Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.8
CVE-2010-3399
The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a conte…
Firefox
No fix yet
MEDIUM 5.8
CVE-2010-3400
The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5…
Firefox
after 2.0.4
MEDIUM 6.5
CVE-2010-2757
The sudo feature in Bugzilla 2.22rc1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 does not properly send impersonat…
Bugzilla
Mitigation only
HIGH 10.0
CVE-2010-2978
Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 does not use an adequate message-digest algorithm for a self-signed certificate, wh…
Unified Wireless Network Solution Software
Mitigation only
HIGH 7.8
CVE-2010-2967
The loginDefaultEncrypt algorithm in loginLib in Wind River VxWorks before 6.9 does not properly support a large set of distinct possible passwords, …
Vxworks
after 6.8
HIGH 10.0
CVE-2010-2468
The S2 Security NetBox 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, uses a weak hash algorithm for storing the Adm…
Netbox
No fix yet
HIGH 9.3
CVE-2010-1377
Open Directory in Apple Mac OS X 10.6 before 10.6.4 creates an unencrypted connection upon certain SSL failures, which allows man-in-the-middle attac…
Mac Os X
Patch available
HIGH 7.5
CVE-2010-2270
Accoria Web Server (aka Rock Web Server) 1.4.7 uses a predictable httpmod-sessionid cookie, which makes it easier for remote attackers to hijack sess…
Rock Web Server
No fix yet
MEDIUM 5.0
CVE-2010-1413
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, sends NTLM credentials in cleartext in …
Safari
after 4.0.5
MEDIUM 5.0
CVE-2006-7239
The _gnutls_x509_oid2mac_algorithm function in lib/gnutls_algorithms.c in GnuTLS before 1.4.2 allows remote attackers to cause a denial of service (c…
Gnutls
after 1.4.1
MEDIUM 5.0
CVE-2010-1568
The Send Secure functionality in the Cisco IronPort Desktop Flag Plug-in for Outlook before 6.5.0-006 does not properly handle simultaneously compose…
Ironport Desktop Flag Plugin For Outlook
after 6.5.0
HIGH 7.2
CVE-2010-1906
tgsrv.exe in the Repair Service in Consona Dynamic Agent, Repair Manager, Subscriber Activation, and Subscriber Agent relies on a predictable timesta…
Consona Dynamic Agent
Patch available
HIGH 9.3
CVE-2010-1911
The site-locking implementation in the SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance…
Consona Dynamic Agent
Patch available
MEDIUM 6.4
CVE-2010-1689EPSS 7%
The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003…
Windows 2000
Mitigation only
MEDIUM 5.0
CVE-2009-4845
The configuration page in ToutVirtual VirtualIQ Pro 3.2 build 7882 contains cleartext SSH credentials, which allows remote attackers to obtain sensit…
Virtualiq
Mitigation only
HIGH 8.5
CVE-2009-4510
The SSH service on the TANDBERG Video Communication Server (VCS) before X5.1 uses a fixed DSA key, which makes it easier for remote attackers to cond…
Tandberg Video Communication Server
Patch available
MEDIUM 6.8
CVE-2010-1192
libESMTP, probably 1.0.4 and earlier, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 …
Libesmtp
after 1.0.4
MEDIUM 6.8
CVE-2010-1194
The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a…
Libesmtp
Patch available
MEDIUM 5.0
CVE-2010-0525
Mail in Apple Mac OS X before 10.6.3 does not properly enforce the key usage extension during processing of a keychain that specifies multiple certif…
Mac Os X
after 10.6.2
HIGH 7.6
CVE-2010-1184EPSS 8%
The Microsoft wireless keyboard uses XOR encryption with a key derived from the MAC address, which makes it easier for remote attackers to obtain key…
27mhz Wireless Keyboard
No fix yet
HIGH 7.8
CVE-2010-0578
The IKE implementation in Cisco IOS 12.2 through 12.4 on Cisco 7200 and 7301 routers with VAM2+ allows remote attackers to cause a denial of service …
iOS
Patch available
HIGH 7.5
CVE-2009-4655EPSS 50%
The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack sessions via…
Edirectory
No fix yet
HIGH 10.0
CVE-2010-0231EPSS 41%
The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1,…
Windows 2000
Mitigation only
MEDIUM 5.0
CVE-2010-0362
Zeus Web Server before 4.3r5 does not use random transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses.
Zeus Web Server
after 4.3
HIGH 10.0
CVE-2008-7252
libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and attack vect…
phpMyAdmin
Patch available
HIGH 7.5
CVE-2009-4565
sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-mid…
Sendmail
after 8.14.3
MEDIUM 6.8
CVE-2009-4144
NetworkManager (NM) 0.7.2 does not ensure that the configured Certification Authority (CA) certificate file for a (1) WPA Enterprise or (2) 802.1x ne…
Networkmanager
Mitigation only
MEDIUM 5.0
CVE-2009-4302
login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 links to an index page on the HTTP port even when the page is served from an H…
Moodle
Patch available
MEDIUM 5.8
CVE-2009-4034
PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not pr…
PostgreSQL
Patch available
HIGH 7.8
CVE-2009-4295
Sun Ray Server Software 4.0 and 4.1 does not generate a unique DSA private key for the firmware on each Sun Ray 1, 1g, 100, and 150 DTU device, which…
Ray Server Software
Patch available