Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2019-14842
Structured reply is a feature of the newstyle NBD protocol allowing the server to send a reply in chunks. A bounds check which was supposed to test f…
Libnbd
1.0.3+
CRITICAL 9.8
CVE-2014-3585
redhat-upgrade-tool: Does not check GPG signatures when upgrading versions
Redhat Upgrade Tool
Mitigation only
CRITICAL 9.8
CVE-2014-3700
eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data
Edeploy
after 1.6.0
CRITICAL 9.8
CVE-2012-3460
cumin: At installation postgresql database user created without password
Enterprise Mrg
Mitigation only
CRITICAL 9.8
CVE-2011-2897
gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw
Enterprise Linux
after 2.31.1
CRITICAL 9.8
CVE-2015-8980EPSS 7%
The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code.
Enterprise Linux
1.0.12+
CRITICAL 9.1
CVE-2010-2548
IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.
Icedtea6
1.7.4+
CRITICAL 9.1
CVE-2010-2783
IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services.
Icedtea6
1.7.4+
CRITICAL 9.1
CVE-2019-17631
From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privil…
Satellite
after 0.16.0
CRITICAL 9.8
CVE-2019-10212
A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to o…
Undertow
2.0.20+
CRITICAL 9.8
CVE-2019-10202EPSS 5%
A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525…
Jboss Enterprise Application Platform
Mitigation only
CRITICAL 9.8
CVE-2019-14813EPSS 11%
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, en…
Openshift Container Platform
Patch available
CRITICAL 9.1
CVE-2019-10141
A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability wa…
Openstack
5.0.2 / 6.0.3+
CRITICAL 9.8
CVE-2018-11307EPSS 6%
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows…
Openshift Container Platform
2.6.7.3 / 2.7.9.4+
CRITICAL 9.8
CVE-2019-10137
A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthen…
Satellite
after 2.9
CRITICAL 9.8
CVE-2019-3888
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connector…
Undertow
2.0.21+
CRITICAL 9.0
CVE-2019-3873
It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An att…
Jboss Enterprise Application Platform
Mitigation only
CRITICAL 9.8
CVE-2016-7043
It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any…
Kie Server
7.21.0+
CRITICAL 9.8
CVE-2019-3899
It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This i…
Openshift Container Platform
Mitigation only
CRITICAL 9.8
CVE-2018-12547
In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects exis…
Satellite
0.12.0+
CRITICAL 9.8
CVE-2018-12549
In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when acceleratin…
Satellite
Mitigation only
CRITICAL 9.8
CVE-2017-1002157
modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.
Modulemd
after 1.3.1
CRITICAL 9.8
CVE-2018-16879
Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging cel…
Ansible Tower
3.3.3+
CRITICAL 9.8
CVE-2018-15981EPSS 10%
Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
Enterprise Linux Desktop
after 31.0.0.148
CRITICAL 9.8
CVE-2018-14667 KEVEPSS 74%
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticate…
Richfaces
after 3.3.4
CRITICAL 9.8
CVE-2018-5156
A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurring. This can result in stream …
Enterprise Linux Desktop
Mitigation only
CRITICAL 9.1
CVE-2018-12387EPSS 8%
A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by…
Enterprise Linux Desktop
Patch available
CRITICAL 9.8
CVE-2018-12378
A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to…
Enterprise Linux Desktop
Mitigation only
CRITICAL 9.8
CVE-2018-12376
Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of memory corruption and we presume that with enoug…
Enterprise Linux Desktop
Mitigation only
CRITICAL 9.8
CVE-2018-12377
A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted whi…
Enterprise Linux Desktop
Mitigation only