Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2023-39976
log_blackbox.c in libqb before 2.0.8 allows a buffer overflow via long log messages because the header size is not considered.
Libqb
2.0.8+
HIGH 8.8
CVE-2021-3020
An issue was discovered in ClusterLabs Hawk (aka HA Web Konsole) through 2.3.0-15. It ships the binary hawk_invoke (built from tools/hawk_invoke.c), …
Hawk
after 2.3.0-15
MEDIUM 5.5
CVE-2010-2496
stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwor…
Cluster Glue
1.0.6 / 1.1.3+
CRITICAL 9.8
CVE-2020-35458EPSS 5%
An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawk_remember_me_id parameter in …
Hawk
Patch available
MEDIUM 5.9
CVE-2014-0104
In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-mid…
Fence Agents
4.0.17+
MEDIUM 5.5
CVE-2011-5271
Pacemaker before 1.1.6 configure script creates temporary files insecurely
Pacemaker
1.1.6+
HIGH 7.1
CVE-2019-12779
libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /t…
Libqb
1.0.5+
MEDIUM 6.1
CVE-2017-2661
ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field when creat…
Pcs
0.9.157+