Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2016-5411
/var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created world readable and contains the …
Quickstart Cloud Installer
Mitigation only
CRITICAL 9.8
CVE-2016-5405
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server …
Enterprise Linux Desktop
Mitigation only
CRITICAL 9.8
CVE-2016-7050
SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and R…
Enterprise Linux Desktop
Mitigation only
CRITICAL 9.8
CVE-2016-3690
The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.
Jboss Enterprise Application Platform
Mitigation only
CRITICAL 9.8
CVE-2017-7504EPSS 24%
HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Se…
Jboss Enterprise Application Platform
after 4.0
CRITICAL 9.8
CVE-2017-7503
It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use th…
Jboss Enterprise Application Platform
Mitigation only
CRITICAL 9.8
CVE-2008-7313
The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CV…
Openstack
after 4.2.3
CRITICAL 9.8
CVE-2014-5008
Snoopy allows remote attackers to execute arbitrary commands.
Openstack
Patch available
CRITICAL 9.8
CVE-2014-5009
Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.
Openstack
after 4.2.3
CRITICAL 9.8
CVE-2017-5929EPSS 8%
QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.
Satellite
1.2.0+
CRITICAL 9.8
CVE-2016-9636EPSS 8%
Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a…
Enterprise Linux Desktop
after 1.10.1
CRITICAL 9.8
CVE-2016-9634EPSS 9%
Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a…
Enterprise Linux Desktop
after 1.10.1
CRITICAL 9.8
CVE-2016-9635EPSS 9%
Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a…
Enterprise Linux Desktop
after 1.10.1
CRITICAL 9.8
CVE-2014-8241
XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return …
Enterprise Linux Desktop
Mitigation only
CRITICAL 9.8
CVE-2016-6330EPSS 9%
The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote a…
Jboss Operations Network
Mitigation only
CRITICAL 9.8
CVE-2016-4999
SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuil…
Dashbuilder
after 0.5.0
CRITICAL 9.8
CVE-2016-3737EPSS 6%
The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, relat…
Jboss Operations Network
after 3.3.5
CRITICAL 9.8
CVE-2016-5008
libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers…
Libvirt
after 1.3.5
CRITICAL 9.8
CVE-2016-2074EPSS 6%
Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute …
Openshift
Patch available
CRITICAL 9.8
CVE-2016-2141
It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use …
Jgroups
4.0+
CRITICAL 9.8
CVE-2016-4171 KEVEPSS 20%
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as expl…
Enterprise Linux Desktop
after 21.0.0.242
CRITICAL 9.8
CVE-2016-4138EPSS 25%
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11…
Enterprise Linux Desktop
after 21.0.0.242
CRITICAL 9.8
CVE-2016-4448EPSS 7%
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
Enterprise Linux Desktop
Mitigation only
CRITICAL 9.1
CVE-2015-5041
The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote at…
Satellite
6.0.16.20 / 6.1.8.20+
CRITICAL 9.8
CVE-2015-4602EPSS 10%
The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remot…
Enterprise Linux
after 5.4.39
CRITICAL 9.8
CVE-2015-4601EPSS 8%
PHP before 5.6.7 might allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected d…
Enterprise Linux Desktop
after 5.6.6
CRITICAL 9.8
CVE-2015-4600EPSS 10%
The SoapClient implementation in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service …
Enterprise Linux Desktop
after 5.4.39
CRITICAL 9.8
CVE-2016-1666
Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.94 allow attackers to cause a denial of service or possibly have other impact …
Enterprise Linux Desktop Supplementary
after 50.0.2661.87
CRITICAL 9.8
CVE-2016-4117 KEVEPSS 94%
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May …
Enterprise Linux Desktop
after 21.0.0.226
CRITICAL 9.8
CVE-2016-2108EPSS 79%
The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of serv…
Enterprise Linux Desktop
after 1.0.1n