Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 9.7
CVE-2014-2046
cgi-bin/rpcBridge in the web interface 1.1 on Broadcom Ltd PIPA C211 rev2 does not properly restrict access, which allows remote attackers to (1) obt…
Pipa C211 Web Interface
No fix yet
MEDIUM 5.0
CVE-2013-0173
Foreman before 1.1 uses a salt of "foreman" to hash root passwords, which makes it easier for attackers to guess the password via a brute force attac…
Foreman
after 1.0
MEDIUM 6.9
CVE-2014-0646
The runtime WS component in the server in EMC RSA Access Manager 6.1.3 before 6.1.3.39, 6.1.4 before 6.1.4.22, 6.2.0 before 6.2.0.11, and 6.2.1 befor…
Rsa Access Manager
Mitigation only
MEDIUM 5.0
CVE-2014-0786
Ecava IntegraXor before 4.1.4393 allows remote attackers to read cleartext credentials for administrative accounts via SELECT statements that leverag…
Integraxor
after 4.1.4390
MEDIUM 5.0
CVE-2013-6445
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, uses the DES-based crypt function to hash passwords, which makes it easier…
Enterprise Mrg
Mitigation only
MEDIUM 5.0
CVE-2013-7372
The engineNextBytes function in classlib/modules/security/src/main/java/common/org/apache/harmony/security/provider/crypto/SHA1PRNG_SecureRandomImpl.…
Harmony
after 6.0
MEDIUM 6.4
CVE-2011-3152
DistUpgrade/DistUpgradeFetcherCore.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x b…
Update Manager
after 1
MEDIUM 6.4
CVE-2014-2992
The Misli.com application for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers …
Misli.com App
Mitigation only
MEDIUM 6.4
CVE-2014-2993
The Birebin.com application for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof server…
Birebin.com App
Mitigation only
MEDIUM 6.4
CVE-2014-0350
The Poco::Net::X509Certificate::verify method in the NetSSL library in POCO C++ Libraries before 1.4.6p4 allows man-in-the-middle attackers to spoof …
Poco C\+\+ Libraries
after 1.4.6
MEDIUM 5.8
CVE-2014-2900
wolfSSL CyaSSL before 2.9.4 does not properly validate X.509 certificates with unknown critical extensions, which allows man-in-the-middle attackers …
Cyassl
after 2.9.0
MEDIUM 5.0
CVE-2013-6371
The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted JSON data,…
Fedora
0.12-20140410+
MEDIUM 6.8
CVE-2014-0036
The rbovirt gem before 0.0.24 for Ruby uses the rest-client gem with SSL verification disabled, which allows remote attackers to conduct man-in-the-m…
Rbovirt
after 0.0.23
MEDIUM 5.8
CVE-2014-0139
cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject'…
Curl
Mitigation only
MEDIUM 5.8
CVE-2014-0636
EMC RSA BSAFE Micro Edition Suite (MES) 3.2.x before 3.2.6 and 4.0.x before 4.0.5 does not properly validate X.509 certificate chains, which allows m…
Bsafe Micro Edition Suite
Mitigation only
MEDIUM 5.8
CVE-2014-1210
VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which allows man-in-the-middle attac…
Vsphere Client
Mitigation only
MEDIUM 5.0
CVE-2013-5444
The server in IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows remote attackers to read encr…
Cognos Express
Mitigation only
MEDIUM 5.0
CVE-2013-5445
IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows local users to obtain sensitive cleartext i…
Cognos Express
Mitigation only
HIGH 8.3
CVE-2014-2250
The random-number generator on Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 does not have sufficient entropy, which makes it easi…
Simatic S7 Cpu 1200 Firmware
after 3.0.2
MEDIUM 5.0
CVE-2013-6401
Jansson, possibly 2.4 and earlier, does not restrict the ability to trigger hash collisions predictably, which allows context-dependent attackers to …
Jansson
after 2.4
MEDIUM 5.8
CVE-2014-1976
The Demaecan application 2.1.0 and earlier for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers …
Demaecan
after 2.1.0
HIGH 8.5
CVE-2013-1398
The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which allows rem…
Puppet Enterprise
after 2.7.0
MEDIUM 5.0
CVE-2014-2319
The Encrypt Files feature in ConeXware PowerArchiver before 14.02.05 uses legacy ZIP encryption even if the AES 256-bit selection is chosen, which ma…
Powerarchiver
after 14.02.03
MEDIUM 5.2
CVE-2014-0102
The keyring_detect_cycle_iterator function in security/keys/keyring.c in the Linux kernel through 3.13.6 does not properly determine whether keyrings…
Linux Kernel
after 3.13.6
MEDIUM 5.8
CVE-2014-0092EPSS 30%
lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from …
Gnutls
after 3.2.11
MEDIUM 5.0
CVE-2013-5468
IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0,…
Algo One
Mitigation only
MEDIUM 5.8
CVE-2014-1967
The Denny's application before 2.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spo…
Denny\'s
after 2.0.0
MEDIUM 6.2
CVE-2014-0741
The certificate-import feature in the Certificate Authority Proxy Function (CAPF) CLI implementation in Cisco Unified Communications Manager (Unified…
Unified Communications Manager
after 10.0
HIGH 10.0
CVE-2013-3712
SUSE Studio Onsite 1.3.x before 1.3.6 and SUSE Studio Extension for System z 1.3 uses "static" secret tokens, which has unspecified impact and vector…
Studio Extension For System Z
No fix yet
MEDIUM 6.4
CVE-2013-6659
The SSLClientSocketNSS::Core::OwnAuthCertHandler function in net/socket/ssl_client_socket_nss.cc in Google Chrome before 33.0.1750.117 does not preve…
Chrome
after 33.0.1750.116