Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2016-4457
CloudForms Management Engine before 5.8 includes a default SSL/TLS certificate.
Cloudforms Management Engine
No fix yet
MEDIUM 5.9
CVE-2016-2107EPSS 89%
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which …
Enterprise Linux Desktop
after 1.0.1s
HIGH 7.5
CVE-2014-3691
Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which allows remot…
Openstack
after 1.5.3
MEDIUM 5.0
CVE-2014-8564
The _gnutls_ecc_ansi_x963_export function in gnutls_ecc.c in GnuTLS 3.x before 3.1.28, 3.2.x before 3.2.20, and 3.3.x before 3.3.10 allows remote att…
Enterprise Linux Desktop
Patch available
MEDIUM 6.8
CVE-2014-5075
The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify that the server hostname match…
Jboss Fuse
after 6.1.0
MEDIUM 5.0
CVE-2014-7968
VDSM allows remote attackers to cause a denial of service (connection blocking) by keeping an SSL connection open.
Virtual Desktop Service Manager
Mitigation only
MEDIUM 5.0
CVE-2013-6445
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, uses the DES-based crypt function to hash passwords, which makes it easier…
Enterprise Mrg
Mitigation only
MEDIUM 5.7
CVE-2011-3588
The SSH configuration in the Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-…
Kexec Tools
after 2.0.0-188
MEDIUM 5.7
CVE-2011-3589
The Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-209 packages in Red Hat E…
Kexec Tools
after 2.0.0-188
MEDIUM 5.7
CVE-2011-3590
The Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-209 packages in Red Hat E…
Kexec Tools
after 2.0.0-188
HIGH 7.9
CVE-2012-5484
The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows ma…
Freeipa
Mitigation only
MEDIUM 6.8
CVE-2012-0861
The vds_installer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, uses the -k curl parameter when downloading d…
Enterprise Virtualization Manager
after 3.0
MEDIUM 5.0
CVE-2011-1096
The W3C XML Encryption Standard, as used in the JBoss Web Services (JBossWS) component in JBoss Enterprise Portal Platform before 5.2.2 and other pro…
Jboss Enterprise Portal Platform
after 5.2.1
MEDIUM 5.8
CVE-2012-2681
Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, uses predictable random numbers to generate session key…
Enterprise Mrg
after 0.1.5192-4
MEDIUM 5.5
CVE-2012-3367
Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System does not properly check certificate revocation requests made through the…
Certificate System
after 8.1