Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2012-4974
Layton Helpbox 4.4.0 allows remote authenticated users to change the login context and gain privileges via a modified (1) loggedinenduser, (2) logged…
Helpbox
Mitigation only
MEDIUM 6.9
CVE-2012-3317
IBM WebSphere Message Broker 6.1 before 6.1.0.11, 7.0 before 7.0.0.5, and 8.0 before 8.0.0.2 has incorrect ownership of certain uninstaller Java Runt…
Websphere Message Broker
Mitigation only
HIGH 7.5
CVE-2012-1598
Joomla! 1.5.x before 1.5.26 has unspecified impact and attack vectors related to "insufficient randomness" and a "password reset vulnerability."
Joomla\!
Mitigation only
MEDIUM 5.0
CVE-2012-1599
Joomla! 1.5.x before 1.5.26 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end information" via…
Joomla\!
Mitigation only
MEDIUM 5.0
CVE-2012-4475
The Security Questions module for Drupal 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.1 does not properly restrict access, which allows remote att…
Security Questions
Patch available
MEDIUM 5.0
CVE-2012-4477
Unspecified vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to bypass access restrictions via unknown attack v…
Drag \& Drop Gallery
Patch available
HIGH 7.5
CVE-2012-4470
The Listhandler module 6.x-1.x before 6.x-1.1 for Drupal does not properly check permissions when importing emails, which allows remote comment autho…
Listhandler
Patch available
MEDIUM 5.0
CVE-2012-4471
The Search Autocomplete module 7.x-2.x before 7.x-2.4 for Drupal does not properly restrict access to the module admin page, which allows remote atta…
Search Autocomplete
Patch available
HIGH 7.5
CVE-2012-4964EPSS 8%
The Samsung printer firmware before 20121031 has a hardcoded read-write SNMP community, which makes it easier for remote attackers to obtain administ…
Printer Firmware
after 20121030
MEDIUM 5.0
CVE-2012-4522
The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlevel 286 and Ruby 2.0.0 before r37163 allows context-dependent attackers to creat…
Ruby
Mitigation only
MEDIUM 6.0
CVE-2012-2244
Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote authenticated administrators to execute arbitrary programs by modifying the path to cl…
Mahara
Patch available
MEDIUM 6.9
CVE-2012-3516
The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 4.2 and Citrix XenServer 6.0.2 allows local guest kernels or administra…
Xenserver
after 6.0.2
HIGH 7.5
CVE-2011-4605
The (1) JNDI service, (2) HA-JNDI service, and (3) HAJNDIFactory invoker servlet in JBoss Enterprise Application Platform 4.3.0 CP10 and 5.1.2, Web P…
Jboss Enterprise Application Platform
after 5.2.0
HIGH 9.0
CVE-2012-5759
The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 allows remote authenticated users to bypass intended a…
Websphere Datapower Xc10 Appliance
Mitigation only
HIGH 10.0
CVE-2012-5863EPSS 25%
These Sinapsi devices do not check for special elements in commands sent
to the system. By accessing certain pages with administrative privileges
t…
Sinapsi Firmware
after 2.0.2870
HIGH 10.0
CVE-2012-5864
These Sinapsi devices
do not check if users that visit pages within the device have properly
authenticated. By directly visiting the pages within t…
Sinapsi Firmware
after 2.0.2870
HIGH 7.2
CVE-2012-3512
Munin before 2.0.6 stores plugin state files that run as root in the same group-writable directory as non-root plugins, which allows local users to e…
Munin
after 2.0.5
HIGH 9.3
CVE-2012-3513
munin-cgi-graph in Munin before 2.0.6, when running as a CGI module under Apache, allows remote attackers to load new configurations and create files…
Munin
after 2.0.5
MEDIUM 6.5
CVE-2012-5479
The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute…
Moodle
Mitigation only
MEDIUM 6.4
CVE-2012-5480
The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended rest…
Moodle
Mitigation only
HIGH 9.3
CVE-2012-4210
The Style Inspector in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 does not properly restrict the context of HTML markup and Casc…
Firefox
after 16.0.2
MEDIUM 6.5
CVE-2012-5471
The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to acce…
Moodle
Patch available
MEDIUM 6.8
CVE-2012-4203
The New Tab page in Mozilla Firefox before 17.0 uses a privileged context for execution of JavaScript code by bookmarklets, which allows user-assiste…
Firefox
after 16.0.2
MEDIUM 5.8
CVE-2012-4510
cups-pk-helper before 0.2.3 does not properly wrap the (1) cupsGetFile and (2) cupsPutFile function calls, which allows user-assisted remote attacker…
Cups Pk Helper
after 0.2.2
MEDIUM 6.4
CVE-2012-4523
radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block b…
Radsecproxy
after 1.6
MEDIUM 6.4
CVE-2012-4566
The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that are unre…
Radsecproxy
after 1.6.1
HIGH 7.2
CVE-2012-5519
CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0…
Cups
No fix yet
HIGH 7.2
CVE-2012-4225
NVIDIA UNIX graphics driver before 295.71 and before 304.32 allows local users to write to arbitrary physical memory locations and gain privileges by…
Unix Graphic Driver
after 304.32
MEDIUM 5.0
CVE-2011-2486
nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prevent Firefox plugins from dete…
Nspluginwrapper
Patch available
HIGH 9.3
CVE-2012-5897
The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and earlier do not properly implem…
Intrust
after 10.4.0.853