Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2004-2761EPSS 10%
The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as de…
Md5
Patch available
HIGH 7.5
CVE-2008-5659
The gnu.java.security.util.PRNG class in GNU Classpath 0.97.2 and earlier uses a predictable seed based on the system time, which makes it easier for…
Classpath
after 0.97.2
HIGH 7.8
CVE-2008-5410
The PK11_SESSION cache in the OpenSSL PKCS#11 engine in Sun Solaris 10 does not maintain reference counts for operations with asymmetric keys, which …
Solaris
Patch available
MEDIUM 5.0
CVE-2008-5411
IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 sends SSL traffic over "unsecured TCP," which makes it easier for remote attackers to obtain …
Websphere Application Server
after 7.0
HIGH 7.5
CVE-2008-5331
Adobe Acrobat 9 uses more efficient encryption than previous versions, which makes it easier for attackers to guess a document's password via a brute…
Acrobat
Mitigation only
MEDIUM 5.0
CVE-2008-3057
Octeth Oempro 3.5.5.1, and possibly other versions before 4, does not set the secure flag for the PHPSESSID cookie in an https session, which makes i…
Oempro
No fix yet
HIGH 7.5
CVE-2008-4227
Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 changes the encryption level of PPTP VPN connections to a lower level th…
Iphone Os
Mitigation only
MEDIUM 6.8
CVE-2008-5230
The Temporal Key Integrity Protocol (TKIP) implementation in unspecified Cisco products and other vendors' products, as used in WPA and WPA2 on Wi-Fi…
iOS
No fix yet
HIGH 10.0
CVE-2008-5100EPSS 8%
The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the pathname o…
.net Framework
No fix yet
MEDIUM 5.0
CVE-2008-4368
The default configuration of Java 1.5 on Apple Mac OS X 10.5.4 and 10.5.5 contains a jurisdiction policy that limits Java Cryptography Extension (JCE…
Mac Os X
Mitigation only
MEDIUM 5.0
CVE-2008-3663
Squirrelmail 1.4.15 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests a…
Squirrelmail
Mitigation only
MEDIUM 5.0
CVE-2008-3102
Mantis 1.1.x through 1.1.2 and 1.2.x through 1.2.0a2 does not set the secure flag for the session cookie in an https session, which can cause the coo…
Mantisbt
Mitigation only
MEDIUM 5.0
CVE-2008-3662
Gallery before 1.5.9, and 2.x before 2.2.6, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be…
Gallery
after 2.2.5
MEDIUM 5.0
CVE-2008-3671
Acronis True Image Echo Server 9.x build 8072 on Linux does not properly encrypt backups to an FTP server, which allows remote attackers to obtain se…
True Image Echo Server
No fix yet
MEDIUM 6.8
CVE-2008-3532
The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user into accepti…
Pidgin
Patch available
MEDIUM 5.0
CVE-2008-3288
The Server Authentication Module in EMC Dantz Retrospect Backup Server 7.5.508 uses a "weak hash algorithm," which makes it easier for context-depend…
Dantz Retrospect Backup Server
Patch available
MEDIUM 5.0
CVE-2008-3236
Unspecified vulnerability in Wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 allo…
Websphere Application Server
Mitigation only
MEDIUM 6.4
CVE-2008-2780
The Anubis (aka Anubis+Ripe160) plugin before 1.3 for encrypt stores the unencrypted file's size in cleartext in the header of the encrypted file, wh…
Anubis Plugin
after 1.2
MEDIUM 5.0
CVE-2008-2558
CRE Loaded 6.2.13.1 and earlier does not set the "Secure" attribute for cookies that are sent over HTTPS, which might allow remote attackers to sniff…
Cre Loaded
after 6.2.13.1
MEDIUM 5.0
CVE-2008-2285
The ssh-vulnkey tool on Ubuntu Linux 7.04, 7.10, and 8.04 LTS does not recognize authorized_keys lines that contain options, which makes it easier fo…
Linux
Mitigation only
MEDIUM 5.0
CVE-2008-2299
Unspecified vulnerability in SecureICA and ICA Basic encryption of Citrix Presentation Server 4.5 and earlier, Access Essentials 2.0 and earlier, and…
Presentation Server
after 4.5
HIGH 7.5
CVE-2008-1886EPSS 7%
The NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download uses weak cryptography for a KeyCode that blocks unauth…
Download Client
No fix yet
MEDIUM 5.0
CVE-2008-1772
iScripts SocialWare stores passwords in cleartext in a database, which allows context-dependent attackers to obtain sensitive information.
Socialware
No fix yet
MEDIUM 5.0
CVE-2008-1711
Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 stores passwords in cleartext in a MySQL database, which allows context-dependent attac…
Advanced Web Photo Gallery
No fix yet
HIGH 7.5
CVE-2008-1527
ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3), support authentication …
Prestige 660
Mitigation only
MEDIUM 5.0
CVE-2008-0759
ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier allows remote attackers to cause a denial of service (daemon crash) via an …
Extremez Ip File Server
after 5.1.2
MEDIUM 6.4
CVE-2007-6635
FAQMasterFlexPlus, possibly 1.5 or 1.52, stores the admin password in cleartext in a database, which might allow context-dependent attackers to obtai…
Faqmasterflexplus
No fix yet
HIGH 10.0
CVE-2007-6521EPSS 5%
Unspecified vulnerability in Opera before 9.25 allows remote attackers to execute arbitrary code via crafted TLS certificates.
Opera Browser
after 9.24
HIGH 9.3
CVE-2007-5863EPSS 23%
Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a man-in-the-middle (MITM) attack between the clie…
Mac Os X
Mitigation only
MEDIUM 6.4
CVE-2007-5502
The PRNG implementation for the OpenSSL FIPS Object Module 1.1.1 does not perform auto-seeding during the FIPS self-test, which generates random data…
Fips Object Module
Patch available