Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2011-4300
The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which a…
Moodle
Patch available
MEDIUM 6.9
CVE-2012-1894
Microsoft Office for Mac 2011 uses world-writable permissions for the "Applications/Microsoft Office 2011/" directory and certain other directories, …
Office
Mitigation only
MEDIUM 5.5
CVE-2012-1860EPSS 13%
Microsoft Office SharePoint Server 2007 SP2 and SP3, SharePoint Server 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 do not properly check…
Office Web Apps
Mitigation only
MEDIUM 5.0
CVE-2012-2138EPSS 14%
The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to co…
Org.apache.sling.servlets.post
after 2.1.0
MEDIUM 5.0
CVE-2012-2640
The NEC BIGLOBE Yome Collection application 1.8.3 and earlier for Android allows remote attackers to read the IMEI value from an SD card via a crafte…
Nec Biglobe Yome Collection
after 1.8.3
MEDIUM 6.4
CVE-2012-1119
MantisBT before 1.2.9 does not audit when users copy or clone a bug report, which makes it easier for remote attackers to copy bug reports without de…
Mantisbt
after 1.2.8
HIGH 7.5
CVE-2012-3814EPSS 10%
Unrestricted file upload vulnerability in font-upload.php in the Font Uploader plugin 1.2.4 for WordPress allows remote attackers to execute arbitrar…
Font Uploader
No fix yet
HIGH 7.2
CVE-2012-2200
The default configuration of sendmail in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, allows local users to gain privileges by entering a comma…
Vios
Mitigation only
HIGH 7.5
CVE-2012-2730
The Protected Node module 6.x-1.x before 6.x-1.6 for Drupal does not properly "protect node access when nodes are accessed outside of the standard no…
Protected Node
Patch available
MEDIUM 5.8
CVE-2012-2707
The Hostmaster (Aegir) module 6.x-1.x before 6.x-1.9 for Drupal does not properly exit when users do not have access to package/task nodes, which all…
Hostmaster
Patch available
MEDIUM 5.1
CVE-2012-2719
The filedepot module 6.x-1.x before 6.x-1.3 for Drupal, when accessed using multiple different browsers from the same IP address, causes Internet Exp…
Filedepot
Patch available
MEDIUM 5.0
CVE-2012-2720
The Token Authentication (tokenauth) module 6.x-1.x before 6.x-1.7 for Drupal does not properly revert user sessions, which might allow remote attack…
Tokenauth
Patch available
MEDIUM 6.8
CVE-2012-2721
The default views in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal do not properly check permissions when all users have the "acce…
Organic Groups
Patch available
MEDIUM 5.0
CVE-2012-2702
The Ubercart Product Keys module 6.x-1.x before 6.x-1.1 for Drupal does not properly check access for product keys, which allows remote attackers to …
Ubercart Product Keys
Patch available
MEDIUM 6.4
CVE-2012-2660
actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly consider …
Rails
No fix yet
MEDIUM 6.9
CVE-2012-2179
libodm.a in IBM AIX 5.3, 6.1, and 7.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
Aix
Patch available
MEDIUM 6.9
CVE-2012-0304
Symantec LiveUpdate Administrator before 2.3.1 uses weak permissions (Everyone: Full Control) for the installation directory, which allows local user…
Liveupdate Administrator
after 2.3.0
MEDIUM 5.0
CVE-2012-0191
The web container in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack does not properly perform access control for requests, which al…
Lotus Expeditor
Mitigation only
HIGH 7.2
CVE-2011-1477
Multiple array index errors in sound/oss/opl3.c in the Linux kernel before 2.6.39 allow local users to cause a denial of service (heap memory corrupt…
Linux Kernel
after 2.6.38.8
HIGH 7.2
CVE-2012-0028
The robust futex implementation in the Linux kernel before 2.6.28 does not properly handle processes that make exec system calls, which allows local …
Linux Kernel
after 2.6.27.62
MEDIUM 6.2
CVE-2011-2709
libgssapi and libgssglue before 0.4 do not properly check privileges, which allows local users to load untrusted configuration files and execute arbi…
Libgssglue
after 0.3
HIGH 7.5
CVE-2012-3577EPSS 14%
Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress allows remote attackers to e…
Member Conversation
after 1.3
MEDIUM 6.8
CVE-2012-3578EPSS 8%
Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.1 and earlier for WordPress allows remote attackers to e…
Fcchat Widget
after 2.2.13.1
HIGH 7.5
CVE-2012-2691
The mc_issue_note_update function in the SOAP API in MantisBT before 1.2.11 does not properly check privileges, which allows remote attackers with bu…
Mantisbt
after 1.2.10
HIGH 10.0
CVE-2012-3575EPSS 15%
Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attackers to execute arbitrary code …
Rbx Gallery
Mitigation only
HIGH 10.0
CVE-2012-3576EPSS 18%
Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows remote attackers to execute arb…
Wpstorecart
after 2.5.29
MEDIUM 5.0
CVE-2011-4328
plugin/npapi/plugin.cpp in Gnash before 0.8.10 uses weak permissions (world readable) for cookie files with predictable names in /tmp, which allows l…
Gnash
after 0.8.9
MEDIUM 5.0
CVE-2012-3557
Opera before 11.65 does not properly restrict the reading of JSON strings, which allows remote attackers to perform cross-domain loading of JSON reso…
Opera Browser
after 11.62
MEDIUM 6.0
CVE-2012-3347
AutoFORM PDM Archive before 7.0 implements user accounts in a way that allows for JMX Console authentication, which allows remote authenticated users…
Autoform Pdm Archive
after 6.920
MEDIUM 6.5
CVE-2012-1827
The web service in AutoFORM PDM Archive before 7.1 does not have authorization requirements, which allows remote authenticated users to perform datab…
Autoform Pdm Archive
after 7.0