Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2016-5401
Cross-site request forgery (CSRF) vulnerability in Red Hat JBoss BRMS and BPMS 6 allows remote attackers to hijack the authentication of users for re…
Jboss Bpm Suite
Mitigation only
MEDIUM 6.1
CVE-2016-6347
Cross-site scripting (XSS) vulnerability in the default exception handler in RESTEasy allows remote attackers to inject arbitrary web script or HTML …
Resteasy
Mitigation only
HIGH 7.5
CVE-2016-5409
Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which makes it easier for remote atta…
Openshift
Mitigation only
MEDIUM 6.8
CVE-2016-6338
ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate atta…
Enterprise Virtualization
No fix yet
MEDIUM 6.1
CVE-2016-2104
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the …
Satellite
Mitigation only
MEDIUM 6.1
CVE-2016-6348
JacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack.
Resteasy
Mitigation only
HIGH 7.5
CVE-2016-4459
Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9.
Mod Cluster
Mitigation only
HIGH 8.8
CVE-2016-3616
The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitra…
Enterprise Linux
Mitigation only
HIGH 7.8
CVE-2016-2568
pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters t…
Enterprise Linux
Mitigation only
CRITICAL 9.8
CVE-2014-8241
XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return …
Enterprise Linux Desktop
Mitigation only
HIGH 8.8
CVE-2016-7065EPSS 12%
The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and pos…
Jboss Enterprise Application Platform
No fix yet
HIGH 8.8
CVE-2016-7040
Red Hat CloudForms Management Engine 4.1 does not properly handle regular expressions passed to the expression engine via the JSON API and the web-ba…
Cloudforms Management Engine
Mitigation only
MEDIUM 5.9
CVE-2016-7046
Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause …
Jboss Enterprise Application Platform
Mitigation only
CRITICAL 9.8
CVE-2016-6330EPSS 11%
The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote a…
Jboss Operations Network
Mitigation only
HIGH 7.5
CVE-2016-3110
mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP mes…
Jboss Enterprise Application Platform
Mitigation only
HIGH 8.4
CVE-2016-6340
The kickstart file in Red Hat QuickStart Cloud Installer (QCI) forces use of MD5 passwords on deployed systems, which makes it easier for attackers t…
Quickstart Cloud Installer
Mitigation only
HIGH 8.4
CVE-2016-6322
Red Hat QuickStart Cloud Installer (QCI) uses world-readable permissions for /etc/qci/answers, which allows local users to obtain the root password f…
Quickstart Cloud Installer
Mitigation only
HIGH 8.8
CVE-2016-7034
The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session and includes them in query s…
Jboss Bpm Suite
Mitigation only
MEDIUM 6.1
CVE-2016-7033
Multiple cross-site scripting (XSS) vulnerabilities in the admin pages in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 allow remote attackers to inje…
Jboss Bpm Suite
Mitigation only
HIGH 7.5
CVE-2016-6346EPSS 6%
RESTEasy enables GZIPInterceptor, which allows remote attackers to cause a denial of service via unspecified vectors.
Resteasy
Mitigation only
MEDIUM 6.5
CVE-2016-6345
RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.
Resteasy
Mitigation only
MEDIUM 5.3
CVE-2016-6344
Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attacke…
Jboss Bpm Suite
Mitigation only
HIGH 8.8
CVE-2016-5383
The web UI in Red Hat CloudForms 4.1 allows remote authenticated users to execute arbitrary code via vectors involving "Lack of field filters."
Cloudforms
Mitigation only
MEDIUM 6.5
CVE-2016-5392
The API server in Kubernetes, as used in Red Hat OpenShift Enterprise 3.2, in a multi tenant environment allows remote authenticated users with knowl…
Openshift
Mitigation only
MEDIUM 6.1
CVE-2016-3097
Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML vi…
Satellite
Mitigation only
MEDIUM 6.1
CVE-2016-3080
Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML vi…
Satellite
Mitigation only
HIGH 8.8
CVE-2016-4474
The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterprise Linux OpenStack Platform…
Openstack
Mitigation only
CRITICAL 9.8
CVE-2016-4448EPSS 7%
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
Enterprise Linux Desktop
Mitigation only
HIGH 7.1
CVE-2016-2150
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to…
Enterprise Linux
Mitigation only
HIGH 8.8
CVE-2016-3738
Red Hat OpenShift Enterprise 3.2 does not properly restrict access to STI builds, which allows remote authenticated users to access the Docker socket…
Openshift
Mitigation only