Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.9
CVE-2013-1662
vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host…
Workstation
Mitigation only
MEDIUM 6.8
CVE-2013-3370
Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 does not properly restrict access to private callback components, which allows remot…
Rt
Patch available
MEDIUM 5.0
CVE-2013-3016
IBM WebSphere Portal 6.1, 7.0, and 8.0 allows remote attackers to access the user directory via a crafted request for a servlet, related to the serve…
Websphere Portal
Mitigation only
MEDIUM 6.0
CVE-2013-4230
The mm_webform submodule in the Monster Menus module 6.x-6.x before 6.x-6.61 and 7.x-1.x before 7.x-1.13 for Drupal does not properly restrict access…
Monster Menus
Patch available
MEDIUM 5.0
CVE-2013-2905
The SharedMemory::Create function in memory/shared_memory_posix.cc in Google Chrome before 29.0.1547.57 uses weak permissions under /dev/shm/, which …
Debian Linux
after 29.0.1547.56
MEDIUM 5.0
CVE-2013-4964
Puppet Enterprise before 3.0.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to…
Puppet Enterprise
after 3.0.0
MEDIUM 6.9
CVE-2013-2796
Schneider Electric Vijeo Citect 7.20 and earlier, CitectSCADA 7.20 and earlier, and PowerLogic SCADA 7.20 and earlier allow remote attackers to read …
Citectscada
after 7.20
HIGH 7.2
CVE-2013-4943
The client application in Siemens COMOS before 9.1 Update 458, 9.2 before 9.2.0.6.37, and 10.0 before 10.0.3.0.19 allows local users to gain privileg…
Comos
Mitigation only
MEDIUM 5.4
CVE-2013-1717
Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20…
Firefox
after 22.0
MEDIUM 5.0
CVE-2013-1190
The C-Series Rack Server component 1.4 in Cisco Unified Computing System (UCS) does not properly restrict inbound access to ports, which allows remot…
Unified Computing System
Mitigation only
MEDIUM 5.0
CVE-2013-3219
bitcoind and Bitcoin-Qt 0.8.x before 0.8.1 do not enforce a certain block protocol rule, which allows remote attackers to bypass intended access rest…
Bitcoin Core
Mitigation only
HIGH 7.2
CVE-2013-4672
The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 has an incorrect sudoers file, which allows local users to bypass int…
Web Gateway
after 5.1
HIGH 7.2
CVE-2013-3956EPSS 8%
The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2 on Windows Vista and Windows…
Client
No fix yet
MEDIUM 6.0
CVE-2013-2113EPSS 21%
The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or …
Openstack
after 1.2.0
MEDIUM 5.8
CVE-2013-2881
Google Chrome before 28.0.1500.95 does not properly handle frames, which allows remote attackers to bypass the Same Origin Policy via a crafted web s…
Chrome
after 28.0.1500.94
MEDIUM 6.4
CVE-2013-4851
The vfs_hang_addrlist function in sys/kern/vfs_export.c in the NFS server implementation in the kernel in FreeBSD 8.3 and 9.x through 9.1-RELEASE-p5 …
FreeBSD
Mitigation only
MEDIUM 5.0
CVE-2013-3445
The firewall subsystem in Cisco Identity Services Engine has an incorrect rule for open ports, which allows remote attackers to cause a denial of ser…
Identity Services Engine
Mitigation only
MEDIUM 5.0
CVE-2013-3438
The web framework in the server in Cisco Unified MeetingPlace Web Conferencing allows remote attackers to bypass intended access restrictions and rea…
Unified Meetingplace Web Conferencing
No fix yet
HIGH 7.5
CVE-2013-2165EPSS 13%
ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform …
Jboss Enterprise Application Platform
after 2.2.0
MEDIUM 5.0
CVE-2013-2355
HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via …
System Management Homepage
after 7.2
MEDIUM 5.0
CVE-2012-5217
HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via …
System Management Homepage
after 7.2
HIGH 9.0
CVE-2013-3274
EMC Avamar Server and Avamar Virtual Edition before 7.0 on Data Store Gen3, Gen4, and Gen4s platforms do not properly determine authorization for cal…
Avamar Server
after 6.1
MEDIUM 5.0
CVE-2013-3436
The default configuration of the Group Encrypted Transport VPN (GET VPN) feature on Cisco IOS uses an improper mechanism for enabling Group Domain of…
iOS
Mitigation only
HIGH 7.5
CVE-2013-4878EPSS 31%
The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias direct…
Parallels Plesk Panel
Mitigation only
MEDIUM 6.9
CVE-2013-4872
Google Glass before XE6 does not properly restrict the processing of QR codes, which allows physically proximate attackers to modify the configuratio…
Glass
Mitigation only
MEDIUM 5.0
CVE-2013-3426
The Serviceability servlet on Cisco 9900 IP phones does not properly restrict paths, which allows remote attackers to read arbitrary files by specify…
Unified Ip Phones 9900 Series Firmware
Mitigation only
MEDIUM 5.0
CVE-2013-1907
The Commons Group module before 7.x-3.1 for Drupal, as used in the Commons module before 7.x-3.1, does not properly restrict access to groups, which …
Commons
after 7.x-3.0
MEDIUM 5.0
CVE-2013-1908
The Commons Wikis module before 7.x-3.1 for Drupal, as used in the Commons module before 7.x-3.1, does not properly restrict access to groups, which …
Commons
after 7.x-3.0
MEDIUM 5.0
CVE-2013-2122
The Edit Limit module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to comments, which allows remote authenticated users with t…
Edit Limit
Mitigation only
MEDIUM 6.2
CVE-2013-3692
BlackBerry 10 OS before 10.0.10.648 on BlackBerry Z10 smartphones uses weak permissions for a BlackBerry Protect object, which allows physically prox…
Blackberry Os
after 10.0.10.261