Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.9
CVE-2008-1669
Linux kernel before 2.6.25.2 does not apply a certain protection mechanism for fcntl functionality, which allows local users to (1) execute code in p…
Linux Kernel
Patch available
MEDIUM 6.9
CVE-2008-1375
Race condition in the directory notification subsystem (dnotify) in Linux kernel 2.6.x before 2.6.24.6, and 2.6.25 before 2.6.25.1, allows local user…
Linux Kernel
2.6.24.6+
MEDIUM 6.9
CVE-2008-1570
Race condition in the create_lockpath function in policyd-weight 0.1.14 beta-16 allows local users to modify or delete arbitrary files by creating th…
Policyd Weight
Mitigation only
HIGH 7.2
CVE-2008-0055
Foundation in Apple Mac OS X 10.4.11 creates world-writable directories while NSFileManager copies files recursively and only modifies the permission…
Mac Os X
Patch available
MEDIUM 5.8
CVE-2008-0058
Race condition in the NSURLConnection cache management functionality in Foundation for Apple Mac OS X 10.4.11 allows remote attackers to execute arbi…
Mac Os X
Patch available
MEDIUM 5.8
CVE-2008-0059
Race condition in NSXML in Foundation for Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a crafted XML file,…
Mac Os X
Patch available
HIGH 9.3
CVE-2008-0379EPSS 9%
Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attackers to …
Crystal Reports Xi
No fix yet
HIGH 9.3
CVE-2007-6429
Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request …
Evi
after 1.4
MEDIUM 6.6
CVE-2007-5847
Race condition in the CFURLWriteDataAndPropertiesToResource API in Core Foundation in Apple Mac OS X 10.4.11 creates files with insecure permissions,…
Mac Os X
Mitigation only
HIGH 7.6
CVE-2007-6180
Race condition in the Remote Procedure Call kernel module (rpcmod) in Sun Solaris 8 through 10 allows local users to cause a denial of service (NULL …
Solaris
Patch available
MEDIUM 6.8
CVE-2007-6077
The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as used in Ruby on Rails, removes the :cookie_only attribute from the DEF…
Rails
Patch available
MEDIUM 5.8
CVE-2007-5154
Session fixation vulnerability in Aipo and Aipo ASP 3.0.1.0 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
Aipo
after 3.0.1.0
MEDIUM 6.9
CVE-2007-0997
Race condition in the tee (sys_tee) system call in the Linux kernel 2.6.17 through 2.6.17.6 might allow local users to cause a denial of service (sys…
Linux Kernel
Mitigation only
HIGH 7.6
CVE-2007-3970EPSS 6%
Race condition in ESET NOD32 Antivirus before 2.2289 allows remote attackers to execute arbitrary code via a crafted CAB file, which triggers heap co…
Nod32 Antivirus
2.2289+
HIGH 7.1
CVE-2007-3091EPSS 28%
Race condition in Microsoft Internet Explorer 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2;…
Windows 2003 Server
Patch available
MEDIUM 6.2
CVE-2007-1741
Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to g…
HTTP Server
Mitigation only
MEDIUM 6.8
CVE-2007-1249
MoveSortedContentAction in C1 Financial Services Contelligent 9.1.4 does not check "the additional environment security configuration," which allows …
C1 Financial Services
Mitigation only
HIGH 9.3
CVE-2007-0099EPSS 25%
Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attacker…
Xml Core Services
Patch available
MEDIUM 6.2
CVE-2006-4801
Race condition in Deja Vu, as used in Roxio Toast Titanium 7 and possibly other products, allows local users to execute arbitrary code via temporary …
Toast
No fix yet
MEDIUM 5.1
CVE-2006-2094EPSS 23%
Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, …
Ie
No fix yet
MEDIUM 5.1
CVE-2005-3240EPSS 6%
Race condition in Microsoft Internet Explorer allows user-assisted attackers to overwrite arbitrary files and possibly execute code by tricking a use…
Ie
Mitigation only
MEDIUM 6.9
CVE-2004-2697
The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via a symlink attack on a comman…
Aix
No fix yet
MEDIUM 6.9
CVE-2004-2698
Race condition in IMWheel 1.0.0pre11 and earlier, when running with the -k option, allows local users to cause a denial of service (IMWheel crash) an…
Imwheel
after 1.0.0pre11
HIGH 7.6
CVE-2003-1562EPSS 6%
sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay afte…
Openssh
Mitigation only
HIGH 10.0
CVE-2002-2374
Unspecified vulnerability in pprosetup in Sun PatchPro 2.0 has unknown impact and attack vectors related to "unsafe use of temporary files."
Patchpro
Patch available
MEDIUM 6.2
CVE-2000-0864
Race condition in the creation of a Unix domain socket in GNOME esound 0.2.19 and earlier allows a local user to change the permissions of arbitrary …
Esound
Patch available