Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.3
CVE-2017-2614
When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is ex…
Enterprise Virtualization
Mitigation only
MEDIUM 6.5
CVE-2017-2595
It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path trave…
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 6.5
CVE-2017-2666
It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction w…
Undertow
Mitigation only
CRITICAL 9.8
CVE-2017-7470
It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorizati…
Spacewalk
Mitigation only
HIGH 7.5
CVE-2017-2639
It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communica…
Cloudforms
Mitigation only
MEDIUM 5.5
CVE-2017-2622
An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malic…
Openstack
Mitigation only
CRITICAL 9.8
CVE-2017-7464
It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use thi…
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 6.5
CVE-2017-12171EPSS 8%
A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines…
Enterprise Linux
Mitigation only
CRITICAL 9.0
CVE-2017-2589
It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored …
Jboss Fuse
Mitigation only
CRITICAL 10.0
CVE-2017-2637
A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed…
Openstack
Mitigation only
HIGH 8.2
CVE-2017-3224
Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNum…
Package Manager
No fix yet
HIGH 7.8
CVE-2018-10905
CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with access to an…
Cloudforms
Mitigation only
CRITICAL 9.8
CVE-2018-10870EPSS 6%
redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any fil…
Certification
Mitigation only
HIGH 7.5
CVE-2018-10869
redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file access…
Certification
Mitigation only
MEDIUM 5.3
CVE-2017-15137
The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a…
Openshift
Mitigation only
HIGH 7.8
CVE-2018-10875
A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module pat…
Ansible Engine
Mitigation only
HIGH 7.8
CVE-2018-10874
In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's con…
Ansible Engine
Mitigation only
CRITICAL 9.8
CVE-2017-7465
It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw …
Jboss Enterprise Application Platform
Mitigation only
CRITICAL 9.8
CVE-2018-5183
Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and…
Enterprise Linux Desktop
Mitigation only
MEDIUM 6.5
CVE-2018-5185
Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird…
Enterprise Linux Desktop
Mitigation only
HIGH 7.5
CVE-2018-5157
Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow th…
Enterprise Linux Desktop
Mitigation only
HIGH 7.5
CVE-2018-5162
Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Th…
Enterprise Linux Desktop
Mitigation only
HIGH 8.8
CVE-2018-5146EPSS 12%
An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.…
Enterprise Linux Desktop
Mitigation only
HIGH 7.8
CVE-2016-8656
Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local p…
Jboss Enterprise Application Platform
Mitigation only
HIGH 8.8
CVE-2018-1131
Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticat…
Jboss Data Grid
Mitigation only
MEDIUM 6.5
CVE-2016-8627
admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be available via …
Jboss Enterprise Application Platform
Mitigation only
CRITICAL 9.8
CVE-2018-10683
An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successful…
Wildfly
No fix yet
HIGH 8.8
CVE-2013-0185
Cross-site request forgery (CSRF) vulnerability in ManageIQ Enterprise Virtualization Manager (EVM) allows remote attackers to hijack the authenticat…
Manageiq Enterprise Virtualization Manager
No fix yet
HIGH 7.5
CVE-2013-2049
Red Hat CloudForms 2 Management Engine (CFME) allows remote attackers to conduct session tampering attacks by leveraging use of a static secret_token…
Cloudforms Management Engine
Mitigation only
MEDIUM 5.5
CVE-2018-10534
The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU B…
Enterprise Linux Desktop
Mitigation only