Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.8
CVE-2013-6918
The web interface on the Satechi travel router 1.5, when Wi-Fi is used for WAN access, exposes the console without authentication on the WAN IP addre…
Smart Travel Router
Mitigation only
MEDIUM 6.9
CVE-2013-6383
The aac_compat_ioctl function in drivers/scsi/aacraid/linit.c in the Linux kernel before 3.11.8 does not require the CAP_SYS_RAWIO capability, which …
Linux Kernel
3.2.53 / 3.4.69+
MEDIUM 5.5
CVE-2013-6373
The Exclusion plugin before 0.9 for Jenkins does not properly prevent access to resource locks, which allows remote authenticated users to list and r…
Exclusion
after 0.8
HIGH 9.0
CVE-2013-6863
SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows re…
Adaptive Server Enterprise
Mitigation only
HIGH 7.2
CVE-2013-1813
util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows lo…
Enterprise Linux
after 1.20.2
HIGH 7.9
CVE-2013-6375
Xen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properly flush the TLB after clearing a present translation table entry, whi…
Xen
Mitigation only
HIGH 7.2
CVE-2013-6831
PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms has a sudoers file that does not properly restrict user specifications, which al…
Mail Secure 5099sk
No fix yet
MEDIUM 6.4
CVE-2013-6823
GRMGApp in SAP NetWeaver allows remote attackers to bypass intended access restrictions via unspecified vectors.
Netweaver
No fix yet
HIGH 7.6
CVE-2013-4559EPSS 11%
lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run a…
Debian Linux
1.4.33+
MEDIUM 6.4
CVE-2013-6818
SAP NetWeaver Logviewer 6.30, when running on Windows, allows remote attackers to bypass intended access restrictions via unspecified vectors.
Netweaver Logviewer
No fix yet
HIGH 7.6
CVE-2013-2271
The D-Link DSL-2740B Gateway with firmware EU_1.0, when an active administrator session exists, allows remote attackers to bypass authentication and …
Dsl 2740b Firmware
No fix yet
MEDIUM 5.8
CVE-2013-5606
The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return va…
Network Security Services
Mitigation only
HIGH 7.2
CVE-2013-5972
VMware Workstation 9.x before 9.0.3 and VMware Player 5.x before 5.0.3 on Linux do not properly handle shared libraries, which allows host OS users t…
Workstation
Patch available
MEDIUM 5.8
CVE-2013-6802
Google Chrome before 31.0.1650.57 allows remote attackers to bypass intended sandbox restrictions by leveraging access to a renderer process, as demo…
Chrome
after 31.0.1650.57
MEDIUM 6.8
CVE-2013-5556
The license-installation module on the Cisco Nexus 1000V switch 4.2(1)SV1(5.2b) and earlier for VMware vSphere, Cisco Nexus 1000V switch 5.2(1)SM1(5.…
Nexus 1000v
after 4.2
MEDIUM 5.0
CVE-2013-3407
The web interface in Cisco Server Provisioner 6.4.0 Patch 5-1301292331 and earlier does not require authentication for unspecified pages, which allow…
Server Provisioner
after 6.4.0
MEDIUM 5.8
CVE-2013-6798
BlackBerry Link before 1.2.1.31 on Windows and before 1.1.1 build 39 on Mac OS X does not properly determine the user account for execution of Peer M…
Blackberry Link
after 1.2.0.28
MEDIUM 5.0
CVE-2013-2032
MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to prevent password changes without using both Special:PasswordReset and S…
Fedora
after 1.19.5
MEDIUM 6.6
CVE-2013-6685
The firmware on Cisco Unified IP phones 8961, 9951, and 9971 uses weak permissions for memory block devices, which allows local users to gain privile…
Unified Ip Phone Firmware
Mitigation only
MEDIUM 6.4
CVE-2013-5552
Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows…
iOS
after 12.4
HIGH 7.8
CVE-2013-5328
Adobe ColdFusion 10 before Update 12 allows remote attackers to read arbitrary files via unspecified vectors.
Coldfusion
after 10.0
MEDIUM 6.0
CVE-2013-4548
The mm_newkeys_from_blob function in monitor_wrap.c in sshd in OpenSSH 6.2 and 6.3, when an AES-GCM cipher is used, does not properly initialize memo…
Openssh
Mitigation only
MEDIUM 6.8
CVE-2013-6230EPSS 6%
The Winsock WSAIoctl API in Microsoft Windows Server 2008, as used in ISC BIND 9.6-ESV before 9.6-ESV-R10-P1, 9.8 before 9.8.6-P1, 9.9 before 9.9.4-P…
Bind
Mitigation only
HIGH 8.5
CVE-2013-4987
PineApp Mail-SeCure before 3.70 allows remote authenticated users to gain privileges by leveraging console access and providing shell metacharacters …
Mail Secure
after 3.69
MEDIUM 6.4
CVE-2013-3264
The WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress does not properly restrict access to (1) list/edit.php and (2) campaig…
Wp Ultimate Email Marketer Plugin
after 1.1.0
MEDIUM 6.8
CVE-2013-4419
The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership o…
Libguestfs
after 1.22.7
MEDIUM 6.4
CVE-2013-4497
The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an…
Havana
Mitigation only
MEDIUM 5.8
CVE-2013-6077
Citrix XenDesktop 7.0, when upgraded from XenDesktop 5.x, does not properly enforce policy rule permissions, which allows remote attackers to bypass …
Xendesktop
Mitigation only
HIGH 10.0
CVE-2013-6617
The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it easier for remote attackers to …
Salt
Mitigation only
MEDIUM 6.9
CVE-2013-4470
The Linux kernel before 3.12, when UDP Fragmentation Offload (UFO) is enabled, does not properly initialize certain data structures, which allows loc…
Linux Kernel
after 3.11.7