Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2013-2835
Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attacker…
Chrome Os
after 26.0.1410.56
MEDIUM 5.8
CVE-2013-2304
The Sleipnir Mobile application 2.8.0 and earlier and Sleipnir Mobile Black Edition application 2.8.0 and earlier for Android allow remote attackers …
Sleipnir Mobile
after 2.8.0
HIGH 8.5
CVE-2012-3022
The SaveToFile method in a certain ActiveX control in TrendDisplay.dll in Canary Labs TrendLink 9.0.2.27051 and earlier does not properly restrict th…
Trendlink
after 9.0.2.27051
MEDIUM 5.0
CVE-2013-0315
The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 allows remote attackers to read arbitrary files via a crafted extern…
Jboss Enterprise Portal Platform
Mitigation only
HIGH 9.3
CVE-2013-0501
The EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control, as used in Edraw Office Viewer Component, the client in IBM Cognos Disclosure Management (CDM)…
Cognos Disclosure Management
Mitigation only
HIGH 9.3
CVE-2013-1169
Cisco Unified MeetingPlace Web Conferencing Server 7.x before 7.1MR1 Patch 2, 8.0 before 8.0MR1 Patch 2, and 8.5 before 8.5MR3 Patch 1, when the Reme…
Unified Meetingplace Web Conferencing Server
Mitigation only
HIGH 7.5
CVE-2013-1800
The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-inje…
Crack
after 0.3.1
HIGH 7.5
CVE-2013-1801
The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-i…
Httparty
after 0.9.0
HIGH 7.5
CVE-2013-1802
The extlib gem 0.9.15 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-in…
Extlib
after 0.9.15
HIGH 7.2
CVE-2013-1858
The clone system-call implementation in the Linux kernel before 3.8.3 does not properly handle a combination of the CLONE_NEWUSER and CLONE_FS flags,…
Linux Kernel
after 3.8.2
HIGH 10.0
CVE-2013-1903
PostgreSQL, possibly 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 incorrectly provides t…
PostgreSQL
Mitigation only
HIGH 10.0
CVE-2013-0795
The System Only Wrapper (SOW) implementation in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird E…
Firefox
after 19.0.2
HIGH 8.2
CVE-2012-5879EPSS 5%
An ActiveX control in McHealthCheck.dll in McAfee Virtual Technician (MVT) and ePO-MVT 6.5.0.2101 and earlier allows remote attackers to modify or cr…
Mcafee Virtual Technician
after 6.5.0.2101
MEDIUM 6.8
CVE-2013-0918
Google Chrome before 26.0.1410.43 does not prevent navigation to developer tools in response to a drag-and-drop operation, which allows user-assisted…
Chrome
after 26.0.1410.42
MEDIUM 6.8
CVE-2013-0921
The Isolated Sites feature in Google Chrome before 26.0.1410.43 does not properly enforce the use of separate processes, which makes it easier for re…
Chrome
after 26.0.1410.42
HIGH 7.5
CVE-2013-0922
Google Chrome before 26.0.1410.43 does not properly restrict brute-force access attempts against web sites that require HTTP Basic Authentication, wh…
Chrome
after 26.0.1410.42
HIGH 7.5
CVE-2013-0924
The extension functionality in Google Chrome before 26.0.1410.43 does not verify that use of the permissions API is consistent with file permissions,…
Chrome
after 26.0.1410.42
HIGH 7.5
CVE-2013-0925
Google Chrome before 26.0.1410.43 does not ensure that an extension has the tabs (aka APIPermission::kTab) permission before providing a URL to this …
Chrome
after 26.0.1410.42
MEDIUM 6.4
CVE-2013-1859
The Node Parameter Control module 6.x-1.x for Drupal does not properly restrict access to the configuration options, which allows remote attackers to…
Node Parameter Control
No fix yet
MEDIUM 5.0
CVE-2013-0182
The Payment module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to payments, which allows remote attackers to read arbitrary p…
Payment
Patch available
MEDIUM 5.0
CVE-2013-0257
The email2image module 6.x-1.x and 6.x-2.x for Drupal does not properly restrict access to nodes, which allows remote attackers to read images of use…
Email2image
Patch available
HIGH 10.0
CVE-2013-0318
The admin page in the Banckle Chat module for Drupal does not properly restrict access, which allows remote attackers to bypass intended restrictions…
Banckle Chat
Mitigation only
MEDIUM 5.0
CVE-2013-0718
The Simeji application 4.8.1 and earlier for Android uses weak permissions for unspecified files, which allows attackers to obtain sensitive informat…
Simeji
after 4.8.1
MEDIUM 5.0
CVE-2013-0719
The ArtIME Japanese Input application 1.1.2 and earlier for Android uses weak permissions for unspecified files, which allows attackers to obtain sen…
Artime Japanese Input
after 1.1.2
MEDIUM 5.0
CVE-2013-0720
The COBIME application before 0.9.4 for Android uses weak permissions for unspecified files, which allows attackers to obtain sensitive information v…
Cobime
after 0.9.3
MEDIUM 5.0
CVE-2013-2300
The FlickWnn (aka OpenWnn/Flick support) application 2.02 and earlier for Android uses weak permissions for unspecified files, which allows attackers…
Flickwnn
after 2.02
MEDIUM 6.5
CVE-2013-1836
Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not properly manage privileges for WebDAV repositories…
Moodle
Mitigation only
MEDIUM 5.0
CVE-2013-1830
user/view.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce the forceloginforprofiles set…
Fedora
Patch available
HIGH 7.6
CVE-2013-0335
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circu…
Ubuntu Linux
Mitigation only
MEDIUM 5.0
CVE-2013-2640
ajax.functions.php in the MailUp plugin before 1.3.2 for WordPress does not properly restrict access to unspecified Ajax functions, which allows remo…
Wp Mailup
after 1.3.1