Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2016-4609EPSS 5%
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watch…
Fedora
1.1.29 / 2.2.2+
CRITICAL 9.8
CVE-2016-4608EPSS 5%
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watch…
Fedora
5.2.1 / 12.4.2+
CRITICAL 9.8
CVE-2016-4607EPSS 5%
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watch…
Fedora
1.1.29 / 2.2.2+
MEDIUM 5.9
CVE-2016-2775EPSS 63%
ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote at…
Fedora
Patch available
HIGH 8.1
CVE-2016-5386EPSS 5%
The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI app…
Fedora
1.6.3+
MEDIUM 5.5
CVE-2015-8808
The DecodeImage function in coders/gif.c in GraphicsMagick 1.3.18 allows remote attackers to cause a denial of service (uninitialized memory access) …
Fedora
after 1.3.17
HIGH 7.5
CVE-2016-5244EPSS 6%
The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structure member, which allows remot…
Fedora
after 4.6.3
HIGH 7.5
CVE-2016-4414
The onReadyRead function in core/coreauthhandler.cpp in Quassel before 0.12.4 allows remote attackers to cause a denial of service (NULL pointer dere…
Fedora
after 0.12.3
CRITICAL 9.1
CVE-2015-8869EPSS 5%
OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive in…
Fedora
after 4.02.3
CRITICAL 9.8
CVE-2016-3720
XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have u…
Fedora
after 2.7.3
HIGH 7.8
CVE-2016-3096
The create_script function in the lxc_container module in Ansible before 1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary file…
Fedora
after 1.9.6
HIGH 7.5
CVE-2016-3075EPSS 8%
Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) before 2.24 allows context-depend…
Fedora
after 2.23
HIGH 7.5
CVE-2016-1234EPSS 5%
Stack-based buffer overflow in the glob implementation in GNU C Library (aka glibc) before 2.24, when GLOB_ALTDIRFUNC is used, allows context-depende…
Fedora
2.24+
HIGH 7.5
CVE-2016-4021
The read_binary function in buffer.c in pgpdump before 0.30 allows context-dependent attackers to cause a denial of service (infinite loop and CPU co…
Fedora
after 0.29
HIGH 7.5
CVE-2015-8853
The (1) S_reghop3, (2) S_reghop4, and (3) S_reghopmaybe3 functions in regexec.c in Perl before 5.24.0 allow context-dependent attackers to cause a de…
Fedora
after 5.23.9
MEDIUM 6.0
CVE-2016-4037
The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU…
Fedora
after 2.5.1
HIGH 7.5
CVE-2016-2850
Botan 1.11.x before 1.11.29 does not enforce TLS policy for (1) signature algorithms and (2) ECC curves, which allows remote attackers to conduct dow…
Fedora
Mitigation only
HIGH 7.5
CVE-2015-7827
Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, …
Fedora
after 1.10.13
HIGH 7.8
CVE-2015-8868
Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to cause a denia…
Fedora
Mitigation only
CRITICAL 9.8
CVE-2016-4002EPSS 6%
Buffer overflow in the mipsnet_receive function in hw/net/mipsnet.c in QEMU, when the guest NIC is configured to accept large packets, allows remote …
Fedora
after 2.6.2
CRITICAL 9.8
CVE-2015-8778EPSS 6%
Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application c…
Fedora
after 2.22
CRITICAL 9.8
CVE-2014-9761EPSS 6%
Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of se…
Fedora
No fix yet
HIGH 8.8
CVE-2016-3960
Integer overflow in the x86 shadow pagetable code in Xen allows local guest OS users to cause a denial of service (host crash) or possibly gain privi…
Fedora
Patch available
HIGH 7.5
CVE-2016-3071
Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform.
Fedora
Mitigation only
HIGH 7.8
CVE-2015-8106
Format string vulnerability in the CmdKeywords function in funct1.c in latex2rtf before 2.3.10 allows remote attackers to execute arbitrary code via …
Fedora
Mitigation only
HIGH 7.5
CVE-2016-2146
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a deni…
Fedora
after 0.11.0
HIGH 7.5
CVE-2016-2145
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows rem…
Fedora
after 0.11.0
MEDIUM 5.9
CVE-2016-0787
The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in…
Fedora
after 1.6.0
HIGH 8.8
CVE-2016-3630
The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, …
Fedora
after 3.7.2
MEDIUM 6.1
CVE-2015-8807
Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Hor…
Fedora
Patch available