Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2018-10915EPSS 5%
A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections…
Openstack
Patch available
HIGH 8.8
CVE-2017-12173
It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulner…
Enterprise Linux Desktop
1.16.0+
MEDIUM 5.5
CVE-2017-2622
An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malic…
Openstack
Mitigation only
MEDIUM 6.5
CVE-2017-2582
It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute …
Keycloak
2.5.1+
MEDIUM 5.5
CVE-2017-12167
It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role ma…
Jboss Enterprise Application Platform
7.0.9+
HIGH 7.1
CVE-2017-12163EPSS 8%
An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A ma…
Enterprise Linux Desktop
4.4.16 / 4.5.14+
HIGH 7.5
CVE-2018-3760EPSS 27%
There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially craft…
Cloudforms
after 3.7.1
MEDIUM 5.3
CVE-2018-1073
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an a…
Virtualization
4.2.3+
HIGH 7.5
CVE-2018-5157
Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow th…
Enterprise Linux Desktop
Mitigation only
HIGH 7.5
CVE-2017-5454
A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file …
Enterprise Linux
52.1.0 / 53.0+
HIGH 7.5
CVE-2016-9904
An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This …
Enterprise Linux Desktop
45.6.0 / 51.0+
HIGH 7.5
CVE-2018-5256
CoreOS Tectonic 1.7.x before 1.7.9-tectonic.4 and 1.8.x before 1.8.4-tectonic.3 mounts a direct proxy to the kubernetes cluster at /api/kubernetes/ w…
Tectonic
1.7.9-tectonic.4 / 1.8.4-tectonic.3+
HIGH 7.2
CVE-2018-1074
ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, includ…
Enterprise Virtualization
after 4.1.11.1
MEDIUM 6.5
CVE-2016-9590
puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object …
Openstack
8.2.1 / 9.4.4+
HIGH 8.8
CVE-2018-1097
A flaw was found in foreman before 1.16.1. The issue allows users with limited permissions for powering oVirt/RHV hosts on and off to discover the us…
Satellite
1.6.1+
MEDIUM 5.9
CVE-2017-2585
Red Hat Keycloak before version 2.5.1 has an implementation of HMAC verification for JWS tokens that uses a method that runs in non-constant time, po…
Keycloak
2.5.1+
HIGH 7.8
CVE-2017-15104
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi serv…
Enterprise Linux
Mitigation only
HIGH 7.5
CVE-2017-15087
It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.
Gluster Storage
Mitigation only
MEDIUM 5.9
CVE-2017-15085
It was discovered that the fix for CVE-2017-12150 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.
Gluster Storage
Mitigation only
MEDIUM 6.5
CVE-2017-16541
Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vec…
Enterprise Linux Desktop
7.0.9+
MEDIUM 5.9
CVE-2015-1849
AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vect…
Jboss Enterprise Application Platform
after 6.4.0
CRITICAL 9.8
CVE-2014-8174
eDeploy makes it easier for remote attackers to execute arbitrary code by leveraging use of HTTP to download files.
Edeploy
after 1.11.0
MEDIUM 5.5
CVE-2016-6310
oVirt Engine discloses the ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD in /var/log/ovirt-engine/engine.log file in RHEV before 4.0.
Enterprise Virtualization
after 3.6
MEDIUM 5.3
CVE-2016-6311
Get requests in JBoss Enterprise Application Platform (EAP) 7 disclose internal IP addresses to remote attackers.
Jboss Enterprise Application Platform
Mitigation only
HIGH 7.5
CVE-2015-3198
The Undertow module of WildFly 9.x before 9.0.0.CR2 and 10.x before 10.0.0.Alpha1 allows remote attackers to obtain the source code of a JSP page via…
Jboss Wildfly Application Server
Mitigation only
MEDIUM 5.5
CVE-2015-1870
The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which all…
Automatic Bug Reporting Tool
after 2.1.11
HIGH 7.5
CVE-2016-4992
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server …
Enterprise Linux Desktop
Patch available
HIGH 7.5
CVE-2016-5416
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server …
Enterprise Linux Desktop
Mitigation only
MEDIUM 5.3
CVE-2016-3702
Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext information.
Cloudforms Management Engine
Mitigation only
HIGH 7.5
CVE-2016-5409
Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which makes it easier for remote atta…
Openshift
Mitigation only