Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2018-12549
In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when acceleratin…
Satellite
Mitigation only
HIGH 7.5
CVE-2018-16889
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files …
Ceph
after 13.2.4
CRITICAL 9.8
CVE-2017-1002157
modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.
Modulemd
after 1.3.1
HIGH 7.5
CVE-2018-6101
A lack of host validation in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML …
Linux Desktop
66.0.3359.117+
MEDIUM 6.5
CVE-2016-2125EPSS 9%
It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to wh…
Gluster Storage
4.3.13 / 4.4.8+
CRITICAL 9.8
CVE-2018-5156
A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurring. This can result in stream …
Enterprise Linux Desktop
Mitigation only
CRITICAL 9.1
CVE-2018-12387EPSS 10%
A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by…
Enterprise Linux Desktop
Patch available
HIGH 7.0
CVE-2018-12385
A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile director…
Enterprise Linux Desktop
Mitigation only
MEDIUM 6.5
CVE-2018-10935
A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.
389 Directory Server
1.3.8.7 / 1.4.0.14+
CRITICAL 9.8
CVE-2018-14620
The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could potentially…
Openstack
Mitigation only
MEDIUM 6.5
CVE-2018-14635
When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP add…
Openstack
after 12.0.3
HIGH 7.5
CVE-2018-14624
A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the error log was not correctly u…
Enterprise Linux Desktop
after 1.4.0.16
MEDIUM 5.3
CVE-2016-1000232
NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial…
Openshift Container Platform
after 5.0.7.2
MEDIUM 6.5
CVE-2018-10930
A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw to write to a destination ou…
Enterprise Linux
3.12.14 / 4.1.4+
HIGH 8.8
CVE-2018-10926
A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to a…
Virtualization Host
3.12.14 / 4.1.8+
HIGH 8.1
CVE-2018-10923
It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker c…
Virtualization Host
3.12.14 / 4.1.8+
HIGH 7.5
CVE-2018-1517
A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack w…
Satellite
Mitigation only
MEDIUM 6.3
CVE-2018-10908
It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By uploading a specially crafted image…
Virtualization
4.20.37+
HIGH 7.5
CVE-2016-9579
A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A re…
Ceph Storage
Patch available
HIGH 7.7
CVE-2016-8631
The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routes can pote…
Openshift
Mitigation only
MEDIUM 6.5
CVE-2016-8626
A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ceph Object Gateway handles POST object requests permits an authenticated attacker to launc…
Ceph
0.94.3.9-8+
HIGH 7.5
CVE-2018-10903
A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user …
Openstack
2.3+
MEDIUM 6.5
CVE-2017-2653
A number of unused delete routes are present in CloudForms before 5.7.2.1 which can be accessed via GET requests instead of just POST requests. This …
Cloudforms Management Engine
5.7.2.1+
MEDIUM 6.5
CVE-2017-2658
It was discovered that the Dashbuilder login page as used in Red Hat JBoss BPM Suite before 6.4.2 and Red Hat JBoss Data Virtualization & Services be…
Jboss Bpm Suite
6.4.2 / 6.4.3+
MEDIUM 5.4
CVE-2017-2674
JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a stored XSS via several lists in Business Central. The flaw is due to lack of sanitation…
Jboss Bpm Suite
6.4.3+
MEDIUM 6.3
CVE-2017-2614
When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is ex…
Enterprise Virtualization
Mitigation only
HIGH 8.8
CVE-2017-12173
It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulner…
Enterprise Linux Desktop
1.16.0+
HIGH 7.2
CVE-2017-12148
A flaw was found in Ansible Tower's interface before 3.1.5 and 3.2.0 with SCM repositories. If a Tower project (SCM repository) definition does not h…
Ansible Tower
3.1.5 / 3.2.0+
MEDIUM 6.5
CVE-2017-12171EPSS 8%
A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines…
Enterprise Linux
Mitigation only
MEDIUM 6.5
CVE-2017-7509
An input validation error was found in Red Hat Certificate System's handling of client provided certificates before 8.1.20-1. If the certreq field is…
Certificate System
8.1.20-1+