Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2014-3642
vmdb/app/controllers/application_controller/performance.rb in Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated …
Cloudforms 3.0.1 Management Engine
after 5.2.5
MEDIUM 5.5
CVE-2014-3521
The component in (1) /luci/homebase and (2) /luci/cluster menu in Red Hat Conga 0.12.2 allows remote authenticated users to bypass intended access re…
Conga
Mitigation only
MEDIUM 5.0
CVE-2014-3558
ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 …
Hibernate Validator
4.3.2 / 5.1.2+
MEDIUM 5.5
CVE-2014-3464
The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not proper…
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 5.0
CVE-2013-0199
The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes,…
Freeipa
Patch available
MEDIUM 6.8
CVE-2011-2514
The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and bef…
Icedtea Web
after 1.8.8
MEDIUM 6.4
CVE-2014-0071
PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass int…
Openstack
Mitigation only
MEDIUM 5.8
CVE-2014-0093
Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by…
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 6.8
CVE-2012-3406
The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the …
Enterprise Virtualization
Mitigation only
MEDIUM 5.2
CVE-2013-6457
The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver.c) in libvirt before 1.2.1 does not properly initialize the nodemap…
Libvirt
after 1.2.0
MEDIUM 5.0
CVE-2013-6448
The InterfaceGenerator handler in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allows remote …
Jboss Seam 2 Framework
after 2.3.1
MEDIUM 6.5
CVE-2013-4404
cumin in Red Hat Enterprise MRG Grid 2.4 does not properly enforce user roles, which allows remote authenticated users to bypass intended role restri…
Enterprise Mrg
Mitigation only
HIGH 7.2
CVE-2013-4400
virt-login-shell in libvirt 1.1.2 through 1.1.3 allows local users to overwrite arbitrary files and possibly gain privileges via unspecified environm…
Libvirt
Patch available
MEDIUM 5.5
CVE-2013-2133
The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly …
Jboss Enterprise Application Platform
after 6.1.0
HIGH 7.2
CVE-2013-1813
util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows lo…
Enterprise Linux
after 1.20.2
HIGH 8.5
CVE-2013-4401
The virConnectDomainXMLToNative API function in libvirt 1.1.0 through 1.1.3 checks for the connect:read permission instead of the connect:write permi…
Libvirt
Patch available
HIGH 7.6
CVE-2013-4342EPSS 6%
xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it e…
Enterprise Linux
Patch available
MEDIUM 6.9
CVE-2013-4291
The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the domain has read an uid:gid label, does not properly …
Libvirt
Patch available
HIGH 7.5
CVE-2013-4182
app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to acces…
Openstack
after 1.2.1
MEDIUM 6.0
CVE-2013-2113EPSS 21%
The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or …
Openstack
after 1.2.0
HIGH 7.5
CVE-2013-2165EPSS 13%
ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform …
Jboss Enterprise Application Platform
after 2.2.0
MEDIUM 5.0
CVE-2013-2144
Red Hat Enterprise Virtualization Manager (RHEVM) before 3.2 does not properly check permissions for the target storage domain, which allows attacker…
Enterprise Virtualization Manager
after 3.1
HIGH 7.2
CVE-2013-2069
Red Hat livecd-tools before 13.4.4, 17.x before 17.17, 18.x before 18.16, and 19.x before 19.3, when a rootpw directive is not set in a Kickstart fil…
Livecd Tools
13.4.4 / 17.17+
MEDIUM 5.0
CVE-2013-0315
The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 allows remote attackers to read arbitrary files via a crafted extern…
Jboss Enterprise Portal Platform
Mitigation only
HIGH 7.5
CVE-2012-5629
The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.…
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 6.9
CVE-2012-5660
abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbit…
Automatic Bug Reporting Tool
after 2.0.9
MEDIUM 5.5
CVE-2012-6118
The Administer tab in Aeolus Conductor allows remote authenticated users to bypass intended quota restrictions by updating the Maximum Running Instan…
Aeolus Conductor
No fix yet
MEDIUM 5.8
CVE-2012-3370
The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platf…
Jboss Enterprise Application Platform
after 5.3.0
MEDIUM 6.5
CVE-2012-4549
A flaw was found in JBoss Enterprise Application Platform. The `processInvocation` function within the `org.jboss.as.ejb3.security.AuthorizationInter…
Jboss Enterprise Application Platform
after 6.0.0
MEDIUM 5.3
CVE-2012-4550
A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system d…
Jboss Enterprise Application Platform
Mitigation only