Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2012-5901
DFLabs PTK 1.0.5 stores data files with predictable names under the web document root with insufficient access control, which allows remote attackers…
Ptk
Mitigation only
MEDIUM 5.0
CVE-2012-5892
Havalite CMS 1.1.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to dow…
Cms
after 1.1.0
MEDIUM 5.0
CVE-2012-5885EPSS 9%
The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.…
Tomcat
Mitigation only
MEDIUM 5.5
CVE-2012-5522
MantisBT before 1.2.12 does not use an expected default value during decisions about whether a user may modify the status of a bug, which allows remo…
Mantisbt
after 1.2.11
MEDIUM 5.5
CVE-2012-5523
core/email_api.php in MantisBT before 1.2.12 does not properly manage the sending of e-mail notifications about restricted bugs, which might allow re…
Mantisbt
after 1.2.11
HIGH 8.3
CVE-2012-5458
VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows use weak permissions for unspecified process threads, which allows …
Player
Mitigation only
HIGH 9.3
CVE-2012-1895EPSS 23%
The reflection implementation in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4 does not properly enforce object permissions, which…
.net Framework
Mitigation only
HIGH 9.3
CVE-2012-4777EPSS 25%
The code-optimization feature in the reflection implementation in Microsoft .NET Framework 4 and 4.5 does not properly enforce object permissions, wh…
.net Framework
Mitigation only
MEDIUM 5.0
CVE-2012-1810
EOSCoreScada.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to cause a denial of service (daemon restart) by sending data to TCP por…
Eoscada
after 11.0.19.1
MEDIUM 5.0
CVE-2012-4734
Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to conduct a "confused deputy" attack to bypass the CSRF warn…
Rt
Mitigation only
MEDIUM 5.5
CVE-2012-5482
The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected image…
Essex
Patch available
MEDIUM 5.5
CVE-2012-4573
The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected image…
Essex
Patch available
MEDIUM 6.8
CVE-2012-4553
Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an e…
Drupal
Patch available
MEDIUM 5.0
CVE-2012-4554EPSS 16%
The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE declaration in an XRDS file.
Drupal
Patch available
MEDIUM 6.8
CVE-2012-3523
The STARTTLS implementation in nnrpd in INN before 2.5.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert…
Inn
after 2.5.2
MEDIUM 6.4
CVE-2012-2455
Advanced Productivity Software DTE Axiom before 12.3.3 does not validate the registration ID, which allows remote attackers to bypass authentication …
Dte Axiom
after 12.3.2
MEDIUM 6.4
CVE-2012-4022
Pebble before 2.6.4 allows remote attackers to trigger loss of blog-entry viewability via a crafted comment.
Pebble
after 2.6.3
HIGH 7.5
CVE-2012-5117
Google Chrome before 23.0.1271.64 does not properly restrict the loading of an SVG subresource in the context of an IMG element, which has unspecifie…
Chrome
after 23.0.1271.62
HIGH 10.0
CVE-2012-5278EPSS 9%
Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux,…
Flash Player
3.5.0.600 / 10.3.183.43+
HIGH 7.5
CVE-2012-4498
The Activism module 6.x-2.x before 6.x-2.1 for Drupal does not properly restrict access to the "Campaign" content type, which might allow remote atta…
Activism
Patch available
HIGH 10.0
CVE-2012-5417
Cisco Prime Data Center Network Manager (DCNM) before 6.1(1) does not properly restrict access to certain JBoss MainDeployer functionality, which all…
Prime Data Center Network Manager
Mitigation only
MEDIUM 5.0
CVE-2012-4488
The Location module 6.x before 6.x-3.2 and 7.x before 7.x-3.0-alpha1 for Drupal does not properly check user or node access permissions, which allows…
Location
Patch available
MEDIUM 5.8
CVE-2012-4491
The Monthly Archive by Node Type module 6.x for Drupal does not properly check permissions defined by node_access modules, which allows remote attack…
Monthly Archive By Node Type
Mitigation only
MEDIUM 5.0
CVE-2012-4499
The contact formatter page in the Email Field module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to email th…
Email
Patch available
MEDIUM 5.0
CVE-2012-4483
The commons_discussion_views_default_views function in modules/features/commons_discussion/commons_discussion.views_default.inc in the Drupal Commons…
Commons
Patch available
HIGH 10.0
CVE-2012-4501EPSS 8%
Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user acc…
Cloudstack
Mitigation only
HIGH 7.5
CVE-2012-5302
The server in TIBCO Formvine 3.1.x and 3.2.x before 3.2.1 does not properly implement access control, which allows remote attackers to obtain sensiti…
Formvine
Mitigation only
HIGH 7.5
CVE-2012-5168
ATutor AContent before 1.2-1 allows remote attackers to modify arbitrary user passwords or category names via a direct request to (1) user/index_inli…
Acontent
after 1.2
MEDIUM 6.5
CVE-2012-5454
user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arb…
Acontent
No fix yet
MEDIUM 6.8
CVE-2012-4845
The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC environment, which allows attacke…
Vios
Mitigation only