Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2019-3884
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namesp…
Openshift
Mitigation only
MEDIUM 5.5
CVE-2019-10194
Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could b…
Virtualization Manager
Mitigation only
HIGH 7.8
CVE-2019-13314
virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password…
Virt Bootstrap
No fix yet
MEDIUM 6.5
CVE-2019-10177
A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user input is no…
Cloudforms Management Engine
Mitigation only
CRITICAL 9.0
CVE-2019-3873
It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An att…
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 5.4
CVE-2019-3872
It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. …
Jboss Enterprise Application Platform
Mitigation only
HIGH 7.0
CVE-2019-9755
An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafte…
Enterprise Linux
Mitigation only
CRITICAL 9.8
CVE-2019-3899
It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This i…
Openshift Container Platform
Mitigation only
HIGH 7.8
CVE-2019-3891
It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin da…
Satellite
No fix yet
HIGH 7.5
CVE-2017-3139
A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly w…
Enterprise Linux Server Aus
Mitigation only
MEDIUM 5.4
CVE-2018-10934
A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can c…
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 5.5
CVE-2019-3835
It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file cou…
Ansible Tower
No fix yet
HIGH 8.8
CVE-2017-7510
In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.
Ovirt Engine
Mitigation only
MEDIUM 5.4
CVE-2018-16838
A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the ser…
Enterprise Linux
Mitigation only
HIGH 7.5
CVE-2019-3816EPSS 15%
Openwsman, versions up to and including 2.6.9, are vulnerable to arbitrary file disclosure because the working directory of openwsmand daemon was set…
Enterprise Linux
Mitigation only
CRITICAL 9.8
CVE-2018-12549
In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when acceleratin…
Satellite
Mitigation only
MEDIUM 5.5
CVE-2019-7664
In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check. Crafted elf in…
Enterprise Linux
No fix yet
HIGH 7.5
CVE-2019-3813
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a deni…
Enterprise Linux Desktop
Mitigation only
HIGH 7.5
CVE-2017-3137EPSS 9%
Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a sit…
Enterprise Linux Desktop
Mitigation only
HIGH 7.5
CVE-2017-3144EPSS 73%
A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors availabl…
Enterprise Linux Desktop
Mitigation only
MEDIUM 5.9
CVE-2017-3135EPSS 17%
Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to eithe…
Enterprise Linux Desktop
Mitigation only
HIGH 8.1
CVE-2018-14657
A flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force detection algorithm will not …
Keycloak
Mitigation only
MEDIUM 6.1
CVE-2018-14658
A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.Red…
Keycloak
Mitigation only
MEDIUM 5.4
CVE-2018-14655
A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible to inject arbitrary Javascrip…
Keycloak
Mitigation only
HIGH 7.8
CVE-2018-19215
Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for the special cases of the % and $ and !…
Enterprise Linux
No fix yet
MEDIUM 6.5
CVE-2018-19208
In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a d…
Enterprise Linux
No fix yet
MEDIUM 5.5
CVE-2018-19139
An issue has been found in JasPer 2.0.14. There is a memory leak in jas_malloc.c when called from jpc_unk_getparms in jpc_cs.c.
Fedora
No fix yet
HIGH 8.8
CVE-2016-5402EPSS 6%
A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with acces…
Cloudforms
Mitigation only
MEDIUM 5.5
CVE-2016-2121
A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitive informat…
Openstack
Mitigation only
HIGH 7.8
CVE-2016-10729
An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binar…
Enterprise Linux
No fix yet