Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.1
CVE-2014-3702
Directory traversal vulnerability in eNovance eDeploy allows remote attackers to create arbitrary directories and files and consequently cause a deni…
Edeploy
Mitigation only
HIGH 7.5
CVE-2014-7851
oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowle…
Ovirt Engine
Mitigation only
MEDIUM 6.1
CVE-2014-0029
Multiple cross-site scripting (XSS) vulnerabilities in the SAM web application in Red Hat katello-headpin allow remote attackers to inject arbitrary …
Subscription Asset Manager
Mitigation only
CRITICAL 9.8
CVE-2017-12149 KEVEPSS 91%
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessF…
Jboss Enterprise Application Platform
Mitigation only
CRITICAL 9.1
CVE-2015-7544
redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the Supe…
Enterprise Virtualization Manager
Mitigation only
HIGH 8.8
CVE-2015-5182
Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ.
Amq
Mitigation only
MEDIUM 6.5
CVE-2015-5248
Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform.
Feedhenry Enterprise Mobile Application Platform
No fix yet
MEDIUM 5.5
CVE-2017-7560
It was found that rhnsd PID files are created as world-writable that allows local attackers to fill the disks or to kill selected processes.
Rhnsd
Mitigation only
MEDIUM 6.5
CVE-2014-8163
Directory traversal vulnerability in the XMLRPC interface in Red Hat Satellite 5.
Satellite
No fix yet
MEDIUM 6.1
CVE-2014-0141
Cross-site scripting (XSS) vulnerability in Red Hat Satellite 6.0.3.
Satellite
No fix yet
MEDIUM 6.1
CVE-2014-8168
Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.
Satellite
Mitigation only
MEDIUM 5.3
CVE-2016-6311
Get requests in JBoss Enterprise Application Platform (EAP) 7 disclose internal IP addresses to remote attackers.
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 6.1
CVE-2016-3113
Cross-site scripting (XSS) vulnerability in ovirt-engine allows remote attackers to inject arbitrary web script or HTML.
Ovirt Engine
Mitigation only
MEDIUM 5.5
CVE-2015-3149
The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitrary files via a symlink attack.
Enterprise Linux Desktop
Mitigation only
HIGH 7.5
CVE-2015-3198
The Undertow module of WildFly 9.x before 9.0.0.CR2 and 10.x before 10.0.0.Alpha1 allows remote attackers to obtain the source code of a JSP page via…
Jboss Wildfly Application Server
Mitigation only
HIGH 7.0
CVE-2016-4996
discovery-debug in Foreman before 6.2 when the ssh service has been enabled on discovered nodes displays the root password in plaintext in the system…
Satellite
Mitigation only
CRITICAL 9.8
CVE-2017-7512
Red Hat 3scale (aka RH-3scale) API Management Platform (AMP) before 2.0.0 would permit creation of an access token without a client secret. An attack…
3scale Api Management Platform
Mitigation only
HIGH 7.8
CVE-2015-1795
Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root.
Gluster Storage
Mitigation only
HIGH 7.8
CVE-2016-7062
rhscon-ceph in Red Hat Storage Console 2 x86_64 and Red Hat Storage Console Node 2 x86_64 allows local users to obtain the password as cleartext.
Storage Console
Mitigation only
HIGH 7.5
CVE-2017-9953
There is an invalid free in Image::printIFDStructure that leads to a Segmentation fault in Exiv2 0.26. A crafted input will lead to a remote denial o…
Enterprise Linux
No fix yet
CRITICAL 9.8
CVE-2016-5411
/var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created world readable and contains the …
Quickstart Cloud Installer
Mitigation only
CRITICAL 9.8
CVE-2016-5405
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server …
Enterprise Linux Desktop
Mitigation only
CRITICAL 9.8
CVE-2016-7050EPSS 5%
SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and R…
Enterprise Linux Desktop
Mitigation only
HIGH 7.5
CVE-2016-3099
mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Wo…
Enterprise Linux Desktop
Mitigation only
HIGH 7.5
CVE-2016-5416
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server …
Enterprise Linux Desktop
Mitigation only
CRITICAL 9.8
CVE-2016-3690EPSS 5%
The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.
Jboss Enterprise Application Platform
Mitigation only
HIGH 7.5
CVE-2016-4457
CloudForms Management Engine before 5.8 includes a default SSL/TLS certificate.
Cloudforms Management Engine
No fix yet
MEDIUM 6.5
CVE-2016-3077
The VersionMapper.fromKernelVersionString method in oVirt Engine allows remote authenticated users to cause a denial of service (process crash) for a…
Ovirt Engine
Mitigation only
CRITICAL 9.8
CVE-2017-7503
It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use th…
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 5.3
CVE-2016-3702
Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext information.
Cloudforms Management Engine
Mitigation only