Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2014-2862
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not check authorization in unspecified situations, which allows remote authenticated user…
Commonspot Content Server
after 7.0.1
HIGH 7.5
CVE-2014-2865
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a '\0' character, as demons…
Commonspot Content Server
after 7.0.1
MEDIUM 5.5
CVE-2014-0642
EMC Documentum Content Server before 6.7 SP1 P26, 6.7 SP2 before P13, 7.0 before P13, and 7.1 before P02 allows remote authenticated users to bypass …
Documentum Content Server
after 6.7
MEDIUM 5.8
CVE-2014-1986
The Content Provider in the KOKUYO CamiApp application 1.21.1 and earlier for Android allows attackers to bypass intended access restrictions and rea…
Camiapp
after 1.21.1
HIGH 9.3
CVE-2014-0514EPSS 72%
The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows remote attackers to execute ar…
Adobe Reader
after 11.1.3
HIGH 7.5
CVE-2014-0107EPSS 14%
The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is en…
Xalan Java
after 2.7.1
MEDIUM 6.0
CVE-2014-0167
The Nova EC2 API security group implementation in OpenStack Compute (Nova) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 does not enforce R…
Compute
Patch available
HIGH 8.5
CVE-2014-2849EPSS 60%
The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user pass…
Web Appliance Firmware
after 3.8.1.1
HIGH 7.8
CVE-2014-2746
net/IOService.java in Tigase before 5.2.1 does not properly restrict the processing of compressed XML elements, which allows remote attackers to caus…
Tigase
after 5.2.0
HIGH 7.8
CVE-2014-2829
Erlang Solutions MongooseIM through 1.3.1 rev. 2 does not properly restrict the processing of compressed XML elements, which allows remote attackers …
Mongooseim
after 1.3.1
HIGH 7.8
CVE-2014-2743
plugins/mod_compression.lua in Lightwitch Metronome through 3.4 does not properly restrict the processing of compressed XML elements, which allows re…
Metronome
after 3.4
HIGH 7.8
CVE-2014-2745
Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service…
Prosody
after 0.9.3
HIGH 7.8
CVE-2014-2741
nio/XMLLightweightParser.java in Ignite Realtime Openfire before 3.9.2 does not properly restrict the processing of compressed XML elements, which al…
Openfire
after 3.9.1
HIGH 7.8
CVE-2014-2742
Isode M-Link before 16.0v7 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of s…
M Link
Mitigation only
MEDIUM 6.0
CVE-2014-0908
The User Attribute implementation in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.2, and 8.5.x through 8.5.0.1 does …
Business Process Manager
Mitigation only
HIGH 7.5
CVE-2013-7364
An unspecified J2EE core service in the J2EE Engine in SAP NetWeaver does not properly restrict access, which allows remote attackers to read and wri…
Netweaver
Mitigation only
HIGH 7.5
CVE-2013-7367
SAP Enterprise Portal does not properly restrict access to the Federation configuration pages, which allows remote attackers to gain privileges via u…
Enterprise Portal
Mitigation only
HIGH 7.5
CVE-2014-2748
The Security Audit Log facility in SAP Enhancement Package (EHP) 6 for SAP ERP 6.0 allows remote attackers to modify or delete arbitrary log classes …
Enhancement Package
Mitigation only
HIGH 8.5
CVE-2014-2126
Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47), 8.4 before 8.4(7.5), 8.7 before 8.7(1.11), 9.0 before 9.0(3.10), and 9.1 befor…
Adaptive Security Appliance Software
Mitigation only
MEDIUM 5.0
CVE-2014-0508
Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR be…
Adobe Air Sdk
after 11.2.202.346
MEDIUM 5.0
CVE-2014-2541
The Rendezvous Daemon (rvd), Rendezvous Routing Daemon (rvrd), Rendezvous Secure Daemon (rvsd), and Rendezvous Secure Routing Daemon (rvsrd) in TIBCO…
Rendezvous
after 8.7.0
HIGH 7.5
CVE-2014-0592
Barclamp (aka barclamp-network) 1.7 for the Crowbar Framework, as used in SUSE Cloud 3, does not enable netfilter on bridges when creating new instan…
Barclamp
Patch available
MEDIUM 5.8
CVE-2014-0093
Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by…
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 5.0
CVE-2014-2237
The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when i…
Keystone
Mitigation only
HIGH 7.5
CVE-2014-0050EPSS 83%
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to c…
Commons Fileupload
after 1.3
HIGH 7.6
CVE-2013-6770
The CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android 4.3 and 4.4 does not properly restrict the set of users who can execute /sys…
Superuser
No fix yet
HIGH 10.0
CVE-2013-6775
The Chainfire SuperSU package before 1.69 for Android allows attackers to gain privileges via the (1) backtick or (2) $() type of shell metacharacter…
Supersu
Mitigation only
MEDIUM 6.5
CVE-2014-0061
The validator functions for the procedural languages (PLs) in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7,…
PostgreSQL
after 8.4.19
MEDIUM 6.5
CVE-2014-0344EPSS 6%
Properties.do in ZOHO ManageEngine OpStor before build 8500 does not properly check privilege levels, which allows remote authenticated users to obta…
Manageengine Opstor
after 8.3
MEDIUM 5.0
CVE-2014-1516
The saltProfileName function in base/GeckoProfileDirectories.java in Mozilla Firefox through 28.0.1 on Android relies on Android's weak approach to s…
Firefox
after 28.0.1