Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2009-2951
Phenotype CMS before 2.9 does not use a random salt value for password encryption, which makes it easier for context-dependent attackers to determine…
Phenotype Cms
after 2.8
HIGH 10.0
CVE-2008-7023
Aruba Mobility Controller running ArubaOS 3.3.1.16, and possibly other versions, installs the same default X.509 certificate for all installations, w…
Aruba Mobility Controller
Mitigation only
HIGH 10.0
CVE-2008-6993
Siemens Gigaset WLAN Camera 1.27 has an insecure default password, which allows remote attackers to conduct unauthorized activities. NOTE: the proven…
Gigaset Wlan Camera
Mitigation only
HIGH 7.5
CVE-2009-2417
lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject'…
Libcurl
Patch available
HIGH 7.5
CVE-2009-2730
libgnutls in GnuTLS before 2.8.2 does not properly handle a '\0' character in a domain name in the subject's (1) Common Name (CN) or (2) Subject Alte…
Gnutls
after 2.8.1
MEDIUM 6.4
CVE-2009-2666
socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 ce…
Fetchmail
after 6.3.10
MEDIUM 6.5
CVE-2008-6909
Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not sign all required data in requests, which has unspecified impact,…
Services
Patch available
HIGH 7.5
CVE-2008-6910
Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not use timeouts for signed requests, which allows remote attackers t…
Services
Patch available
HIGH 7.5
CVE-2008-6908
Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, uses an insecure hash when signing requests, which allows remote attackers…
Services
Patch available
MEDIUM 5.0
CVE-2009-2661
The asn1_length function in strongSwan 2.8 before 2.8.11, 4.2 before 4.2.17, and 4.3 before 4.3.3 does not properly handle X.509 certificates with cr…
Strongswan
Patch available
MEDIUM 5.0
CVE-2009-2319
The default configuration of the Wi-Fi component on the Axesstel MV 410R does not use encryption, which makes it easier for remote attackers to obtai…
Mv 410r
Mitigation only
HIGH 9.3
CVE-2009-2061
Mozilla Firefox before 3.0.10 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to ex…
Firefox
after 3.0.9
MEDIUM 5.0
CVE-2009-1696
WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 uses predictable random numbers in Jav…
Safari
after 4.0_beta
HIGH 10.0
CVE-2008-6824
The management interface on the A-LINK WL54AP3 and WL54AP2 access points has a blank default password for the admin account, which makes it easier fo…
Wl54ap2
Patch available
HIGH 10.0
CVE-2009-1472
The Java client program for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.104 has a hardcoded A…
Kh1516i Ip Kvm Switch
Mitigation only
HIGH 10.0
CVE-2009-1473
The (1) Windows and (2) Java client programs for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.…
Kh1516i Ip Kvm Switch
Mitigation only
HIGH 7.6
CVE-2009-1474
The ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.104 do not (1) encrypt mouse events, which makes …
Kh1516i Ip Kvm Switch
Mitigation only
HIGH 10.0
CVE-2009-1477
The https web interfaces on the ATEN KH1516i IP KVM switch with firmware 1.0.063, the KN9116 IP KVM switch with firmware 1.1.104, and the PN9108 powe…
Kh1516i Ip Kvm Switch
Mitigation only
HIGH 7.8
CVE-2008-6797
The server in Mitel NuPoint Messenger R11 and R3 sends usernames and passwords in cleartext to Exchange servers, which allows remote attackers to obt…
Mitel Nupoint Messenger
Mitigation only
MEDIUM 5.0
CVE-2008-6792
system-tools-backends before 2.6.0-1ubuntu1.1 in Ubuntu 8.10, as used by "Users and Groups" in GNOME System Tools, hashes account passwords with 3DES…
Linux
Mitigation only
HIGH 7.8
CVE-2009-1560
The Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 stores passwords and wireless-network keys in cleartext in (1) pas…
Wvc54gc
No fix yet
HIGH 7.5
CVE-2009-1416
lib/gnutls_pk.c in libgnutls in GnuTLS 2.5.0 through 2.6.5 generates RSA keys stored in DSA structures, instead of the intended DSA keys, which might…
Gnutls
Patch available
MEDIUM 5.0
CVE-2009-1417
gnutls-cli in GnuTLS before 2.6.6 does not verify the activation and expiration times of X.509 certificates, which allows remote attackers to success…
Gnutls
after 2.6.5
MEDIUM 6.8
CVE-2009-1283
glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows remote attackers to gain privile…
Glfusion
after 1.1.2
HIGH 10.0
CVE-2009-1174
The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 and 7.0 before 7.0.0.3 has an unspecified "securi…
Websphere Application Server
Patch available
MEDIUM 5.0
CVE-2009-1074
Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not use SSL in all expected circumstances, which makes it easier for remote attackers to …
Java System Identity Manager
Patch available
HIGH 7.8
CVE-2009-0742
The username command in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers and Cisco ACE 4710 Application Contro…
Application Control Engine Module
Patch available
MEDIUM 5.0
CVE-2008-6193
Sam Crew MyBlog stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.
Myblog
No fix yet
MEDIUM 5.0
CVE-2009-0547
Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to…
Evolution
Mitigation only
MEDIUM 5.0
CVE-2009-0047
Gale 0.99 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass val…
Gale
after 0.99