Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2013-4294
The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Folsom 2012.2.x and Grizzly before 2013.1.4 do not properly compare the …
Keystone
Patch available
MEDIUM 5.0
CVE-2013-5502
The web interface in Cisco MediaSense does not properly protect the client-server communication channel, which allows remote attackers to obtain sens…
Mediasense
Mitigation only
MEDIUM 6.9
CVE-2013-5691
The (1) IPv6 and (2) ATM ioctl request handlers in the kernel in FreeBSD 8.3 through 9.2-STABLE do not validate SIOCSIFADDR, SIOCSIFBRDADDR, SIOCSIFD…
FreeBSD
Patch available
MEDIUM 6.9
CVE-2013-4325
The check_permission_v1 function in base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.9 does not properly use D-Bus for communicatio…
Linux Imaging And Printing Project
Mitigation only
MEDIUM 6.8
CVE-2013-1130
Cisco AnyConnect Secure Mobility Client on Mac OS X uses weak permissions for a library directory, which allows local users to gain privileges via a …
Anyconnect Secure Mobility Client
Mitigation only
MEDIUM 6.3
CVE-2013-4706
The SSH implementation on the D-Link Japan DWL-2100AP with firmware before R252JP-RC572 allows remote authenticated users to cause a denial of servic…
Dwl 2100ap
after 2.50
MEDIUM 6.3
CVE-2013-4707
The SSH implementation on D-Link Japan DES-3810 devices with firmware before R2.20.011 allows remote authenticated users to cause a denial of service…
Des 3810 Firmware
Mitigation only
MEDIUM 5.0
CVE-2013-5157
The Twitter subsystem in Apple iOS before 7 does not require API conformity for access to Twitter daemon interfaces, which allows attackers to post T…
Iphone Os
after 6.1.4
MEDIUM 6.3
CVE-2013-5145
kextd in Kext Management in Apple iOS before 7 does not properly verify authorization for IPC messages, which allows local users to (1) load or (2) u…
Iphone Os
after 6.1.4
MEDIUM 5.8
CVE-2013-0957
Data Protection in Apple iOS before 7 allows attackers to bypass intended limits on incorrect passcode entry, and consequently avoid a configured Era…
Iphone Os
after 6.1.4
MEDIUM 6.2
CVE-2013-1726
Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaM…
Firefox
after 23.0.1
MEDIUM 5.0
CVE-2013-1737
Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 d…
Firefox
after 23.0.1
HIGH 10.0
CVE-2013-5754
The authorization implementation on Dahua DVR appliances accepts a hash string representing the current date for the role of a master password, which…
Dvr0404hd A
Mitigation only
HIGH 9.3
CVE-2013-3614EPSS 7%
Dahua DVR appliances have a small value for the maximum password length, which makes it easier for remote attackers to obtain access via a brute-forc…
Dvr0404hd A
No fix yet
MEDIUM 5.5
CVE-2013-2296
Walrus in Eucalyptus before 3.2.2 does not verify authorization for the GetBucketLoggingStatus, SetBucketLoggingStatus, and SetBucketVersioningStatus…
Eucalyptus
after 3.2.1
MEDIUM 6.0
CVE-2013-2256
OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows r…
Nova
2013.1.3+
HIGH 7.5
CVE-2013-4182
app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to acces…
Openstack
after 1.2.1
MEDIUM 6.8
CVE-2013-1027
Installer in Apple Mac OS X before 10.8.5 provides an option to continue a package's installation after encountering a revoked certificate, which mig…
Mac Os X
after 10.8.4
MEDIUM 5.5
CVE-2013-1033
Screen Lock in Apple Mac OS X before 10.8.5 does not properly track sessions, which allows remote authenticated users to bypass locking by leveraging…
Mac Os X
after 10.8.4
MEDIUM 5.0
CVE-2013-5489
The gadget implementation in Cisco SocialMiner does not properly restrict the content of GET requests, which allows remote attackers to obtain sensit…
Socialminer
Mitigation only
MEDIUM 6.5
CVE-2013-4329
The xenlight library (libxl) in Xen 4.0.x through 4.2.x, when IOMMU is disabled, provides access to a busmastering-capable PCI passthrough device bef…
Xen
Patch available
HIGH 10.0
CVE-2013-2934
Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 does not properly restrict access to web services, which has unspeci…
Cloudportal Services Manager
after 10.0
MEDIUM 6.9
CVE-2013-3859
Microsoft Pinyin IME 2010, when used in conjunction with Microsoft Office 2010 SP1, does not properly restrict configuration options, which allows lo…
Office
Mitigation only
HIGH 7.2
CVE-2013-4984EPSS 8%
The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain…
Web Appliance
after 3.7.9
MEDIUM 6.0
CVE-2013-3601
Coursemill Learning Management System (LMS) 6.6 does not properly restrict JSP function calls, which allows remote authenticated users to perform arb…
Coursemill Learning Management System
Mitigation only
MEDIUM 6.0
CVE-2013-3276
EMC RSA Archer GRC 5.x before 5.4 allows remote authenticated users to bypass intended access restrictions and complete a login by leveraging a deact…
Rsa Archer Egrc
Mitigation only
MEDIUM 5.8
CVE-2013-2123
The Node access user reference module 6.x-3.x before 6.x-3.5 and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to content cont…
Nodeaccess Userreference Module
Patch available
HIGH 7.5
CVE-2013-2247
The Fast Permissions Administration module 6.x-2.x before 6.x-2.5 and 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to the moda…
Fast Permission Administration
Patch available
MEDIUM 5.2
CVE-2013-2077
Xen 4.0.x, 4.1.x, and 4.2.x does not properly restrict the contents of a XRSTOR, which allows local PV guest users to cause a denial of service (unha…
Xen
Mitigation only
HIGH 7.4
CVE-2013-2211
The libxenlight (libxl) toolstack library in Xen 4.0.x, 4.1.x, and 4.2.x uses weak permissions for xenstore keys for paravirtualised and emulated ser…
Xen
Mitigation only