Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2014-7822
The implementation of certain splice_write file operations in the Linux kernel before 3.16 does not enforce a restriction on the maximum size of a si…
Linux Kernel
after 3.15.8
HIGH 7.5
CVE-2015-0981
The SOAP web interface in SCADA Engine BACnet OPC Server before 2.1.371.24 allows remote attackers to bypass authentication and read or write to arbi…
Bacnet Opc Server
after 2.1.359.22
HIGH 7.2
CVE-2015-2151
The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment overrides for instructions with register operands, which allows local gu…
Fedora
Patch available
HIGH 7.2
CVE-2015-0078
win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not prop…
Windows 8
Patch available
HIGH 7.2
CVE-2015-0075
The kernel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 does not properly constrain…
Windows 2003 Server
Mitigation only
HIGH 7.2
CVE-2015-0073
The Windows Registry Virtualization feature in the kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows …
Windows 7
Patch available
MEDIUM 5.0
CVE-2015-1226
The DebuggerFunction::InitAgentHost function in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 41.0.2272.76 does not properl…
Chrome
after 40.0.2214.115
MEDIUM 5.0
CVE-2014-9689
content/renderer/device_sensors/device_orientation_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate …
Chrome
after 40.0.2214.115
MEDIUM 5.0
CVE-2011-5319
content/renderer/device_sensors/device_motion_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate accel…
Chrome
after 40.0.2214.115
HIGH 7.2
CVE-2015-1170
The NVIDIA Display Driver R304 before 309.08, R340 before 341.44, R343 before 345.20, and R346 before 347.52 does not properly validate local client …
Gpu Driver R304
after 347.51
MEDIUM 6.5
CVE-2014-2130
Cisco Secure Access Control Server (ACS) provides an unintentional administration web interface based on Apache Tomcat, which allows remote authentic…
Secure Access Control System
Mitigation only
MEDIUM 5.0
CVE-2015-2075
SAP BusinessObjects Edge 4.0 allows remote attackers to delete audit events from the auditee queue via a clearData CORBA operation, aka SAP Note 2011…
Businessobjects Edge
No fix yet
MEDIUM 6.8
CVE-2015-0821
Mozilla Firefox before 36.0 allows user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges…
Firefox
after 35.0.1
MEDIUM 6.5
CVE-2014-8115
The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitrary files, bypass intended ac…
Kie Workbench
Patch available
MEDIUM 6.8
CVE-2014-8114
The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted conte…
Uberfire
Patch available
HIGH 7.2
CVE-2015-1515
The dwall.sys driver in SoftSphere DefenseWall Personal Firewall 3.24 allows local users to write data to arbitrary memory locations, and consequentl…
Defensewall Personal Firewall
No fix yet
MEDIUM 6.4
CVE-2014-5286
The ActiveMatrix Policy Manager Authentication module in TIBCO ActiveMatrix Policy Agent 3.x before 3.1.2, ActiveMatrix Policy Manager 3.x before 3.1…
Activematrix Management Agent
Mitigation only
HIGH 8.5
CVE-2015-1499
The ActiveMQ Broker in Samsung Security Manager (SSM) before 1.31 allows remote attackers to delete arbitrary files, and consequently cause a denial …
Samsung Security Manager
after 1.30
HIGH 10.0
CVE-2015-1498
Persistent Systems Radia Client Automation does not properly restrict access to certain request, which allows remote attackers to (1) enumerate user …
Radia Client Automation
Mitigation only
HIGH 7.2
CVE-2015-1496
Motorola Scanner SDK uses weak permissions for (1) CoreScanner.exe, (2) rsmdriverproviderservice.exe, and (3) ScannerService.exe, which allows local …
Motorola Scanner Sdk
Mitigation only
HIGH 9.0
CVE-2015-0518
The Properties service in the D2FS web-service component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P22, and 4.2 before P11 allows …
Documentum D2
Mitigation only
HIGH 7.2
CVE-2014-6185
dsmtca in the client in IBM Tivoli Storage Manager (TSM) 6.3 before 6.3.2.3, 6.4 before 6.4.2.2, and 7.1 before 7.1.1.3 does not properly restrict sh…
Tivoli Storage Manager
Patch available
MEDIUM 5.0
CVE-2015-0227EPSS 8%
Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors …
Wss4j
after 1.6.16
MEDIUM 6.5
CVE-2015-0611
The administrative web-management portal in Cisco IX 8 (.0.1) and earlier on Cisco TelePresence IX5000 devices does not properly restrict the device-…
Telepresence System Software Ix
Mitigation only
HIGH 7.2
CVE-2015-0062
Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local…
Windows 7
Patch available
MEDIUM 6.9
CVE-2015-0059EPSS 11%
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2…
Windows 7
Patch available
HIGH 7.2
CVE-2015-0057EPSS 13%
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Win…
Windows 7
Patch available
MEDIUM 6.9
CVE-2015-0012
Microsoft System Center Virtual Machine Manager (VMM) 2012 R2 Update Rollup 4 does not properly validate the roles of users, which allows local users…
Virtual Machine Manager
Patch available
MEDIUM 5.0
CVE-2014-9675
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers…
Ubuntu Linux
No fix yet
MEDIUM 6.9
CVE-2015-1305
McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, and consequently gain privilege…
Data Loss Prevention Endpoint
after 9.3.300