Security News
-
Security Reviews
-
Exploits
-
Tools
-
UNIX Focus
-
Windows Focus
Home
Ask the Team
Mailing Lists
Advertising Info
Advisories
About SecuriTeam
Blogs
Brought to you by:
Suppliers of:
Website Testing Tools
Network Testing Tools
Software Testing Tools
SecuriTeam in Your Inbox
New vulnerability?
New tool?
Tell us
(Our
PGP key
).
Select Year:
2013
2012
2011
2010
2009
2008
2007
2006
2005
2004
2003
2002
2001
2000
1999
1998
0000
December
2012
Apple Itunes Memory Corruption and Application Crash Remote Vulnerability
WireShark Buffer Overflow Vulnerability
TVMOBiLi Media Server Multiple Remote DoS Vulnerabilities
Symantec Web Gateway LFI Remote ROOT RCE Exploit Vulnerability
Socusoft Photo 2 Video Buffer Overflow Vulnerability
Siemens SIMATIC WinCC Flexible (Runtime) Multiple Vulnerabilities
Photodex ProShow Producer Buffer Overflow Vulnerability
Oracle MySQL Server Username Enumeration Weakness Remote Vulnerability
MyBB HM My Country Flags SQL Injection Vulnerability
Novell Netware XNFS.NLM STAT Notify Remote Code Execution Vulnerability
Kordil EDMS SQL Injection Vulnerability
IrfanView JLS Formats PlugIn Heap Overflow Vulnerability
IBM eDiscovery Manager Unspecified Cross Site Scripting Vulnerability
Free Mp3 Player Local Denial of Service Vulnerability
Computer Associates XCOM Data Transport Remote Arbitrary Command Execution Vulnerability
AhnLab V3 Internet Security Privilege Escalation Vulnerability
Able2Extract and Able2Extract Server Memory Corruption Vulnerability
VBulletin ajaxReg Module SQL Injection Vulnerability
Sumatra PDF and MuPDF 'lex_number()' Function Remote Integer Overflow Vulnerability
OpenStack Keystone Insecure File Permissions Vulnerability
MyYoutube MyBB Plugin SQL Injection Vulnerability
MySQL (Linux) Database Privilege Elevation Zeroday Exploit
Guru Auction Multiple SQL Injection Vulnerabilities
MyBB Bank v3 Plugin 'r_username' Parameter SQL Injection Vulnerability
ManageEngine MSPCentral Multiple Security Vulnerabilities
Joomla! JooProperty Component SQL Injection and Cross Site Scripting Vulnerabilities
IrfanView IMXCF PlugIn Remote Code Execution Vulnerability
HP Multiple LaserJet Printers Cross Site Scripting Vulnerability
FOOT Gestion 'id' Parameter SQL Injection Vulnerability
Clockstone and other CMSMasters Theme File Upload Vulnerabilities
Cerberus FTP Server Web Admin Cross Site Scripting Vulnerability
Banana Dance Multiple vulnerabilities
Apache Tomcat Denial Of Dervice Vulnerability
Adobe Flash Player and AIR Remote Buffer Overflow Vulnerability
VMware View Connection Server Directory Traversal Vulnerability
Sourcefabric Newscoop 'f_email' Parameter SQL Injection Vulnerability
Snare Linux Cross-Site Scripting via Log Injection Vulnerability
SmarterMail 'txtDisplayAs_SettingText' Parameter HTML Injection Vulnerability
Qualcomm Android kernel Remote Code Execution and Denial of Service Vulnerabilities
Multiple Rockwell Automation Products Remote Denial of Service Vulnerability
M0n0wall Multiple Cross Site Request Forgery Vulnerabilities
HP OpenVMS Multiple Denial of Service Vulnerabilities
FreeVimager GIF File Remote Denial of Service Vulnerability
Firefly MediaServer Multiple Remote DoS Vulnerabilities
Facebook Profile MyBB Plugin Persistant XSS Vulnerability
Ekiga UTF-8 Parsing Denial of Service Vulnerability
Dell SonicWall SonicOS WAF - POST Inject Vulnerability
Cerberus FTP Server Multiple XSS vulnerabilities
Apache Tomcat Security Bypass Vulnerability
Adobe Flash Player and AIR Remote Integer Overflow Vulnerability
Wordpress URL Video Lead Form Plugin Cross-Site Scripting Vulnerabilities
Symantec Network Access Control Local Privilege Escalation Vulnerability
Red Hat OpenShift Enterprise Cross Site Request Forgery Vulnerability
Oracle MySQL and MariaDB Insecure Salt Generation Security Bypass Weakness
Opera Web Browser Memory Corruption Denial of Service Vulnerability
NVIDIA Install Application 'AddPackages()' Function Buffer Overflow Vulnerability
MyBB kingchat Plugin 'kingchat.php' Script HTML Injection Vulnerability
Kent Web Access Report Unspecified Cross-Site Scripting Vulnerability
IBM Director CIM Server Privilege Escalation Vulnerability
Google Chrome Prior to 23.0.1271.97 Multiple Security Vulnerabilities
FirePass SSL VPN 'sessionId' Parameter Local File Include Vulnerability
ConcourseConnect HTML Injection and Cross Site Request Forgery Vulnerabilities
ClipBucket Multiple SQL Injection vulnerabilities
Citrix XenApp XML Service Interface Remote Code Execution Vulnerability
Axis Multiple HTML Injection Vulnerabilities
Apache Tomcat Denial of Service Vulnerability
Adobe Flash Player and AIR Memory Corruption Vulnerability
SimpleInvoices 2011.1 Cross-Site-Scripting (XSS) Vulnerabilities
Xen 'XENMEM_exchange' Local Privilege Escalation Vulnerability
Wordpress Simple Gmail Login Plugin Stack Trace Information Disclosure Vulnerability
Symantec Messaging Gateway Arbitrary File Download Vulnerabilities
Smartphone Pentest Framework Multiple Remote Command Execution Vulnerabilities
Red Hat Certificate System Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
OpenStack Nova Local Information Disclosure Vulnerability
MyBB Profile Blog Plugin SQL Injection and HTML Injection Vulnerabilities
Kordil EDMS 'Password' Parameter SQL Injection Vulnerability
IBM Flex System CMM and IMM2 Modules Information Disclosure Vulnerability
Freefloat FTP Server 'WMI' Service Arbitrary File Upload Vulnerability
HP Network Node Manager i Remote Unspecified Unauthorized Access Vulnerability
Apache Tomcat Cross-Site Request Forgery Vulnerability
Adobe ColdFusion Security Bypass Vulnerability
Ektron CMS 'XslCompiledTransform' Class Remote Code Execution Vulnerability
Citrix XenDesktop Virtual Desktop Agent Local Security Bypass Vulnerability
BlackBerry PlayBook Unspecified Information Disclosure Vulnerability
Xen 'get_page_from_gfn()' Function Local Denial of Service Vulnerability
WordPress Nest Theme 'codigo' Parameter SQL Injection Vulnerability
WordPress GRAND Flash Album Gallery Plugin Multiple Remote Vulnerabilities
Symantec Endpoint Protection Manager Remote Code Execution Vulnerability
SafeNet Privilege 'PrivAgent.ocx' ActiveX Controls Multiple Buffer Overflow Vulnerabilities
Red Hat CloudForms Multiple Insecure File Permissions and Security Bypass Vulnerabilities
Oracle MySQL Server Privilege Escalation Vulnerability
Oracle Fusion Middleware Reports Developer Remote Security Vulnerability
MyBB kingchat Plugin 'username' Parameter SQL Injection Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey Heap Buffer Function Overflow Vulnerability
ManageEngine AssetExplore Multiple HTML Injection Vulnerabilities
IBM Tivoli Monitoring HTTP Monitoring Console Cross Site Scripting Vulnerability
HP LaserJet Pro 400 Multi Function Printers Remote Unspecified Unauthorized Access Vulnerability
Buffalo LinkStation Information Disclosure and Security Bypass Vulnerabilities
Linux Kernel 'taskstats' Local Denial of Service Vulnerability
WordPress Spider Calendar Plugin 'many_sp_calendar' Parameter Cross Site Scripting Vulnerability
Winmail Server Multiple HTML Injection Vulnerabilities
VLC Media Player Read Access Violation Arbitrary Code Execution Vulnerability
VicBlog Multiple SQL Injection Vulnerabilities
UMPlayer 'wintab32.dll' DLL Loading Arbitrary Code Execution Vulnerability
Trillian SSL Certificate Validation Security Bypass Vulnerability
Sysax FTP Automation Local Privilege Escalation Vulnerability
Ruby 'error.c' Multiple Security Bypass Vulnerabilities
KMPlayer '.avi' File Local Denial of Service Vulnerability
Gajim '_ssl_verify_callback()' Function SSL Certificate Validation Spoofing Vulnerability
Drupal Twitter Pull Module Cross Site Scripting Vulnerability
Drupal Organic Groups SA-CONTRIB-2012-148 Security Bypass Vulnerability
Broadcom BCM4325 and BCM4329 Wireless Chipset Out of Bound Read Denial of Service Vulnerability
AWStats Unspecified Cross Site Scripting Vulnerability
Joomla! 'language search' Component Cross Site Scripting Vulnerability
WordPress Pretty Link Lite Plugin 'search' Parameter Cross Site Scripting Vulnerability
WordPress FireStorm Professional Real Estate Plugin Multiple SQL Injection Vulnerabilities
WeeChat Color Decoding Heap Buffer Overflow Vulnerability
WebCalendar Multiple HTML Injection Vulnerabilities
Steam 'vgui2_s.dll' Heap Buffer Overflow Vulnerability
Samsung Kies Multiple Security Vulnerabilities
ProjectPier 'upload.php' Arbitrary File Upload Vulnerability
Plone and Zope Unspecified Security Bypass and Code Execution Vulnerabilities
Perl Heap-Based Memory Corruption Vulnerability
Oracle E-Business Suite Remote Oracle iRecruitment Vulnerability
Multiple Horde Products Multiple Unspecified HTML Injection Vulnerabilities
ModSecurity POST Parameters Security Bypass Vulnerability
Inventory Multiple Cross Site Scripting and SQL Injection Vulnerabilities
Greenstone Multiple Security Vulnerabilities
EasyITSP 'customers_edit.php' Authentication Security Bypass Vulnerability
Check Point UTM-1 Edge and Safe Multiple Security Vulnerabilities Updated
Cisco Unified MeetingPlace Web Conferencing Buffer Overflow Vulnerability Updated
World of Phaos SQL Injection and Cross Site Scripting Vulnerabilities
WordPress Zingiri Web Shop Plugin 'path' Parameter Arbitrary File Upload Vulnerability
WordPress UnGallery Plugin 'search' Parameter Remote Arbitrary Command Execution Vulnerability
Wordpress Facebook Survey SQL Injection Vulnerability
WordPress 'doing_wp_cron' Parameter Cross Site Scripting Vulnerability
TLS Protocol Information Disclosure Vulnerability
SolarWinds Orion IP Address Manager (IPAM) 'search.aspx' Cross Site Scripting Vulnerability
OrangeHRM 'sortField' Parameter SQL Injection Vulnerability
OpenStack Glance Arbitrary File Deletion Vulnerability
FleetCommander Multiple Remote Security Vulnerabilities
Drupal Announcements Module Access Bypass Vulnerability
DCForum 'auth_user_file.txt' File Multiple Information Disclosure Vulnerabilities
Apple iOS Multiple Local Security Bypass Vulnerability
PrestaShop 'message' Field HTML Injection Vulnerability
Mutiny Command Injection Vulnerability
Multiple IBM products GSKit Client Hello Message Remote Denial of Service Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey Heap Buffer Overflow Vulnerability
Monkey HTTP Daemon '/var/run/monkey.pid' Symlink Attack Local Privilege Escalation Vulnerability
MantisBT 'Delete Attachments Threshold()' Function Security Bypass Vulnerability
Mahara Multiple Cross Site Scripting Vulnerabilities
Kunena 'search' Parameter SQL Injection and Cross Site Scripting Vulnerabilities
HP Intelligent Management Centre 'uam.exe' Stack Buffer Overflow Vulnerability
Google Chrome Multiple Security Vulnerabilities Updated
BSW Gallery 'uploadpic.php' Arbitrary File Upload Vulnerability
Apache OFBiz Unspecified Security Vulnerability
XiVO Cross-Site Request Forgery Vulnerability
Wordpress Plugin Catalog HTML Code Injection and Cross-site Scripting Vulnerability
WordPress AJAX Post Search Plugin 'srch_txt' Parameter SQL Injection Vulnerability
VBulletin ChangUonDyU - Advanced Statistics SQL Injection Vulnerability
Tiki Wiki CMS Groupware 'unserialize()' PHP Code Execution Vulnerability
RT and RT RTFM Extension Security Bypass Vulnerability
Oracle PeopleSoft Enterprise PeopleTools Remote Security Vulnerability
Novell ZENWorks Asset Management Information Disclosure Vulnerability
Mozilla Firefox, SeaMonkey, and Thunderbird HZ-GB-2312 Cross Site Scripting Vulnerability
Joomla! Freestyle Testimonials Component Unspecified SQL Injection Vulnerability
HelpBox Multiple Security Vulnerabilities
F5 FirePass Remote SQL Injection Vulnerability
ClanSphere 'cs_lang' Cookie Parameter Local File Include Vulnerability
Apache Axis and Axis2/Java SSL Certificate Validation Security Bypass Vulnerability
Zoner AntiVirus Free for Android X.509 Certificate Security Bypass Vulnerability
WordPress Wordfence Security Plugin Cross Site Scripting Vulnerability
WordPress Simple Slider Plugin Cross Site Scripting Vulnerability
WordPress Bookings Plugin 'error' Parameter Cross Site Scripting Vulnerability
SMF 'view' Parameter Cross Site Scripting Vulnerability
Ruby '#to_s' Method Incomplete Fix Security Bypass Vulnerability
Oracle Fusion Middleware Sites Remote Security Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey Heap Based Use After Free Denial Of Service Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey Cross Site Scripting Vulnerability
Liferay Portal Security Bypass and HTML Injection Vulnerabilities
Inout Article Base 'ViewController.class.php' SQL Injection Vulnerability
FreeBSD Linux Compatibility Layer Local Privilege Escalation Vulnerabiity
Drupal Core Arbitrary PHP Code Execution and Information Disclosure Vulnerabilities
Amateur Photographer's Image Gallery Multiple Security Vulnerabilities
Twitter App 5.0 Eavesdropping Vulnerability
ZPanel Multiple Remote Security Vulnerabilities
WordPress Zarzadzonie Kontem Plugin 'ajaxfilemanager.php' Script Arbitrary File Upload Vulnerability
Wordpress Simple Slider Plugin Cross-Site Scripting Vulnerabilities
WordPress Crayon Syntax Highlighter Plugin 'wp_load' Parameter Remote File Include Vulnerabilities
Ubuntu 'unity-firefox-extension' Package Denial of Service Vulnerability
SilverStripe 'Title' Parameter Multiple HTML Injection Vulnerabilities
Ruby Local File Creation Vulnerability
PHP Server Monitor HTML Injection Vulnerability
Oracle Identity Manageme Remote Security Vulnerability
Oracle Agile PLM Framework Remote Security Vulnerability
Mozilla Firefox Arbitrary Code Execution Vulnerability
libdbus 'DBUS_SYSTEM_BUS_ADDRESS' Variable Local Privilege Escalation Vulnerability Updated
IBM WebSphere DataPower XC10 Denial of Service and Security Bypass Vulnerabilities
Grandstream GXP1405 Multiple HTML Injection Vulnerabilities
Empire CMS Template Parser Remote PHP Code Execution Vulnerability
Bitweaver Multiple Cross Site Scripting and Local File Include Vulnerabilities
Amazon Web Services SDK SSL Certificate Validation Security Bypass Vulnerability
Xlockmore 'dclock' Mode Security Bypass Vulnerability UPDATED
WordPress Zingiri Form Builder Plugin Cross Site Scripting Vulnerability
WordPress Thank You Counter Button Plugin 'paged' Parameter Cross Site Scripting Vulnerability
WordPress Easy Webinar Plugin 'wid' Parameter SQL Injection Vulnerability
Ubuntu Remote Login Service Local Information Disclosure Vulnerability
SilverStripe CMS - Multiple Vulnerabilities
Oracle E-Business Suite Remote Oracle Human Resources Vulnerability
NetCat CMS Multiple Cross Site Scripting Vulnerabilities
Mozilla Firefox/Thunderbird/SeaMonkey Integer Overflow Vulnerability
Linux Kernel 'ethtool.c' Information Disclosure Vulnerability
IBM WebSphere Application Server 'Liberty Profile' Cross Site Scripting Vulnerability
GE Proficy Real-Time Information Portal Multiple Denial of Service Vulnerabilities
Campaign Enterprise Multiple Security Vulnerabilities
BIGACE Web CMS Session Fixation Vulnerability
Akeni LAN Filter Bypass Vulnerability
Safend Data Protector Multiple Vulnerabilities
Zenphoto Multiple Security Vulnerabilities
WordPress Magazine Basic Theme 'id' Parameter SQL Injection Vulnerability
WordPress All Video Gallery Plugin 'vid' Parameter Multiple SQL Injection Vulnerabilities
VAM Shop Multiple Cross Site Scripting and SQL Injection Vulnerabilities
TIBCO Formvine Unspecified Unauthorized Access Security Bypass Vulnerability
Siemens SiPass Integrated 'SiPass server' Component Buffer Overflow Vulnerability
Real Networks RealPlayer Write Access Violation Arbitrary Code Execution Vulnerability
Performance Co-Pilot Insecure Temporary File Creation Vulnerability
Oracle October Security Update Multiple Vulnerabilities
Munin Insecure Temporary File Creation Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey Heap Based Memory Corruption Vulnerability
HP SiteScope UploadFilesHandler Directory Traversal Vulnerability
AWStats 'awredir.pl' Unspecified Security Vulnerability
airVision NVR Arbitrary File Disclosure and SQL Injection Vulnerabilities
WordPress Poll Plugin 'wp-admin/admin-ajax.php' Script Multiple SQL Injection Vulnerabilities
WordPress eShop Magic Plugin 'File' Parameter Arbitrary File Disclosure Vulnerability
Python tweepy Library SSL Certificate Validation Security Bypass Vulnerability
Oracle WebCenter Forms Recognition 'Sssplt30.ocx' ActiveX Control Remote Code Execution Vulnerabilty
openSIS 'modname' Parameter Local File Include Vulnerability
Mozilla Firefox Privilege Escalation Vulnerability
Mcrypt Stack Buffer Overflow Vulnerability
LetoDMS Multiple Cross Site Scripting and SQL Injection Vulnerabilities
IBM WebSphere Application Server LPTA Tokens Security Bypass Vulnerability
Google Chrome Prior to 22.0.1229.92 Multiple Security Vulnerabilities
Eduserv OpenAthens SP for Java Security Bypass Vulnerability
Dotproject Unspecified SQL Injection and Cross Site Scripting Vulnerabilities
Adobe Reader Memory Corruption Denial of Service Vulnerability
AWAuctionScript CMS Multiple Remote Vulnerabilities
Red Hat Network Configuration Client Insecure File Permissions Vulnerability
Oracle Solaris inetd(1M) Local Security Vulnerability
Oracle BI Publisher HTTP Remote Security Vulnerability
MYREphp Vacation Rental Software Cross Site Scripting and SQL Injection Vulnerabilities
Mozilla Firefox/Thunderbird/SeaMonkey Use After Free Memory Corruption Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey Denial of Service Vulnerability
Mantis Multiple Cross-Site Scripting Vulnerabilities UPDATED
LibTIFF 'TIFFScanlineSize()' Function Heap-based Buffer Overflow Vulnerability
Joomla! 'com_sqlreport' Component Password Disclosure Vulnerability
IBM AIX FTP Client Security Bypass Vulnerability
Gitolite Security Bypass Vulnerability
Eduserv Security Bypass Vulnerability
Drupal Chaos Tool Suite Module Cross Site Scripting Vulnerability
Dokeos 'profile.php' Multiple HTML Injection Vulnerabilities
Broadcom WIDCOMM Bluetooth 'btkrnl.sys' Driver Local Privilege Escalation Vulnerability
Apple iPhone/iPad/iPod touch Prior to iOS 6 Information Disclosure Vulnerability
Adobe Shockwave Player Unspecified Memory Corruption Vulnerability
SonicWALL CDP 5040 Multiple Web Vulnerabilities
WordPress DX-Contribute Plugin Cross Site Request Forgery Vulnerability
TYPO3 Formhandler Extension Unspecified Cross-Site Scripting and SQL-Injection Vulnerabilities
SAP Netweaver Cross Site Scripting and Cross Site Request Forgery Vulnerabilities
Real Networks RealPlayer Remote Stack Buffer Overflow Vulnerability
Palo Alto Networks GlobalProtect X.509 Certificate Validation Security Bypass Vulnerability
Oracle Java SE Remote Java Runtime Environment in Libraries Vulnerability
Oracle Database Server Local Core RDBMS Vulnerability
Narcissus Remote Command Execution Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey Use After Free Function Memory Corruption Vulnerability
Hitachi JP1/File Transmission Server/FTP Security Bypass and Buffer Overflow Vulnerabilities
FirePass SSL VPN 'refreshURL' Parameter URI Redirection Vulnerability
Drupal Monthly Archive by Node Type Module Access Bypass Vulnerability
cups-pk-helper 'cupsGetFile()' and 'cupsPutFile()' Local Security Vulnerabilities
bloofoxCMS Multiple Cross Site Scripting Vulnerabilities
Adobe Shockwave Player Unspecified Buffer Overflow Vulnerability
November
2012
Yii Framework 'Search' Form Field SQL Injection Vulnerability
WordPress Webplayer Plugin 'id' Parameter SQL Injection Vulnerability
WordPress FLV Player Plugin 'id' Parameter SQL Injection Vulnerability
ViewVC HTML Injection Vulnerability
TP-LINK TL-WR841N Router Local File Include Vulnerability
SAP NetWeaver PMI Agent XML External Entity Information Disclosure Vulnerability
PLIB 'ssgParser.cxx' Remote Stack Buffer Overflow Vulnerability
Oracle MySQL Server Remote Security Vulnerability Updated
Multiple IBM WebSphere Products Security Bypass Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey Security Bypass Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey 'defaultValue()' Security Bypass Vulnerability
Mantis 'summary_api.php' HTML Injection Vulnerability
LetoDMS Multiple Cross Site Scripting Vulnerabilities
Joomla! com_parcoauto Component 'idVeicolo' Parameter Remote SQL Injection Vulnerability
IBM Tivoli Endpoint Manager for Remote Control Denial of Service Vulnerability
Fortigate UTM appliances CA SSL Certificate Creation Security Bypass Vulnerability
Drupal Mandrill Module Information Disclosure Vulnerability
CoDeSys Unspecified Directory Traversal Vulnerability
Axigen Mail Server 'fileName' Parameter Directory Traversal Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey WebSockets Memory Corruption Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey Cross Domain Information Disclosure Vulnerability
Magento SSL Certificate Validation Security Bypass Vulnerability
libssh Multiple Buffer Overflow and Denial of Service Vulnerabilities
Joomla! Spider Catalog Extension 'product_id' Parameter SQL Injection Vulnerability
Instagram For iOS Man in the Middle Information Disclosure Vulnerability
IBM WebSphere Application Server Remote Privilege Escalation Vulnerability
IBM Cognos Business Intelligence Denial of Service Vulnerability
Gramophone 'rs' Parameter Cross Site Scripting Vulnerability
EMC NetWorker 'nsrd' RPC Service Format String Vulnerability
Drupal Gallery Formatter Module Unspecified HTML Injection Vulnerability Updated
Debian 'android-tools' Package Insecure Temporary File Creation Vulnerability
Cisco WAG120N Multiple Remote Command Execution Vulnerabilities
cgit 'syntax-highlighting.sh' Remote Command Injection Vulnerability
Apple QuickTime Use-After-Free Remote Code Execution Vulnerability
Apache Tomcat Header Denial-of-Service Vulnerability.
Adobe Reader Unspecified Remote Code Execution Vulnerability
June
2012
Oracle Database Server OCIPasswordChange API CVE-2012-0510 Security Bypass Vulnerability
November
2012
WordPress Madebymilk Theme 'id' Parameter SQL Injection Vulnerability
Webmin 'real name' Field Cross Site Scripting Vulnerability
TrouSerS Denial Of Service Vulnerability
Request Tracker (RT) Multiple Security Vulnerabilities
Oracle Java Virtual Machine (JVM) Remote Information Disclosure Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey Use-After-Free Memory Corruption Vulnerability Updated
Mozilla Firefox/Thunderbird/SeaMonkey Heap Memory Corruption Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey Buffer Overflow Vulnerability
Linux Kernel KVM Local Denial of Service Vulnerability
IBM Java Multiple Remote Code Execution Vulnerabilities UPDATED
Google Chrome Multiple Security Vulnerabilities
Drupal Search API Module Cross Site Request Forgery Vulnerability
Drupal Excluded Users Module Multiple HTML Injection Vulnerabilities
Cisco Unified MeetingPlace SQL Injection and Cross Site Scripting Vulnerabilities
Apple QuickTime Multiple Buffer Overflow Vulnerabilities
Adobe Flash Player and AIR Unspecified Security Vulnerability
HP Performance Insight Multiple Unspecified Security Vulnerabilities
Drupal CiviCRM Module SSL Certificate Validation Security Bypass Vulnerability
Dotproject Multiple SQL Injection and Cross Site Scripting Vulnerabilities
Dell OpenManage Server Administrator Cross Site Scripting Vulnerability
CoDeSys Buffer Overflow Vulnerability and Integer Overflow Vulnerability
Cisco Secure Access Control System (ACS) Authentication Bypass Vulnerability
AWCM Cookie Authentication Bypass and Multiple Security Bypass Vulnerabilities
Apple QuickTime Buffer Overflow Vulnerability
Android SMS Spoofing Vulnerability
Achievo Multiple Input Validation Vulnerabilities
GIMP XWD File Handling Buffer Overflow Vulnerability
Joomla Clickjacking Security Bypass Vulnerability
IBM Tivoli Federated Identity Manager 'OpenID' Attribute Validation Security Bypass Vulnerability
ESRI ArcGIS for Server 'where' Form Field SQL Injection Vulnerability
eBay Payflow SDK SSL Certificate Validation Security Bypass Vulnerability
Drupal Secure Login Module Open Redirection Vulnerability Updated
Drupal Hostip Module Cross Site Scripting Vulnerability UPDATED
lighttpd 'http_request_split_value()' Function Remote Denial of Service Vulnerability
OpenJPEG Heap Based Buffer Overflow Vulnerability Updated
Mozilla Firefox/Thunderbird/SeaMonkey 'str_unescape' Heap Buffer Overflow Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey 'Cross-origin wrappers' Cross Site Scripting Vulnerability
Mozilla Firefox Style Inspector Remote Code Execution Vulnerability
Mozilla Firefox Developer Toolbar Cross Site Scripting Vulnerability
Moneris eSelectPlus PHP API SSL Certificate Validation Security Bypass Vulnerability
WordPress Plg Novana Plugin 'id' Parameter SQL Injection Vulnerability
VeriCentre Multiple SQL Injection Vulnerabilities
TP-LINK TL-WR841N Router Multiple HTML Injection Vulnerabilities
PHP 'Open_Basedir' Security-Bypass Vulnerability UPDATED
PayPal SDK SSL Certificate Validation Security Bypass Vulnerability
Xen PV Domain Builder Kernel Decompression Local Denial Of Service Vulnerability UPDATED
Open-Realty CMS Cross Site Request Forgery (CSRF) Vulnerability
Mozilla Firefox/SeaMonkey/Thunderbird Cross-Origin Security Bypass Vulnerability
Linux Kernel 'uname()' System Call Local Information Disclosure Vulnerability UPDATED
Django 'HttpRequest.get_host()' Information Disclosure Vulnerability UPDATED
BabyGekko Multiple Web Vulnerabilities
Adobe Flash Player and AIR Buffer Overflow Vulnerability
SWFUpload 'movieName' Parameter Cross Site Scripting Vulnerability-UPDATED
Ruby Hash Collision Denial of Service Vulnerability
Opera Web Browser Multiple Vulnerabilities
Invision Power Board 'core.php' PHP Code Execution Vulnerability
IBM Java Multiple Remote Code Execution Vulnerabilities
CryENGINE Remote Shell Command Execution Vulnerability
Media Player Classic WebServer Cross Site Scripting and Denial of Service Vulnerabilities
Zoner Photo Studio Buffer Overflow Vulnerabilities
Eventy CMS Multiple Web Vulnerablities
Applicure DotDefender WAF Format String Vulnerability
Xen 'TMEM hypercall' Multiple Security Vulnerabilities UPDATED
Novell File Reporter 'NFRAgent.exe' Multiple Security Vulnerabilities
BananaDance Wiki CMS Multiple Web Vulnerabilities
Iceape Security Denial Of Service And Remote Arbitrary Code Execution Vulnerabilities
Wordpress Plugin in AJAX Post Search Sql injection Vulnerability
Wordpress Answer my question plugin Multiple Cross-Site Scripting Vulnerabilities
OrangeHRM SQL Injection Vulnerability
LibreOffice Multiple Vulnerabilities
HP ProLiant SL Advanced Power Manager (SL-APM), Remote User Validation Failure Vulnerability
EmpireCMS Template Parser Remote PHP Code Execution Vulnerability
CMS Made Simple Cross-Site Request Forgery (CSRF) Vulnerability
Cisco Secure Access Control System TACACS+ Authentication Bypass Vulnerability
Cisco Ironport Appliances Sophos Anti-virus Multiple Vulnerabilities
AWCM Content Manager Multiple Vulnerability
IcedTea OpenJDK6 Remote Security Vulnerability
VaM Shop Multiple Web Vulnerabilities
SIEMENS Sipass Integrated Ethernet Bus Arbitrary Pointer Dereference
Oracle Java SE 'Libraries' sub-component Remote Java Runtime Environment Vulnerability
MoinMoin Virtual Group ACL Evaluation Security Bypass Vulnerability
Linux Kernel 'binfmt_script.c' Local Information Disclosure Vulnerability
Konqueror Multiple Memory Corruption Vulnerabilities
HP SiteScope SOAP Remote Disclosure of Information, Remote Code Execution Vulnerabilities
Dokeos Multiple Cross-Site Scripting Vulnerabilities
Cisco Prime Data Center Network Manager Remote Command Execution Vulnerability
Apple iOS Denial of Service Remote Attackers Vulnerability
Self Service Password Unspecified LDAP Injection Vulnerability
PrestaShop Persistant XSS vulnerability
NetCat CMS Multiple Web Vulnerabilities
LibreOffice and OpenOffice Multiple NULL Pointer Dereference Denial of Service Vulnerabilities
HP-UX Running Java, Remote Execution of Arbitrary Code, and Other Vulnerabilities
HP Performance Insight with Sybase Remote Denial of Service (DoS) and Loss of Data Vulnerability
Cisco Unified MeetingPlace Web Conferencing Buffer Overflow Vulnerability
Apple Safari Denial of Service Remote Attackers Vulnerability
Achievo XSS, LFI and SQL Injection Vulnerabilities
Symphony Multiple SQL Injection and Cross Site Scripting Vulnerabilities
SIEMENS Sipass Integrated 2.6 Ethernet Bus Arbitrary Pointer Dereference
QQPlayer 'quartz.dll' Heap-Based Buffer Overflow Vulnerability
Palo Alto Network's Global Protect And SSL VPN Portal
Linux Kernel 'uname()' System Call Local Information Disclosure Vulnerability
Limny (login.php) Remote URI Based Cross-Site Scripting Vulnerability
Efront Learning Cross-Site Scripting Vulnerability
CmyDocument Content Management Application XSS Vulnerabilities
Cisco CUCM Multiple Vulnerabilities
Zenphoto 'admin-News-Articles.php' Cross Site Scripting Vulnerability
WordPress Cimy User Manager Plugin Arbitrary File Disclosure Vulnerability
WordPress BackWPup Multiple Information Disclosure Vulnerabilities
Ubuntu Linux Local Privilege Escalation Vulnerabilities
Ubuntu Software Properties PPA GPG Keys Validation Security Bypass Vulnerability
Ubuntu Linux Kernel Key Management Denial of Service Vulnerability
Sisfokol Multiple Arbitrary File Upload Vulnerabilities
Schoolhos CMS 'index.php' Script SQL Injection Vulnerability
Piwik Unspecified Cross Site Scripting Vulnerability
phpMyAdmin Multiple HTML Injection Vulnerabilities
MyBB Profile Album Plugin 'album' Parameter SQL Injection Vulnerability
Mutiny Technology Virtual Appliance Mutiny Command Injection Vulnerability
Linux Kernel 'fs/proc/root.c' Remote Denial of Service Vulnerability
Limny 'login.php' Script Cross Site Scripting Vulnerability
October
2012
libsocialweb Non-SSL Connection Man in The Middle Vulnerability
Librdmacm Service Port Connection Security Vulnerability
Libproxy Heap-Based Buffer Overflow Vulnerability
KDE Konqueror Multiple Security Vulnerabilities
Joomla Commedia Component 'id' Parameter SQL Injection Vulnerability
IPtools Remote Command Server Buffer Overflow Vulnerability
IBM Lotus Notes Traveler Multiple Input Validation Vulnerabilities
Hostapd 'hostapd.conf' Configuration File Insecure File Permissions Vulnerability
GraphicsMagick 'png_IM_malloc()' Function Denial of Service Vulnerability
GraphicsClone Script 'term' parameter Cross-Site Scripting Vulnerability
Google Chrome For Linux Remote Denial Of Service Vulnerability.
FFmpeg Multiple Remote Vulnerabilities
FFmpeg libavcodec 'vqavideo.c' '.vaq' File Heap Memory Corruption Vulnerability
eShop Magic Plugin 'File' Parameter Arbitrary File Disclosure Vulnerability
cgit 'Author' Field Remote Denial of Service Vulnerability
Cartweaver 'helpFileName' Parameter Local File Include Vulnerability
Bacula Console ACL Bypass Security Vulnerability
Apache Axis2 XML Signature Wrapping Security Vulnerability
BigPond Wireless Broadband Gateway Command Injection and Authentication Bypass Vulnerabilities
Mozilla Firefox/Thunderbird/SeaMonkey Use After Free Denial of Service Vulnerability
Metasploit Project Metasploit Framework Local Privilege Escalation Vulnerability
IBM Tivoli Monitoring Web Server HTTP TRACE/TRACK Methods Information Disclosure Vulnerability
Hostapd Message Handling Denial Of Service Vulnerability
Google Chrome 'use-after-free' Multiple Security Vulnerabilities
Computer Associates ARCserve Backup Remote Code Execution and Denial of Service Vulnerabilities
Ezhometech EzServer AMF Request Remote Heap Corruption Vulnerability
Dolibarr 'idmenu' Parameter Cross Site Scripting Vulnerability
Cisco WebEx WRF File Format Multiple Remote Memory Corruption Vulnerabilities
SilverStripe 'BackURL' Parameter URI Redirection Vulnerability
Piwigo 'username_or_email' Parameter Cross Site Scripting Vulnerability
PhpMyAdmin Security Bypass Certain Security Restrictions Vulnerability
Oracle Virtual Desktop Infrastructure (VDI) Remote Vulnerability
GE Proficy Historian 'KeyHelp.ocx' ActiveX Control Remote Code Execution Vulnerability
ActivePython Insecure File Permissions Vulnerability
Drupal Views Bulk Operations Security Bypass Vulnerability
ComponentOne FlexGrid ActiveX Control Buffer Overflow Vulnerability
Claws Mail 'strchr()' Function NULL Pointer Denial of Service Vulnerability
Barracuda Spam & Virus WAF Unspecified Multiple HTML Injection Vulnerabilities
appRain CMF 'uploadify.php' Remote Arbitrary File Upload Vulnerability
WordPress White Label CMS Plugin HTML Injection and Cross Site Request Forgery Vulnerabilities
WHMCS 'googlecheckout.php' SQL Injection Vulnerability
TurboFTP Server 'PORT' Command Processing Stack Based Buffer Overflow Vulnerability
RubyInstaller Insecure File Permissions Vulnerability
Pre Printing Press 'pid' Parameter SQL Injection Vulnerability
LAN Messenger Persistent Software Vulnerability
Oracle Clinical Remote Data Capture Remote Security Vulnerability
Oracle Central Designe Remote Security Vulnerability
Oracle Business Intelligence Enterprise Edition Remote Security Vulnerability
OpenStack Keystone Token Validation Multiple Security Bypass Vulnerabilities
Layton Technologies Helpbox Multiple Remote Security Vulnerabilities
TYPSoft FTP Server 'APPE' Command Remote Buffer Overflow Vulnerability
Symantec Ghost Solutions Suite Backup File Memory Corruption Vulnerability
Oracle Oracle VM Virtual Box Local Security Vulnerability
Oracle Multiple SPARC Products Local Security Vulnerability
Oracle Imaging and Process Management Remote Security Vulnerability
Wordpress Slideshow Plugin Multiple Cross Site Scripting Vulnerabilities
Samba 'FD_SET' Memory Corruption Vulnerability
WordPress Guest Posting Plugin 'uploadify.php' Arbitrary File Upload Vulnerability
Oracle WebCenter Sites Remote Security Vulnerability
OTRS Email Body HTML Injection Vulnerability
Samba 'Perl-Based DCE/RPC IDL' Compiler Remote Code Execution Vulnerability
Symphony Multiple Remote Security Vulnerabilities
Videosmate Organizer Security Bypass Vulnerability
WebCalendar Local File Include and PHP Code Injection Vulnerabilities
Wordpress Social Discussions Plugin Remote File Include Vulnerability
Oracle Solaris Remote Security Vulnerability
Oracle Solaris Local Security Vulnerability
Oracle Secure Global Desktop Remote Security Vulnerability
WordPress WP e-Commerce Plugin Unspecified SQL Injection Vulnerability
Oracle BI Publisher Remote Security Vulnerability
Oracle Agile PLM for Process Remote Security Vulnerability
OpenSAML XML Signature Wrapping Security Vulnerability
Movable Type HTML Injection Vulnerability
ManageEngine Support Center Plus Multiple Security Vulnerabilities
Magento uStoreLocator Module Multiple SQL Injection Vulnerabilities
libvirt 'virNetServerProgramDispatchCall()' Function Remote Denial Of Service Vulnerability
Legrand and Bticino Information Disclosure Vulnerability
JBoss Enterprise Application Platform Insecure Directory Permissions Vulnerability
FFmpeg Multiple Remote Code Execution Vulnerabilities
Apache HTTP Server HTML-Injection And Information Disclosure Vulnerabilities
Xavi 7968 ADSL Router Multiple Remote Vulnerabilities
Oracle FLEXCUBE Direct Banking Remote Security Vulnerability
Oracle E-Business Suite Local Oracle Applications Framework Vulnerability
HP Network Node Manager i (NNMi) Remote Disclosure of Information Vulnerability
HP IBRIX X9000 Storage Remote Disclosure of Information Vulnerability
GTA UTM Firewall GB Multiple Web Vulnerabilities
Endpoint Protector Multiple Web Vulnerabilities
CMSQLITE Multiple Web Vulnerabiltiies
CMSMini Cross-Site Scripting Vulnerability
ClipBucket Cross-Site Scripting Vulnerability
Better WP Security Wordpress Web Vulnerabilities
Oracle Identity Managemet Remote Security Vulnerability
HP Secure Web Server (SWS) for OpenVMS, DoS, Unauthorized Access, Disclosure of Information Vulnerability
WingFTP Server Denial of Service Vulnerability
Logica HotScan SWIFT Alliance Access Interface BufferOverflow Vulnerability
Hard-coded BigPond 3G21WB Credentials and Command-Injection Vulnerability
F5 FirePass SSL VPN 4xxx Series Arbitrary URL Redirection
Oracle Multiple Products Remote Security Vulnerability
Oracle JRockit Remote Security Vulnerability
Oracle JavaFX Remote Security Vulnerability
HP-UX Running OpenSSL, Remote Denial of Service (DoS) Vulnerability
Samsung Kies NULL Pointer Dereference and Improper Access Control Vulnerability
phpFreeChat XSS Cross-Site Scripting Vulnerability
OpenX Cross-Site Scripting and SQL Injection Vulnerability
JCore SQL Injection and Cross-Site Scripting Vulnerability
Ezhometech EzServer 7.0 Remote Heap Corruption Vulnerability
Oracle Siebel UI Framework Remote Security Vulnerability
IBM DB2 LUW GET_WRAP_CFG_C and GET_WRAP_CFG_C2 XML File Disclosure Vulnerability
Interspire Email Marketer Multiple Vulnerabilites
XnView JLS File Decompression Heap Overflow Vulnerability
Visual Tools DVR Multiple Vulnerabilities
Unirgy uStoreLocator SQL Injection Magento Extension Vulnerability
Template CMS Cross-Site Scripting and Cross-Site Request Forgery Vulnerability
Subrion CMS SQL Injection , Cross-Site Scripting and Cross-Site Request Forgery Vulnerability
phptax 0.8 Remote Code Execution Vulnerability
ISC BIND Remote Attackers Denial of Service Vulnerability
Sense of Security FileBound Privilege Escalation Vulnerability
WellinTech KingView Backdoor Unauthorized Access Vulnerability
VMware vCenter CapacityIQ Unspecified Directory Traversal Vulnerability
Oracle Java SE 'Beans' Remote Java Runtime Environment Vulnerability
Oracle FLEXCUBE Universal Banking Remote Security Vulnerability
Oracle Agile Product Supplier Collaboration for Process Remote Security Vulnerability
Oracle Agile PLM for Process 'Supply Chain Relationship Mgmt' Remote Security Vulnerability
Oracle Agile PLM for Process 'Global Spec Management' Remote Security Vulnerability
Oracle Agile PLM for Process 'Document Reference Library' Remote Security Vulnerability
Google Chrome 22.0.1229.92 Regular Expression Vulnerability
Google Chrome 22.0.1229.92 Compositor Vulnerability
Krzysztof Kowalczyk Sumatra PDF Multiple Remote Memory Corruption Vulnerabilities
Omnistar Document Manager Multiple Vulnerabilities
Oracle JDK 'Networking' Remote Java Runtime Environment Vulnerability
Oracle JDK 'Beans' Remote Java Runtime Environment Vulnerability
Oracle Java SE 'Libraries' Remote Java Runtime Environment Vulnerability
Omnistar Mailer Multiple Web Vulnerabilities
Oracle Supply Chain Products Suite Agile PLM for Process Remote Security Vulnerability
AsaanCart Multiple Input Validation Vulnerabilities
Crawlability vBSEO 'proc_deutf()' Remote Code Execution Vulnerability
Atar2b CMS pageE.php gallery_e.php and pageH.php SQL Injection Vulnerability
Adobe Adobe Air Denial of Service Memory Corruption Vulnerabilities
Accomplishtechnology phpMyDirectory page.php SQL Injection Vulnerability
Oracle Enterprise Manager Multiple SQL Injection Vulnerability
Oracle WebCenter Sites Fusion Middleware Local Security Vulnerability
Apache Axis2 "Signature exclusion attack" Remote Attackers Vulnerability
AsaanCart Multiple Input Validation Remote Attackers Vulnerabilities
Drupal Stickynote Module Unspecified Cross Site Scripting Vulnerability
SilverStripe CMS Persistent Cross Site Scripting Vulnerability
Eliteweaver xClick Cart 'shopping_url' Parameter Cross Site Scripting Vulnerability
Autodesk Design Review Insecure Library Loading Vulnerability
Switchvox Asterisk Multiple Web Vulnerabilities
ISC BIND 9 DNS RDATA Handling Remote Denial of Service Vulnerability
Apple Mac Os X Denial of Service Vulnerability
Sybase Java Operating System Command Execution Vulnerability
Mavili Guestbook Project Mavili Guestbook Multiple Security Vulnerabilities
TaskFreak Cross-Site Scripting Vulnerability
OcPortal 'redirect' Parameter URI Redirection Vulnerability
Coppermine Photo Gallery Multiple Vulnerabilities
vOlk Botnet Framework Multiple Web Vulnerabilities
CorelDRAW Graphics Suite Insecure Library Loading Vulnerability
PHPList 'testtarget' Parameter Cross-Site Scripting Vulnerability
Drupal Vote Up/Down Module Taxonomy Script Insertion Vulnerability
Possesports Posse Softball Director CMS team.php SQL injection Vulnerability
Firewall Analyzer Multiple Cross Site Scripting Vulnerabilities
Redgraphic SAPID CMS Multiple Remote File Include Vulnerabilities
Google Chrome 22.0.1229.79 SSE2 Optimization Functionality Buffer Overflow Vulnerability
Wireshark Versions Prior to 1.8.3 Multiple Security Vulnerabilities
Honeywellprocess Enterprise Building Manager Stack-based Buffer Overflow Vulnerability
WordPress Slideshow Gallery Plugin gallery-css.php cross-site scripting Vulnerability
HP Network Node Manager i Multiple Cross-Site Scripting Vulnerabilities
Activestate Activeperl 'wlbsctrl.dll' Privilege Escalation Vulnerability
IBM Maximo Asset Management SmartCloud Control Desk Products Multiple Vulnerabilities
Intel Trusted Execution Technology SINIT ACMs Buffer Overflow Vulnerability
Linux Kernel CIFS 'O_DIRECT' NULL Pointer Deference Local Denial of Service Vulnerability
LiteSpeed Web Server WebAdmin "gtitle" Cross-Site Scripting Vulnerability
MediaWiki Multiple Security Vulnerabilities
September
2012
Mozilla Firefox,Thunderbird And SeaMonkey Information Disclosure Cross Site Vulnerability
Opera Insecure Library Loading Vulnerability
Mozilla Firefox Diagnostics Online Edition Multiple Cross Site Scripting Vulnerabilities
Novell Groupwise WebConsole Component Integer Overflow Vulnerability
SAP GUI Insecure Library Loading Vulnerability
Siemens Simatic Pcs7 Cross-site Request Forgery (CSRF) Vulnerability
SonicWall Viewpoint SQL Injection Vulnerability
Symantec PGP Universal Server Private Key Information Disclosure Vulnerability
Ektron CMS XXE Injection and Unauthenticated File Upload Vulnerabilities
August
2012
Linux IPv6 nf_conntrack_reasm Denial of Service Vulnerability
Tickets Multiple Security Vulnerabilities
WebKit Multiple Unspecified Remote Code Execution Vulnerabilities UPDATED
t1lib Type 1 Font Parsing Multiple Denial of Service Vulnerabilities UPDATED
Ruby on Rails SQL Injection Vulnerability UPDATED
PolarisCMS 'WebForm_OnSubmit()' Function Cross Site Scripting Vulnerability
Oracle Java SE 'JAXP'' Remote Java Runtime Environment Vulnerability UPDATED
Mozilla Firefox/Thunderbird/SeaMonkey Privilege Escalation Vulnerability UPDATED
Mozilla Firefox/Thunderbird/SeaMonkey Information Disclosure Vulnerability UPDATED
Linux Kernel UDF Filesystem Local Buffer Overflow Vulnerability UPDATED
Linux Kernel NFS Client 'decode_getacl()' Remote Denial of Service Vulnerability UPDATED
LibreOffice and OpenOffice Multiple Heap Based Buffer Overflow Vulnerabilities UPDATED
ISC BIND 9 TCP Query Remote Denial of Service Vulnerability UPDATED
Gajim Insecure Temporary File Creation Vulnerability UPDATED
EMC AutoStart Multiple Buffer Overflow Vulnerabilities UPDATED
Drupal Simplenews Module Information Disclosure Vulnerability UPDATED
Drupal Organic Groups Module Cross Site Scripting and Security Bypass Vulnerabilities UPDATED
Drupal Linkit Module Access Security Bypass Vulnerability UPDATED
acpid Event Scripts Local Information Disclosure Vulnerability UPDATED
WebKit Unspecified Memory Corruption Vulnerability UPDATED
Ubisoft Uplay ActiveX Control Buffer Overflow Vulnerability
TCExam Edit SQL Injection
Ruby on Rails Unsafe SQL Query Generation Vulnerability UPDATED
Oracle Outside In Technology Remote Code Execution Vulnerability UPDATED
Oracle Java SE 'Networking' Remote Java Runtime Environment Vulnerability UPDATED
Novell ZENWorks Asset Management 'rtrlet' Component Remote Code Execution Vulnerability UPDATED
Mozilla Firefox/Thunderbird/Seamonkey Multiple Memory Corruption Vulnerabilities UPDATED
Mozilla Firefox/SeaMonkey/Thunderbird XSLT Stylesheets Denial of Service Vulnerability UPDATED
Linux Kernel HFS Plus Filesystem Local Buffer Overflow Vulnerability UPDATED
ISC BIND 9 DNSSEC Validation Denial of Service Vulnerability UPDATED
Google Chrome Prior to 21 Multiple Security Vulnerabilities UPDATED
Google Chrome Prior to 20.0.1132.57 Multiple Security Vulnerabilities UPDATED
Gajim SQL Injection and Code Execution Vulnerabilities UPDATED
Evince Multiple Remote Code Execution Vulnerabilities UPDATED
Drupal Share Buttons (AddToAny) Module Unspecified Cross Site Scripting Vulnerability UPDATED
Drupal Node Embed Module Access Security Bypass Vulnerability UPDATED
Drupal Fivestar Module Remote Input Validation Vulnerability UPDATED
Django Multiple Security Vulnerabilities UPDATED
Apache Tomcat HTTP DIGEST Authentication Multiple Security Weaknesses UPDATED
YT-Videos Script 'id' Parameter SQL Injection Vulnerability
Xeams Email Server 'Body' Field HTML Injection Vulnerability
Worksforweb iAuto Multiple Cross Site Scripting and HTML Injection Vulnerabilities
WordPress WP-FaceThumb 'pagination_wp_facethum' Parameter Cross Site Scripting Vulnerability UPDATED
WordPress ShareYourCart plugin Path-Disclosure Vulnerability UPDATED
WordPress Image News slider Plugin Multiple Unspecified Vulnerabilities UPDATED
WordPress BulletProof Security 'Accept-Encoding' Header Cross Site Scripting Vulnerability UPDATED
Symantec Web Gateway 'deptUploads_data.php' SQL Injection Vulnerability UPDATED
Samsung TV and BD Products Multiple Denial Of Service Vulnerabilities UPDATED
Ruby on Rails 'authenticate_or_request_with_http_digest' Method Denial Of Service Vulnerability UPDATED
Ruby on Rails Active Record SQL Injection Vulnerability UPDATED
Palo Alto Networks Multiple Products 'inputStr' Parameter Cross Site Scripting Vulnerability UPDATED
Oracle Outside In Technology 'Outside In Filters' Sub Component Remote Code Execution Vulnerability UPDATED
Oracle Outside In Technology 'Outside In Filters' Remote Code Execution Vulnerability UPDATED
Oracle Java SE 'Hotspot'' Remote Java Runtime Environment Vulnerability UPDATED
Oracle Java SE 'Deployment' Multiple Protocols Remote Java Runtime Environment Vulnerability UPDATED
Oracle Java SE 'CORBA' Multiple Protocols Remote Java Runtime Environment Vulnerability UPDATED
Oracle GlassFish Server Multiple Cross Site Scripting and HTML Injection Vulnerabilities UPDATED
MyBB Versions Prior to 1.6.7 Multiple Security Vulnerabilities UPDATED
Mozilla Firefox/SeaMonkey/Thunderbird XPConnect Security Check Cross Domain Scripting Vulnerability UPDATED
Mozilla Firefox Address Bar URI Spoofing Vulnerability UPDATED
Mozilla Firefox, SeaMonkey, and Thunderbird Multiple Remote Memory Corruption Vulnerabilities UPDATED
MIT Kerberos 5 Uninitialized Pointer Dereference Remote Multiple Denial of Service Vulnerabilities UPDATED
ManageEngine Service Desk Plus Multiple HTML Injection Vulnerabilities
Linux Kernel 'fs/eventpoll.c' Local Denial of Service Vulnerability UPDATED
Linux Kernel dl2k Network Driver IOCTL Handling Local Denial of Service Vulnerability UPDATED
IBM Rational Directory Server Multiple Security Vulnerabilities UPDATED
IBM Lotus Protector for Mail Security Multiple Security Vulnerabilities UPDATED
Hitachi JP1 Multiple Products Unspecified Privilege Escalation Vulnerability UPDATED
Google Chrome Prior to 18.0.1025.151 Multiple Security Vulnerabilities UPDATED
Google Chrome Prior to 17.0.963.83 Multiple Security Vulnerabilities UPDATED
Google Chrome Prior to 17.0.963.78 Multiple Security Vulnerabilities UPDATED
Drupal Counter Module SQL Injection Vulnerability UPDATED
Drupal Contact Save Module Unspecified Cross Site Scripting Vulnerability UPDATED
Drupal CDN2 Video Module Cross Site Request Forgery and Cross Site Scripting Vulnerabilities UPDATED
CuteZip '.zip' File Buffer Overflow Vulnerability UPDATED
Bugzilla Multiple Information Disclosure Vulnerabilities UPDATED
Apache Tomcat Hash Collision Denial Of Service Vulnerability UPDATED
WordPress Better WP Security 'User-Agent' Header Cross Site Scripting Vulnerability UPDATED
WordPress Bad Behavior Plugin Multiple Cross Site Scripting Vulnerabilities UPDATED
Samsung NET-i ware Multiple Remote Vulnerabilities UPDATED
SmarterMail 'Body' Field HTML Injection Vulnerability
Samsung NET-i Viewer 'msls31.dll' ActiveX Buffer Overflow Vulnerability UPDATED
PBBoard Multiple Security Vulnerabilities
PBBoard Authentication Bypass Vulnerability
Oracle Java SE Remote Code Execution Vulnerability UPDATED
Opera Web Browser Prior to 11.64 Remote Code Execution Vulnerability UPDATED
Linux Kernel Multiple Local Information Disclosure Vulnerabilities UPDATED
Linux Kernel 'i915_gem_execbuffer.c' Multiple Integer Overflow Vulnerabilities UPDATED
Linux GNU Debugger 'debug_gdb_scripts' Loading Arbitrary Code Execution Vulnerability UPDATED
Joomla CCNewsLetter Module 'id' Parameter SQL Injection Vulnerability UPDATED
Drupal Ubercart Views Module Information Disclosure Vulnerability UPDATED
Drupal Ubercart Module Multiple Security Vulnerabilities UPDATED
Drupal Bundle Copy Module Arbitrary PHP Code Execution Vulnerability UPDATED
Drupal Autosave Module Cross Site Request Forgery Vulnerability UPDATED
Debian 'php_crypt_revamped.patch' Patch Security Bypass Vulnerability
Debian 'logol' Package Insecure File Permissions Vulnerability
Cisco IOS XR Software Route Processor Denial of Service Vulnerability UPDATED
Bitcoin-Qt Denial Of Service Vulnerability
Bitcoin WxBitcoin and Bitcoind Denial of Service Vulnerability denial-of-service condition.
Apple QuickTime Information Disclosure Vulnerability UPDATED
Apple Mac OS X Multiple Information Disclosure Vulnerabilities UPDATED
OpenStack Nova _ Memory Corruption Vulnerability
Zoho BugTracker Multiple HTML Injection Vulnerabilities
Xen CVE-2012-3433 Denial of Service Vulnerability
Total Shop UK eCommerce Generic Cross-Site Scripting
TCExam Prior 11.3.008 Multiple SQL Injection Vulnerabilities
PHPList 'unconfirmed' Parameter Cross-Site Scripting Vulnerability
OTRS 'Body' Field HTML Injection Vulnerability
NCompress Decompress Buffer Underflow Vulnerability
GoodReader App Unspecified Cross Site Scripting Vulnerability
Cyclope Employee Surveillance Solution 'username' Parameter SQL Injection Vulnerability
Axigen Mail Server 'Body' Field HTML Injection Vulnerability
SurgeMail 'Body' Field HTML Injection Vulnerability
Sleipnir Mobile for Android Arbitrary Code Execution and Arbitrary Script Execution Vulnerabilities
PNP4Nagios 'process_perfdata.cfg' Information Disclosure Vulnerability
ownCloud 'sharing.php' Cross Site Scripting Vulnerability
Open Constructor Multiple Input Validation Vulnerabilities
Mibew Messenger 'threadid' Parameter SQL Injection Vulnerability
Liferay Portal JSON Service API Multiple Security Bypass Vulnerabilities
IBM WebSphere Application Server Unspecified Cross Site Scripting Vulnerability
IBM Multiple Products Local Privilege Escalation Vulnerability
HTC Mail Insecure Password Management Information Disclosure Vulnerability
Flogr Multiple Cross Site Scripting Vulnerabilities
Debian 'openvswitch-pki' Package Multiple Insecure File Permissions Vulnerabilities
Bitcoin 'WxBitcoin' and 'Bitcoind' Security Bypass Vulnerability
AuditLogKeeper 'auditlog-keeper.conf' Insecure File Permissions Vulnerability
WordPress WP Effective Lead Management Plugin HTML Injection Vulnerability
WordPress Vitamin Plugin 'path' Parameter Multiple Remote File Disclosure Vulnerabilities
WordPress Featured Post with Thumbnail Unspecified Security Vulnerability
PHP PDO Memory Access Violation Denial of Service Vulnerability
Oracle Business Transaction Management Server 'deleteFile()' Arbitrary File Deletion Vulnerability
Oracle Business Transaction Management Server Arbitrary File Write Vulnerability
Opera Web Browser Unspecified Security Vulnerability
Opera Web Browser Prior to 12.01 Remote Code Execution Vulnerability
Opera Web Browser Cross Site Scripting Sanitizer Security Bypass Vulnerability
Multiple Cisco Nexus Devices Remote Denial of Service Vulnerability
meetOneToGo Plaintext Credentials Information Disclosure Vulnerability
Joomla! 'com_photo' module Multiple SQL Injection Vulnerabilities
Intuit GoPayment Card Reader Information Disclosure Vulnerability
Inout Webmail Multiple HTML Injection Vulnerabilities
HP Arcsight Multiple Products HTML Injection Vulnerability
Hitachi JP1/Integrated Management - Service Support Unspecified Cross-Site Scripting Vulnerability
GNU Bash Remote Stack Based Buffer Overflow Vulnerability
GNOME ScreenSaver Lock Bypass Vulnerability
GNOME Gnome-keyring 'GPG' Password Security Bypass Vulnerability
FreeBSD SCTP NULL Pointer Dereference Remote Denial of Service Vulnerability
Elefant CMS 'id' Parameter Cross Site Scripting Vulnerability
Drupal Shorten URLs Module Cross Site Scripting Vulnerability
Cisco Unified Computing System Multiple Remote Denial of Service Vulnerabilities
Cisco NX-OS Remote Denial of Service Vulnerability
Cisco IP Communicator Security Bypass Vulnerability
Cisco IOS SSH2 Sessions Remote Denial of Service Vulnerability
Cisco IOS Remote Denial of Service Vulnerability
Cisco IOS Information Disclosure Vulnerability
Cisco IOS _ Remote Denial of Service Vulnerability
Cisco Carrier Routing System ACL Security Bypass Vulnerability
Cisco Carrier Routing System _ ACL Security Bypass Vulnerability
Cisco ASA 5500 Series Denial of Service Vulnerability
Cisco AnyConnect Secure Mobility Client Denial of Service Vulnerability
Cisco AnyConnect Secure Mobility Client Certificate Validation Vulnerability
Cisco AnyConnect Secure Mobility Client Certificate Validation Security Bypass Vulnerabilities
Bitcoin 'WxBitcoin' and 'Bitcoind' _ Security Bypass Vulnerability
BeneficialBank Business Multiple SQL Injection Vulnerabilities
Apache Libcloud Man In The Middle Vulnerability
am4ss 'pages.php' PHP Code Injection Vulnerability
Am4ss Multiple HTML Injection and Cross Site Scripting Vulnerabilities
Alt-N MDaemon Body HTML Injection Vulnerability
Alligra Calligra Heap Based Buffer Overflow Vulnerability
WordPress WP SimpleMail Plugin Multiple HTML Injection Vulnerabilities
Wordpress ThreeWP Email Reflector Plugin 'Subject' Field HTML Injection Vulnerability
Wordpress Postie Plugin 'From' Field HTML Injection Vulnerability
WordPress Mini Mail Dashboard Widget Plugin HTML Injection Vulnerability
Wespa Digital WespaJuris 'webshell.php' SQL Injection Vulnerabilities
Solaris 10 Patch 137097-01 Symlink Attack Local Privilege Escalation Vulnerability
Ruby on Rails 'select_tag()' Method Cross Site Scripting Vulnerability
Ruby on Rails Cross Site Scripting Vulnerability
ownCloud 'sharedstorage.php' Security Bypass Vulnerability
Oracle Database 'CTXSYS.CONTEXT' Index Privilege Escalation Vulnerability
Opera Web Browser HTML Injection Vulnerability
NVIDIA UNIX Driver VGA Window Local Privilege Escalation Vulnerability
Multiple Iomega Network Storage Devices Security Bypass Vulnerability
MobileCartly 'deletepage.php' Arbitrary File Deletion Vulnerability
MobileCartly 'add.php' Remote Code Execution Vulnerability
Mailtraq Multiple HTML Injection Vulnerabilities
MailEnable Enterprise Multiple HTML Injection Vulnerabilities
Linux kernel NCI Multiple Remote Stack Buffer Overflow Vulnerabilities
Kamads Classifieds 'admin.php' Multiple Information Disclosure Vulnerabilities
Joomla En Masse Component 'sortBy' Parameter Remote SQL Injection Vulnerability
Joomla! En Masse Component Local and Remote File Include Vulnerabilities
Joomla! FireBoard Component 'func fb_' Parameter SQL Injection Vulnerability
JBoss Enterprise Application Platform Cross Site Request Forgery Vulnerability
Google Chrome Prior to 21.0.1180.75 Multiple Memory Corruption Vulnerabilities
Google Chrome Prior to 21.0.1180.50 Multiple Security Vulnerabilities
Google Chrome Prior to 18.0.1025.168 Multiple Security Vulnerabilities
Google Chrome Prior to 18.0.1025.151 Multiple Security Vulnerabilities
Google Chrome Prior to 13.0.782.107 Multiple Security Vulnerabilities
EmailArchitect Email Server Multiple HTML Injection Vulnerabilities
Drupal Shibboleth authentication Module Access Bypass Vulnerability
Drupal Mime Mail Module Access Bypass Vulnerability
Adobe Acrobat and Reader APSB12-16 Advance Multiple Remote Vulnerabilities
AfterLogic Mailsuite Pro 'Body' Field HTML Injection Vulnerability
Apache QPID NullAuthenticator Authentication Bypass Vulnerability
Baby Gekko URI Cross Site Scripting Vulnerability
Bitcoin Bitcoin-Qt and Bitcoind Unspecified Remote Denial of Service Vulnerability
Bitcoin 'WxBitcoin' and 'Bitcoind' CVE-2010-5140 Denial of Service Vulnerability
Bitcoin WxBitcoin and Bitcoind Denial of Service Vulnerability
Bitcoin 'WxBitcoin' and 'Bitcoind' Integer Overflow Vulnerability
Chef 'clients.rb' Security Bypass Vulnerability
Chef 'cookbooks.rb' Security Bypass Vulnerability
ConcourseSuite Multiple Cross Site Scripting and Cross Site Request Forgery Vulnerabilities
Debian 'libotr2' Package Multiple Heap Based Buffer Overflow Vulnerabilities
dirLIST Multiple Local File Include and Arbitrary File Upload Vulnerabilities
Drupal Better Revisions Module Cross Site Scripting Vulnerability
Drupal Chaos Tool Suite Module Local File Include Vulnerability
TigerVNC SSL Certificate Validation Security Bypass Vulnerability
Snack Sound Toolkit 'GetWavHeader()' Function Buffer Overflow Vulnerability
Oracle Sun Products Suite 'TCP/IP' Remote Solaris Vulnerability
Oracle Sun Products Suite 'SCTP(7P)' Remote Solaris Vulnerability
Oracle Sun Products Suite Remote Solaris Vulnerability
Oracle Sun Products Suite 'pkg.depotd(1M)' Remote Solaris Vulnerability
Oracle Sun Products Suite 'Network/NFS' Remote Solaris Vulnerability
Oracle Sun Products Suite 'in.tnamed(1M)' Remote Solaris Vulnerability
Oracle Sun Products Suit 'SCTP(7P)' Remote Solaris Vulnerability
Oracle Sun Products Suit Remote Solaris Vulnerability
Oracle Sun Products Suit 'Logical Domains (LDOM)' Local Solaris Vulnerability
Oracle Sun Products Suit Local Solaris Vulnerability
Oracle Sun Products Suit 'Apache Tomcat Agent' Local Solaris Cluster Vulnerability
Oracle MySQL Server 'CM' Remote Security Vulnerability
extplorer Cross Site Request Forgery Vulnerability
Eucalyptus Multiple Authentication Mechanism Security Bypass Vulnerabilities
Simple Machines Multiple HTML Injection Vulnerabilities
WordPress Global Content Blocks PHP Code Execution and Information Disclosure Vulnerabilities
Oracle PeopleSoft Enterprise PeopleTools Remote Security Vulnerability
WordPress Cimy User Extra Fields Plugin Arbitrary File Upload Vulnerability
Oracle Outside In Technology 'Outside In Filters' Local Security Vulnerability
Oracle Sun Products Suite 'Kerberos/klist' Local Solaris Vulnerability
Oracle Siebel CRM Remote Security Vulnerability
Oracle Sun Products Suite 'Gnome PDF viewer' Remote Solaris Vulnerability
Open Upload Cross-Site Scripting and Arbitrary Code Execution Vulnerabilities
GNU Automake Local Arbitrary Code Execution Vulnerability
GLPI Cross Site Scripting and Cross Site Request Forgery Vulnerabilities
Eclydre Web Manager 'upload.php' Arbitrary File Upload Vulnerability
Apache Hadoop Information Disclosure Vulnerability
Zenphoto Unspecified Cross Site Scripting Vulnerability
WordPress WP-Predict Plugin 'index.php' Script Multiple SQL Injection Vulnerabilities
WordPress Sendit Newsletter plugin 'id' SQL Injection Vulnerability
WordPress Post Recommendations Plugin 'abspath' Parameter Remote File Include Vulnerability
WordPress PHPFreeChat 'url' Parameter Cross Site Scripting Vulnerability
WordPress Paid Memberships Pro Plugin 'memberslist-csv.php' Information Disclosure Vulnerability
WordPress PageflipBook Plugin 'pageflipbook_language' Parameter Local File Include Vulnerability
WordPress Artiss Code Embed Plugin Cross Site Scripting Vulnerability
WebsiteBaker 'lang' Cross Site Scripting Vulnerability
WeBid 'adsearch.php' HTML Injection Vulnerability
VLC Media Player 'OGG' File Remote Heap-Based Buffer Overflow Vulnerability
VAMCart CMS 0.9 Multiple HTML Injection Vulnerabilities
Umbraco CMS 'codeEditorSave.asmx' Arbitrary File Upload Vulnerability
Pidgin 'Libpurple' Cipher API Information Disclosure Vulnerability UPDATED
Oracle Sun Produts Suite 'sort(1)' Local Solaris Vulnerability
Oracle Sun Products Suite 'mailx(1)' Local Solaris Vulnerability
Oracle Sun Products Suite 'Integrated Lights Out Manager' Local SPARC T-Series Servers Vulnerability
Microsoft Office for Mac Improper Folder Permissions Local Privilege Escalation Vulnerability
Hitachi HiRDB Control Manager Agent Unspecified Remote Command Execution Vulnerability
Flogr 'tag' Parameter Multiple Cross Site Scripting Vulnerabilities
Drupal Colorbox Node Module Multiple Cross Site Scripting Vulnerabilities
Drupal Book Block Module Book Title HTML Injection Vulnerability
DotNetNuke Cross Site Scripting and Security Bypass Vulnerabilities
BookNux Multiple Cross Site Scripting and SQL Injection Vulnerabilities
WordPress LeagueManager Plugin Multiple Cross-Site Scripting Vulnerabilities
WordPress Generic Plugin Arbitrary File Upload Vulnerability
vBulletin vBExperience 'sort' Parameter Cross Site Scripting Vulnerability
TP Link Gateway Multiple HTML Injection Vulnerabilities
Telnet FTP Server 'PASV' Command Remote Memory Corruption Vulnerability
Oracle Transportation Management Local Security Vulnerability
Oracle MySQL Server 'Server Optimizer' Remote Security Vulnerability
Oracle MySQL Server 'MySQL Server Optimizer' Remote Security Vulnerability
Oracle MySQL Server 'GIS Extension' Remote Security Vulnerability
Oracle Database Server Remote Network Layer Vulnerability
Multiple Cisco Products Remote Code Execution Vulnerability
Invision Power Board 'search.php' Cross Site Scripting Vulnerability
Drupal Security Questions Module Security Bypass Vulnerability
Chyrp SQL Injection and Arbitrary File Upload Vulnerabilities
Apache HTTP Server Denial Of Service Vulnerability UPDATED
PHPList 'footer' Parameter Cross Site Scripting Vulnerability
ZipItFast PRO '.zip' File Heap Buffer Overflow Vulnerability
web@all 'name' Parameter Cross Site Scripting Vulnerability
WebsitePanel 'ReturnUrl' Parameter URI Redirection Vulnerability
Check Point Abra Security Bypass and Information Disclosure Vulnerabilities
Drupal Listhandler Module Access Security Bypass Vulnerability
Drupal Restrict Node Page View Module Security Bypass Vulnerability
Drupal Search Autocomplete Module Access Security Bypass Vulnerability
EMC Multiple Products Security Bypass Vulnerability
Nginx Naxsi Module 'nx_extract.py' Script Remote File Disclosure Vulnerability
Oracle MySQL User Login Security Bypass Vulnerability UPDATED
RSA Access Manager Server Session Replay Security Bypass Vulnerability
Cisco ASA 5500 Series SIP Traffic Denial of Service Vulnerability
July
2012
Dnsmasq Remote Denial of Service Vulnerability
Drupal Drag & Drop Gallery Module Arbitrary PHP Code Execution Vulnerability
FileZilla Server CPU Exhaustion Denial Of Service Vulnerability
Hitachi JP1 Multiple Products Unspecified Privilege Escalation Vulnerability
IBM Web Application Firewall Security Bypass Vulnerability
If-CMS 'newlang' Parameter Local File Include Vulnerability
Joomla! 'com_team' Component SQL Injection Vulnerability
Linux Kernel 'flock()' Syscall Local Denial of Service Vulnerability
Linux Kernel UDF Filesystem Local Buffer Overflow Vulnerability
Microsoft IIS Multiple FTP Command Request Denial of Service Vulnerability
Movable Type Unspecified Local File Disclosure Vulnerability
Nagios XI Unspecified Command Injection Vulnerability
pam_ssh Incorrect 'SetGID()' Local Privilege Escalation Vulnerability
php MBB Cross Site Scripting and SQL Injection Vulnerabilities
PHPList 'id' Parameter Cross-Site Scripting Vulnerability
phpMyBackupPro 'lang' Parameter Local File Include Vulnerability
plow '.plowrc' File Buffer Overflow Vulnerability
Poison Ivy 'C&C' Server Buffer Overflow Vulnerability
Polycom SoundPoint IP 'reg_1.html' Information Disclosure Vulnerability
Quest Foglight Multiple Security Bypass Vulnerabilities
SAP Netweaver Multiple Vulnerabilities
sflog! 'blog' Parameter Local File Include Vulnerability
Sitemagic CMS 'SMTpl' Parameter Directory Traversal Vulnerability
Solar FTP Server Denial of Service Vulnerability
SPIP 'connect' Parameter PHP Code Injection Vulnerability
VTE Remote Escape Sequences Denial of Service Vulnerability
WebCAT 'cms_view.php' Multiple SQL Injection Vulnerabilities
Winamp 5.61 Multiple Remote Vulnerabilities
WordPress Email Newsletter Unspecified Security Vulnerability
WordPress WP Symposium Plugin 'symposium_ajax_functions.php' S
WordPress WPtouch Plugin 'wptouch_redirect' Parameter URI Redirection Vulnerability
xAurora 'RSRC32.DLL' DLL Loading Arbitrary Code Execution Vulnerability
XnView '.jp2' Remote Denial of Service Vulnerability
Zoom Player '.avi' File Divide-By-Zero Denial of Service Vulnerability
Cisco TelePresence Immersive Endpoint Devices Remote Command Injection Vulnerability
python 'distutils' Component '~/.pypirc' File Local Race Condition Vulnerability UPDATED
PHP Calendar Extension 'SdnToJulian()' Remote Integer Overflow Vulnerability UPDATED
Novell ZENworks Configuration Management AdminStudio Remote Code Execution Vulnerabilities UPDATED
Mozilla Firefox SeaMonkey and Thunderbird Multiple Memory Corruption Vulnerabilities UPDATED
HP Device Access Manager for HP ProtectTools Heap Memory Corruption Vulnerability UPDATED
Google Chrome prior to 7.0.517.44 Multiple Security Vulnerabilities UPDATED
Google Chrome prior to 7.0.517.41 Multiple Security Vulnerabilities UPDATED
Apache Wicket Cross Site Scripting Vulnerability
PHP 'php_register_variable_ex()' Function Arbitrary Code Execution Vulnerability UPDATED
PHP 'exif_process_IFD_TAG()' Remote Integer Overflow Vulnerability UPDATED
PHP Directory Traversal Vulnerability UPDATED
Linux kernel fcaps Local Security Bypass Vulnerability UPDATED
PHP 'magic_quotes_gpc' Directive Security Bypass Weakness UPDATED
keepalived Insecure PID Files Insecure File Permissions Vulnerability UPDATED
Expat XML Parsing Multiple Remote Denial of Service Vulnerability UPDATED
Cisco IOS SSH2 Sessions Remote Denial of Service Vulnerability
PostgreSQL 'RESET ALL' Unauthorized Access Vulnerability UPDATED
PHP Remote Denial Of Service Vulnerability UPDATED
Opera Web Browser Information Disclosure Vulnerability UPDATED
Linux Kernel Reliable Datagram Sockets (RDS) Local Denial of Service Vulnerability UPDATED
IBM LTPA STS Module Threads Security Vulnerability
PHP Versions Prior to 5.3.7 Multiple Security Vulnerabilities UPDATED
OpenSSL DTLS Remote Denial of Service Vulnerability UPDATED
WordPress UnGallery 'zip' Parameter Local File Disclosure Vulnerability
WordPress SEO Ultimate Plugin 'wp-admin/post.php' Cross Site Scripting Vulnerability
Mono 'EnableViewStateMac' Cross-Site Scripting Weakness UPDATED
Mozilla Firefox/Thunderbird/SeaMonkey CSP's Inline-Script Blocking Feature Security Bypass WeaknessUPDATED
Linux Kernel 'sock_alloc_send_pskb()' Function Heap Buffer Overflow Vulnerability UPDATED
OpenJPEG Gray16 TIFF Image File Memory Corruption Vulnerability UPDATED
LibTIFF 'tiff2pdf' Utility Remote Integer Overflow Vulnerability UPDATED
Oracle Database Server Remote Core Network Layer RDBMS Vulnerability
Oracle Database Server ' Oracle NET ' Remote Network Layer Vulnerability
Oracle Database Server 'Oracle NET' Protocol Remote Network Layer Vulnerability
Oracle Clinical Remote Data Capture Option Remote Security Vulnerability
Oracle AutoVue Remote Oracle Security Vulnerabilityy
Oracle AutoVue 'File' protocol Remote Security Vulnerability
Oracle AutoVue '-' sub component Remote Oracle Security Vulnerability
Niagara Framework Directory Traversal Vulnerability
Moodle Multiple Security Vulnerabilities
MGB Multiple Cross Site Scripting and SQL Injection Vulnerabilities
Linux Kernel IPv6 'nf_ct_frag6_reasm()' Remote Denial of Service Vulnerability
Linux Kernel IPv6 Fragment Identification Remote Denial of Service Vulnerability
libytnef TNEF File Buffer Overflow Vulnerability
Kool Media Converter '.ogg' File Buffer Overflow Vulnerability
Joomla! OS Property Component Arbitrary File Upload Vulnerability
Cisco Linksys PlayerPT ActiveX Control 'SetSource()' Buffer Overflow Vulnerability
Joomla! KSAdvertiser Component Arbitrary File Upload Vulnerability
Johnson Controls Multiple Products Remote Command Execution Vulnerability
IBM Lotus Protector for Mail Security Multiple Security Vulnerabilities
HP StorageWorks File Migration Agent 'RsaCIFS.dll' Stack-Based Buffer Overflow Vulnerability
eXtplorer 'lang' Parameter Cross Site Scripting Vulnerability
Event Calender PHP Multiple Input Validation Vulnerabilities
EmbryoCore CMS 'loadcss.php' Multiple Directory Traversal Vulnerabilities
Elite Bulletin Board Multiple SQL Injection Vulnerabilities
EGallery 'egallery/uploadify.php' Arbitrary File Upload Vulnerability
Drupal Campaign Monitor Module HTML Injection Vulnerability
Blackboard Mobile Learn HTML Injection Vulnerability
Barracuda SSL VPN Unspecified Cross Site Scripting Vulnerability
Apple Safari 'libxml' Remote Code Execution Vulnerability
ALLMediaServer Stack-Based Buffer Overflow Vulnerability
TCP/IP Protocol Stack Multiple Remote Denial Of Service Vulnerabilities UPDATED
Reserve Logic Booking CMS Multiple Input Validation Vulnerabilities
PHP Web Form Hash Collision Denial Of Service Vulnerability UPDATED
perl-DBD-Pg Module Multiple Format String Vulnerabilities UPDATED
Oracle Java SE and Java for Business Remote Java Runtime Environment Vulnerability SAAJ subcomponent UPDATED
Oracle Java SE and Java for Business Remote CORBA Vulnerability UPDATED
OpenSSL Encoded ASN.1 Data Integer Truncation Memory Corruption Vulnerability UPDATED
Netsweeper Cross Site Scripting and Cross Site Request Forgery Vulnerabilities
mod_auth_openid Local Information Disclosure Vulnerability UPDATED
LibTIFF 't2p_read_tiff_init()' Function Heap-based Buffer Overflow Vulnerability
libpng 'png_set_text_2()' Function Memory Corruption Vulnerability UPDATED
libgdata SSL Certificate Validation Security Bypass Vulnerability UPDATED
libcrypt 'crypt()' Password Encryption Weakness UPDATED
ISC BIND Security Bypass Vulnerability UPDATED
ISC BIND 9 DNS Resource Records Handling Remote Denial of Service Vulnerability UPDATED
Google Chrome Prior to 18.0.1025.168 Multiple Security Vulnerabilities UPDATED
gdk-pixbuf 'gdk_pixbuf__gif_image_load()' Remote Denial of Service Vulnerability UPDATED
CLScript CClassified Software Multiple SQL Injection and HTML Injection Vulnerabilities
WordPress Resume Submissions & Job Postings Unrestricted File Upload Vulnerability
WordPress Leaflet Maps Marker Plugin Multiple Unspecified Input Validation Vulnerabilities
Symantec Endpoint Protection Manager Remote Denial of Service Vulnerability UPDATED
Oracle Java SE and Java for Business Remote Java 2D Vulnerability 'Multiple' protocol. UPDATED
Oracle Java SE and Java for Business JPEGImageWriter.writeImage Vulnerability UPDATED
Multiple Mini-stream Software Products '.m3u' File Remote Stack Buffer Overflow Vulnerability UPDATED
Mono 'HttpForbiddenHandler.cs' Cross-Site Scripting Vulnerability
libpng 'png_inflate()' Function Heap Based Buffer Overflow Vulnerability UPDATED
Google Chrome Prior to 19 Multiple Security Vulnerabilities UPDATED
Google Chrome Prior to 18.0.1025.142 Multiple Security Vulnerabilities UPDATED
Oracle Mojarra EL Expression Evaluation Security Bypass Vulnerability UPDATED
OpenLDAP LDAP Search Request Remote Denial of Service Vulnerability UPDATED
Novell ZENworks Configuration Management Multiple Security Vulnerabilities UPDATED
Mozilla Firefox/SeaMonkey/Thunderbird NSS Parsing Multiple Denial of Service Vulnerabilities UPDATED
Google Chrome Prior to 17.0.963.83 Multiple Security Vulnerabilitiesty UPDATED
Google Chrome Prior to 17.0.963.65 Multiple Security Vulnerabilities UPDATED
Google Chrome Prior to 17.0.963.46 Multiple Security Vulnerabilities UPDATED
Google Chrome Prior to 16.0.912.77 Multiple Security Vulnerabilities UPDATED
Intel CPU Hardware Local Privilege Escalation Vulnerability UPDATED
IBM WebSphere Portal Dojo Module Directory Traversal Vulnerability
HP Operations Agent Multiple Unspecified Remote Code Execution Vulnerabilities
HP AssetManager Multiple HTML Injection Vulnerabilities
Cisco TelePresence Recording Server Web Interface Remote Command Injection Vulnerability
Cisco TelePresence Immersive Endpoint Devices System-Level Remote Command Injection Vulnerability
Cisco Multiple Products CVE-2012-3073 Denial of Service Vulnerability
OpenSSL Encoded ASN.1 Data Incomplete Fix Memory Corruption Vulnerability
Debian 'extplorer' Package Insecure File Permissions Vulnerability
WordPress Knews Multilingual Newsletters Plugin Cross Site Scripting Vulnerability
Todd Miller Sudo Host_List Local Privilege Escalation Vulnerability UPDATED
Samba Remote Security Bypass Vulnerability UPDATED
PostgreSQL 'SECURITY DEFINER' and 'SET' Attributes Remote Denial of Service Vulnerability UPDATED
Pidgin OSCAR Protocol UTF-8 Message Denial of Service Vulnerability UPDATED
Oracle Java SE Rhino Script Engine Remote Code Execution Vulnerability UPDATED
Oracle Java SE Remote Java Runtime Environment Sub-Component Vulnerability UPDATED
Oracle Java SE and Java for Business Multiple Remote Java Runtime Environment Vulnerability UPDATED
MIT Kerberos 5 'check_1_6_dummy()' Function NULL Pointer Dereference Denial Of Service Vulnerability UPDATED
Linux Kernel NFS Client 'decode_getacl()' Incomplete Fix Remote Denial of Service Vulnerability UPDATED
Kent Web YY-BOARD Unspecified Cross Site Scripting Vulnerability
Kajona 'getAllPassedParams()' Function Multiple Cross-Site Scripting Vulnerabilities
CUPS 'lppasswd' Tool Localized Message String Security Weakness UPDATED
WordPress church_admin Plugin 'id' parameter Cross-Site Scripting Vulnerability
WordPress WP Socializer Plugin 'val' Parameter Cross Site Scripting Vulnerability
Pidgin 'msn_oim_report_to_user()' Denial of Service Vulnerability UPDATED
Python PyCrypto Key Generation Weakness UPDATED
Oracle Java SE 'Swing' Remote Java Runtime Environment Vulnerability UPDATED
WordPress SocialFit Plugin 'msg' Parameter Cross Site Scripting Vulnerability
WordPress Front-end Editor Plugin 'upload.php' Arbitrary File Upload Vulnerability
Xen 64-bit PV Guests Local Denial of Service Vulnerability UPDATED
Oracle Java SE Remote 'RMI' Java Runtime Environment Vulnerability UPDATED
OpenLDAP Weak Cipher Encryption Security Weakness UPDATED
Oracle Java SE and Java for Business Remote Security Vulnerability UPDATED
Oracle Java SE and Java for Business Remote Java Runtime Environment Vulnerability UPDATED
Linux Kernel 'mmap()' Failure Local Denial of Service Vulnerability UPDATED
CUPS 'gif_read_lzw()' GIF File Heap Buffer Overflow Vulnerability UPDATED
CUPS 'cupsDoAuthentication()' Infinite Loop Denial of Service Vulnerability
arpwatch Security Bypass Vulnerability UPDATED
WordPress Count Per Day Plugin Multiple Cross Site Scripting Vulnerabilities
WordPress Contus Vblog Plugin 'save.php' Arbitrary File Upload Vulnerability
Pidgin MSN Denial of Service Vulnerability UPDATED
OpenStack Compute (Nova) CVE-2012-3371 Denial Of Service Vulnerability
MoodThingy Mood Rating Widget 'admin-ajax.php' Multiple SQL Injection Vulnerabilities
GuestBook Script PHP Multiple SQL Injection and Cross Site Scripting Vulnerabilities
Apache HTTP Server 'mod_proxy' Reverse Proxy Information Disclosure Vulnerability UPDATED
Yome Collection for Android Information Disclosure Vulnerability
WP Symposium Multiple SQL Injection Vulnerabilities
WordPress The Guardian News Feed Plugin Cross Site Request Forgery Vulnerability
WebPagetest Multiple Input Validation Vulnerabilities
Ubercart SecureTrading Payment Method Drupal Module Security Bypass Vulnerability
SMC Networks SMC8024L2 Switch Web Interface Authentication Bypass
JBoss 'mod_cluster' CVE-2012-1154 Security Bypass Vulnerability
Elfet ElfChat 'signup.php' Cross Site Scripting Vulnerability
Synel SY-780/A Denial of Service Vulnerability
Webify Link Directory 'id' Parameter SQL Injection Vulnerability
sflog! 'index.php' Arbitrary File Upload Vulnerability
Basilic 'diff.php' Remote Command Execution Vulnerability UPDATED
ZipItFree '.zip' File Buffer Overflow Vulnerability
Vivotek Network Cameras Information Disclosure Vulnerability
Shopware SQL Injection Vulnerability
Rama Zeiten CMS 'download.php' Remote File Disclosure Vulnerability
PBBoard 'answer' Field HTML Injection Vulnerability
Oracle MySQL Server 'MySQL' Remote Security Vulnerability
Oracle MySQL Server Is Prone To Remote Security Vulnerability
MetaSploit Framework 'pcap_log' Plugin Local Privilege Escalation Vulnerability
HP StorageWorks File Migration Agent 'RsaFTP.dll' Remote Code Execution Vulnerability
easyCMSlite Database Information Disclosure Vulnerability
Dr. Web Anti-Virus for Android Information Disclosure Vulnerability
DomsHttpd Remote Denial of Service Vulnerability
ClipBucket 'view_item.php' SQL Injection Vulnerability
CakePHP XML External Entity Injection Vulnerability
AVA VoIP Multiple Security Vulnerabilities
Arora Browser Remote Denial of Service Vulnerability
Oracle Transportation Management Remote Security Vulnerability
Oracle Sun Products Suit Remote Oracle iPlanet Web Server Vulnerability
Oracle PeopleSoft Enterprise PeopleTools 'MCF' Remote Security Vulnerability
Oracle E-Business Suite 'Password Management' Remote Security Vulnerability
Oracle Transportation Management '-' Remote Security Vulnerability
Oracle Sun Products Suite 'Solaris Management Console' Remote Solaris Vulnerability
Oracle Sun Products Suite 'Kernel/NFS' Local Solaris Vulnerability
Oracle Sun Products Suit 'Web Server' Remote Solaris Vulnerabilityy
Oracle Siebel CRM 'UI Framework' Remote Security Vulnerability
Oracle E-Business SuiteRemote Security 'Document Repository' Vulnerability
Oracle E-Business Suite 'HTTP' Remote Security Vulnerability
Adobe Shockwave Player Multiple Remote Vulnerabilities
X.Org X Server Record Module and SECURITY Extension Multiple Heap Memory Corruption Vulnerabilities
WordPress GD Star Rating Plugin 'votes' Parameter SQL Injection Vulnerability
WebSVN 'path' Parameter Remote Command Injection Vulnerability
Squiz Matrix 'colour_picker.php' Cross Site Scripting Vulnerability
RXS-3211 IP Camera Password Information Disclosure Vulnerability
PopScript 'index.php' Multiple Input Validation Vulnerabilities
PikaCMS Multiple Local File Disclosure Vulnerabilities
Winlog Pro Malformed Packet Stack Buffer Overflow Vulnerability
Multiple Cybozu Products Multiple Cross Site Scripting Vulnerabilities
Cybozu Garoon Unspecified Cross Site Scripting Vulnerability
Cachelogic Expired Domains Script Cross Site Scripting and SQL Injection Vulnerabilities
Simple Machines Forum Multiple Security Vulnerabilities
Avactis Shopping Cart Security Bypass and HTML Injection Vulnerabilities
OpenLDAP X.509 Certificate NULL Character Certificate Validation Security Bypass Vulnerability
Linux Kernel 'set_ftrace_filter' File Local Denial Of Service Vulnerability
Linux Kernel 'drivers/net/niu.c' Local Denial of Service Vulnerability
Apple Mac OS X Embedded Font (CVE-2011-0198) Heap Buffer Overflow Vulnerability
Apple Mac OS X Certificate Trust Policy EV Certificate Security Bypass Vulnerability
Fetchmail STARTTLS Remote Denial of Service Vulnerability
Apple Mac OS X 'servermgrd' XML-RPC Request Information Disclosure Vulnerability
Apple Mac OS X AppleID Local Information Disclosure Vulnerability
Rampart 'util/rampart_timestamp_token.c' Remote Security Bypass Vulnerability
Ubisoft CoGSManager ActiveX Control 'Initialize()' Method Stack Buffer Overflow Vulnerability
WordPress Beer Recipes Plugin HTML Injection Vulnerability
DATAC RealWin SCADA Server Multiple Remote Buffer Overflow Vulnerabilities
Apple Mac OS X AirPort Denial of Service Vulnerability
Sybase Advantage Server 'ADS' Process Off By One Buffer Overflow Vulnerability
klibc DHCP Options Processing Remote Shell Command Execution Vulnerability
JomSocial Event Module HTML Injection Vulnerability
FanUpdate 'pageTitle' Parameter Cross Site Scripting Vulnerability
Drupal Juitter Module HTML Injection Vulnerability
Drupal Download Count Module HTML Injection Vulnerability
BrewBlogger Multiple Input Validation Vulnerabilities
ActivDesk Multiple Cross Site Scripting and SQL Injection Vulnerabilities
SmallFTPD Multiple Connection Requests Remote Denial Of Service Vulnerability
Crawlability vBSEO 'vbseo.php' Local File Include Vulnerability
Easewe FTP OCX ActiveX Control 'EaseWeFtp.ocx' Multiple Insecure Method Vulnerabilities
FreeAmp '.pls' File Buffer Overflow Vulnerability
idevSpot iSupport 'x_category' Parameter SQL Injection Vulnerability
Joomla! 'com_morfeoshow' Component 'idm' Parameter SQL Injection Vulnerability
LEADTOOLS Imaging LEADSmtp ActiveX Control 'SaveMessage()' Insecure Method Vulnerability
ManageEngine ServiceDesk Plus 'FILENAME' Parameter Directory Traversal Vulnerability
Multiple WordPress Plugins Compromised Source Packages Backdoor Vulnerability
MySQLDriverCS SQL Injection Vulnerability
Nodesforum '_nodesforum_node' Parameter SQL Injection Vulnerability
Novell File Reporter 'NFRAgent.exe' Security Bypass Vulnerability
Eshop Manager Multiple SQL Injection Vulnerabilities
H3C ER5100 Authentication Bypass Vulnerability
AeroMail Cross Site Request Forgery, HTML Injection and Cross Site Scripting Vulnerabilities
Oracle Java Ephemeral Ports SE Remote Java Runtime Environment Vulnerability UPDATED
iSCSI Enterprise Target Multiple Implementations iSNS Message Stack Buffer Overflow Vulnerability
Oracle Java SE and Sound Subcomponent Java for Business Remote Java Runtime Environment Vulnerability UPDATED
Oracle Java 'RMI' SE Remote Java Runtime Environment Vulnerability UPDATED
Open Journal Systems Multiple HTML Injection Vulnerabilities
Oracle Java SE 'Deserialization' Remote Java Runtime Environment Vulnerability UPDATED
Oracle Java SE and XML Digital Signature Java for Business CVE-2010-4472 Remote Java Runtime Environment Vulnerability UPDATED
Oracle Java SE and Java for Business Remote Integer Overflow Vulnerability UPDATED
Oracle Java SE and Java for Business ICC Profile Multiple Remote Code Execution Vulnerabilities UPDATED
Oracle Java SE and ' HotSpot subcomponent ' Java for Business Remote Java Runtime Environment Vulnerability UPDATED
Oracle Java Floating-Point Value Denial of Service Vulnerability UPDATED
OpenOffice Prior to 3.4 Multiple Memory Corruption Vulnerabilities UPDATED
JustSystems Ichitaro Memory Management Program Remote Heap Buffer Overflow Vulnerability
Microsoft Excel Heap Memory Corruption Remote Code Execution Vulnerability
IBM WebSphere Application Server JAX-RPC WS-Security/JAX-WS Runtime Security Bypass Vulnerability
IBM WebSphere Application Server Administration Console Cross Site Request Forgery Vulnerability
IBM Rational ClearQuest 'cqole.dll' ActiveX Control Heap Buffer Overflow Vulnerability UPDATED
Google SketchUp '.SKP' File Invalid Edge Geometry Remote Code Execution Vulnerability
Cisco RVS4000/WRVS4400N Web Management Interface Remote Command Injection Vulnerability
Apple QuickTime Prior To 7.7.2 QTMovie Objects Stack Overflow Vulnerability UPDATED
Adobe Shockwave Player 'IML32.dll' Remote Memory Corruption Vulnerability
Adobe Shockwave Player 'IML32.dll' Multiple Memory Corruption Vulnerabilities
Adobe Shockwave Player Adequate Boundary Multiple Remote Vulnerabilities
Oracle Java SE and Protocols Java for Business Remote Java Runtime Environment Vulnerability UPDATED
Oracle Java SE and Multiple Protocols Java for Business Remote Java Runtime Environment Vulnerability UPDATED
Novell Groupwise WebAccess 'User.interface' Parameter Directory Traversal Vulnerability
myBloggie HTML-injection and SQL Injection Vulnerabilities
FKDE kdelibs IP Address SSL Certificate Security Bypass Vulnerability
Cisco RVS4000/WRVS4400N Web Management Interface Information Disclosure Vulnerability
Oracle Java SE '2D' Remote Java Runtime Environment Vulnerability UPDATED
Red Hat Satellite Server 'spacewalk-java' Cross Site Request Forgery Vulnerability
Trend Micro Control Manager 'ApHost' Parameter Cross Site Scripting Vulnerability
Ruby on Rails Message Digest Verification Security Weakness
Oracle Java SE and Java for Business Remote Information Disclosure Vulnerability UPDATED
Oracle Java SE Remote Java Runtime Environment Vulnerability UPDATED
Oracle Java SE and Java for Business Prone Remote Java Runtime Environment Vulnerability UPDATED
Microsoft Windows MHTML Mime-Formatted Request Information Disclosure Vulnerability
Microsoft Internet Explorer MIME Sniffing Information Disclosure Vulnerability
Foxit Reader Freetype Engine Remote Integer Overflow Vulnerabiliy
Cisco RVS4000 and WRVS4400N Web Management Private/Public Key's Information Disclosure Vulnerability
Adobe Shockwave Player Multiple Memory Corruption Vulnerabilities
Sitemagic CMS 'SMExt' Parameter Cross Site Scripting Vulnerability
RESTEasy XML Entity References Information Disclosure Vulnerability UPDATED
Microsoft Windows 'win32k.sys' OpenType Font Parsing Remote Code Execution Vulnerability
Linux Kernel 'Clone()' Function 'CLONE_IO' Flag Multiple Denial Of Service Vulnerabilities UPDATED
Linux Kernel CIFS DNS Lookup Cache Poisoning Vulnerability
IBM Lotus Domino Server 'diiop' Multiple Remote Code Execution Vulnerabilities
GIMP PCX Image Parsing Heap Buffer Overflow Vulnerability
Adobe Shockwave Player Multiple Remote Memory Corruption Vulnerabilities
Xen 'syscall/sysenter' Instruction Local Denial of Service Vulnerability UPDATED
WordPress custom tables Plugin 'key' Parameter Cross Site Scripting Vulnerability
WellinTech KingHistorian Memory Corruption Vulnerability
WANGKONGBAO CNS '/src/acloglogin.php' Directory Traversal Vulnerabilities
Taha Portal 'sitemap.php' Cross Site Scripting Vulnerability
Python Hash Collision Denial Of Service Vulnerability UPDATED
NNT Change Tracker and Remote Angel Insecure File Permissions Vulnerability
Multiple IP Cameras 'productmaker' Account Unauthorized Access Vulnerability
Immophp Cross Site Scripting and SQL Injection Vulnerabilities
IBM Rational Team Concert Multiple Unspecified Cross Site Scripting Vulnerabilities
HP Network Node Manager i Unspecified Cross Site Scripting vulnerability
GetSimple CMS Items Manager Plugin 'php.php' Arbitrary File Upload Vulnerability
CIDWeb Multiple Cross Site Scripting Vulnerabilities
Apple Mac OS X MobileMe Email Aliases Information Disclosure Vulnerabilityy
Apple Mac OS X FTP Server (CVE-2011-0203) Directory Traversal Vulnerability
Apache HttpComponents 'HttpClient' Information Disclosure Vulnerability
WordPress Quotes Collection Plugin Cross Site Request Forgery Vulnerability
Sight2k iGiveTest 'userids' Parameter SQL Injection Vulnerability
Wing FTP Server 'ssh public key' Authentication Security Bypass VulnerabilityAiCart Cross Site Scripting and SQL Injection Vulnerabilities
BSD Kernel 'IEEE80211_IOC_CHANINFO' IOCTL Local Information Disclosure Vulnerability
CLScript Classifieds Script 'catId' Parameter SQL Injection Vulnerability
Cyberoam DPI Security Bypass Vulnerability
EQDKP Plus 'HTML' Tag HTML Injection Vulnerability
Freeside Multiple Input Validation Vulnerabilities
gp Easy CMS Minishop Plugin HTML Injection Vulnerability
Group-Office Multiple Unspecified SQL Injection Vulnerabilities
Helium Music Manager DLL Loading Arbitrary Code Execution Vulnerability
Joomla! Language Switcher ModuleMultiple Cross Site Scripting Vulnerabilities
Joomla Minitek FAQ Book 'id' Parameter SQL Injection Vulnerability
Microsoft Windows SMB Server Remote Denial of Service Vulnerability
Nagios XI Unspecified Cross Site Scripting and HTML Injection Vulnerabilities
Nibbleblog Multiple SQL Injection Vulnerabilities
Oracle MySQL Server Multiple Unspecified Security Vulnerabilities UPDATED
phpMyVisites 'phpMyVisites.php' Script Multiple SQL Injection Vulnerabilities
Piwik Unspecified PHP Code Execution Vulnerability
Red Hat Sos Information Disclosure Vulnerability UPDATED
Blue Coat ProxySG core Files Local Information Disclosure Vulnerability
Catalog Builder 'cat_id' Parameter SQL Injection Vulnerability
Classified Ads Script PHP 'admin.php' Multiple SQL Injection Vulnerabilities
Event Script PHP 'eventscript.php' Multiple SQL Injection Vulnerabilities
Forum Oxalis 'id' Parameter SQL Injection Vulnerability
Hitachi Web Server Unspecified Remote Denial of Service Vulnerability
AlgoPars Software Co 'id' Parameter SQL Injection Vulnerability
Donar Player '.wma' Remote Denial of Service Vulnerability
Apple Mac OS X JPEG-encoded TIFF Images Integer Overflow Vulnerability
WordPress Mac Photo Gallery Plugin 'albid' Parameter Remote File Disclosure Vulnerability
Oracle Java SE Remote 'Security ' Java Runtime Environment Vulnerability
Oracle Java SE Remote 'Java-Runtime-Environment' Vulnerability
Oracle Java SE Remote 'Hotspot 'Java Runtime Environment Vulnerability
Linux Kernel 'sock_alloc_send_pskb()' Function Heap Buffer Overflow Vulnerability
Mozilla Firefox, SeaMonkey, and Thunderbird Use After Free Vulnerability
Moonlight Prior to 2.4.1/3.99.3 Multiple Security Vulnerabilities
Mono 'loader.c' Library Loading Local Privilege Escalation Vulnerability
MediaWiki 'profileinfo.php' Cross Site Scripting Vulnerability
Linux Kernel Reliable Datagram Sockets (RDS) CVE-2012-2372 Local Denial of Service Vulnerability
Pidgin XMPP Protocol File Transfer Request Handling Denial of Service Vulnerability
OpenSSL Encoded ASN.1 Data Integer Truncation Memory Corruption Vulnerability
WordPress WP Marketplace Plugin 'uploadify.php' Arbitrary File Upload Vulnerability
Vanilla Forums kPoll Plugin 'index.php' HTML Injection Vulnerability
Adobe Acrobat and Reader Remote Memory Corruption Vulnerability
Adobe Acrobat and Reader Memory-Corruption Vulnerability
Apple Mac OS X Image RAW Multiple Buffer Overflow Vulnerabilities
June
2012
Oracle JavaFX Remote Code Execution Vulnerability
libpng 'pngerror.c' Off-By-One Error Denial Of Service Vulnerability
Asterisk Shell Command Execution Security Bypass Vulnerability
Agora-Project Multiple Cross Site Scripting and SQL Injection Vulnerabilities
Adobe Acrobat and Reader Integer Overflow Vulnerability
OpenSSL Encoded ASN.1 Data Incomplete Fix Memory Corruption Vulnerability
Linux Kernel 'mmap()' Failure Local Denial of Service Vulnerability
TinyCMS Local File Include and Arbitrary File Upload Vulnerabilities
Joomla! A Cool Debate 'controller' Parameter Local File Include Vulnerability
Wyse ThinOS Network Packet Denial of Service Vulnerability
Tele Data's Contact Management Server Directory Traversal Vulnerability
TEDE Simplificado Multiple SQL Injection Vulnerabilities
Simple web-server Directory Traversal Vulnerability
Post Revolution Multiple HTML Injection and Denial of Service Vulnerabilities
HP OpenView Performance Manager Remote Code Execution Vulnerability
taglib Buffer Overflow and Divide-By-Zero Denial of Service Vulnerabilities
Pidgin MSN Denial of Service Vulnerability
Drupal Token Authentication Module Access Bypass Vulnerability
IBM Lotus Expeditor 'Eclipse Help' Component Directory Traversal Vulnerability
Pidgin 'silc_private_message()' Denial of Service Vulnerability
MediaWiki Multiple Local File Include Vulnerabilities
libpng 'png_set_text_2()' Function Memory Corruption Vulnerability
Asterisk SIP Channel Driver Denial Of Service Vulnerability
XnView Multiple Image Decompression Memory Corruption Vulnerabilities
OpenSSL S/MIME Header Processing Null Pointer Dereference Denial Of Service Vulnerability
OpenSSL DTLS Remote Denial of Service Vulnerability
Linux Kernel Race Condition Local Denial of Service Vulnerability
Apache HTTP Server 'LD_LIBRARY_PATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
Apache Axis2 '/axis2/axis2-admin' Session Fixation Vulnerability
SN News 'visualiza.php' SQL Injection Vulnerability
FeedDemon 'Feed Preview' Arbitrary Script Injection Vulnerability
Winamp AVI / IT File Multiple Memory Corruption Vulnerabilities
LiveStreet Multiple Cross Site Scripting And Path Disclosure Vulnerabilities
Linux Kernel '__split_huge_page()' Race Condition Local Denial of Service Vulnerability
IBM Lotus Expeditor Request Header Spoofing Security Bypass Vulnerability
IBM DB2 Multiple Security Vulnerabilities
Cisco AnyConnect Secure Mobility Client VPN Downloader Arbitrary Code Execution Vulnerabilities
Bitweaver Multiple HTML Injection Vulnerabilities
AOL Deskbar Uninitialized Pointer Remote Code Execution Vulnerability
Adiscan LogAnalyzer Cross Site Scripting Vulnerability
Mozilla Firefox/SeaMonkey/Thunderbird NSS Parsing Multiple Denial of Service Vulnerabilities
Mono ASP.NET 'mod_mono' Source Code Information Disclosure Vulnerability
MediaWiki Multiple Remote Vulnerabilities
ejabberd XML Parsing Denial of Service Vulnerability
libpng 'png_inflate()' Function Heap Based Buffer Overflow Vulnerability
Adobe Acrobat and Reader Memory Corruption Vulnerability
OpenStack Compute (Nova) Security Bypass Vulnerability
Nmedia Users File Uploader Plugin Arbitrary File Upload Vulnerability
IrfanView Formats PlugIn TTF File Buffer Overflow Vulnerability
WordPress VideoWhisper Video Presentation Plugin 'vw_upload.php' Arbitrary File Upload Vulnerability
ScrumWorks Pro Remote Privilege Escalation Vulnerability
Drupal Organic Groups Module Cross Site Scripting and Security Bypass Vulnerabilities
MyBB 'announcements.php' SQL Injection Vulnerability
Linux kernel fcaps Local Security Bypass Vulnerability
Lattice Diamond Programmer Buffer Overflow Vulnerability
Interspire Shopping Cart Multiple HTML Injection Vulnerabilities
Huawei HG866 'password.html' Security Bypass Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey '.lnk' Files Information Disclosure Vulnerability
Microsoft .NET Framework ASP.NET Padding Oracle Information Disclosure Vulnerability
MediaWiki 'api.php' Information Disclosure Vulnerability
Asterisk Skinny Channel Driver Heap-Based Buffer Overflow Vulnerability
WordPress MM Forms Community Plugin 'doajaxfileupload.php' Arbitrary File Upload Vulnerability
Drupal Maestro Module Cross Site Request Forgery and Cross Site Scripting Vulnerabilities
MediaWiki Versions Prior to 1.16.3 Multiple Remote Vulnerabilities
Simple Web Content Management System Multiple SQL Injection Vulnerabilities
WordPress WP Mass Mail Plugin Open Email Relay Vulnerability
Quagga bgpd 'bgp_capability_orf()' BGP OPEN Message Remote Denial Of Service Vulnerability
MyBB 'member.php' SQL Injection Vulnerability
SyndeoCMS 'newsletter_email' Parameter SQL Injection Vulnerability
WordPress WP-Property Plugin 'uploadify.php' Arbitrary File Upload Vulnerability
WordPress Foxypress Plugin 'uploadify.php' Arbitrary File Upload Vulnerability
GIMP Buffer Overflow Vulnerability
MyBB 'customfield' Parameter SQL Injection Vulnerability
ISC BIND Security Bypass Vulnerability
PHP Volunteer Management Multiple SQL Injection Vulnerabilities
Apache Tomcat Hash Collision Denial Of Service Vulnerability
Asterisk SCCP Skinny Channel Driver Denial Of Service Vulnerability
WordPress HTML5 AV Manager Plugin 'custom.php' Arbitrary File Upload Vulnerability
WHMCompleteSolution Unspecified SQL Injection Vulnerability
strongSwan GMP Plugin Authentication Bypass Vulnerability
OpenLDAP Weak Cipher Encryption Security Weakness
Collabtive 'manageuser.php' Arbitrary File Upload Vulnerability
Siemens WinCC Multiple Security Vulnerabilities
Xinetd Security Bypass Vulnerability
WHMCS Cross Site Scripting and Multiple HTTP Parameter Pollution Vulnerabilities
SEIL Multiple Products Security Bypass Vulnerability
PyroCMS HTTP Response Splitting and HTML Injection Vulnerabilities
Nmedia WordPress Member Conversation Plugin 'doupload.php' Arbitrary File Upload Vulnerability
Moodle Information Disclosure and Security Bypass Vulnerabilities
dotCMS Arbitrary Code Execution Vulnerability
Asterisk IAX2 Channel Driver Denial Of Service Vulnerability
Piwik Multiple Security Vulnerabilities
WHMCS 'boleto_bb.php' SQL Injection Vulnerability
Tftpd32 DNS Server Denial Of Service Vulnerability
Sectool DBus File Local Privilege Escalation Vulnerability
Restlet Framework XML External Entity Information Disclosure Vulnerability
RabidHamster R4 File Disclosure and Multiple Buffer Overflow Vulnerabilities
ikiwiki Multiple Cross Site Scripting Vulnerabilities
DynPage 'ckfinder' Multiple Arbitrary File Upload Vulnerabilities
DornCMS 'add_page.php' Remote Arbitrary File Upload Vulnerability
PHPList 'Sajax.php' PHP Code Injection Vulnerability
Bloxx Web Filter Multiple Remote Security Vulnerabilities
Bind DynDB LDAP 'bind-dyndb-ldap' Package Remote Denial of Service Vulnerability
AzDGDatingMedium Multiple Remote Vulnerabilities
RSSOwl RSS Feeds Multiple HTML Injection Vulnerabilities
Moodle Multiple Access Permissions Security Bypass Vulnerabilities
LibreOffice '.rtf' File Denial of Service Vulnerability
WinRadius Password Option Size Validation Buffer Overflow Vulnerability
SCLIntra Enterprise Multiple SQL Injection and Authentication Bypass Vulnerabilities
Santilga CMS SQL Injection Vulnerability
Rugged Operating System Backdoor Unauthorized Access Vulnerability
unixODBC 'SQLDriverConnect()' 'FILEDSN' and 'DRIVER' Options Buffer Overflow Vulnerabilities
RPM Multiple Denial of Service Vulnerabilities
Yamamah Photo Gallery Database Information Disclosure Vulnerability
Nilehoster Topics Viewer Multiple SQL Injection and Local File Include Vulnerabilities
b2ePMS Multiple SQL Injection Vulnerabilities
OpenStack Dashboard Horizon Session Fixation Vulnerability
AutoFORM PDM Archive Multiple Security Vulnerabilities
VoipNow Professional 'nsextt' Parameter Cross Site Scripting Vulnerability
Ruby on Rails Active Record SQL Injection Vulnerability
cPanel Multiple Unspecified Vulnerabilities
Sielco Sistemi Winlog Lite Buffer Overflow Vulnerability
MIT Kerberos 5 'check_1_6_dummy()' Function NULL Pointer Dereference Denial Of Service Vulnerability
Globus Toolkit GridFTP 'getpwnam_r()' Security Bypass Vulnerability
WordPress Email Newsletter Plugin 'option' Parameter Information Disclosure Vulnerability
ISC BIND 9 DNS Resource Records Handling Remote Denial of Service Vulnerability
Network Instruments Observer Multiple Security Vulnerabilities
Drupal Fill PDF Module Security Bypass and Arbitrary Code Execution Vulnerabilities
bionic Buffer Overflow Vulnerability
724CMS SQL Injection Vulnerability
WordPress Top Quark Architecture Plugin 'script.php' Arbitrary File Upload Vulnerability
Wordpress SFBrowser Plugin 'sfbrowser.php' Arbitrary File Upload Vulnerability
WordPress Mac Photo Gallery Plugin 'upload-file.php' Arbitrary File Upload Vulnerability
WordPress Drag & Drop File Uploader Plugin 'dnd-upload.php' Arbitrary File Upload Vulnerability
WordPress Custom Content Type Manager Plugin 'upload_form.php' Arbitrary File Upload Vulnerability
WordPress Contus Video Gallery Plugin 'upload1.php' Arbitrary File Upload Vulnerability
TheBlog Multiple SQL Injection and HTML Injection Vulnerabilities
ModSecurity Quote Parsing Security Bypass Vulnerability
Joomla! Simple SWFUpload Component 'uploadhandler.php' Arbitrary File Upload Vulnerability
Joomla! Joomsport Component SQL Injection and Arbitrary File Upload Vulnerabilities
Joomla! DentroVideo Component 'upload.php' Arbitrary File Upload Vulnerability
Joomla! Art Uploader Component 'upload.php' Arbitrary File Upload Vulnerability
NetEase WeiboHD for Android Unspecified Security Vulnerability
Mozilla Firefox Drag and Drop Same Origin Policy Security Bypass Vulnerability
ClipBucket Multiple SQL Injection and Cross Site Scripting Vulnerabilities
XOOPS Cube PROJECT FileManager 'xupload.php' Arbitrary File Upload Vulnerability
WordPress WP GPX Maps Plugin Arbitrary File Upload Vulnerability
WordPress User Meta Plugin 'uploader.php' Arbitrary File Upload Vulnerability
webSPELL Dailyinput Movie-Addon 'portal' Parameter SQL Injection Vulnerability
Joomla! Alphacontent Component 'limitstart' Parameter SQL Injection Vulnerability
Freepost 'edit.php' SQL Injection and HTML Injection Vulnerabilities
ET - Chat Multiple Arbitrary File Upload Vulnerabilities
Clansuite 'uploadify.php' Arbitrary File Upload Vulnerability
M-Player '.mp3' File Denial Of Service Vulnerability
MangosWeb Enhanced 'Login' field SQL Injection Vulnerability
JW Player HTML Injection And Content Spoofing Vulnerability
IpTools Tiny TCP/IP servers Directory Traversal Vulnerability
ImpressPages CMS 'actions.php' Remote Code Execution Vulnerability
HServer Directory Traversal Vulnerability
GPSMapEdit LST File Buffer Overflow Vulnerability
eFront 'download' Parameter Directory Traversal Vulnerability
DIGIT CMS Cross Site Scripting and SQL Injection Vulnerabilities
Atar2b CMS 'id' parameter Multiple SQL Injection Vulnerabilities
Apache CXF Elements Validation Security Bypass Vulnerability
Apache CXF Child Policies Security Bypass Vulnerability
AirTies Air 4450 'cgi-bin/loader' Denial of Service Vulnerability
Python 'virtualenvwrapper' Package Unspecified Security Vulnerability
PHPAccounts SQL Injection and Arbitrary File Upload Vulnerabilities
Agora-Project 'dossierup' Parameter Remote Arbitrary File Upload Vulnerability
Adobe Flash Player Remote Memory Corruption And Denial Of Service Vulnerability
WordPress Timthumb Plugin 'timthumb' Cache Directory Arbitrary File Upload Vulnerability
WordPress Pretty Link Lite Plugin 'slug' Parameter Cross Site Scripting Vulnerability
WordPress PICA Photo Gallery 'imgname' Parameter Remote File Disclosure Vulnerability
WordPress PDW File Browser Plugin 'upload.php' Arbitrary File Upload Vulnerability
WordPress Pay With Tweet Plugin SQL Injection and Cross Site Scripting Vulnerabilities
WordPress Omni Secure Files Plugin 'Upload.php' Arbitrary File Upload Vulnerability
WordPress Newsletter 'preview.php' Remote File Disclosure Vulnerability
WordPress Hungred Post Thumbnail Plugin 'hpt_file_upload.php' Arbitrary File Upload Vulnerability
WordPress Front File Manager Plugin 'Upload.php' Arbitrary File Upload Vulnerability
WordPress FCChat Widget Plugin 'Upload.php' Arbitrary File Upload Vulnerability
WordPress Easy Contact Forms Export 'file' Parameter Remote File Disclosure Vulnerability
webSPELL FIRSTBORN Movie-Addon 'id' Parameter SQL Injection Vulnerability
VertrigoServ 'extensions.php' Script Cross Site Scripting Vulnerability
VBDrupal 'vaispy.php' Cross Site Scripting Vulnerability
TYPO3 Powermail Extension HTML Injection Vulnerability
TinyWebGallery Multiple Remote Command Execution Vulnerabilities
Super Remote Buffer Overflow Vulnerability
Squid Proxy Caching Server CNAME Denial of Service Vulnerability
SQLiteManager Multiple Cross Site Scripting Vulnerabilities
SN News 'loger.php' Multiple SQL Injection Vulnerabilities
SAPID CMS Multiple Remote File Include Vulnerabilities
Redmine Multiple Vulnerabilities
PHPNet SQL Injection and HTML Injection Vulnerabilities
phpMyDirectory 'page.php' SQL Injection Vulnerability
phpMyAdmin Setup Interface Cross Site Scripting Vulnerability
phpMyAdmin Prior to 3.4.8 Multiple Cross Site Scripting Vulnerabilities
phpMyAdmin Prior to 3.3.10.3 and 3.4.3.2 Multiple Remote Vulnerabilities
phpMyAdmin Prior to 3.3.10.2 and 3.4.3.1 Multiple Remote Vulnerabilities
phpMyAdmin Multiple Cross Site Scripting Vulnerabilities
phpMyAdmin Debug Backtrace Cross Site Scripting Vulnerability
phpMyAdmin Configuration File PHP Code Injection Vulnerability
phpMyAdmin Bookmark Security Bypass Vulnerability
phpMyAdmin '$host' Variable HTML Injection Vulnerability
Oracle MySQL Prior to 5.1.49 'DDL' Statements Denial Of Service Vulnerability
Oracle Mojarra 'FacesContext' Information Disclosure Vulnerability
WordPress ALO EasyMail Newsletter Plugin Unspecified Cross Site Scripting Vulnerabilities
Sony VAIO Wireless Manager ActiveX Control 'WifiMan.dll' Multiple Buffer Overflow Vulnerabilities
MPlayer SAMI Subtitle File Buffer Overflow Vulnerability
NewsAdd Multiple SQL Injection Vulnerabilities
ispVM System '.xcf' File Multiple Buffer Overflow Vulnerabilities
Cobbler Remote Command Injection Vulnerability
VAMCart 'tinybrowser.php' Remote Arbitrary File Upload Vulnerability
Mapserver for Windows Local File Include Vulnerability
GDL Multiple Cross Site Scripting and SQL Injection Vulnerabilities
Symfony 'regenerate()' Method Session Fixation Vulnerability
Zoph Multiple Remote Security Vulnerabilities
WordPress Comment Extra Fields Plugin 'cef-upload.php' Arbitrary File Upload Vulnerability
SuperNews 'noticias.php' SQL Injection Vulnerability
Ruby on Rails SQL Injection Vulnerability
pidgin-otr 'log_message_cb()' Function Format String Vulnerability
Mnews 'view.php' SQL Injection Vulnerability
IBM WebSphere Application Snoop Servlets Information Disclosure Vulnerability
Hexamail Server Mail Body HTML Injection Vulnerability
Drupal Simplenews Module Information Disclosure Vulnerability
AdaptCMS Mulitiple SQL Injection Vulnerabilities
XAMPP for Windows Multiple Cross Site Scripting and SQL Injection Vulnerabilities
WordPress kk Star Ratings Plugin 'root' Parameter Remote File Include Vulnerability
Swoopo Gold Multiple Security Vulnerabilities
qdPM Arbitrary File Upload Vulnerability
PEamp '.mp3' File Memory Corruption Vulnerability
PacketFence 'Web Admin Guest Management' Interface Unspecified Cross Site Scripting Vulnerability
Joomla! IDoEditor Component 'image.php' Arbitrary File Upload Vulnerability
Joomla! Easy Flash Uploader Component 'helper.php' Arbitrary File Upload Vulnerability
Bradford Network Sentry Authentication Bypass Vulnerability
QEMU KVM CVE-2012-0029 Local Privilege Escalation Vulnerability
OpenConnect CVE-2012-3291 Heap Based Buffer Overflow Vulnerability
Multiple Vendor SSL/TLS Renegotiation Denial Of Service Vulnerability
Joomla! Maian Media Component 'uploadhandler.php' Arbitrary File Upload Vulnerability
Drupal Privatemsg Module Cross Site Scripting Vulnerability
Commentics 'index.php' Cross Site Scripting Vulnerability
Apple iTunes '.m3u' Playlist File Heap Based Buffer Overflow Vulnerability
Ubuntu Linux APT Security-Bypass Vulnerability
Opera Web Browser Remote Code Execution And Other Vulnerabilities
VMware Hosted Products Memory Corruption and Denial Of Service Vulnerability
phpLinks 'PID' Parameter SQL Injection Vulnerability
Nuked-Klan 'eid' Parameter SQL Injection Vulnerability
Nagios XI Multiple Cross-Site Scripting Vulnerabilities
Drupal SimpleMeta Module Cross Site Request Forgery Vulnerability
Drupal Protected Node Module Access Bypass Vulnerability
Drupal Node Hierarchy Module Cross Site Request Forgery Vulnerability
Contao 'field' Parameter SQL Injection Vulnerability
ADICO 'index.php' Script SQL Injection Vulnerability
WAGO Multiple Remote Vulnerabilities
Simple Document Management System Multiple SQL Injection Vulnerabilities
QEMU '-runas' Argument Local Security Bypass Vulnerability
OpenSSH 'ssh_gssapi_parse_ename()' Function Denial Of Service Vulnerability
Joomla JCal Pro Calendar Component SQL Injection Vulnerability
IBM Rational Directory Server URI Redirection and Cross Site Scripting Vulnerabilities
Cisco Application Control Engine Administrator IP Address Overlap Security Bypass Vulnerability
annexwareTexolution Microworkers Clone Script Multiple SQL Injection Vulnerabilities
Oracle Java SE Remote 'Swing' Java Runtime Environment Vulnerability
Oracle Java SE Remote 'Libraries' Java Runtime Environment Vulnerability
Oracle Java SE Remote 'Deployment' Java Runtime Environment Vulnerability
WordPress NS Utilities Plugin Unspecified Security Vulnerability
Simple Forum PHP Multiple SQL Injection Vulnerabilities
Rocket U2 UniData Remote Command Execution Vulnerability
Quest Webthority Cross Site Request Forgery Vulnerability
o0mBBS 'Forum' Parameter SQL Injection Vulnerability
Microsoft Windows OpenType 'atmfd.dll' Denial of Service Vulnerability
IObit Protected Folder Local Authentication Bypass Vulnerability
Drupal Ubercart AJAX Cart Module Information Disclosure Vulnerability
AdSpy Pro 'settings.php' Security Bypass Vulnerability
PHP Jobsite Multiple Cross Site Scripting Vulnerabilities
NOCC Email Body HTML Injection Vulnerability
Karafun Player '.m3u' File Denial of Service Vulnerability
FireDesign fireshop 'news.php' Script SQL Injection Vulnerability
Edimax IC-3030iWn UDP Packet Password Information Disclosure Vulnerability
Commentics 'index.php' Arbitrary File Deletion Vulnerability
Oracle Java SE Remote '2D' Java Runtime Environment Vulnerability
Vanilla Forums and Vanilla Forum Tagging Plug-In HTML Injection Vulnerability
Audio Editor Master '.cda' File Processing Remote Buffer Overflow Vulnerability
Sorensoft Power Media '.asz' File Buffer Overflow Vulnerability
Membris Multiple Input Validation Vulnerabilities
Python PyCrypto Key Generation Weakness
Moodle Personal communication access issue Vulnerabilities
Horde IMP Webmail Client Multiple Cross Site Scripting Vulnerabilities
WordPress Asset Manager Plugin 'upload.php' Arbitrary File Upload Vulnerability
IrfanView Formats PlugIn 'NCSEcw.dll' Heap Based Buffer Overflow Vulnerability
Citrix Provisioning Services Remote Code Execution Vulnerability
PHP 5.3.10 Multiple Denial of Service Vulnerabilities
Ignite Solutions CMS 'car-details.php' SQL Injection Vulnerability
Puella Magi Madoka Magica iP for Android Information Disclosure Vulnerability
PHP Volunteer Management Arbitrary File Upload and HTML Injection Vulnerabilities
Multiple DeltaV Products Multiple Remote Vulnerabilities
activeCollab Planning Module Cross-Site Scripting and XQuery Injection Vulnerabilities
WordPress Theme My Login Plugin Cross Site Scripting Vulnerability
WEB ShoppingCart Unspecified Cross Site Scripting Vulnerability
Store Locator Plus WordPress Plugin Multiple Input Validation Vulnerabilities
f2blog 'uploadimg.php' Remote File Upload Vulnerability
IBM WebSphere Sensor Events Multiple Input Validation Vulnerabilities
DJabberd XML Parsing Denial of Service Vulnerability
WordPress Gallery Plugin Arbitrary File Upload Vulnerability
Pligg CMS 'status' Parameter SQL Injection Vulnerability
Bigware Shop 'main_bigware_54.php' SQL Injection Vulnerability
Drupal Node Embed Module Access Security Bypass Vulnerability
HP Database Archiving Software Remote Arbitrary Code Execution Vulnerability
Real Networks RealPlayer Remote Code Execution Vulnerability
OpenOffice Multiple Memory Corruption Vulnerabilities
Serendipity 'functions_trackbacks.inc.php' SQL Injection Vulnerability
IBM AIX 'socketpair()' Local Denial of Service Vulnerability
WordPress Font Uploader Plugin 'font-upload.php' Arbitrary File Upload Vulnerability
socat 'xioscan_readline()' Heap Based Buffer Overflow Vulnerability
Samsung NET-i ware Multiple Remote Vulnerabilities
Real Networks RealPlayer 'rvrender' RMFF Flags Remote Code Execution Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey HTTP Header Security Bypass Vulnerability
Oracle PeopleSoft Enterprise SCM 'Billing' Remote Vulnerability
vBulletin 'subject' Parameter Cross Site Scripting Vulnerability
Microsoft Windows SSL/TLS Protocol Initialization Vector Implementation Information Disclosure Vulnerability
Microsoft Windows Firewall 'tcpip.sys' Security Bypass Vulnerability
Microsoft Excel Memory Corruption Remote Code Execution Vulnerability
Microsoft .NET Framework Input Serialization Remote Code Execution Vulnerability
HP Diagnostics Server 'magentservice.exe' Remote Stack Buffer Overflow Vulnerability
May
2012
Skype Technologies Skype for Mac Unspecified Remote Code Execution Vulnerability
OpenSSL Invalid TLS/DTLS Record Attack Vulnerability
Joomla! JCE Component 'index.php' Cross Site Scripting Vulnerability
SSL/TLS Protocol Initialization Vector Implementation Information Disclosure Vulnerability
Oracle PeopleSoft Enterprise HRMS Remote Vulnerability
D-Link DCS-5605 PTZ ActiveX Control 'SelectDirectory()' Method Buffer Overflow Vulnerability
Joomla! 'ja_purity' Template Cross Site Scripting Vulnerability
Joomla! JCE Component 'file.php' Arbitrary File Upload Vulnerability
Linux Kernel 'xfs_readlink()' Local Privilege Escalation Vulnerability
Joomla JCE Component Security Bypass and Cross-Site Scripting Vulnerabilities
Wireshark Multiple Dissector Denial of Service Vulnerabilities
Wireshark Buffer Overflow and Denial of Service Vulnerabilities
Wireshark OpenSafety Dissector Denial of Service Vulnerability
Skype Technologies Skype Client for Windows File Transfer Remote Buffer Overflow Vulnerability
Skype Multiple Fields Multiple HTML Injection Vulnerabilities
Skype Chat Logs Local Information Disclosure Vulnerability
OpenSSL ASN1 BIO Vulnerability
Samba NDR PULL DFS EnumArray1 Heap Overflow Remote Code Execution Vulnerability
Oracle Industry Applications 'Web UI' Remote Siebel Clinical Vulnerability
Apple Quicktime "sean atoms" Arbitrary Code Execution Vulnerability
Social Engine Multiple XSS and CSRF Vulnerabilities
Multiple vBulletin Products Unspecified Security Vulnerability
Apple Quicktime "handling of Sorenson" Arbitrary Code Execution Vulnerability
Apple OS X Lion V10.7.4 "libarchive" Arbitrary Code Execution Vulnerability
Oracle Database Server Remote Enterprise Manager Base Platform Vulnerability
Apple Safari 5.1.7 Arbitrary Code Execution Vulnerability
Apple Quicktime Arbitrary Code Execution Vulnerability
Apple OS X Lion Bluetooth Arbitrary Code Execution Vulnerability
Scalable Vector Graphics (SVG) Arbitrary Code Execution Vulnerability
Drupal Access Bypass Vulnerability
VMware vCenter Chargeback Manager Information Disclosure and Denial of Service Vulnerabilities
Apple OS X Lion V10.7.4 "ImageIO" Arbitrary Code Execution Vulnerability
Apple OS X Lion V10.7.4 "ImageIO" Application Termination Vulnerability
Apple OS X Lion V10.7.4 "HFS" Arbitrary Code Execution Vulnerability
Apple OS X Lion V10.7.4 "Directory Service" Information Disclosure Vulnerability
Apple OS X Lion V10.7.4 "curl" Protocol-Specific Data Injection Vulnerability
Apple OS X Lion V10.7.4 "curl" Arbitrary Code Execution Vulnerability
Small-Cms 'hostname' Parameter Remote PHP Code Injection Vulnerability
RubyGems mail Directory Traversal and Command Injection Vulnerabilities
Xen PyGrub Kernel Decompression Local Denial Of Service Vulnerability
WordPress Multiple Remote Vulnerabilities
Apple Webkit Cross Site Scripting (XSS) Vulnerability
Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities
Apache HTTP Server Denial_Of_Service Vulnerability
Drupal Access bypass in File module Vulnerability
VMware View Manager Portal Cross-site Scripting Vulnerability
Php-Decoda Video Tags Cross-Site Scripting Vulnerability
April
2012
Multiple AntiVirus Products CHM File Scan Evasion Vulnerability
Pidgin Possible MSN Remote Crash Vulnerability
Pidgin MSN Emoticon Denial Of Service Vulnerability
Pidgin AIM And ICQ Remote Crash Vulnerability
Oracle Outside In Technology 8.3.7 'Outside In Image Export SDK' Remote Vulnerability
Oracle BI Publisher Remote Vulnerability
Oracle PeopleSoft Enterprise FCSM 'Receivables' Remote Vulnerability
Oracle Financial Services 'Core' Remote Oracle FLEXCUBE Universal Banking Vulnerability
Oracle PeopleSoft Enterprise HRMS 'eCompensation' Remote Vulnerability
Oracle GlassFish Server Multiple Cross Site Scripting and HTML Injection Vulnerabilities
Oracle E-Business Suite 'Runtime Catalog' Remote Oracle iStore Vulnerability
Oracle Supply Chain Products Suite Remote Oracle AutoVue Office Vulnerability
Oracle Database Server OCIPasswordChange API Security Bypass Vulnerability
Oracle PeopleSoft Enterprise PeopleTools 'Search' Remote Vulnerability
Oracle FLEXCUBE Universal Bank 'Core' Remote Vulnerability
Mozilla Firefox/Thunderbird/Seamonkey Cross-Site-Scripting Vulnerability
Mozilla Firefox Multiple Remote Memory Corruption Vulnerabilities
Oracle PeopleSoft Enterprise SCM 'eProcurement' Remote Vulnerability
Oracle FLEXCUBE Universal Banking 'Core' Remote Vulnerability
vBulletin Multiple HTML Injection Vulnerabilities
Oracle Sun Products Suite 'Administration Console' Remote Oracle iPlanet Web Server Vulnerability
Oracle Primavera P6 Enterprise Project Portfolio Management 'Web application' Remote Vulnerability
Oracle WebCenter Forms Recognition Remote Vulnerability
Adobe Acrobat and Reader 'msiexec.exe' Search Path Remote Arbitrary Code Execution Vulnerability
Drupal Session Fixation Vulnerability
Oracle Database Server Remote XML Developer Kit Vulnerability
Symantec pcAnywhere Session Closure Access Violation Vulnerability
RealPlayer Realvideo Renderer Memory Corruption Vulnerability
Joomla! nBill Component Cross Site Scripting Vulnerability
Drupal Cross Site Request Forgeries Vulnerability
Drupal core - Cross Site Scripting (UTF8) Vulnerability
Drupal Password leak Vulnerability in URL
Microsoft Print Feature Remote Code Execution Vulnerability
arpwatch Security Bypass Vulnerability
Apache HTTP Server 'httpOnly' Cookie Information Disclosure Vulnerability
Drupal XSS Vulnerabilities
Drupal 5 and 6 Cross site scripting Vulnerability
WordPress MU 'wp-includes/wpmu-functions.php' Cross-Site Scripting Vulnerability
Webkit.org Webkit copyNonAttributeProperties Remote Code Execution Vulnerability
IBM SPSS ExportHTML.dll ActiveX Control Render Method Remote Code Execution Vulnerability
IBM Rational Rhapsody BBFlashBack.Recorder.1 InsertMarker Remote Code Execution Vulnerability
EMC Networker indexd.exe Opcode 0x01 Parsing Remote Code Execution
Samba ndr_pull_dfs_Info3 Heap Overflow Remote Code Execution Vulnerability
Samba NDR PULL LSA TrustDomainInfoControllers Heap Overflow Remote Code Execution Vulnerability
Samba GetAliasMembership SidArray Remote Code Execution Vulnerability
Samba lsa_LookupNames Heap Overflow Remote Code Execution Vulnerability
Samba ReportEventW Heap Overflow Remote Code Execution Vulnerability
Samba ndr_ValidatePassword heap overflow Remote Code Execution Vulnerability
Samba NDR PULL LSA TrustDomainInfoControllers Memory Corruption Vulnerability
Adobe BlazeDS XML and XML External Entity Injection Vulnerabilities
VideoLAN VLC MMS Support Stack Overflow Vulnerability
VideoLAN MP4 Demultiplexer Heap Corruption Vulnerability
Adobe Shockwave Player 'DIRapi.dll' Director File Parsing Multiple Memory Corruption Vulnerabilities
Adobe Flash Player APSB12-07 Multiple Memory Corruption Vulnerabilities
Drupal Various Upload Module Vulnerabilities
Drupal Cross Site Request Forgery Vulnerability
Drupal Core Cross Site Request Forgery Vulnerability
Drupal Access Rules Bypass Vulnerability
Adobe Shockwave Player CSWV Chunk Memory Corruption Remote Code Execution Vulnerability
VMware vCenter Server Unspecified Directory Traversal Vulnerability
VMware Hosted Products UDF File Systems Buffer Overflow Vulnerability
BlackBerry Desktop Manager Remote Code Execution Vulnerability
BlackBerry Enterprise Server MDS Connection Service Cross Site Scripting(XSS) Vulnerability
VideoLAN Stack Overflow In MPA, AVI And ASF Demuxer
VideoLAN Integer overflow in XSPF playlist parser
VideoLAN Heap overflows in VLC Real RTSP support
VideoLAN Buffer overflow in VLC TiVo demuxer
VideoLAN Arbitrary File Overwrite And Other Abuses Through M3U Parser
VideoLAN Arbitrary Code Execution Through Rogue VLC Plugins In The Current Directory
Drupal OpenID not verifying signed attributes in SREG and AX
Drupal OpenID Impersonation Vulnerability
Drupal Open Redirection Vulnerability
Drupal OpenID Association Cross Site Request Forgeries Vulnerability
Drupal File Upload Vulnerability
Drupal Cross Site Request Forgery Vulnerability In Aggregator Module
Drupal Core Cross Site Request Forgeries Vulnerability
Drupal core - SQL Injection Vulnerability
Drupal core - Form action attribute injection Vulnerability
Drupal core - Cross site scripting (XSS) Vulnerability (UTF8) Vulnerability
Drupal core - Arbitrary code execution Vulnerability
Drupal Core - API handling of unpublished comment Vulnerability
Drupal Contact Category Name Cross-Site Scripting Vulnerability
Drupal BlogAPI access bypass Vulnerability
Drupal Blocked user session regeneration Vulnerability
Drupal Access bypass in node listings Vulnerability
Drupal 6 Cross site scripting Vulnerability
Drupal 4.6 and 4.7 core - Cross site scripting Vulnerability
Drupal core - Access bypass Vulnerability
Drupal 6 Local File Inclusion On Windows Vulnerability
Drupal Cross-Site Scripting Vulnerability
Drupal Core - HTTP response splitting Vulnerability
Drupal Menu Description Cross-Site Scripting Vulnerability
Drupal core - Cross site request forgeries Vulnerability
Drupal Arbitrary File Uploads via BlogAPI Vulnerability
Drupal Comment Unpublishing Bypass Vulnerability
VMware vSphere Client Installer Package Digital Signature Security Weakness
VMware vFabric tc Server JMX Authentication Security Bypass Vulnerability
VMware Hosted Products VMware Tools Library Reference Remote Code Execution Vulnerability
VMware ESXi and ESX Local Privilege Escalation Vulnerability
Multiple VMware products 'vmware-mount' Local Privilege Escalation Vulnerability
Multiple VMware Products Multiple Input Validation Vulnerabilities
Multiple VMware products 'Mount.vmhgfs' Mutiple Security Vulnerabilities
Nokia Affix BTFTP Client Filename Remote Buffer Overflow Vulnerability
GraceNote CDDBControl ActiveX Control Remote Buffer Overflow Vulnerability
BlackBerry Browser Address Parsing Denial Of Service Vulnerability
TeamOn Import Object ActiveX control vulnerability
Oracle Fusion Middleware Remote Oracle Containers for J2EE Vulnerability
Oracle Database Server Remote Instance Management Vulnerability
Oracle Database Server Core RDBMS 'Create session' privilege Remote Vulnerability
Symantec IM Manager SQL Injection Vulnerability 2011
Multiple AntiVirus Products ELF File Scan Evasion Vulnerability
WordPress Comment Author URL Cross-Site Scripting Vulnerability
Insecure Library Loading In The BlackBerry Desktop Software
Cross-site scripting (XSS) vulnerability in the BlackBerry Web Desktop Manager component of the BlackBerry Enterprise Server
Drupal core - Multiple Cross Site Scripting Vulnerabilities
Oracle Database and Enterprise Manager Grid Control Multiple SQL Injection Vulnerabilities
Samba SetInfoPolicy AuditEventsInfo Remote Code Execution Vulnerability
IBM Tivoli Provisioning Manager Express Multiple Remote Code Execution Vulnerabilities
Adobe Flash Player and AIR 'exception_count' Integer Overflow Vulnerability
VideoLAN VLC Media Player CDDA and VCDX Plugins URL Format String Injection Vulnerability
VideoLAN VLC RealText and CUE Demuxers Buffer Overflow Vulnerability
Adobe Flash Player Remote Command Execution Vulnerability
DRUPAL XSS Taxonomy Module Vulnerability
Drupal File Upload Access Bypass Vulnerability
Drupal core - Cross site scripting(XSS) Vulnerability
Drupal OpenID Cross Site Scripting Vulnerability
Adobe Shockwave Player 3D Assets Module Input Validation Remote Code Execution Vulnerability
Adobe Acrobat and Reader 'newfunction' Remote Code Execution Vulnerability
Adobe Shockwave Player 'DIRAPIX.dll' File Remote Memory Corruption Vulnerability
VMware Multiple Products Local Privilege Escalation Vulnerability
BlackBerry Enterprise Server Denial of Service Vulnerability
Oracle Database Target Type Menus Remote Security Vulnerability
Oracle Database Server Remote Enterprise Config Management Vulnerability
WordPress 2.8.2 Remote Code Execution Vulnerabilitiy
Nokia GGSN Kernel Panic Denial of Service Vulnerability
Oracle Database Network Foundation Remote Denial of Service Vulnerability
Multiple AntiVirus Products ZIP File Scan Evasion Vulnerability
Symantec libTIFF CCITT Group 4 Encoded TIFF Image Buffer Overflow Vulnerability
Multiple Symantec Altiris Products 'RunCmd()' ActiveX Control Buffer Overflow Vulnerability
Symantec Norton AntiSpam SymSpamHelper Class Buffer Overrun Vulnerability
Symantec Brightmail Multiple Remote Denial of Service Vulnerabilities
Entrust LibKMP ISAKMP Library Remote IPsec/ISAKMP Buffer Overflow Vulnerability
MIT Kerberos GSS-API Checksum NULL Pointer Dereference Denial Of Service Vulnerability
WordPress 2.7.1 Username Information Disclosure Vulnerability
Oracle Outside In 'JPEG 2000 Filter' Remote Heap Buffer Overflow Vulnerabilities
WordPress 'press-this.php' Cross Site Scripting Vulnerability
Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability
Oracle Supply Chain Remote Agile Core Technology Vulnerability
Oracle Oracle Enterprise Manager Grid Control Remote EMCTL Vulnerability
Oracle Enterprise Manger Grid Control SQL Performance Advisories/UIs Vulnerability
Microsoft .NET Framework Parameter Validation Vulnerability
Oracle Database Server Remote Security Management Vulnerability
Oracle Database Server 'HTTP' protocol Remote Instance Management Vulnerability
Oracle Database Server 'Create session and trigger as SYSDBA' Remote Core RDBMS Vulnerability
Oracle Database Server and Enterprise Manager Grid 'Authentication' Security Framework Vulnerability
Pidgin 'msn_oim_report_to_user()' Denial of Service Vulnerability
Multiple Vendor BIOS Keyboard Buffer Password Persistence Weakness
McAfee Web Gateway 'Host' HTTP Header Security Bypass Vulnerability
McAfee Unified Threat Management Firewall 'page' Parameter Cross Site Scripting Vulnerability
McAfee SmartFilter Multiple Information Disclosure Vulnerabilities
McAfee SaaS Endpoint Protection 'MyAsUtil5.2.0.603.dll' ActiveX Remote Code Execution Vulnerability
McAfee Products TAR and PDF Files Scan Evasion Vulnerabilities
McAfee Network Security Manager Multiple Cross Site Scripting Vulnerabilities
McAfee Network Security Manager Information Disclosure Vulnerability
McAfee ePolicy Orchestrator MSDE SA Account Information Disclosure Vulnerability
McAfee ePolicy Orchestrator HTTP GET Request Format String Vulnerability
McAfee ePolicy Orchestrator Agent HTTP POST Buffer Mismanagement Vulnerability
McAfee Antivirus Library LHA Archive Handler Stack Based Buffer Overflow Vulnerability
IrfanView Formats PlugIn DJVU Image Processing Heap Buffer Overflow Vulnerability
IBM InfoSphere Guardium Local Denial of Service Vulnerability
IBM AIX Temporary File Creation Vulnerability
Hitachi Command Suite Multiple Products Cross-Site Scripting and Denial of Service Vulnerabilities
Eaton Network Shutdown Module Arbitrary PHP Code Execution Vulnerability
Croogo CMS Multiple HTML Injection Vulnerabilities
Cotonti 'admin.php' SQL Injection Vulnerability
Linux Kernel DRM 'drivers/gpu/drm/crm_crtc.c' IOCTL Local Privilege Escalation Vulnerability
LimeSurvey Remote File Include and Directory Traversal Vulnerabilities
libpng 'png_formatted_warning()' Function Off-By-One Error Buffer Overflow Vulnerability
libpng Buffer Overflow and Denial of Service Vulnerabilities
HP Data Protector Express Multiple Remote Code Execution Vulnerabilities
Google Chrome Prior to 19 Multiple Security Vulnerabilities
ejabberd 'mod_pubsub' Module Denial of Service Vulnerability
Eclipse IDE Multiple Cross Site Scripting Vulnerabilities
Apache Wicket 'pageMapName' Parameter Cross Site Scripting Vulnerability
Apache Tomcat 'sendfile' Request Attributes Information Disclosure Vulnerability
Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability
Apache Tomcat Java AJP Connector Invalid Header Denial of Service Vulnerability
Apache Tomcat HTML Manager Interface HTML Injection Vulnerability
Apache Tomcat Authentication Header Realm Name Information Disclosure Vulnerability
Apache Tomcat AJP Protocol Security Bypass Vulnerability
Apache Struts Multiple HTML Injection Vulnerabilities
Apache Struts Conversion Error OGNL Expression Evaluation Vulnerability
Apache OFBiz Multiple Cross Site Scripting Vulnerabilities
Apache mod_proxy_ftp Module NULL Pointer Dereference Denial Of Service Vulnerability
Apache HTTP Server Solaris Event Port Pollset Support Remote Denial Of Service Vulnerability
Apache HTTP Server mod_log_config Denial Of Service Vulnerability
Apache HTTP Server Denial-Of-Service Vulnerability
Apache Commons Compress and Apache Ant Denial Of Service Vulnerability
Apache ap_escape_html Memory Allocation Denial Of Service Vulnerability
Apache ActiveMQ 'admin/queueBrowse' Cross Site Scripting Vulnerability
Oracle Java SE Remote 'Java Runtime Environment' Vulnerability
KVM Local Denial of Service Vulnerability
IBM Lotus Expeditor DLL Loading Arbitrary Code Execution Vulnerability
Etomite Multiple Fields Multiple HTML Injection Vulnerabilities
Eaton Network Shutdown Module Multiple Information Disclosure Vulnerabilities
Wicd 'wicd/configmanager.py' Local Information Disclosure Vulnerability
Mozilla Firefox, SeaMonkey, and Thunderbird Heap-Based Buffer Overflow Vulnerability
Mono 'LD_LIBRARY_PATH' Local Privilege Escalation Vulnerability
McAfee SaaS Endpoint Protection 'myCIOScn' ActiveX Remote Code Execution Vulnerability
McAfee Policy Manager 'naPolicyManager.dll' Arbitrary File Overwrite Vulnerability
McAfee Firewall Reporter 'GernalUtilities.pm' Authentication Bypass Vulnerability
Apache Wicket Hidden Files Information Disclosure Vulnerability
Apache Tomcat Form Authentication Existing/Non-Existing Username Enumeration Weakness
Apache Struts 'ParameterInterceptor' Class OGNL Security Bypass Vulnerability
Apache 'mod_fcgid' Module Denial Of Service Vulnerability
Apache HTTP Server 'mod_proxy' Reverse Proxy Information Disclosure Vulnerability
Apache APR 'apr_fnmatch.c' Denial of Service Vulnerability
WordPress Nmedia MailChimp Plugin 'abs_path' Parameter Remote File Include Vulnerability
Net-SNMP SNMP GET Request Denial of Service Vulnerability
Joomla! 'com_szallasok' Component 'id' Parameter SQL Injection Vulnerability
Wicd 'SetWirelessProperty()' Local Privilege Escalation Vulnerability
Mozilla Firefox, SeaMonkey, and Thunderbird Heap Buffer Overflow Vulnerability
libpng PNG File Denial Of Service Vulnerability
gdk-pixbuf 'gdk_pixbuf__gif_image_load()' Remote Denial of Service Vulnerability
Adobe Acrobat and Reader Heap Corruption Vulnerability
Linux Kernel NFS Client 'decode_getacl()' Incomplete Fix Remote Denial of Service Vulnerability
McAfee Web Gateway Web Access Cross Site Scripting Vulnerability
McAfee VirusScan 4.5 Unquoted ImagePath Vulnerability
McAfee Remote Desktop Denial of Service Vulnerability
McAfee LinuxShield 'nailsd' Daemon Remote Code Execution Vulnerability
McAfee Email and Web Security Appliance Unspecified Information Disclosure Vulnerability
Apache Tomcat Directory Host Appbase Authentication Bypass Vulnerability
Apache OFBiz Unspecified Remote Code Execution Vulnerability
Apache HTTP Server Scoreboard Local Security Bypass Vulnerability
Apache Hadoop Unspecified User Impersonation Vulnerability
Apache And Microsoft IIS Range Denial of Service Vulnerability
McAfee Security-as-a-Service ActiveX Control Remote Command Execution Vulnerability
McAfee Internet Security Suite Local Insecure Default Permissions Vulnerability
McAfee Email Gateway Prior To 6.7.2 Hotfix 2 Multiple Vulnerabilities
Apache Tomcat 'sort' and 'orderBy' Parameters Cross Site Scripting Vulnerabilities
Apache Struts Multiple Cross Site Scripting Vulnerabilities
Apache POI Denial Of Service Vulnerability
Apache mod_proxy_ftp Remote Command Injection Vulnerability
Apache HTTP Server 'ap_pregsub()' Function Local Privilege Escalation Vulnerability
Apple QuickTime Prior To 7.7.2 Multiple Stack Overflow Vulnerabilities
Eclipse IDE Help Component Multiple Cross Site Scripting Vulnerabilities
McAfee Virtual Technician ActiveX Control 'GetObject()' Insecure Method Vulnerability
McAfee Security ePolicy Orchestrator ComputerList Format String Vulnerability
McAfee ePolicy Orchestrator Server Remote Code Execution Vulnerability
McAfee ePolicy Orchestrator Agent File Disclosure Vulnerability
Linux Kernel KVM 'kvm_set_irq()' Function Local Buffer Overflow Vulnerability
CMS Lokomedia Multiple Cross Site Scripting and HTML Injection Vulnerabilities
AdNovum nevisProxy Cross Site Scripting Vulnerability
nginx 'ngx_http_mp4_module.c' Buffer Overflow Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey Use-After-Free Remote Code Execution Vulnerability
MediaWiki CSS Comments Cross Site Scripting Vulnerability
libpng 'png_decompress_chunk()' Remote Integer Overflow Vulnerability
ejabberd 'client2server' Message Remote Denial of Service Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey CSP's Inline-Script Blocking Feature Security Bypass Weakness
Adobe Acrobat and Reader Remote-MemoryCorruption Vulnerability
Virtualenv Insecure Temporary File Creation Vulnerability
taglib Memory Corruption and Infinite Loop Denial Of Service Vulnerabilities
McAfee Email and Web Security Appliance and Email Gateway Multiple Vulnerabilities
Apache Commons Daemon 'jsvc' Information Disclosure Vulnerability
Mono/Moonlight Generic Type Argument Local Privilege Escalation Vulnerability
McAfee VirusScan Command Line Updater Script Insecure Temporary File Creation Vulnerability
McAfee ePolicy Orchestrator Agent POST Request Heap Overflow Vulnerability
Apache Tomcat HTTP DIGEST Authentication Multiple Security Weaknesses
Apache Tomcat SSL Anonymous Cipher Configuration Information Disclosure Vulnerability
Apache Tomcat Host Working Directory WAR File Directory Traversal Vulnerability
Apache Struts2 'XSLTResult.java' Remote Arbitrary File Upload Vulnerability
Adobe Reader and Acrobat Forms Data Format Remote Security Bypass Vulnerability
Drupal XSS Bypass "view User Profiles" Permission
Drupal Mail Header Injection Vulnerability
Drupal core SQL injection vulnerability
Adobe Shockwave Player 'DEMX' Integer Overflow Vulnerability
Adobe Shockwave Player 'AudioMixer.x32' Module Remote Memory Corruption Vulnerability
Adobe Reader and Acrobat DLL Loading in 3D Remote Code Execution Vulnerability
Adobe Photoshop TIFF Handling Multiple Unspecified Security Vulnerabilities
Adobe LiveCycle Data Services and BlazeDS Remote Denial of Service Vulnerability
Adobe Flash Player and AIR JPEG File Parsing Heap Buffer Overflow Vulnerability
Apache Tomcat Request Object Security Bypass Vulnerability
Apache Tomcat 'MemoryUserDatabase' Information Disclosure Vulnerability
Adobe Flash Player 'BitmapData.scroll' Remote Integer Overflow Vulnerability
Adobe Flash Media Server NULL Pointer Dereference Remote Denial of Service Vulnerability
Adobe Acrobat and Reader JPEG Markers Use After Free Vulnerability
Adobe Acrobat and Reader Cross Site Scripting Vulnerability
Adobe Acrobat and Reader '3difr.x3d' Remote Buffer Overflow Vulnerability
Adobe Shockwave Player Unspecified Buffer Overflow Remote Code Execution Vulnerability
Adobe Shockwave Player 'TextXtra.x32' Module Heap Based Buffer Overflow Vulnerability
Adobe Shockwave Player rcsL Chunk EAX Register Memory Corruption Vulnerability
Adobe Shockwave Player Director File Memory Corruption Remote Code Execution Vulnerability
Adobe RoboHelp Server and RoboHelp Cross Site Scripting Vulnerability
Adobe Reader and Acrobat U3D Remote Code Execution Vulnerability
Adobe Flash Player and AIR URI Parsing Cross Domain Scripting Vulnerability
Adobe Flash Player and AIR Image Processing Use After Free Remote Code Execution Vulnerability
Adobe Acrobat and Reader Thumbnails Use-After-Free Remote Code Execution Vulnerability
Adobe Acrobat and Reader NULL Pointer Dereference Denial of Service Vulnerability
Adobe Acrobat and Reader GIF Data Remote Buffer Overflow Vulnerability
Adobe Acrobat and Reader BMP Data Remote Buffer Overflow Vulnerability
Adobe Shockwave Player rcsL Chunk Remote Memory Corruption Vulnerability
Adobe Shockwave Player Director mmap Trusted Chunk Size Remote Memory Corruption Vulnerability
Adobe Shockwave Player Director File FFFFFF88 Record Remote Memory Corruption Vulnerability
Adobe Shockwave Player 'DIRAPIX.dll' Remote Memory Corruption Vulnerability
Apache Tomcat Windows Installer Insecure Password Vulnerability
Apache Tomcat WAR File Directory Traversal Vulnerability
Apache Tomcat 'Transfer-Encoding' Information Disclosure and Denial Of Service Vulnerabilities
Adobe Shockwave Player 'DIRAPI.dll' Remote Code Execution Vulnerability
Symantec PCAnywhere Privilege Escalation Vulnerability
Symantec Norton AntiVirus MS-DOS Name Scan Evasion Vulnerability
Symantec LiveUpdate for Macintosh Local Privilege Escalation Vulnerability
Symantec LiveUpdate Client Local Information Disclosure Vulnerability
Symantec IM Manager 'eval()' Code Injection Vulnerability
Symantec IM Manager Console HTML Injection Vulnerability
Symantec Endpoint Protection Reporting Module 'fw_charts.php' Remote Code Execution Vulnerability
Symantec Client Firewall Products SYMNDIS.SYS Driver Remote Denial Of Service Vulnerability
Symantec Client Firewall DNS Response Buffer Overflow Vulnerability
Symantec AntiVirus Scan Engine For Red Hat Linux Insecure Temporary File Vulnerabilities
Symantec Altiris WISE Package Studio Multiple SQL Injection Vulnerabilities
Symantec Altiris eXpress NS SC Download ActiveX Control Arbitrary File Download Vulnerability
Multiple Symantec Products 'SYMLTCOM.dll' ActiveX Stack Buffer Overflow Vulnerability
Multiple AntiVirus Products 'TAR' File Scan Evasion Vulnerability
Multiple AntiVirus Products GZIP File Scan Evasion Vulnerability
Novell ZENworks Configuration Management 'DoFindReplace()' Method Buffer Overflow Vulnerability
Novell Messenger Server Memory Information Disclosure Vulnerability
Novell GroupWise 8 WebAccess 'Directory.Item' Parameters Cross-Site Scripting Vulnerabilities
Novell File Reporter Agent XML Tag Remote Code Execution Vulnerability
Linux Kernel Unauthorized Access Vulnerability
Linux Kernel 'taskstats' Access Restriction Local Security Bypass Vulnerability
Linux Kernel 'security_filter_rule_init()' Local Security Bypass Vulnerability
Linux Kernel SCTP Remote Denial of Service Vulnerability
Linux Kernel kexec-tools 'kdump/mkdumprd' Utility Information Disclosure Vulnerability
Linux Kernel EXT4 'ext4_fill_flex_info()' Local Denial of Service Vulnerability
Novell ZENWorks Asset Management 'rtrlet' Component Remote Code Execution Vulnerability
Novell GroupWise Messenger 'NM_A_PARM1' Tag Heap Memory Corruption Vulnerability
Novell Data Synchronizer Mobility Pack Multiple Remote Security Vulnerabilities
Novell ZENworks Handheld Management Multiple Remote Code Execution Vulnerabilities
Linux Kernel 'perf_count_sw_cpu_clock' Event Denial of Service Vulnerability
Linux Kernel Headroom Check 'udp6_ufo_fragment()' Remote Denial of Service Vulnerability
Linux Kernel EFI Partition Denial of Service Vulnerability
Multiple AntiVirus Products RAR File Scan Evasion Vulnerability
Microsoft Internet Explorer OnReadyStateChange Remote Code Execution Vulnerability
Drupal Core - Execution Of Arbitrary Files In Certain Apache Configurations
Drupal Installation Cross Site Scripting Vulnerability
Oracle PeopleSoft 'Personalization' Remote PeopleSoft Enterprise HRMS Vulnerability
Oracle OpenSSO 'Authentication' Remote Vulnerability
Oracle MySQL Remote MySQL Server Vulnerability
Oracle JDEdwards EnterpriseOne Tools Arbitrary File Upload Vulnerability
Oracle GlassFish Server Hash Collision Denial Of Service Vulnerability
Oracle Fusion Middleware 'Content Server' Remote Oracle WebCenter Content Vulnerability
Oracle E-Business Suite 'Online Help' sub component Oracle Application Object Library Remote Vulnerability
Oracle Database 'CTXSYS.DRVDISP' Buffer Overflow Vulnerability
Cisco Show and Share Admin Web Page Security Bypass Vulnerability
Oracle Containers for J2EE 'JavaServer Pages' Sub Component Remote Vulnerability
Cisco Show and Share Anonymous Access Security Bypass Vulnerability
Oracle Weblogic Server Remote Security Vulnerability
Oracle WebLogic Server 'JMS' sub component Remote Vulnerability
Oracle Web Services Manager 'HTTP' protocol Remote Oracle Web Services Manager Vulnerability
Oracle Virtual Desktop Infrastructure (VDI) 'Session' Remote Vulnerability
Oracle Sun Solaris Local Security Vulnerability
Oracle Sun Products Suite 'DTrace Software Library (libdtrace(3LIB))' Local Vulnerability
Oracle Solaris 'Zones' Local Vulnerability
Oracle Solaris Local Solaris Vulnerability
Oracle Solaris 'Kernel' Local Vulnerability
Oracle PeopleSoft Products 'Security' Remote PeopleSoft Enterprise PeopleTools Vulnerability
Oracle Sun Solaris Process File System (procfs) Local Vulnerability
Oracle Waveset 'User Administration' Remote Vulnerability
Oracle WebLogic Portal 'Web Services' sub component Remote Vulnerability
Oracle E-Business Suite 'Attachments / File Upload' Remote Oracle Application Object Library Vulnerability
Oracle GlassFish Enterprise Server 'Web Container' Remote Vulnerability
Oracle JDEdwards Remote File Disclosure Vulnerability
Oracle PeopleSoft Enterprise HCM 'ePerformance' Remote Vulnerability
Oracle PeopleSoft 'Talent Acquisition Manager' Remote PeopleSoft Enterprise HRMS Vulnerability
Oracle Database Vault 'SYSDBA' Privileges Remote Vulnerability
Cisco Unified Contact Center Express Directory Traversal Vulnerability
D-Link DSL-2650U Remote Denial of Service Vulnerability
D-Link DNS-320 ShareCenter Denial of Service Vulnerability
D-Link DIR-685 Encryption Failure Authentication Bypass Vulnerability
D-Link DIR-601 TFTP Server Directory Traversal Vulnerability
D-Link DIR-300 Unspecified Remote Code Execution and Remote File Disclosure Vulnerabilities
D-Link DAP-1150 Cross Site Request Forgery Vulnerability
Oracle Database Server Remote Oracle Warehouse Builder Vulnerability
Oracle Solaris 'Network' Remote Vulnerability
Oracle PeopleSoft Enterprise HCM 'Talent Acquisition Management' Remote Vulnerability
Oracle JDEdwards Information Disclosure Vulnerability
Oracle Fusion Middleware 'WLS-Console' Remote Oracle WebLogic Server Vulnerability
Oracle Communications Unified 'Calendar Server' Remote Security Vulnerability
Cisco Show and Share Arbitrary Code Execution Vulnerability
Cisco Security Agent Remote Code Execution Vulnerability
Oracle Solaris 'ZFS' Local Vulnerability
Oracle Sun Products 'Integrated Lights Out Manager CLI' Local SPARC T3, Netra SPARC T3, Sun Fire, Sun Blade Vulnerability
Oracle Sun Products Suite 'xscreensaver' Local Solaris Vulnerability
Oracle Sun Solaris 'LDAP library' Remote Vulnerability
Oracle Sun Solaris 'Remote Quota Server (rquotad(1M))' Remote Vulnerability
Oracle WebLogic Portal 'WLS Security' sub component Remote Vulnerability
Oracle MySQL '-' Sub Component Remote MySQL Server Vulnerability
Oracle VM VirtualBox "Shared Folders" Remote Vulnerability
Oracle E-Business Suite 'HTML Pages' sub component Oracle Application Object Library Remote Vulnerability
Oracle E-Business Suite 'REST Services' Sub Component Remote Vulnerability
Oracle PeopleSoft Products 'Job Profile Manager (JPM)' Remote PeopleSoft Enterprise HRMS Vulnerability
Oracle Siebel CRM 'User Interface' Siebel Core - UIF Client Remote Vulnerability
Oracle HTTP Server Denial Of Service Vulnerability
Oracle Database Remote Application Express Vulnerability
Apple Safari Remote Code execution Vulnerability
March
2012
Oracle E-Business Suite 'Attachments / File Upload' sub component Oracle Application Object Library Remote Vulnerability
Oracle E-Business Suite 'Single Sign On' sub component Oracle Application Object Library Remote Vulnerability
Oracle GlassFish Server/Java System App Server 'Web Container' Remote Vulnerability
Oracle Industry Applications 'RDC Help' Remote Health Sciences - Oracle Clinical, Remote Data Cap
Oracle Linux 'Oracle validated' Unspecified Security Vulnerability
Oracle PeopleSoft Products 'Candidate Gateway' Remote PeopleSoft Enterprise HRMS Vulnerability
Oracle Siebel CRM 'Email Marketing' Siebel Apps - Marketing Remote Vulnerability
Oracle Solaris 'Network Services Library (libnsl(3LIB))' Remote Vulnerability
Oracle Solaris 'ZFS' Sub Component Local Vulnerability
Oracle Sun Product Suite 'Kernel/Filesystem' Local Vulnerability
Oracle Sun Products Suite 'Authentication' Remote Oracle OpenSSO Vulnerability
Oracle Sun Solaris 'iSCSI DataMover(IDM)' Remote Vulnerability
Oracle Sun Solaris 'Network Status Monitor (statd(1M))' Remote Vulnerability
Oracle Supply Chain Products Suite 'Supplier Portal' Remote Oracle Agile Product Supplier Collaboration
Oracle Supply Chain Products Suite 'Supplier Portal' Remote Oracle Agile Vulnerability
Oracle Supply Chain Products Suite 'SCRM - Company Profiles' Remote Oracle Agile Vulnerability
Oracle Sun Solaris 'SSH' Remote Vulnerability
Oracle Sun Solaris 'KSSL' Remote Security Vulnerability
Oracle Solaris 'UFS' sub component Local Vulnerability
Oracle Solaris 'Trusted Extensions' Local Vulnerability
Oracle Solaris 'Kernel/sockfs' Local Vulnerability
Oracle PeopleSoft 'ePerformance' Remote PeopleSoft Enterprise HRMS Vulnerability
Oracle PeopleSoft Enterprise 'HTTP(s)' protocol Remote Vulnerability
Oracle Outside In Technology 'Outside In Image Export SDK' Remote Vulnerability
Oracle E-Business Suite 'REST Services' Remote Code Execution Vulnerabilty
Oracle E-Business Suite 'Change Password Page' Remote Oracle Application Object Library Vulnerability
Oracle Supply Chain Products Suite Remote Oracle Agile Vulnerability
Oracle Supply Chain Products Suite Remote Oracle Agile PLM for Process Vulnerability
Oracle PeopleSoft Enterprise PeopleTools Remote Vulnerability
Oracle Identity Manager Remote Vulnerability
Oracle Identity Manager Connector Remote Vulnerability
Oracle Fusion Middleware Remote Vulnerability
Oracle Database Server Remote Session Fixation Vulnerability
Oracle Database Server Remote RDBMS Core Vulnerability
Oracle Database Server Remote Oracle Spatial Vulnerability
Oracle Database Server Remote Core RDBMS Vulnerability
Oracle Secure Backup 'HTTP' protocol Remote Vulnerability
Oracle Outside In Technology Local Security Vulnerability
Oracle Java SE and Java for Business ' SAAJ' Remote Java Runtime Environment Vulnerability
Oracle Database Server Streams, AQ & Replication Mgmt Remote Code Execution Vulnerability
Oracle Database Server 'Oracle NET' protocol Remote Core RDBMS Vulnerability
Oracle Database Server Local Enterprise Config Management Vulnerability
Oracle Database Server 'Execute on DBMS_SYS_SQL' Remote Database Vault Vulnerability
Oracle Database Server Core RDBMS 'FTP' protocol Local Security Vulnerability
Oracle Database 'Create session' Remote Core RDBMS Vulnerability
Oracle Database Server and Enterprise Grid Manager 'Scheduler' Content Management Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey nsDOMAttribute Use After Free Memory Corruption Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey Memory-Corruption Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey Enter Key Dialog Bypass Weakness
Mozilla Firefox/SeaMonkey/Thunderbird 'window.fullScreen' Security Bypass Vulnerability
Mozilla Firefox Pseudo URL Same Origin Policy Security Bypass Vulnerability
Mozilla Firefox and Thunderbird Shift-JIS Encoding HTML Injection Vulnerability
Mozilla Firefox and Thunderbird Memory Corruption Vulnerability
Mozilla Firefox and SeaMonkey 'nsDOMAttribute' Use-After-Free Memory Corruption Vulnerability
Mozilla Firefox, SeaMonkey, and Thunderbird Buffer Overflow Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey 'shlwapi.dll' Use-After-Free Memory Corruption Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey 'Array.reduceRight()' Remote Code Execution Vulnerability
VBulletin Multiple Module HTML Injection Vulnerability
vBulletin Adsense Component 'viewpage.php' SQL Injection Vulnerability
Multiple vBulletin Products 'Search Multiple Content Types' SQL Injection Vulnerability
VBulletin Registration Requests Remote Denial of Service Vulnerability
Phorum Common.PHP Cross-Site Scripting Vulnerability
Simple Machines Forum 'Themes.php' Local File Include Vulnerability
Simple Machines Forum Moderation Zone Information Disclosure Vulnerability
Simple Machines Forum '[url]' Tag HTML Injection Vulnerability
PHPBB News Defilante Horizontale PHPBB_Root_Path Parameter Remote File Include Vulnerability
Phorum Register.PHP Connection Proxying Vulnerability
vBulletin vbActivity Pro module 'reason' parameter Multiple HTML Injection Vulnerabilities
Mozilla Firefox/Thunderbird/SeaMonkey YARR Library Denial Of Service Vulnerability
MyBB Versions Prior to 1.6.6 Multiple Security Vulnerabilities
Adobe Flash Player 'flash.display' Class Remote Memory Corruption Vulnerability
Oracle OpenSSO 'Administration' Remote Security Vulnerability
Oracle PeopleSoft Enterprise PeopleTools 'Upgrade Change Assistance' Remote Vulnerability
Oracle Solaris 'Kernel' Local Solaris Vulnerability
Oracle Web Services Manager Remote Oracle Web Services Manager Vulnerability
Oracle Database Vault 'DV_ACCTMGR' Privileges Remote Security Bypass Vulnerability
Oracle Outside In Technology 'Outside In Filters' Sub Component Local Vulnerability
Oracle WebLogic Portal '-' sub component Remote Vulnerability
Oracle VM VirtualBox "Windows Guest Additions" Local Vulnerability
Cisco Unified Communications Manager Directory Traversal Vulnerability
Cisco IOS Software NAT of Crafted SIP Over UDP Packets DoS Vulnerability
Cisco IOS Software NAT of H.323 Packets DoS Vulnerability
Cisco IOS Software NAT of SIP Over TCP Vulnerability
Cisco IOS Software Provider Edge Multiprotocol Label Switching (MPLS) NAT of SIP Over UDP Packets DoSVulnerability
Cisco IOS Software Smart Install Remote Code Execution Vulnerability
Cisco IP Video Phone E20 Default Root Account
Cisco IronPort Appliances Telnet Remote Code Execution Vulnerability
Cisco Video Surveillance IP Cameras Denial of Service Vulnerability
Apple iOS libxslt Information Disclosure Vulnerability
Bugzilla Content Sniffing Cross-Site Scripting (XSS) Vulnerability
Microsoft Windows Kernel 'Win32k.sys' Local Privilege Escalation Vulnerability
Oracle Communications Unified 'Calendar Server' Local Security Vulnerability
Oracle Communications Unified 'Calendar Server' Local Vulnerability
Oracle Database Listener Remote Vulnerability
Oracle Fusion Middleware Remote Oracle WebCenter Content Vulnerability
Oracle GlassFish Enterprise Server 'Administration' Local Server Vulnerability
Oracle JDEdwards EnterpriseOne Tools Information Disclosure Vulnerability
Oracle JDEdwards EnterpriseOne Tools 'SEC (JDENET)' Information Disclosure Vulnerability
Oracle Outside In 'Image Export SDK' Remote Code Execution Vulnerability
Oracle PeopleSoft Enterprise HCM 9.1 'ePerformance' Remote Vulnerability
Oracle Solaris 'ksh93 Shell' Local Solaris Vulnerability
Oracle Sun Solaris Remote Security Vulnerability
Oracle Transportation Management Denial Of Service Vulnerability
Oracle Business Intelligence Enterprise Edition 'BI Platform Security' Sub Component Remote Vulnerability
Oracle Core RDBMS SQL Injection Vulnerability
Wireshark 'call_dissector()' NULL Pointer Dereference Denial Of Service Vulnerability
Skype UTF-8 Symbol Messages Denial of Service Vulnerability
OpenSSL CMS And S/MIME Bleichenbacher Attack Vulnerability
FlexNet License Server Manager lmgrd Remote Code Execution Vulnerability
Minify And Related Plugins DOM-Based XSS Vulnerability
RealNetworks RealPlayer VIDOBJ_START_CODE Remote Code Execution Vulnerability
RealNetworks RealPlayer RV30 Sample Arbitrary Index Remote Code Execution Vulnerability
Cisco ASA 5500 Series Adaptive Security Appliance Clientless VPN ActiveX Control Remote Code Execution Vulnerability
Dell Webcam 'crazytalk4.ocx' ActiveX Multiple Buffer Overflow Vulnerabilities
Dell Webcam Center 'CrazyTalk4Native.dll' ActiveX Multiple Buffer Overflow Vulnerabilities
Cisco Identity Services Engine 1.0.4.MR2 Database Default Credentials Vulnerability
Microsoft DirectWrite Unicode Characters Denial of Service Vulnerability
Cisco IOS Software NAT for NetMeeting Directory (LDAP) Vulnerability
Cisco IOS Software IPv6 Denial of Service Vulnerability
Cisco IOS Software IP Service Level Agreement Vulnerability
Cisco Guard Enables Cross Site Scripting
Cisco IOS Software Data-Link Switching Vulnerability
Cisco IOS ICMPv6 Packet May Cause MPLS-Configured Device to Reload
Cisco Identity Services Engine Database Default Credentials Vulnerability
Cisco IOS Crafted IPv6 Packet May Cause MPLS-Configured Device to Reload
Cisco ASA 5500 Series TACACS+ Authentication Bypass Vulnerability
Cisco ASA 5500 Series SunRPC traffic Inspection Denial of Service Vulnerability(CVE-2011-3299)
Cisco ASA 5500 Series MSN IM Inspection Denial of Service Vulnerability
Cisco ASA 5500 Series ILS Inspection Denial of Service Vulnerability
Cisco 10000 Series Denial of Service Vulnerability
Bugzilla UTF-8 User Impersonation Vulnerability
Bugzilla 'jsonrpc.cgi' Cross Site Request Forgery Vulnerability
Bugzilla Crafted Parameter Information Disclosure Vulnerability
Apache HTTPd Range Header Denial of Service Vulnerability
Bugzilla Cross-Site Request Forgery Vulnerability(CVE-2011-3669)
Bugzilla Cross Site Scripting Vulnerabilities(CVE-2011-3657)
Bugzilla Cross Site Request Forgery Vulnerability
IBM Rational Rhapsody BBFlashBack.FBRecorder.1 Control Multiple Code Execution Vulnerabilities
IBM Rational Rhapsody BBFlashBack.Recorder.1 TestCompatibilityRecordMode Code Execution Vulnerability
IBM Rational Rhapsody BBFlashBack.Recorder.1 InsertMarker Code Execution Vulnerability
Total Defense Suite UNC Management Web Service Database Credentials Disclosure Vulnerability
Total Defense Suite UNC Management Console ExportReport SQL Injection Vulnerability
Adobe Reader BMP Resource Signedness Code Execution Vulnerability
IBM SPSS VsVIEW6.ocx ActiveX Control SaveDoc Method Code Execution Vulnerability
IBM SPSS ExportHTML.dll ActiveX Control Render Method Code Execution Vulnerability
EMC Networker indexd.exe Opcode 0x01 Parsing Code Execution
Total Defense Suite UNC Management Web Service uncsp_ViewReportsHomepage SQL Injection Vulnerability
Apple Webkit Cross Site Scripting Vulnerability
Novell ZENworks Configuration Management Multiple Security Vulnerabilities
Linux Kernel 'semtimedop' OABI Wrapper Heap Buffer Overflow Vulnerability
Linux Kernel kexec-tools 'mkdumprd' Utility Information Disclosure Vulnerability
Apple Safari URL Redirection Vulnerability
GNU libc glob(3) 'GLOB_LIMIT' Remote Denial of Service Vulnerability
Apple WebKit Unspecified Memory Corruption Vulnerabilities
Apple WebKit Unspecified Denial of Service Vulnerability
Apple WebKit SVG documents denial of service Vulnerability
Apple WebKit Information Disclosure Vulnerability
Apple WebKit Cascading Style Sheets (CSS) denial of service Vulnerability
Apple WebKit Bypass Cookie Restrictions Vulnerability
Apple Mac OS X Safari Directory Traversal Vulnerability
Apple Mac OS X Safari Code Execution vulnerability
Apple Mac OS X QuickLook Code Execution Vulnerability
Apple Mac OS X JPEG2000 Image Handling Heap Buffer Overflow Vulnerability
Apple Mac OS X iWork Numbers Code Execution Vulnerability
Apple Mac OS X International Components for Unicode Buffer Overflow Vulnerability
Apple Mac OS X GNU patch Path Name Directory Traversal Vulnerability
Apple Mac OS X 'getBandProcTiff()' TIFF Image Handling Heap Buffer Overflow Vulnerability
Apple Mac OS X FTP Server Directory Traversal Vulnerability
Apple Mac OS X CoreFoundation Buffer Overflow Vulnerability
Apple Mac OS X ColorSync Integer Overflow Vulnerability
Apple iWork Numbers Code Execution Vulnerability
Apple ATS Code Execution Vulnerability
Apple App Store Information Disclosure Vulnerability
Apple OS X Airport Denial of Service Vulnerability
Apple Mac OS X Integer Overflow Vulnerability
Apple iOS racoon Configuration Files Code Execution Vulnerability
Apple iOS handling of HFS catalog files Code Execution Vulnerability
Apple iOS WebKit Cross-site scripting Vulnerability
Cisco Wireless LAN Controllers WebAuth Denial of Service Vulnerability
Cisco Wireless LAN Controllers Unauthorized Access Vulnerability
Cisco Wireless LAN Controllers IPv6 Denial of Service Vulnerability
Cisco Wireless LAN Controllers HTTP Denial of Service Vulnerability
Cisco Unity Connection Privilege Escalation Vulnerability
Cisco Unity Connection Denial of Service Vulnerability
Cisco Unified Communications Manager Vulnerable to Blind SQL Injection During Registration
Cisco Unified Communications Manager SCCP Registration may Cause Reload
Cisco TelePresence Video Communication Server Session Initiation Protocol Denial of Service Vulnerability
Cisco TelePresence Video Communication Server Session Initiation Protocol Denial of Service Vulnerabilities
Cisco SRP 500 Series Web Interface Command Injection Vulnerability
Cisco SRP 500 Series Unauthenticated Configuration Upload Vulnerability
Cisco SRP 500 Series Directory Traversal Vulnerability
Cisco Cius Denial of Service Vulnerability
HP Diagnostics Server magentservice.exe Code Execution Vulnerability
IBM SPSS mraboutb.dll ActiveX Control SetLicenseInfoEx Method Code Execution Vulnerability
Symantec PCAnywhere awhost32 Code Execution Vulnerability
Oracle Outside In OOXML Relationship Tag Parsing Code Execution Vulnerability
Novell GroupWise 8 Windows Client Address Book Remote Code Execution Vulnerability
Microsoft Windows Ancillary Function Driver Elevation of Privilege Vulnerability
Microsoft Visio Viewer 2010 File Format Memory Corruption Vulnerabilities
Microsoft Visio Viewer 2010 File Format Memory Corruption Vulnerability(CVE-2012-0020)
Microsoft SharePoint 2010 XSS in wizardlist.aspx Vulnerability
Microsoft SharePoint 2010 XSS in themeweb.aspx Vulnerability
HP Easy Printer Care XMLCacheMgr Class ActiveX Control Code Execution Vulnerability
HP StorageWorks P2000 G3 Directory Traversal and Default Account Vulnerabilities
HP Easy Printer Care XMLSimpleAccessor ActiveX Control Code Execution Vulnerability
Oracle Java Web Start java-vm-args Command Argument Injection Remote Code Execution
Oracle Java JavaFX Arbitrary Argument Remote Code Execution Vulnerability
Adobe Shockwave iml32.dll DEMX Remote Code Execution Vulnerability
D-Link DSL-2640B MAC Address Authentication Bypass Vulnerability
Adobe Acrobat U3D Texture .fli RLE Decompression Remote Code Execution Vulnerability
February
2012
Mozilla Firefox/Thunderbird/SeaMonkey XUL Document Handling Remote Code Execution Vulnerability
Mozilla Firefox/SeaMonkey/Thunderbird Denial-of-Service Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey XUL Document Use-After-Free Vulnerability
Mozilla Firefox/Thunderbird/SeaMonkey Multiple Memory-Corruption Vulnerabilities
Mozilla Firefox/Thunderbird/SeaMonkey Remote-Memory-Corruption Vulnerability
RealNetworks RealPlayer RV40 Remote Code Execution Vulnerability
RealNetworks RealPlayer RV10 Encoded Height/Width Remote Code Execution Vulnerability
RealNetworks RealPlayer RV20 Frame Size Array Remote Code Execution Vulnerability
RealNetworks RealPlayer rvrender RMFF Flags Remote Code Execution Vulnerability
McAfee SaaS myCIOScn.dll ShowReport Method Command Execution
Novell Netware XNFS caller_name xdrDecodeString Code Execution Vulnerability
Citrix Provisioning Services Stream Service 0x40020006 Code Execution Vulnerability
Skype Windows/Linux Communication Handling Denial of Service Vulnerability
Samba Remote code execution vulnerability in smbd
IBM SPSS VsVIEW6.ocx ActiveX Control SaveDoc Method Remote Code Execution Vulnerability
ABB WebWare RobNetScanHost.exe Remote Code Execution Vulnerability
D-Link DSL-2640B 'redpass.cgi' Cross-Site Request Forgery Vulnerability
IBM Rational Rhapsody BBFlashBack.FBRecorder.1 Control Multiple Remote Code Execution Vulnerabilities
IBM Rational Rhapsody BBFlashBack.Recorder.1 TestCompatibilityRecordMode Remote Code Execution Vulnerability
VMware ESXi Update Installer Unauthorized Access Vulnerability
Techphoebe QuickShare File Server FTP Directory Traversal Vulnerability
Apache Geronimo Hash Collision Denial Of Service Vulnerability
Novell GroupWise Messenger 'createsearch' Command Remote Memory Corruption Vulnerability
Drupal XSS Submitted Content Vulnerability
Iron Mountain Connected Backup Agent Unauthenticated Command Execution Vulnerability
Novell ZENworks Asset Management Code Execution Vulnerability
Cisco WebEx Player WRF Type 0 Parsing Code Execution Vulnerability
Apple Quicktime Font Table Signed Length Code Execution Vulnerability
Multiple D-Link DCS Products 'security.cgi' Cross-Site Request Forgery Vulnerability
D-Link ShareCenter Products Multiple Remote Code Execution Vulnerabilities
RealNetworks RealPlayer RV10 Sample Height Parsing Code Execution Vulnerability
RealNetworks RealPlayer IVR MLTI Chunk Length Parsing Code Execution Vulnerability
RealNetworks RealPlayer RV30 Uninitialized Index Value Code Execution Vulnerability
RealNetworks RealPlayer Invalid Codec Name Code Execution Vulnerability
RealNetwork RealPlayer MPG Width Integer Underflow Code Execution Vulnerability
RealNetworks RealPlayer genr Sample Size Parsing Code Execution Vulnerability
RealNetworks RealPlayer ATRC Code Data Parsing Code Execution Vulnerability
RealNetworks RealPlayer Malformed AAC File Parsing Code Execution Vulnerability
January
2012
HP Data Protector LogBackupLocationStatus SQL Injection Vulnerabilty
InduSoft WebStudio Unauthenticated Operations Code Execution Vulnerabilityy
InduSoft WebStudio CEServer Operation 0x15 Code Execution Vulnerability
Mozilla Firefox/SeaMonkey/Thunderbird Cross Domain Security Bypass Vulnerability
Wireshark Buffer Underflow and Denial of Service Vulnerabilities
HP Data Protector Notebook Extension RequestCopy SQL Injection Vulnerabilty
HP Data Protector Notebook Extension LogClientInstallation SQL Injection Vulnerabilty
HP Data Protector Notebook Extension GetPolicies SQL Injection Vulnerabilty
OpenSSL Invalid GOST parameters DoS Attack Vulnerability
OpenSSL SGC Restart DoS Attack Vulnerability
OpenSSL Uninitialized SSL 3.0 Padding Vulnerability
Samba Memory leak and Denial of service Vulnerability
GE Proficy Historian ihDataArchiver.exe Trusted Header Size Code Execution Vulnerability
HP Data Protector Notebook Extension LogClientHealth SQL Injection Vulnerabilty
HP Data Protector Notebook Extension LogCopyOperation SQL Injection Vulnerabilty
HP Data Protector Notebook Extension FinishedCopy SQL Injection Vulnerabilty
Novell ZENWorks Software Packaging ISGrid.Grid2.1 Text Parameter Code Execution Vulnerabilit
Drupal Actions Cross Site Scripting Vulnerability
Adobe Reader BMP Image RLE Decoding Code Execution Vulnerability
Apple QuickTime H264 Matrix Conversion Code Execution Vulnerability
Apple QuickTime FLC Delta Decompression Code Execution Vulnerability
Apple Quicktime PnPixPat PatType 3 Parsing Code Execution Vulnerability
Google Chrome Prior to 15.0.874.102 Multiple Security Vulnerabilities UPDATED
Adobe Reader U3D IFF RGBA Parsing Code Execution Vulnerability
Adobe Reader U3D PCX Parsing Code Execution Vulnerability
Apple QuickTime FlashPix JPEG Tables Selector Code Execution Vulnerabilit
Symantec IM Manager ProcessAction Code Execution Vulnerability
Xlockmore 'dclock' Mode Security Bypass Vulnerability
Cisco Unified Service Monitor brstart add_dm Code Execution Vulnerability
Avaya Identity Engines Ignition Server Code Execution Vulnerability
Cisco Unified Service Monitor brstart sm_read_string_length Code Execution Vulnerability
Apache APR Hash Collision Denial Of Service Vulnerability
Microsoft Internet Explorer SetExpandedClipRect Code Execution Vulnerability
Adobe Reader U3D PICT 10h Encoding Code Execution Vulnerability
Adobe Reader PICT Parsing Code Execution Vulnerability
eEye Retina Audit Script Execution of Arbitrary Code
Adobe Reader Image Data Buffer Allocation Integer Overflow Code Execution Vulnerability
Novell Groupwise Client DOCX Loader Relationship Id Code Execution Vulnerability
Novell Groupwise iCal COMMENT, RRULE, TZNAME Code Execution Vulnerabilities
Adobe Reader U3D TIFF Resource Buffer Overflow Code Execution Vulnerability
Adobe Reader U3D PICT 0Eh Encoding Code Execution Vulnerability
RealPlayer RealMedia File Handling Buffer Overflow Vulnerability
MyBB AwayList Plugin (index.php, id parameter) SQL Injection Vulnerability
Adobe Reader U3D BMP Colors Code Execution Vulnerability
Novell Cloud Manager Insufficient Framework User Validation Vulnerability
Apple Quicktime Advanced Audio Codec Frame Parsing Code Execution Vulnerability
Apple QuickTime H264 Stream frame_cropping Code Execution Vulnerability
Witness Systems eQuality Unify Code Execution Vulnerability
Nortel Media Application Server cstore.exe cs_anams Code Execution Vulnerability
Apple QuickTime STSZ atom Parsing Code Execution Vulnerability
Apple QuickTime STSC atom Parsing Code Execution Vulnerability
Oracle Java IIOP Deserialization Type Confusion Code Execution Vulnerability
Oracle Java Applet Rhino Script Engine Code Execution Vulnerability
Select Year:
2013
2012
2011
2010
2009
2008
2007
2006
2005
2004
2003
2002
2001
2000
1999
1998
0000
Security News
-
Security Reviews
-
Exploits
-
Tools
-
UNIX Focus
-
Windows Focus
All Sections
Security News
Unix focus
Exploits
Tools
Windows focus
Security Reviews
More ›››
Featured Articles
Copyright ©
Beyond Security
All rights reserved.
Terms of Use
Site Privacy Statement
.