Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.8
CVE-2011-4705
The Ming Blacklist Free (vc.software.blacklist) application 1.8.1 and 1.9.2.1 for Android does not properly protect data, which allows remote attacke…
Blacklist Free
Mitigation only
MEDIUM 5.8
CVE-2011-4769
The 360 MobileSafe (com.qihoo360.mobilesafe) application 2.x before 2.3.0 for Android does not properly protect data, which allows remote attackers t…
Mobilesafe
Mitigation only
MEDIUM 5.8
CVE-2011-4770
The QIWI Wallet (ru.mw) application before 1.14.2 for Android does not properly protect data, which allows remote attackers to read or modify financi…
Wallet
after 1.14.2
MEDIUM 5.8
CVE-2011-4771
The Scan to PDF Free (com.scan.to.pdf.trial) application 2.0.4 for Android does not properly protect data, which allows remote attackers to read or m…
Scan To Pdf Free
Mitigation only
MEDIUM 5.8
CVE-2011-4772
The 360 KouXin (com.qihoo360.kouxin) application 1.5.3 for Android does not properly protect data, which allows remote attackers to read or modify SM…
Kouxin
Mitigation only
MEDIUM 5.8
CVE-2011-4773
The AnGuanJia (com.anguanjia.safe) application 2.10.343 for Android does not properly protect data, which allows remote attackers to read or modify S…
Anguanjia
Mitigation only
MEDIUM 5.8
CVE-2011-4863
The Tencent QQPimSecure (com.tencent.qqpimsecure) application 3.0.2 for Android does not properly protect data, which allows remote attackers to read…
Qqpimsecure
Mitigation only
MEDIUM 5.8
CVE-2011-4864
The Tencent MobileQQ (com.tencent.mobileqq) application 2.2 for Android does not properly protect data, which allows remote attackers to read or modi…
Mobileqq
Mitigation only
MEDIUM 5.8
CVE-2011-4865
The Tencent WBlog (com.tencent.WBlog) 3.3.1 and MicroBlogPad 1.4.0 applications for Android do not properly protect data, which allows remote attacke…
Microblogpad
Mitigation only
MEDIUM 5.8
CVE-2011-4867
The Tencent QQPhoto (com.tencent.qqphoto) application 0.97 for Android does not properly protect data, which allows remote attackers to read or modif…
Qqpphoto
Mitigation only
MEDIUM 5.8
CVE-2011-4700
The UberMedia UberSocial (com.twidroid) application 7.x before 7.2.4 for Android does not properly protect data, which allows remote attackers to rea…
Ubersocial
Mitigation only
MEDIUM 5.8
CVE-2011-4701
The CallConfirm (jp.gr.java_conf.ofnhwx.callconfirm) application 2.0.0 for Android does not properly protect data, which allows remote attackers to r…
Callconfirm
Mitigation only
MEDIUM 5.8
CVE-2011-4702
The Nimbuzz (com.nimbuzz) application 2.0.8 and 2.0.10 for Android does not properly protect data, which allows remote attackers to read or modify a …
Nimbuzz
Mitigation only
MEDIUM 5.8
CVE-2011-4703
The Limit My Call (com.limited.call.view) application 2.11 for Android does not properly protect data, which allows remote attackers to read or modif…
Limit My Call
Mitigation only
HIGH 10.0
CVE-2011-4659
Cisco TelePresence Software before TE 4.1.1 on the Cisco IP Video Phone E20 has a default password for the root account after an upgrade to TE 4.1.0,…
Telepresence E20 Software
Mitigation only
MEDIUM 5.0
CVE-2011-1184EPSS 9%
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the…
Tomcat
Patch available
MEDIUM 5.0
CVE-2011-5062EPSS 8%
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qo…
Tomcat
Patch available
MEDIUM 6.4
CVE-2011-5058
The CmbWebserver.dll module of the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to create arbitrary directories under the we…
Codesys
No fix yet
MEDIUM 5.0
CVE-2011-5057EPSS 29%
Apache Struts 2.3.1.2 and earlier, 2.3.19-2.3.23, provides interfaces that do not properly restrict access to collections such as the session and req…
Struts
2.3.3+
MEDIUM 6.4
CVE-2012-0393EPSS 37%
The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to c…
Struts
2.3.1.1+
MEDIUM 6.9
CVE-2011-3337
eEye Audit ID 2499 in eEye Digital Security Audits 2406 through 2423 for eEye Retina Network Security Scanner on HP-UX, IRIX, and Solaris allows loca…
Digital Security Audits
Mitigation only
HIGH 7.5
CVE-2011-4197
etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constraint, whi…
Pfsense
after 2.0
HIGH 7.2
CVE-2011-5044
SopCast 3.4.7.45585 uses weak permissions (Everyone:Full Control) for Diagnose.exe, which allows local users to execute arbitrary code by replacing D…
Sopcast
No fix yet
HIGH 10.0
CVE-2011-5010EPSS 65%
apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via shell metacharacters in the PIN…
Skyrouter
Mitigation only
HIGH 7.5
CVE-2011-3839
The administration functionality in Wuzly 2.0 allows remote attackers to bypass authentication by setting the dXNlcm5hbWU cookie.
Wuzly
Mitigation only
MEDIUM 5.8
CVE-2011-2768
Tor before 0.2.2.34, when configured as a client or bridge, sends a TLS certificate chain as part of an outgoing OR connection, which allows remote r…
Tor
after 0.2.2.33
MEDIUM 6.8
CVE-2011-3666
Mozilla Firefox before 3.6.25 and Thunderbird before 3.1.17 on Mac OS X do not consider .jar files to be executable files, which allows user-assisted…
Firefox
after 3.6.24
HIGH 10.0
CVE-2011-4861
The modbus_125_handler function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) allows re…
Quantum Ethernet Module 140noe77100
after 5.0
MEDIUM 6.8
CVE-2011-2741
EMC RSA Adaptive Authentication On-Premise (AAOP) 6.0.2.1 SP1 Patch 2, SP1 Patch 3, SP2, SP2 Patch 1, and SP3 does not properly implement Device Reco…
Rsa Adaptive Authentication On Premise
Mitigation only
MEDIUM 6.8
CVE-2011-2742
EMC RSA Adaptive Authentication On-Premise (AAOP) 6.0.2.1 SP1 Patch 2, SP1 Patch 3, SP2, SP2 Patch 1, and SP3 does not properly perform forensic eval…
Rsa Adaptive Authentication On Premise
Mitigation only