Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2020-1700
A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making mult…
Openshift Container Storage
Mitigation only
HIGH 7.5
CVE-2013-4166
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does…
Enterprise Linux Desktop
after 3.9.5
HIGH 7.8
CVE-2014-8141EPSS 7%
Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a cra…
Enterprise Linux Desktop
after 6.0
HIGH 7.8
CVE-2014-8139EPSS 7%
Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafte…
Enterprise Linux Desktop
after 6.0
HIGH 7.8
CVE-2014-8140EPSS 7%
Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a cr…
Enterprise Linux Desktop
after 6.0
CRITICAL 9.8
CVE-2013-2060EPSS 6%
The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a req…
Openshift
No fix yet
HIGH 7.5
CVE-2012-5626
EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and…
Jboss Brms
Mitigation only
HIGH 7.5
CVE-2019-14888
A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to…
Undertow
after 2.0.28
HIGH 8.8
CVE-2019-3864
A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameter which i…
Quay
3.0.0+
MEDIUM 6.5
CVE-2019-19339
It was found that the Red Hat Enterprise Linux 8 kpatch update did not include the complete fix for CVE-2018-12207. A flaw was found in the way Intel…
Enterprise Linux
Mitigation only
HIGH 8.3
CVE-2019-9503
The Broadcom brcmfmac WiFi driver prior to commit a4176ec356c73a46c07c181c6d04039fafa34a9f is vulnerable to a frame validation bypass. If the brcmfma…
Enterprise Linux
Patch available
HIGH 8.1
CVE-2020-2604
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE…
Enterprise Linux
after 13.0.1
HIGH 8.8
CVE-2020-0603EPSS 20%
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfull…
Enterprise Linux
Patch available
HIGH 7.5
CVE-2020-0602EPSS 8%
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
Enterprise Linux
Patch available
HIGH 7.8
CVE-2015-1869
The default event handling scripts in Automatic Bug Reporting Tool (ABRT) allow local users to gain privileges as demonstrated by a symlink attack on…
Automatic Bug Reporting Tool
Patch available
HIGH 7.8
CVE-2015-3151
Directory traversal vulnerability in abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to read, write to, or change ownership of ar…
Automatic Bug Reporting Tool
Patch available
HIGH 7.8
CVE-2015-3159
The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) does not properly handle the process environment …
Automatic Bug Reporting Tool
Patch available
HIGH 7.1
CVE-2015-3150
abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory ar…
Automatic Bug Reporting Tool
Patch available
MEDIUM 6.5
CVE-2015-3147
daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to w…
Automatic Bug Reporting Tool
Patch available
HIGH 7.8
CVE-2014-7844
BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.
Enterprise Linux Desktop
Patch available
HIGH 7.8
CVE-2012-2142
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence…
Enterprise Linux
0.21.4+
HIGH 7.5
CVE-2014-2686
Ansible prior to 1.5.4 mishandles the evaluation of some strings.
Ansible
1.5.4+
CRITICAL 9.8
CVE-2019-14906
A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL pack…
Enterprise Linux
after 2.0.9
HIGH 8.8
CVE-2019-14819
A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to…
Openshift Container Platform
No fix yet
CRITICAL 9.1
CVE-2019-14837
A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name …
Keycloak
8.0.0+
HIGH 8.8
CVE-2019-14843
A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a mal…
Single Sign On
Patch available
HIGH 7.3
CVE-2019-14866
In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives fro…
Enterprise Linux
2.13+
MEDIUM 6.5
CVE-2019-14854
OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or hig…
Openshift Container Platform
No fix yet
MEDIUM 6.5
CVE-2014-3590
Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Therefore, an attacker can log …
Satellite
Mitigation only
MEDIUM 6.1
CVE-2014-0183
Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering.
Subscription Asset Manager
Mitigation only