Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.0
CVE-2014-5403
Hospira MedNet before 6.1 uses hardcoded cryptographic keys for protection of data transmission from infusion pumps, which allows remote attackers to…
Mednet
after 5.8
MEDIUM 5.0
CVE-2015-0282
GnuTLS before 3.1.0 does not verify that the RSA PKCS #1 signature algorithm matches the signature algorithm in the certificate, which allows remote …
Gnutls
after 3.0.9
MEDIUM 5.0
CVE-2015-2091
The authentication hook (mgs_hook_authz) in mod-gnutls 0.5.10 and earlier does not validate client certificates when "GnuTLSClientVerify require" is …
Mod Gnutls
after 0.5.1
HIGH 7.5
CVE-2014-3691
Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which allows remot…
Openstack
after 1.5.3
MEDIUM 5.8
CVE-2015-1596
The Siemens SPCanywhere application for Android and iOS does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle …
Spcanywhere
after 1.4.1
MEDIUM 5.0
CVE-2015-2078
The SDK for Komodia Redirector with SSL Digestor, as used in Lavasoft Ad-Aware Web Companion 1.1.885.1766 and Ad-Aware AdBlocker (alpha) 1.3.69.1, Qu…
Redirector Sdk
No fix yet
MEDIUM 5.0
CVE-2015-1358
The remote-management module in the (1) Multi Panels, (2) Comfort Panels, and (3) RT Advanced functionality in Siemens SIMATIC WinCC (TIA Portal) bef…
Wincc
Mitigation only
HIGH 7.1
CVE-2015-1454
Blue Coat ProxyClient before 3.3.3.3 and 3.4.x before 3.4.4.10 and Unified Agent before 4.1.3.151952 does not properly validate certain certificates,…
Proxyclient
3.3.3.3 / 3.4.4.10+
MEDIUM 5.0
CVE-2015-1453
The qm class in Fortinet FortiClient 5.2.3.091 for Android uses a hardcoded encryption key of FoRtInEt!AnDrOiD, which makes it easier for attackers t…
Forticlient
after 5.2.3.091
MEDIUM 5.8
CVE-2014-8918
IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-mi…
Security Appscan
Mitigation only
MEDIUM 5.0
CVE-2014-6136
IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 supports unencrypted sessions, which allows remote attackers to obtain sensitive informa…
Security Appscan
Mitigation only
MEDIUM 6.8
CVE-2014-8840
The iTunes Store component in Apple iOS before 8.1.3 allows remote attackers to bypass a Safari sandbox protection mechanism by leveraging redirectio…
Iphone Os
after 8.1.2
MEDIUM 5.0
CVE-2013-7252
kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes i…
Kde Applications
after 14.11.3
MEDIUM 5.0
CVE-2014-5419
GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmwar…
Multilink Ml3100 Firmware
after 5.2.0
MEDIUM 5.0
CVE-2014-5386
The mcrypt_create_iv function in hphp/runtime/ext/mcrypt/ext_mcrypt.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 does not seed the rand…
Hiphop Virtual Machine
after 3.2.0
MEDIUM 5.0
CVE-2013-4442
Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which makes it easier for context-dep…
Pwgen
after 2.06
MEDIUM 5.0
CVE-2014-6087
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 make it easier…
Security Access Manager For Web
Mitigation only
MEDIUM 5.0
CVE-2014-6084
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 make it easier…
Security Access Manager For Mobile
Mitigation only
HIGH 9.3
CVE-2014-6140EPSS 6%
IBM Tivoli Endpoint Manager Mobile Device Management (MDM) before 9.0.60100 uses the same secret HMAC token across different customers' installations…
Tivoli Endpoint Manager Mobile Device Management
after 9.0
MEDIUM 6.8
CVE-2014-9037
WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle…
WordPress
after 3.7.4
MEDIUM 5.0
CVE-2014-8627
PolarSSL 1.3.8 does not properly negotiate the signature algorithm to use, which allows remote attackers to conduct downgrade attacks via unspecified…
Polarssl
Mitigation only
MEDIUM 5.0
CVE-2014-3620
cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a …
Curl
after 10.10.4
MEDIUM 5.0
CVE-2014-3613EPSS 7%
cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send…
Curl
after 10.10.4
HIGH 10.0
CVE-2014-7878EPSS 10%
The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node image, uses…
Helion Cloud Development Platform
Mitigation only
MEDIUM 5.0
CVE-2014-8564
The _gnutls_ecc_ansi_x963_export function in gnutls_ecc.c in GnuTLS 3.x before 3.1.28, 3.2.x before 3.2.20, and 3.3.x before 3.3.10 allows remote att…
Enterprise Linux Desktop
Patch available
HIGH 7.5
CVE-2014-8587
SAPCRYPTOLIB before 5.555.38, SAPSECULIB, and CommonCryptoLib before 8.4.30, as used in SAP NetWeaver AS for ABAP and SAP HANA, allows remote attacke…
Commoncryptolib
after 8.4.29
HIGH 7.5
CVE-2014-7228EPSS 55%
Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla! Professi…
Joomla\!
No fix yet
MEDIUM 5.0
CVE-2012-6661
Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it e…
Plone
after 4.2.2
MEDIUM 5.0
CVE-2014-8495
Citrix XenMobile MDX Toolkit before 9.0.4, when used to wrap iOS 8 applications, does not properly encrypt cached application data, which allows cont…
Xenmobile
after 9.0.3
MEDIUM 5.4
CVE-2014-8538
The Hijab Modern (aka com.Aisyaidea.HijabModern) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in…
Hijab Modern
Mitigation only