CVE-2006-7098
The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when http…
Apache
Mitigation only
MEDIUM 6.6
CVE-2007-1227
VShieldCheck in McAfee VirusScan for Mac (Virex) before 7.7 patch 1 allow local users to change permissions of arbitrary files via a symlink attack o…
Virex
after 7.7
MEDIUM 5.0
CVE-2006-7047
include.php in Shoutpro 1.0 might allow remote attackers to bypass IP ban restrictions via a URL in the path parameter that points to an alternate ba…
Shoutpro
Mitigation only
HIGH 7.2
CVE-2007-1072
The command line interface (CLI) in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier allows l…
Unified Ip Phone Firmware 7906g
Patch available
HIGH 7.2
CVE-2007-1056
VMware Workstation 5.5.3 build 34685 does not provide per-user restrictions on certain privileged actions, which allows local users to perform restri…
Workstation
Mitigation only
HIGH 10.0
CVE-2007-1045
mAlbum 0.3 has default accounts (1) "login"/"pass" for its administrative account and (2) "dqsfg"/"sdfg", which allows remote attackers to gain privi…
Malbum
No fix yet
HIGH 7.5
CVE-2007-1036EPSS 82%
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to by…
Jboss Application Server
Mitigation only