Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2014-5527
The Tapjoy library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obt…
Tapjoy Library
Mitigation only
MEDIUM 5.4
CVE-2014-5528
The Appsflyer library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and …
Appsflyer
Mitigation only
MEDIUM 5.4
CVE-2014-5529
The Gameloft library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and o…
Gameloft Library
Mitigation only
MEDIUM 5.4
CVE-2014-2379
Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not use encryption, which allows remote attackers to …
Trafficdot
after 2.10.2
MEDIUM 5.8
CVE-2014-3908
The Amazon.com Kindle application before 4.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attack…
Kindle
after 4.4.4
MEDIUM 5.0
CVE-2014-3436
Symantec Encryption Desktop 10.3.x before 10.3.2 MP3, and Symantec PGP Desktop 10.0.x through 10.2.x, allows remote attackers to cause a denial of se…
Pgp Desktop
Mitigation only
MEDIUM 5.8
CVE-2014-3902
The CyberAgent Ameba application 3.x and 4.x before 4.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-mi…
Ameba
after 4.4.0
MEDIUM 5.8
CVE-2014-3302
user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allow…
Webex Meetings Server
after 1.5
MEDIUM 5.0
CVE-2014-4911
The ssl_decrypt_buf function in library/ssl_tls.c in PolarSSL before 1.2.11 and 1.3.x before 1.3.8 allows remote attackers to cause a denial of servi…
Debian Linux
after 1.2.10
MEDIUM 5.0
CVE-2014-3503EPSS 6%
Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via…
Syncope
No fix yet
MEDIUM 5.0
CVE-2014-0860
The firmware before 3.66E in IBM BladeCenter Advanced Management Module (AMM), the firmware before 1.43 in IBM Integrated Management Module (IMM), an…
Integrated Management Module Firmware
after 3.65
MEDIUM 5.8
CVE-2014-2001
The East Japan Railway Company JR East Japan application before 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows m…
Jr East Japan
after 1.0
MEDIUM 5.0
CVE-2014-4040
snap in powerpc-utils 1.2.20 produces an archive with fstab and yaboot.conf files potentially containing cleartext passwords, and lacks a warning abo…
Powerpc Utils
Mitigation only
MEDIUM 5.0
CVE-2014-4191
The TLS implementation in EMC RSA BSAFE-C Toolkits (aka Share for C and C++) sends a long series of random bytes during use of the Dual_EC_DRBG algor…
Bsafe Share
Mitigation only
MEDIUM 5.0
CVE-2014-4192
The Dual_EC_DRBG implementation in EMC RSA BSAFE-C Toolkits (aka Share for C and C++) processes certain requests for output bytes by considering only…
Bsafe Share
Mitigation only
MEDIUM 5.0
CVE-2014-4193
The TLS implementation in EMC RSA BSAFE-Java Toolkits (aka Share for Java) supports the Extended Random extension during use of the Dual_EC_DRBG algo…
Bsafe Share
Mitigation only
MEDIUM 5.8
CVE-2013-6078
The default configuration of EMC RSA BSAFE Toolkits and RSA Data Protection Manager (DPM) 20130918 uses the Dual Elliptic Curve Deterministic Random …
Rsa Bsafe Toolkits
Mitigation only
MEDIUM 5.0
CVE-2014-3812
The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS before 7.4r5 and 8.x before 8.0r1 and Junos Pulse Access Control Service …
Ive Os
Mitigation only
MEDIUM 5.8
CVE-2012-5583
phpCAS before 1.3.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X…
Phpcas
after 1.3.1
MEDIUM 5.0
CVE-2013-1941
The installation routine in ownCloud Server before 4.0.14, 4.5.x before 4.5.9, and 5.0.x before 5.0.4 uses the time function to seed the generation o…
Owncloud
after 4.0.13
MEDIUM 5.0
CVE-2013-2125
OpenSMTPD before 5.3.2 does not properly handle SSL sessions, which allows remote attackers to cause a denial of service (connection blocking) by kee…
Opensmtpd
after 5.3.1
MEDIUM 5.8
CVE-2012-5662
x3270 before 3.3.12ga12 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of t…
X3270
after 3.3.12
MEDIUM 5.8
CVE-2014-0878
The IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers in IBM SDK Java Technology Edition 5.0 before Service Refresh…
Java Sdk
Mitigation only
MEDIUM 5.0
CVE-2013-2758EPSS 6%
Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C uses a hash of a predictable se…
Cloudstack
Patch available
MEDIUM 5.8
CVE-2013-4347
The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, w…
Python Oauth2
Patch available
MEDIUM 6.8
CVE-2013-7385
LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php,…
Livezilla
after 5.1.2.1
MEDIUM 5.0
CVE-2013-6805
OpenText Exceed OnDemand (EoD) 8 uses weak encryption for passwords, which makes it easier for (1) remote attackers to discover credentials by sniffi…
Exceed Ondemand
Mitigation only
MEDIUM 6.8
CVE-2013-6807
The client in OpenText Exceed OnDemand (EoD) 8 supports anonymous ciphers by default, which allows man-in-the-middle attackers to bypass server certi…
Exceed Ondemand
Mitigation only
MEDIUM 6.4
CVE-2013-6994
OpenText Exceed OnDemand (EoD) 8 transmits the session ID in cleartext, which allows remote attackers to perform session fixation attacks by sniffing…
Exceed Ondemand
Mitigation only
MEDIUM 5.8
CVE-2014-3750
The Bilyoner application before 2.3.1 for Android and before 4.6.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-t…
Bilyoner
after 4.6