Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2016-0639EPSS 8%
Unspecified vulnerability in Oracle MySQL 5.6.29 and earlier and 5.7.11 and earlier allows remote attackers to affect confidentiality, integrity, and…
Enterprise Linux
after 5.7.11
CRITICAL 9.8
CVE-2010-5325EPSS 5%
Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0.6 allows remote attackers to cause a denial of se…
Enterprise Linux Desktop
after 4.0.5
CRITICAL 9.8
CVE-2016-0791
Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to…
Openshift
after 1.649
CRITICAL 9.0
CVE-2015-7512EPSS 8%
Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial…
Enterprise Linux Desktop
Mitigation only
CRITICAL 9.8
CVE-2015-5254EPSS 35%
Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitr…
Openshift
Mitigation only
CRITICAL 9.8
CVE-2015-8103EPSS 87%
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized J…
Openshift Container Platform
1.625.2 / 1.638+
CRITICAL 9.8
CVE-2015-5123 KEVEPSS 18%
Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Wind…
Enterprise Linux Desktop
after 18.0.0.203
CRITICAL 9.8
CVE-2015-5122 KEVEPSS 94%
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on W…
Enterprise Linux Desktop
after 18.0.0.204
CRITICAL 9.8
CVE-2015-5119 KEVEPSS 99%
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x…
Enterprise Linux Desktop
after 18.0.0.194
CRITICAL 9.8
CVE-2015-0192
Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 F…
Enterprise Linux Desktop
5.0.16.10 / 6.1.8.4+
CRITICAL 9.8
CVE-2015-3113 KEVEPSS 100%
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.46…
Enterprise Linux Desktop
11.2.202.468 / 13.0.0.296+
CRITICAL 9.8
CVE-2015-3043 KEVEPSS 74%
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to…
Enterprise Linux Desktop
11.2.202.457 / 13.0.0.281+
CRITICAL 9.8
CVE-2013-2729 KEVEPSS 67%
Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code…
Enterprise Linux Desktop
9.5.5 / 10.1.7+
CRITICAL 9.8
CVE-2013-1591
Stack-based buffer overflow in libpixman, as used in Pale Moon before 15.4 and possibly other products, has unspecified impact and context-dependent …
Enterprise Virtualization
15.4+
CRITICAL 9.8
CVE-2012-4681 KEVEPSS 99%
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute a…
Enterprise Linux Desktop
Mitigation only
CRITICAL 9.8
CVE-2012-3503
The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default in…
Enterprise Linux Server
after 1.0
CRITICAL 9.8
CVE-2012-1723 KEVEPSS 94%
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update…
Icedtea6
1.10.8 / 1.11.3+
CRITICAL 9.9
CVE-2009-3616
Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitrary code on…
Enterprise Linux Server
after 0.10.6
CRITICAL 9.1
CVE-2008-2369
manzier.pxt in Red Hat Network Satellite Server before 5.1.1 has a hard-coded authentication key, which allows remote attackers to connect to the ser…
Satellite
5.1.1+
CRITICAL 9.8
CVE-2003-0466EPSS 78%
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demon…
Wu Ftpd
after 5.0
CRITICAL 9.8
CVE-1999-0043EPSS 45%
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
Linux
Mitigation only