Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2014-4844
The import/export functionality in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 allows re…
Business Process Manager
Mitigation only
HIGH 10.0
CVE-2014-9357EPSS 6%
Docker 1.3.2 allows remote attackers to execute arbitrary code with root privileges via a crafted (1) image or (2) build in a Dockerfile in an LZMA (…
Docker
Mitigation only
HIGH 7.5
CVE-2014-9249
The default configuration of Zenoss Core before 5 allows remote attackers to read or modify database information by connecting to unspecified open po…
Zenoss Core
after 4.2.5
HIGH 7.2
CVE-2014-8609
The addAccount method in src/com/android/settings/accounts/AddAccountSettings.java in the Settings application in Android before 5.0.0 does not prope…
Android
after 4.4.4
HIGH 7.2
CVE-2014-7911EPSS 25%
luni/src/main/java/java/io/ObjectInputStream.java in the java.io.ObjectInputStream implementation in Android before 5.0.0 does not verify that deseri…
Android
after 4.4.4
MEDIUM 5.0
CVE-2014-6257
Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions by using a web-endpoint URL to invoke an object helper me…
Zenoss Core
after 5.0.0
HIGH 7.5
CVE-2014-6256
Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions and place files in a directory with public (1) read or (2…
Zenoss Core
after 5.0.0
MEDIUM 5.0
CVE-2014-6408
Docker 1.3.0 through 1.3.1 allows remote attackers to modify the default run profile of image containers and possibly bypass the container by applyin…
Docker
Mitigation only
MEDIUM 5.0
CVE-2014-8270EPSS 20%
BMC Track-It! 11.3 allows remote attackers to gain privileges and execute arbitrary code by creating an account whose name matches that of a local sy…
Track It\!
Mitigation only
HIGH 9.0
CVE-2014-8373
The VMware Remote Console (VMRC) function in VMware vCloud Automation Center (vCAC) 6.0.1 through 6.1.1 allows remote authenticated users to gain pri…
Vcloud Automation Center
No fix yet
MEDIUM 5.0
CVE-2014-8453EPSS 13%
Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow remote attackers to bypass the Same Origin Policy via …
Acrobat
Mitigation only
HIGH 7.5
CVE-2014-9304EPSS 8%
Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrati…
Media Server
after 0.9.9.2
HIGH 7.8
CVE-2014-8868EPSS 7%
EntryPass N5200 Active Network Control Panel does not properly restrict access, which allows remote attackers to obtain the administrator username an…
N5200 Active Network Control Panel
No fix yet
HIGH 7.2
CVE-2014-8651
The KDE Clock KCM policykit helper in kde-workspace before 4.11.14 and plasma-desktop before 5.1.1 allows local users to gain privileges via a crafte…
Plasma Desktop
after 5.1
HIGH 9.0
CVE-2014-4629
EMC Documentum Content Server 7.0, 7.1 before 7.1 P10, and 6.7 before SP2 P19 allows remote authenticated users to read or delete arbitrary files via…
Documentum Content Server
No fix yet
HIGH 7.2
CVE-2014-2273
The hx170dec device driver in Huawei P2-6011 before V100R001C00B043 allows local users to read and write to arbitrary memory locations via unspecifie…
P2 6011 Firmware
No fix yet
HIGH 7.2
CVE-2014-9141
The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which allows local users to execute ar…
Fixed Assets Cs
after 13.1.4
HIGH 7.2
CVE-2014-9113
CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Users: Modify and Write) for the…
Prosystem Fx Engagement
after 7.1
HIGH 7.2
CVE-2014-5284
host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local users to modi…
Ossec
after 2.8.0
MEDIUM 5.0
CVE-2014-3703
OpenStack PackStack 2012.2.1, when the Open vSwitch (OVS) monolithic plug-in is not used, does not properly set the libvirt_vif_driver configuration …
Packstack
Mitigation only
MEDIUM 5.8
CVE-2014-5268
The Fasttoggle module 7.x-1.3 and 7.x-1.4 for Drupal allows remote attackers to block or unblock an account via a crafted user status link.
Fasttoggle
Patch available
HIGH 7.2
CVE-2014-8419
Wibu-Systems CodeMeter Runtime before 5.20 uses weak permissions (read and write access for all users) for codemeter.exe, which allows local users to…
Codemeter Runtime
after 5.10c
MEDIUM 6.5
CVE-2014-8558
JExperts Channel Platform 5.0.33_CCB allows remote authenticated users to bypass access restrictions via crafted action and key parameters.
Channel Platform
No fix yet
HIGH 9.0
CVE-2014-8368
The web interface in Aruba Networks AirWave before 7.7.14 and 8.x before 8.0.5 allows remote authenticated users to gain privileges and execute arbit…
Airwave
7.7.14 / 8.0.5+
MEDIUM 6.8
CVE-2014-9015
Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to …
Drupal
6.34 / 7.34+
HIGH 9.0
CVE-2014-8418
The DB dialplan function in Asterisk Open Source 1.8.x before 1.8.32, 11.x before 11.1.4.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified …
Certified Asterisk
11.14.1 / 12.7.1+
MEDIUM 6.5
CVE-2014-8417
ConfBridge in Asterisk 11.x before 11.14.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified Asterisk 11.6 before 11.6-cert8 allows remote au…
Asterisk
11.14.1 / 12.7.1+
HIGH 7.5
CVE-2014-8413
The res_pjsip_acl module in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1 does not properly create and load ACLs defined in pjsip.co…
Asterisk
12.7.1 / 13.0.1+
MEDIUM 5.0
CVE-2014-8412
The (1) VoIP channel drivers, (2) DUNDi, and (3) Asterisk Manager Interface (AMI) in Asterisk Open Source 1.8.x before 1.8.32.1, 11.x before 11.14.1,…
Certified Asterisk
1.8.32.1 / 11.14.1+
MEDIUM 6.4
CVE-2014-1424
apparmor_parser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu 14.04 allows attackers to bypass AppArmor policies via unspecified ve…
Apparmor
after 2.8.94-0ubuntu1.4