Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2009-2487
Use-after-free vulnerability in the frpr_icmp function in the ipfilter (aka IP Filter) subsystem in Sun Solaris 10, and OpenSolaris snv_45 through sn…
Opensolaris
Patch available
HIGH 10.0
CVE-2009-2300
The management interface in the phion airlock Web Application Firewall (WAF) 4.1-10.41 does not properly handle CGI requests that specify large width…
Airlock Web Application Firewall
Patch available
MEDIUM 5.0
CVE-2009-1889
The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote…
Pidgin
after 2.5.7
MEDIUM 5.0
CVE-2009-2214
The Secure Gateway service in Citrix Secure Gateway 3.1 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an uns…
Secure Gateway
after 3.1
HIGH 7.8
CVE-2009-1163
Memory leak on the Cisco Physical Access Gateway with software before 1.1 allows remote attackers to cause a denial of service (memory consumption) v…
Physical Access Gateway
after 1.0
HIGH 9.3
CVE-2009-0691EPSS 6%
The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 for Foxit Reader 3.0 before Build 1817 does not properly handle a fatal error during deco…
Jpeg2000 Jbig2 Decoder Add On
after 2.0.2009.303
HIGH 7.8
CVE-2009-2137
Memory leak in the Ultra-SPARC T2 crypto provider device driver (aka n2cp) in Sun Solaris 10, and OpenSolaris snv_54 through snv_112, allows context-…
Opensolaris
Patch available
HIGH 7.1
CVE-2009-1692
WebKit before r41741, as used in Apple iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Safari, and other software, allows re…
Safari
No fix yet
MEDIUM 5.0
CVE-2009-2108EPSS 6%
git-daemon in git 1.4.4.5 through 1.6.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a request contai…
Git
Patch available
HIGH 9.3
CVE-2009-1857EPSS 7%
Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 allow attackers t…
Acrobat
Patch available
HIGH 9.3
CVE-2009-1858EPSS 9%
The JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1…
Acrobat
Patch available
HIGH 9.3
CVE-2009-1859EPSS 7%
Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow attac…
Acrobat
Patch available
HIGH 9.3
CVE-2009-0560EPSS 28%
Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and S…
Office
Mitigation only
HIGH 7.8
CVE-2009-1139EPSS 39%
Memory leak in the LDAP service in Active Directory on Microsoft Windows 2000 SP4 and Server 2003 SP2, and Active Directory Application Mode (ADAM) o…
Adam
Mitigation only
HIGH 9.3
CVE-2009-1701EPSS 8%
Use-after-free vulnerability in the JavaScript DOM implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS fo…
Safari
after 3.2.2
HIGH 9.3
CVE-2009-1709EPSS 7%
Use-after-free vulnerability in the garbage-collection implementation in WebCore in WebKit in Apple Safari before 4.0 allows remote attackers to exec…
Safari
after 4.0_beta
HIGH 9.3
CVE-2009-1711EPSS 7%
WebKit in Apple Safari before 4.0 does not properly initialize memory for Attr DOM objects, which allows remote attackers to execute arbitrary code o…
Safari
after 4.0_beta
HIGH 9.3
CVE-2009-1687EPSS 8%
The JavaScript garbage collector in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 do…
Safari
after 4.0_beta
HIGH 9.3
CVE-2009-1690EPSS 7%
Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, …
Safari
after 4.0_beta
MEDIUM 5.0
CVE-2009-1196
The directory-services functionality in the scheduler in CUPS 1.1.17 and 1.1.22 allows remote attackers to cause a denial of service (cupsd daemon ou…
Cups
Patch available
MEDIUM 5.0
CVE-2009-1957
charon/sa/ike_sa.c in the charon daemon in strongSWAN before 4.3.1 allows remote attackers to cause a denial of service (NULL pointer dereference and…
Strongswan
after 4.3.0
MEDIUM 5.0
CVE-2009-1958
charon/sa/tasks/child_create.c in the charon daemon in strongSWAN before 4.3.1 switches the NULL checks for TSi and TSr payloads, which allows remote…
Strongswan
after 4.2.9
MEDIUM 5.0
CVE-2009-1827
The SVG component in Mozilla Firefox 3.0.4 allows remote attackers to cause a denial of service (application hang) via a large value in the r (aka Ra…
Firefox
No fix yet
MEDIUM 5.0
CVE-2009-1828EPSS 9%
Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory consumption) via a KEYGEN el…
Firefox
No fix yet
MEDIUM 5.0
CVE-2009-1758
The hypervisor_callback function in Xen, possibly before 3.4.0, as applied to the Linux kernel 2.6.30-rc4, 2.6.18, and probably other versions allows…
Xen
after 3.3.1
MEDIUM 5.0
CVE-2009-1632
Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) …
Ipsec Tools
after 0.7.1
MEDIUM 5.0
CVE-2009-1514
Google Chrome 1.0.154.53 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a throw statement …
Chrome
No fix yet
HIGH 9.3
CVE-2009-1313EPSS 8%
The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of …
Firefox
Mitigation only
HIGH 9.3
CVE-2009-1492EPSS 26%
The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial o…
Acrobat
after 9.1
MEDIUM 6.8
CVE-2009-1493EPSS 22%
The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers …
Reader
No fix yet