Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2013-0912
WebKit in Google Chrome before 25.0.1364.160 allows remote attackers to execute arbitrary code via vectors that leverage "type confusion."
Chrome
Mitigation only
HIGH 7.5
CVE-2013-2549EPSS 6%
Unspecified vulnerability in Adobe Reader 11.0.02 allows remote attackers to execute arbitrary code via vectors related to a "break into the sandbox,…
Acrobat Reader
Mitigation only
MEDIUM 6.6
CVE-2013-1762
stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, whic…
Stunnel
after 4.54
MEDIUM 5.0
CVE-2012-4840
IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote attackers to conduct XP…
Cognos Business Intelligence
Mitigation only
HIGH 10.0
CVE-2012-4707
3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors that trigger an out-of-bounds memory access.
Codesys Gateway Server
after 2.3.9.19
MEDIUM 6.8
CVE-2013-0108EPSS 27%
An ActiveX control in HscRemoteDeploy.dll in Honeywell Enterprise Buildings Integrator (EBI) R310, R400.2, R410.1, and R410.2; SymmetrE R310, R410.1,…
Enterprise Buildings Integrator
Mitigation only
HIGH 9.3
CVE-2012-0439EPSS 39%
An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute ar…
Groupwise
Mitigation only
HIGH 9.3
CVE-2013-1637
Opera before 12.13 allows remote attackers to execute arbitrary code via vectors involving DOM events.
Opera Browser
after 12.12
HIGH 9.3
CVE-2013-1638EPSS 8%
Opera before 12.13 allows remote attackers to execute arbitrary code via crafted clipPaths in an SVG document.
Opera Browser
after 12.12
HIGH 9.3
CVE-2013-0758EPSS 73%
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 a…
Firefox
2.15 / 10.0.12+
HIGH 9.3
CVE-2013-0745
The AutoWrapperChanger class in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 1…
Firefox
2.15 / 17.0.2+
HIGH 10.0
CVE-2013-0614EPSS 6%
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code via unspecified vecto…
Acrobat
Mitigation only
HIGH 10.0
CVE-2013-0618EPSS 6%
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code via unspecified vecto…
Acrobat
Mitigation only
HIGH 10.0
CVE-2013-0607EPSS 6%
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code via unspecified vecto…
Acrobat
Mitigation only
HIGH 10.0
CVE-2013-0608EPSS 6%
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code via unspecified vecto…
Acrobat
Mitigation only
HIGH 9.3
CVE-2013-0007EPSS 32%
Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary cod…
Xml Core Services
Mitigation only
HIGH 7.5
CVE-2012-6329EPSS 62%
The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly handle backslashes and fully qual…
Perl
after 5.16.2
HIGH 9.3
CVE-2012-6465
Opera before 12.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed SVG image.
Opera Browser
after 12.10
HIGH 10.0
CVE-2012-5932EPSS 63%
Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 allo…
Privileged User Manager
Mitigation only
HIGH 9.3
CVE-2012-5690
RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allow remote attackers to execute arbitrary code via a RealAudio file t…
Realplayer
after 16.0.0
HIGH 10.0
CVE-2012-5142
Google Chrome before 23.0.1271.97 does not properly handle history navigation, which allows remote attackers to execute arbitrary code or cause a den…
Chrome
after 23.0.1271.96
HIGH 9.3
CVE-2012-2556EPSS 21%
The OpenType Font (OTF) driver in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Se…
Windows 2003 Server
Mitigation only
HIGH 10.0
CVE-2012-5973
CA XCOM Data Transport r11.0 and r11.5 on UNIX and Linux allows remote attackers to execute arbitrary commands via a crafted request.
Xcom Data Transport
Mitigation only
MEDIUM 6.0
CVE-2012-5537
The Simplenews Scheduler module 6.x-2.x before 6.x-2.4 for Drupal allows remote authenticated users with the "send scheduled newsletters" permission …
Simplenews Scheduler
Patch available
HIGH 10.0
CVE-2012-6046
Static code injection vulnerability in admin/banners.php in PHP Enter allows remote attackers to inject arbitrary PHP code into horad.php via the cod…
Php Enter
Mitigation only
HIGH 7.5
CVE-2012-5836
Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allow remote attackers to execute arbitrary code or cause a denial of…
Firefox
2.14 / 17.0+
MEDIUM 6.8
CVE-2012-5837
The Web Developer Toolbar in Mozilla Firefox before 17.0 executes script with chrome privileges, which allows user-assisted remote attackers to condu…
Firefox
after 16.0.2
MEDIUM 6.8
CVE-2012-5777
Eval injection vulnerability in the ReplaceListVars function in the template parser in e/class/connect.php in EmpireCMS 6.6 allows user-assisted remo…
Empirecms
No fix yet
MEDIUM 5.0
CVE-2012-4884
Argument injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to create arbitrary files…
Rt
Mitigation only
HIGH 7.5
CVE-2012-2971
The server in CA ARCserve Backup r12.5, r15, and r16 on Windows does not properly process RPC requests, which allows remote attackers to execute arbi…
No fix yet