Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.4
CVE-2009-2749
Feature Pack for Communications Enabled Applications (CEA) before 1.0.0.1 for IBM WebSphere Application Server 7.0.0.7 uses predictable session value…
Websphere Application Server
after 1.0
MEDIUM 5.0
CVE-2009-2843
Java for Mac OS X 10.5 before Update 6 and 10.6 before Update 1 accepts expired certificates for applets, which makes it easier for remote attackers …
Mac Os X
Patch available
MEDIUM 5.0
CVE-2009-3941
Martin Lambers mpop before 1.0.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name …
Mpop
after 1.0.18
MEDIUM 6.4
CVE-2009-3942
Martin Lambers msmtp before 1.4.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name…
Msmtp
after 1.4.18
MEDIUM 5.8
CVE-2009-3936
Unspecified vulnerability in Citrix Online Plug-in for Windows 11.0.x before 11.0.150 and 11.x before 11.2, Online Plug-in for Mac before 11.0, Recei…
Online Plug In For Mac
after 11.2
MEDIUM 5.4
CVE-2009-2808
Help Viewer in Apple Mac OS X before 10.6.2 does not use an HTTPS connection to retrieve Apple Help content from a web site, which allows man-in-the-…
Mac Os X
after 10.6.1
MEDIUM 5.0
CVE-2009-3875
The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update …
Jdk
Patch available
MEDIUM 5.8
CVE-2009-3639EPSS 6%
The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the dNSNameRequired TLS option is enabled, does not properly handle a '\…
Proftpd
after 1.3.2
MEDIUM 6.8
CVE-2009-3765
mutt_ssl.c in mutt 1.5.19 and 1.5.20, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (…
Mutt
Mitigation only
MEDIUM 6.8
CVE-2009-3766
mutt_ssl.c in mutt 1.5.16 and other versions before 1.5.19, when OpenSSL is used, does not verify the domain name in the subject's Common Name (CN) f…
Mutt
1.5.19+
HIGH 9.3
CVE-2009-2982
An unspecified certificate in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow remote attackers …
Acrobat
after 9.1.3
MEDIUM 6.8
CVE-2009-2510EPSS 5%
The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Ser…
Windows 2000
Mitigation only
HIGH 7.5
CVE-2009-3602
Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgrade…
Unbound
after 1.3.3
MEDIUM 6.4
CVE-2009-0209
PI Server in OSIsoft PI System before 3.4.380.x does not properly use encryption in the default authentication process, which allows remote attackers…
Pi Server
after 3.4.375.99
MEDIUM 6.8
CVE-2009-3490
GNU Wget before 1.12 does not properly handle a '\0' character in a domain name in the Common Name field of an X.509 certificate, which allows man-in…
Wget
after 1.11.4
HIGH 7.5
CVE-2009-3474
OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow the KeyDe…
Opensaml
Patch available
HIGH 7.5
CVE-2009-3475
Internet2 Shibboleth Service Provider software 1.3.x before 1.3.3 and 2.x before 2.2.1, when using PKIX trust validation, does not properly handle a …
Shibboleth Sp
Mitigation only
MEDIUM 6.8
CVE-2009-3477
The Blackberry Browser in RIM BlackBerry Device Software 4.5.0 before 4.5.0.173, 4.6.0 before 4.6.0.303, 4.6.1 before 4.6.1.309, 4.7.0 before 4.7.0.1…
Blackberry Device Software
Mitigation only
HIGH 7.5
CVE-2009-3455
Apple Safari, possibly before 4.0.3, on Mac OS X does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field o…
Safari
after 4.0.2
HIGH 7.5
CVE-2009-3456
Google Chrome, possibly 3.0.195.21 and earlier, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of…
Chrome
after 3.0.195.21
MEDIUM 5.9
CVE-2009-3200
The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create an undocumented recovery key and store it in the ENCK …
Ts 239 Pro Turbo Nas
No fix yet
HIGH 7.5
CVE-2009-3273
iPhone Mail in Apple iPhone OS, and iPhone OS for iPod touch, does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof…
Iphone Os
Mitigation only
HIGH 7.5
CVE-2009-2702
KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.50…
Kdelibs
Mitigation only
MEDIUM 5.0
CVE-2009-3045
Opera before 10.00 trusts root X.509 certificates signed with the MD2 algorithm, which makes it easier for man-in-the-middle attackers to spoof arbit…
Opera Browser
after 10.00
MEDIUM 5.0
CVE-2009-3044
Opera before 10.00 does not properly handle a (1) '\0' character or (2) invalid wildcard character in a domain name in the subject's Common Name (CN)…
Opera Browser
after 10.00
MEDIUM 5.0
CVE-2008-7138
The Manager in Eye-Fi 1.1.2 generates predictable snonce values based on the time of day, which allows remote attackers to bypass authentication and …
Eye Fi Manager
Mitigation only
MEDIUM 5.0
CVE-2009-3026
protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting t…
Pidgin
Patch available
MEDIUM 6.4
CVE-2008-7113
The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 uses a small space of predictable user identification numbers for access control…
Scanner File Utility
Mitigation only
MEDIUM 6.4
CVE-2009-2973
Google Chrome before 2.0.172.43 does not prevent SSL connections to a site with an X.509 certificate signed with the (1) MD2 or (2) MD4 algorithm, wh…
Chrome
after 2.0.172.37
HIGH 7.8
CVE-2009-2976
Cisco Aironet Lightweight Access Point (AP) devices send the contents of certain multicast data frames in cleartext, which allows remote attackers to…
Aironet Ap1100
Mitigation only