Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2017-7957
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during…
Fuse
after 1.4.9
MEDIUM 5.5
CVE-2016-7796
The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received o…
Enterprise Linux Desktop
Patch available
HIGH 7.5
CVE-2016-3110
mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP mes…
Jboss Enterprise Application Platform
Mitigation only
HIGH 7.5
CVE-2016-5418
The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to …
Enterprise Linux Desktop
Patch available
HIGH 7.5
CVE-2016-4809
The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a…
Enterprise Linux Desktop
Patch available
CRITICAL 9.8
CVE-2016-3737EPSS 7%
The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, relat…
Jboss Operations Network
after 3.3.5
MEDIUM 6.5
CVE-2016-5009
The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph mon…
Ceph Storage Mon
after 0.94.6
MEDIUM 6.5
CVE-2016-6170EPSS 41%
ISC BIND through 9.9.9-P1, 9.10.x through 9.10.4-P1, and 9.11.x through 9.11.0b1 allows primary DNS servers to cause a denial of service (secondary D…
Enterprise Linux
after 9.10.3
HIGH 8.1
CVE-2016-0363
The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 be…
Satellite
Mitigation only
MEDIUM 6.5
CVE-2015-4598
PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not ensure that pathnames lack %00 sequences, which might allow remote attackers…
Enterprise Linux Desktop
after 5.4.41
MEDIUM 6.5
CVE-2015-3411
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers …
Enterprise Linux
after 5.4.39
MEDIUM 6.5
CVE-2016-1665
The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrome before 50.0.2661.94, mishandles comparison oper…
Enterprise Linux Desktop Supplementary
after 50.0.2661.87
HIGH 8.0
CVE-2016-1661
Blink, as used in Google Chrome before 50.0.2661.94, does not ensure that frames satisfy a check for the same renderer process in addition to a Same …
Enterprise Linux Desktop Supplementary
after 50.0.2661.87
HIGH 8.8
CVE-2016-1660
Blink, as used in Google Chrome before 50.0.2661.94, mishandles assertions in the WTF::BitArray and WTF::double_conversion::Vector classes, which all…
Enterprise Linux Desktop Supplementary
after 50.0.2661.87
CRITICAL 9.8
CVE-2015-5254EPSS 38%
Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitr…
Openshift
Mitigation only
MEDIUM 6.8
CVE-2015-5234
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .app…
Enterprise Linux Desktop
after 1.5.2
MEDIUM 6.8
CVE-2014-9751
The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP addr…
Enterprise Linux Desktop
4.2.8+
MEDIUM 5.8
CVE-2014-9750EPSS 6%
ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtain sensitive information from …
Enterprise Linux Desktop
4.2.8+
MEDIUM 5.0
CVE-2015-4148EPSS 20%
The do_soap_call function in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that the uri property …
Enterprise Linux Desktop
after 10.10.4
HIGH 7.5
CVE-2014-7840
The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers to execute arbitrary code via…
Enterprise Linux Desktop
after 2.1.3
MEDIUM 6.4
CVE-2014-7839
DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which …
Resteasy
Mitigation only
MEDIUM 5.0
CVE-2013-0336
The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_extop.c in the directory server (dirsrv) in FreeIPA before 3.2.0 allows…
Freeipa
after 3.1.5
MEDIUM 5.0
CVE-2014-0136
The (1) get and (2) log methods in the AgentController in Red Hat CloudForms 3.0 Management Engine (CFME) 5.x allow remote attackers to insert arbitr…
Cloudforms 3.0 Management Engine
after 5.2.5.3
MEDIUM 6.5
CVE-2014-3573
The oVirt Engine backend module, as used in Red Hat Enterprise Virtualization Manager before 3.4.2, uses an "insecure DocumentBuilderFactory," which …
Enterprise Virtualization Manager
after 3.4.1
MEDIUM 5.0
CVE-2012-2682
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, allows attackers with certain database privileges to cause a denial of ser…
Enterprise Mrg
Mitigation only
MEDIUM 6.5
CVE-2013-2143EPSS 48%
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows r…
Network Satellite
after 1.5.0-14
MEDIUM 6.0
CVE-2010-2236
The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and …
Network Proxy
after 2.1.147-1
MEDIUM 5.8
CVE-2011-2941
Open redirect vulnerability in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allows remote attackers to redirect users to arbitrary web sites…
Jboss Enterprise Portal Platform
after 5.1.1
MEDIUM 5.8
CVE-2012-0052
Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 does not check the JON agent key, which allows remote attackers to spoof t…
Jboss Operations Network
after 2.4.1
MEDIUM 6.5
CVE-2011-1594
A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to ar…
Network Satellite
Patch available