Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.4
CVE-2017-12191
A flaw was found in the CloudForms account configuration when using VMware. By default, a shared account is used that has privileged access to VMRC (…
Cloudforms
Patch available
HIGH 7.8
CVE-2017-15131
It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting…
Enterprise Linux
0.15.5+
MEDIUM 6.1
CVE-2014-8168
Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.
Satellite
Mitigation only
MEDIUM 5.9
CVE-2015-5293
Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which m…
Enterprise Virtualization Manager
after 3.6.0
MEDIUM 6.8
CVE-2016-6338
ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate atta…
Enterprise Virtualization
No fix yet
HIGH 8.8
CVE-2016-4286EPSS 6%
Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to…
Enterprise Linux Desktop
after 23.0.0.162
HIGH 8.8
CVE-2016-7040
Red Hat CloudForms Management Engine 4.1 does not properly handle regular expressions passed to the expression engine via the JSON API and the web-ba…
Cloudforms Management Engine
Mitigation only
HIGH 8.8
CVE-2016-5383
The web UI in Red Hat CloudForms 4.1 allows remote authenticated users to execute arbitrary code via vectors involving "Lack of field filters."
Cloudforms
Mitigation only
HIGH 8.1
CVE-2016-5388EPSS 51%
Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not prote…
Enterprise Linux Desktop
Patch available
CRITICAL 9.8
CVE-2016-5008
libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers…
Libvirt
after 1.3.5
HIGH 8.1
CVE-2016-3698
libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remot…
Enterprise Linux Desktop
Patch available
HIGH 7.1
CVE-2016-2150
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to…
Enterprise Linux
Mitigation only
HIGH 7.1
CVE-2016-3708
Red Hat OpenShift Enterprise 3.2, when multi-tenant SDN is enabled and a build is run in a namespace that would normally be isolated from pods in oth…
Openshift
Mitigation only
MEDIUM 5.3
CVE-2016-3703
Red Hat OpenShift Enterprise 3.2 and 3.1 do not properly validate the origin of a request when anonymous access is granted to a service/proxy or pod/…
Openshift
Mitigation only
MEDIUM 6.5
CVE-2014-8177
The Red Hat gluster-swift package, as used in Red Hat Gluster Storage (formerly Red Hat Storage Server), allows remote authenticated users to bypass …
Gluster Storage Management Console
Mitigation only
MEDIUM 6.5
CVE-2015-5247
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of s…
Libvirt
Mitigation only
HIGH 7.5
CVE-2015-5325
Jenkins before 1.638 and LTS before 1.625.2 allow attackers to bypass intended slave-to-master access restrictions by leveraging a JNLP slave. NOTE: …
Openshift
after 3.1
MEDIUM 5.3
CVE-2015-4902 KEVEPSS 13%
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployme…
Satellite
Patch available
HIGH 9.0
CVE-2015-0297
Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java met…
Jboss Operations Network
Mitigation only
MEDIUM 6.4
CVE-2013-4213
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attacker…
Jboss Enterprise Application Platform
Mitigation only
CRITICAL 9.8
CVE-2012-4681 KEVEPSS 99%
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute a…
Enterprise Linux Desktop
Mitigation only
CRITICAL 9.8
CVE-2012-1723 KEVEPSS 94%
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update…
Icedtea6
1.10.8 / 1.11.3+