Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2012-5385
install/index.php in Craig Knudsen WebCalendar before 1.2.5 allows remote attackers to modify settings.php and possibly execute arbitrary code via ve…
Webcalendar
Mitigation only
HIGH 9.3
CVE-2012-3991
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 d…
Firefox
10.0.8 / 16.0+
MEDIUM 5.0
CVE-2010-5065
popup.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to bypass intended member restrictions and read news posts via a modified newsid…
Virtual War
No fix yet
MEDIUM 5.0
CVE-2012-1623
The Registration Codes module before 6.x-2.4 for Drupal does not restrict access to the registration code list, which might allow remote attackers to…
Regcode
after 6.x-2.3
MEDIUM 6.9
CVE-2012-4443
Monkey HTTP Daemon 0.9.3 uses a real UID of root and a real GID of root during execution of CGI scripts, which might allow local users to gain privil…
Monkey
Mitigation only
MEDIUM 5.0
CVE-2012-5298
Mavili Guestbook, as released in November 2007, stores guestbook.mdb under the web root with insufficient access control, which allows remote attacke…
Mavili Guestbook
No fix yet
HIGH 7.5
CVE-2012-5299
Mavili Guestbook, as released in November 2007, allows remote attackers to edit, delete, and approve arbitrary messages via a direct request to (1) e…
Mavili Guestbook
No fix yet
HIGH 7.2
CVE-2012-0692
CA License (aka CA Licensing) before 1.90.03 allows local users to modify or create arbitrary files, and consequently gain privileges, via unspecifie…
License Software
after 1.90.02
HIGH 7.2
CVE-2012-0691
CA License (aka CA Licensing) before 1.90.03 does not properly restrict system commands, which allows local users to gain privileges via unspecified …
License Software
after 1.90.02
MEDIUM 5.0
CVE-2012-4063
The Apache Santuario configuration in Eucalyptus before 3.1.1 does not properly restrict applying XML Signature transforms to documents, which allows…
Eucalyptus
after 3.1.0
MEDIUM 6.5
CVE-2012-4064
Eucalyptus before 3.1.1 does not properly restrict the binding of external SOAP web-services messages, which allows remote authenticated users to gai…
Eucalyptus
after 3.1.0
MEDIUM 6.9
CVE-2011-4945
PolicyKit 0.103 sets the AdminIdentities to "wheel" by default, which allows local users in the wheel group to gain root privileges without authentic…
Policykit
Patch available
MEDIUM 6.0
CVE-2012-1576
The myuser_delete function in libathemecore/account.c in Atheme 5.x before 5.2.7, 6.x before 6.0.10, and 7.x before 7.0.0-beta2 does not properly cle…
Atheme
Mitigation only
MEDIUM 6.0
CVE-2012-4450
389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users …
389 Directory Server
Patch available
MEDIUM 5.0
CVE-2012-1591
The image module in Drupal 7.x before 7.14 does not properly check permissions when caching derivative image styles of private images, which allows r…
Drupal
Patch available
MEDIUM 5.0
CVE-2012-1833
VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allow remote attackers to bypass …
Grails
after 1.3.7
MEDIUM 5.0
CVE-2012-2680
Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, does not properly restrict access to resources, which a…
Enterprise Mrg
after 0.1.5192-4
MEDIUM 6.8
CVE-2012-0956
ubiquity-slideshow-ubuntu before 58.2, during installation, allows remote man-in-the-middle attackers to execute arbitrary web script or HTML and rea…
Ubiquity Slideshow Ubuntu
after 58.1
MEDIUM 5.0
CVE-2012-3742
Safari in Apple iOS before 6 does not properly restrict use of an unspecified Unicode character that looks similar to the https lock indicator, which…
Iphone Os
after 5.1.1
MEDIUM 5.0
CVE-2012-3743
The System Logs implementation in Apple iOS before 6 does not restrict /var/log access by sandboxed apps, which allows remote attackers to obtain sen…
Iphone Os
after 5.1.1
MEDIUM 6.9
CVE-2012-3728
The kernel in Apple iOS before 6 dereferences invalid pointers during the handling of packet-filter data structures, which allows local users to gain…
Iphone Os
after 5.1.1
MEDIUM 5.0
CVE-2012-5007
The Fill PDF module 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to write to arbitrary PDF files via unspecified vectors related to the …
Fillpdf
Patch available
HIGH 7.5
CVE-2012-4993
torrent_functions.php in RivetTracker 1.03 and earlier does not properly restrict access, which allows remote attackers to have an unspecified impact.
Rivettracker
after 1.03
MEDIUM 5.5
CVE-2012-4408
course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, …
Moodle
Patch available
MEDIUM 6.9
CVE-2012-4425
libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute …
Spice Gtk
Patch available
MEDIUM 6.9
CVE-2012-3524
libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileg…
Libdbus
after 1.5.12
MEDIUM 5.0
CVE-2012-3030
WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, stores sensitive information under the web root with i…
Simatic Pcs7
after 7.0
HIGH 7.5
CVE-2012-2994EPSS 6%
The CoSoSys Endpoint Protector 4 appliance establishes an EPProot password based entirely on the appliance serial number, which makes it easier for r…
Endpoint Protector Appliace 4
Mitigation only
MEDIUM 5.0
CVE-2012-2058
The Ubercart Payflow module for Drupal does not use a secure token, which allows remote attackers to forge payments via unspecified vectors.
Ubercart Payflow
Mitigation only
MEDIUM 5.0
CVE-2010-5078
SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 stores sensitive information under the web root with insufficient access control, which allow…
Silverstripe
Mitigation only