Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2016-6257
The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ult…
Firmware
after 024.003.00027
HIGH 8.1
CVE-2016-5672
Intel Crosswalk before 19.49.514.5, 20.x before 20.50.533.11, 21.x before 21.51.546.0, and 22.x before 22.51.549.0 interprets a user's acceptance of …
Crosswalk
after 19.49.514.4
HIGH 8.1
CVE-2016-5774
The HTTPS server in Blue Coat PacketShaper S-Series 11.5.x before 11.5.3.2 might allow remote attackers to obtain sensitive credentials and other inf…
Packetshaper S Series
Mitigation only
HIGH 7.5
CVE-2016-2364
The Chrome HUDweb plugin before 2016-05-05 for Fonality (previously trixbox Pro) 12.6 through 14.1i uses the same hardcoded private key across differ…
Hud Web
after 1.4.1
MEDIUM 6.1
CVE-2016-5433
Citrix iOS Receiver before 7.0 allows attackers to cause TLS certificates to be incorrectly validated via unspecified vectors.
Ios Receiver
after 6.1.5
MEDIUM 5.9
CVE-2012-6702
Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat …
Ubuntu Linux
2.2.0+
MEDIUM 5.5
CVE-2016-4005
The Huawei Hilink App application before 3.19.2 for Android does not validate SSL certificates, which allows local users to have unspecified impact v…
Hilink App
after 3.19.1
MEDIUM 6.5
CVE-2016-4524
ABB PCM600 before 2.7 improperly stores OPC Server IEC61850 passwords in unspecified temporary circumstances, which allows local users to obtain sens…
Pcm600
after 2.6
MEDIUM 5.3
CVE-2016-4495
KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allow remote attackers to bypass intended access restrictions and read a configuration f…
Bac 5051e Firmware
Mitigation only
HIGH 7.5
CVE-2016-1902
The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate ran…
Debian Linux
after 2.3.36
HIGH 7.5
CVE-2014-9742
The Miller-Rabin primality check in Botan before 1.10.8 and 1.11.x before 1.11.9 improperly uses a single random base, which makes it easier for remo…
Botan
after 1.10.7
MEDIUM 5.9
CVE-2016-2107EPSS 89%
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which …
Enterprise Linux Desktop
after 1.0.1s
HIGH 7.5
CVE-2016-2333
SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 use the same hardcoded encryption key across different cu…
Syslink Sl 1000 Modular Gateway Firmware
Mitigation only
HIGH 7.4
CVE-2016-2113
Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not verify X.509 certificates from TLS servers, which allows man-in-the-midd…
Ubuntu Linux
Patch available
HIGH 7.5
CVE-2016-2306
The HMI web server in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive cleartext information by sniffing the networ…
Integraxor
after 4.2.4502
MEDIUM 6.5
CVE-2013-7449
The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matches a do…
Ubuntu Linux
after 2.10.1
HIGH 7.5
CVE-2016-3071
Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform.
Fedora
Mitigation only
MEDIUM 5.9
CVE-2016-1273
Juniper Junos OS before 13.2X51-D40, 14.x before 14.1X53-D30, and 15.x before 15.1X53-D20 on QFX5100 and QFX10002 switches do not have sufficient ent…
Junos
after 13.2x51
HIGH 7.5
CVE-2016-3125EPSS 7%
The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weak…
Fedora
after 1.3.5
MEDIUM 5.9
CVE-2016-1788
Messages in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 does not properly implement a cryptographic protection mechanism, which…
Iphone Os
after 10.11.3
HIGH 7.5
CVE-2016-1777
Web Server in Apple OS X Server before 5.1 supports the RC4 algorithm, which makes it easier for remote attackers to defeat cryptographic protection …
Mac Os X Server
after 5.0.15
MEDIUM 5.9
CVE-2016-1731
Apple Software Update before 2.2 on Windows does not use HTTPS, which makes it easier for man-in-the-middle attackers to spoof updates by modifying t…
Software Update
after 2.1.3.127
MEDIUM 5.9
CVE-2016-0800EPSS 82%
The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message bef…
OpenSSL
Mitigation only
CRITICAL 9.8
CVE-2015-8805
The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implement…
Ubuntu Linux
after 3.1.1
CRITICAL 9.8
CVE-2015-8804
x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-…
Ubuntu Linux
after 3.1.1
CRITICAL 9.8
CVE-2015-8803
The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implement…
Ubuntu Linux
after 3.1.1
HIGH 7.5
CVE-2015-5012
The SSH implementation on IBM Security Access Manager for Web appliances 7.0 before 7.0.0 FP19, 8.0 before 8.0.1.3 IF3, and 9.0 before 9.0.0.0 IF1 do…
Security Access Manager 9.0 Firmware
Patch available
MEDIUM 5.9
CVE-2015-3197EPSS 11%
ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-m…
OpenSSL
Patch available
MEDIUM 6.8
CVE-2016-2268
Dell SecureWorks app before 2.1 for iOS does not validate SSL certificates, which allows man-in-the-middle attackers to spoof servers and obtain sens…
Secureworks
Patch available
MEDIUM 5.3
CVE-2016-1948
Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme installation, which allows man-in-the-middle attack…
Firefox
Mitigation only