Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2017-7539EPSS 6%
An assertion-failure flaw was found in Qemu before 2.10.1, in the Network Block Device (NBD) server's initial connection negotiation, where the I/O c…
Openstack
2.10.1+
CRITICAL 9.8
CVE-2018-10870EPSS 6%
redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any fil…
Certification
Mitigation only
CRITICAL 9.8
CVE-2017-7481
Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of looku…
Openshift Container Platform
2.3.1.0 / 2.4.0.0+
MEDIUM 5.3
CVE-2017-15137
The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a…
Openshift
Mitigation only
HIGH 7.5
CVE-2018-10885
In atomic-openshift before version 3.10.9 a malicious network-policy configuration can cause Openshift Routing to crash when using ovs-networkpolicy …
Openshift
3.10.9+
HIGH 8.8
CVE-2018-10843
source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privile…
Openshift Container Platform
3.7.53+
HIGH 7.8
CVE-2018-10874
In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's con…
Ansible Engine
Mitigation only
HIGH 8.0
CVE-2017-7466
Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An attacker with control over a cl…
Ansible
2.3+
MEDIUM 6.5
CVE-2018-1103
Openshift Enterprise source-to-image before version 1.1.10 is vulnerable to an improper validation of user input. An attacker who could trick a user …
Source To Image
1.1.10+
HIGH 7.5
CVE-2018-1070
routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which can cause an entire shard to b…
Openshift Container Platform
3.10+
MEDIUM 5.3
CVE-2017-7829
It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not d…
Enterprise Linux Aus
52.5.2+
HIGH 7.8
CVE-2017-7814
File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature …
Enterprise Linux Desktop
52.4.0 / 56.0+
HIGH 7.5
CVE-2017-7762
When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing…
Enterprise Linux Desktop
54.0+
HIGH 7.5
CVE-2017-5449
A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS animations. This vulnerabilit…
Enterprise Linux
52.1.0 / 53.0+
CRITICAL 9.8
CVE-2016-9901
HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-sa…
Enterprise Linux Aus
45.6.0 / 50.1+
HIGH 8.8
CVE-2018-1104
Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrar…
Ansible Tower
after 3.2.3
HIGH 8.8
CVE-2018-1102
A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFr…
Openshift
Patch available
HIGH 8.1
CVE-2016-9587EPSS 18%
Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacke…
Ansible
2.1.4 / 2.2.1+
MEDIUM 5.5
CVE-2018-1099
DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser in…
Etcd
after 3.3.1
MEDIUM 5.5
CVE-2018-8945
The bfd_section_from_shdr function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows rem…
Enterprise Linux Desktop
Patch available
HIGH 8.1
CVE-2016-9606EPSS 6%
JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted dat…
Resteasy
after 3.1.1
HIGH 7.5
CVE-2018-7549
In params.c in zsh through 5.4.2, there is a crash during a copy of an empty hash table, as demonstrated by typeset -p.
Enterprise Linux Desktop
after 5.4.2
HIGH 7.8
CVE-2018-7208
In the coff_pointerize_aux function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, an in…
Enterprise Linux Desktop
Mitigation only
HIGH 8.1
CVE-2018-1051
It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yam…
Resteasy
Mitigation only
MEDIUM 5.5
CVE-2018-1047
A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResou…
Jboss Wildfly Application Server
Mitigation only
HIGH 8.8
CVE-2017-15103EPSS 5%
A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted r…
Enterprise Linux
Patch available
MEDIUM 5.5
CVE-2017-15121
A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not e…
Enterprise Linux
Mitigation only
MEDIUM 6.5
CVE-2015-5248
Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform.
Feedhenry Enterprise Mobile Application Platform
No fix yet
HIGH 7.5
CVE-2015-3215
The NetKVM Windows Virtio driver allows remote attackers to cause a denial of service (guest crash) via a crafted length value in an IP packet, as de…
Virtio Win
Patch available
HIGH 8.8
CVE-2014-3498
The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands.
Ansible
after 1.6.5