Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2010-5087
SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism …
Silverstripe
Patch available
MEDIUM 5.0
CVE-2010-5093
Member_ProfileForm in security/Member.php in SilverStripe 2.3.x before 2.3.7 allows remote attackers to hijack user accounts by saving data using the…
Silverstripe
Patch available
MEDIUM 5.0
CVE-2010-5094
The deleteinstallfiles function in control/ContentController.php in SilverStripe 2.3.x before 2.3.7 does not require ADMIN permissions, which allows …
Silverstripe
Mitigation only
HIGH 7.5
CVE-2012-2289EPSS 5%
EMC ApplicationXtender Desktop before 6.5 SP2 and ApplicationXtender Web Access .NET before 6.5 SP2 allow remote attackers to upload files to any loc…
Applicationxtender Desktop
after 6.5
HIGH 7.5
CVE-2012-3441
The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in Icinga 1.7.1 grants access to all databases to the icinga user, which …
Icinga
Mitigation only
MEDIUM 5.0
CVE-2009-5121
Websense Email Security 7.1 before Hotfix 4 allows remote attackers to bypass the sender-based blacklist by using the 8BITMIME EHLO keyword in the SM…
Websense Email Security
Mitigation only
HIGH 7.5
CVE-2011-5102
The Investigative Reports web interface in the TRITON management console in Websense Web Security 7.1 before Hotfix 109, 7.1.1 before Hotfix 06, 7.5 …
Websense Web Filter
No fix yet
MEDIUM 5.0
CVE-2012-4593
McAfee Application Control and Change Control 5.1.x and 6.0.0 do not enforce an intended password requirement in certain situations involving attribu…
Application Control
Mitigation only
MEDIUM 6.4
CVE-2010-3497
Symantec Norton AntiVirus 2011 does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it…
Norton Antivirus
Mitigation only
MEDIUM 6.4
CVE-2010-3498
AVG Anti-Virus does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for remo…
Anti Virus
Mitigation only
MEDIUM 6.4
CVE-2010-3499
F-Secure Anti-Virus does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for…
Anti Virus
Mitigation only
MEDIUM 6.5
CVE-2009-5115
McAfee Common Management Agent (CMA) 3.5.5 through 3.5.5.588 and 3.6.0 through 3.6.0.608, and McAfee Agent 4.0 before Patch 3, allows remote authenti…
Common Management Agent
Mitigation only
MEDIUM 6.4
CVE-2010-3496
McAfee VirusScan Enterprise 8.5i and 8.7i does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, whi…
Virusscan Enterprise
No fix yet
MEDIUM 5.5
CVE-2012-2164
The Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to bypass intended access res…
Rational Clearquest
Mitigation only
HIGH 8.5
CVE-2012-3009
Siemens COMOS before 9.1 Patch 413, 9.2 before Update 03 Patch 023, and 10.0 before Patch 005 allows remote authenticated users to obtain database ad…
Comos
after 9.1
MEDIUM 5.0
CVE-2012-2770
The Authen::ExternalAuth extension before 0.11 for Best Practical Solutions RT allows remote attackers to obtain a logged-in session via unspecified …
Authen\
after 0.08
MEDIUM 6.0
CVE-2012-2073
The Bundle copy module 7.x-1.x before 7.x-1.1 for Drupal does not check for the "use PHP for settings" permission while importing settings, which all…
Bundle Copy
Patch available
MEDIUM 5.0
CVE-2012-2081
The Organic Groups (OG) module 6.x-2.x before 6.x-2.3 for Drupal does not properly restrict access, which allows remote attackers to obtain sensitive…
Organic Groups
Patch available
MEDIUM 5.0
CVE-2012-4069
Dir2web 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database …
Dir2web
Mitigation only
HIGH 9.3
CVE-2012-4248
The Amazon Kindle Touch before 5.1.2 does not properly restrict access to the libkindleplugin.so NPAPI plugin interface, which might allow remote att…
Kindle Touch
after 5.1.1
MEDIUM 6.4
CVE-2012-2969
Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to bypass intended restrictions on filename extensions for created fil…
Resin
after 4.0.28
HIGH 7.5
CVE-2012-4035
The new_password page in PBBoard 2.1.4 allows remote attackers to change the password of arbitrary user accounts via the member_id and new_password p…
Pbboard
No fix yet
MEDIUM 5.5
CVE-2011-5097
chef-server-api/app/controllers/cookbooks.rb in Chef Server in Chef before 0.9.18, and 0.10.x before 0.10.2, does not require administrative privileg…
Chef
after 0.9.16
MEDIUM 6.5
CVE-2011-5098
chef-server-api/app/controllers/clients.rb in Chef Server in Chef before 0.9.20, and 0.10.x before 0.10.6, does not require administrative privileges…
Chef
after 0.9.18
HIGH 7.5
CVE-2012-2203
IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, uses…
Global Security Kit
after 8.0.13
MEDIUM 6.5
CVE-2010-5142
chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and upda…
Chef
after 0.8.10
HIGH 7.2
CVE-2012-2188
IBM Power Hardware Management Console (HMC) 7R3.5.0 before SP4, 7R7.1.0 and 7R7.2.0 before 7R7.2.0 SP3, and 7R7.3.0 before SP2, and Systems Director …
Power Hardware Management Console Firmware
Mitigation only
HIGH 7.5
CVE-2010-5141
wxBitcoin and bitcoind before 0.3.5 do not properly handle script opcodes in Bitcoin transactions, which allows remote attackers to spend bitcoins ow…
Bitcoin Core
after 0.3.4
HIGH 9.0
CVE-2012-2163
IBM Scale Out Network Attached Storage (SONAS) 1.1 through 1.3.1 allows remote authenticated administrators to execute arbitrary Linux commands via t…
Scale Out Network Attached Storage
Mitigation only
MEDIUM 6.8
CVE-2011-2658
The ISList.ISAvi ActiveX control in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 provides access to the mscom…
Zenworks Configuration Management
Patch available