Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.9
CVE-2008-4192
The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack…
Cman
Mitigation only
HIGH 7.5
CVE-2008-2932
Heap-based buffer overflow in Red Hat adminutil 1.1.6 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitra…
Adminutil
Mitigation only
MEDIUM 5.0
CVE-2008-3274
The default configuration of Red Hat Enterprise IPA 1.0.0 and FreeIPA before 1.1.1 places ldap:///anyone on the read ACL for the krbMKey attribute, w…
Enterprise Ipa
after 1.1.0
HIGH 10.0
CVE-2008-2928EPSS 7%
Multiple buffer overflows in the adminutil library in CGI applications in Red Hat Directory Server 7.1 before SP7 allow remote attackers to cause a d…
Directory Server
Patch available
CRITICAL 9.1
CVE-2008-2369
manzier.pxt in Red Hat Network Satellite Server before 5.1.1 has a hard-coded authentication key, which allows remote attackers to connect to the ser…
Satellite
5.1.1+
HIGH 7.5
CVE-2008-1376
A certain Red Hat build script for nfs-utils before 1.0.9-35z.el5_2 on Red Hat Enterprise Linux (RHEL) 5 omits TCP wrappers support, which might allo…
Nfs Utils
Mitigation only
HIGH 7.6
CVE-2008-3323
setup.exe before 2.573.2.3 in Cygwin does not properly verify the authenticity of packages, which allows remote Cygwin mirror servers or man-in-the-m…
Cygwin
after 1.7
HIGH 7.1
CVE-2008-2375
Memory leak in a certain Red Hat deployment of vsftpd before 2.0.5 on Red Hat Enterprise Linux (RHEL) 3 and 4, when PAM is used, allows remote attack…
Vsftpd
No fix yet
HIGH 7.2
CVE-2008-2359
The default configuration of consolehelper in system-config-network before 1.5.10-1 on Fedora 8 lacks the USER=root directive, which allows local use…
Fedora 8
Mitigation only
HIGH 7.5
CVE-2008-1767EPSS 13%
Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent attackers to cause a denial of service (crash) and possibly execute ar…
Desktop
No fix yet
HIGH 7.1
CVE-2007-5962EPSS 12%
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux a…
Enterprise Linux
Patch available
HIGH 7.5
CVE-2008-1677
Buffer overflow in the regular expression handler in Red Hat Directory Server 8.0 and 7.1 before SP6 allows remote attackers to cause a denial of ser…
Directory Server
Mitigation only
HIGH 7.1
CVE-2007-6282
The IPsec implementation in Linux kernel before 2.6.25 allows remote routers to cause a denial of service (crash) via a fragmented ESP packet in whic…
Enterprise Linux
No fix yet
HIGH 9.0
CVE-2008-0892EPSS 14%
The replication monitor CGI script (repl-monitor-cgi.pl) in Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, allow…
Directory Server
Mitigation only
HIGH 7.5
CVE-2008-0893
Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, does not properly restrict access to CGI scripts, which allows re…
Directory Server
Patch available
HIGH 7.2
CVE-2007-4130
The Linux kernel 2.6.9 before 2.6.9-67 in Red Hat Enterprise Linux (RHEL) 4 on Itanium (ia64) does not properly handle page faults during NUMA memory…
Enterprise Linux
Patch available
MEDIUM 6.8
CVE-2007-5503EPSS 5%
Multiple integer overflows in Cairo before 1.4.12 might allow remote attackers to execute arbitrary code, as demonstrated using a crafted PNG image w…
Cairo
after 1.4.10
HIGH 8.5
CVE-2007-6181EPSS 6%
Heap-based buffer overflow in cygwin1.dll in Cygwin 1.5.7 and earlier allows context-dependent attackers to execute arbitrary code via a filename wit…
Cygwin
after 1.5.19
MEDIUM 5.0
CVE-2007-4136
The ricci daemon in Red Hat Conga 0.10.0 allows remote attackers to cause a denial of service (loss of new connections) by repeatedly sending data or…
Conga
Patch available
HIGH 7.5
CVE-2007-4994
Certificate Server 7.2 in Red Hat Certificate System (RHCS) does not properly handle new revocations that occur while a Certificate Revocation List (…
Certificate Server
Mitigation only
MEDIUM 6.0
CVE-2007-5079
Red Hat Enterprise Linux 4 does not properly compile and link gdm with tcp_wrappers on x86_64 platforms, which might allow remote attackers to bypass…
Linux
Mitigation only
MEDIUM 6.8
CVE-2007-4134
Directory traversal vulnerability in extract.c in star before 1.5a84 allows user-assisted remote attackers to overwrite arbitrary files via certain /…
Fedora
Patch available
MEDIUM 6.5
CVE-2007-4132
Unspecified vulnerability in Red Hat Network Satellite Server 5.0.0 allows remote authenticated users to execute arbitrary code via unknown vectors i…
Network Satelite Server
Patch available
MEDIUM 5.8
CVE-2007-2874
Buffer overflow in the wpa_printf function in the debugging code in wpa_supplicant in the Fedora NetworkManager package before 0.6.5-3.fc7 allows use…
Fedora Core
after 0.6.5-3.fc7
MEDIUM 6.2
CVE-2007-3103
The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the permissions of arbitrary fil…
Enterprise Linux
Patch available
MEDIUM 5.0
CVE-2007-3373
daemon.c in cman (redhat-cluster-suite) before 20070622 does not clear a buffer for reading requests, which might allow local users to obtain sensiti…
Cluster Suite
Patch available
HIGH 10.0
CVE-2007-1007EPSS 7%
Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbit…
Enterprise Linux
Patch available
HIGH 10.0
CVE-2006-6235EPSS 6%
A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary c…
Enterprise Linux
Patch available
MEDIUM 6.8
CVE-2006-4811
Integer overflow in Qt 3.3 before 3.3.7, 4.1 before 4.1.5, and 4.2 before 4.2.1, as used in the KDE khtml library, kdelibs 3.1.3, and possibly other …
Kdelibs
Patch available
HIGH 7.5
CVE-2006-5170
pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition wh…
Enterprise Linux
Patch available