Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2014-0241
rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable
Satellite
Mitigation only
CRITICAL 9.8
CVE-2014-0175
mcollective has a default password set at install
Openshift
Mitigation only
HIGH 8.8
CVE-2014-0197
CFME: CSRF protection vulnerability via permissive check of the referrer header
Cloudforms
after 5.9.3.1
MEDIUM 6.5
CVE-2019-16775
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of…
Enterprise Linux
6.13.3+
MEDIUM 5.4
CVE-2019-14849
A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to …
3scale
2.6+
HIGH 8.8
CVE-2014-0163
Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.
Openshift
Mitigation only
MEDIUM 6.5
CVE-2014-0026
katello-headpin is vulnerable to CSRF in REST API
Subscription Asset Manager
No fix yet
MEDIUM 6.1
CVE-2013-6495
JBossWeb Bayeux has reflected XSS
Jboss Enterprise Application Platform
6.1.0 / 6.1.1+
MEDIUM 6.1
CVE-2013-7370
node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware
Openshift
2.8.1+
CRITICAL 9.8
CVE-2013-2166
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
Openstack
after 0.2.5
CRITICAL 9.8
CVE-2013-2167
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass
Openstack
after 0.2.5
MEDIUM 6.1
CVE-2014-3656
JBoss KeyCloak: XSS in login-status-iframe.html
Jboss Keycloak
No fix yet
HIGH 7.5
CVE-2013-1793
openstack-utils openstack-db has insecure password creation
Openstack
Mitigation only
CRITICAL 9.8
CVE-2019-19333
In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "bits…
Enterprise Linux
Patch available
CRITICAL 9.8
CVE-2019-19334
In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "iden…
Enterprise Linux
Patch available
MEDIUM 6.5
CVE-2019-19624
An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifically, variable coarsest_scale is assumed to be greater than or equal to finest_s…
Enterprise Linux
4.1.1+
CRITICAL 9.8
CVE-2019-14910
A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDA…
Keycloak
Mitigation only
MEDIUM 5.5
CVE-2013-0163
OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS
Openshift
Mitigation only
HIGH 8.3
CVE-2019-14909
A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will…
Keycloak
Mitigation only
MEDIUM 6.5
CVE-2019-13456
In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iteratio…
Enterprise Linux
after 3.0.19
CRITICAL 9.8
CVE-2013-4486
Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging
Zanata
after 3.1.2
HIGH 8.1
CVE-2013-2103
OpenShift cartridge allows remote URL retrieval
Openshift
Mitigation only
MEDIUM 5.4
CVE-2013-2101
Katello has multiple XSS issues in various entities
Satellite
No fix yet
HIGH 8.6
CVE-2012-5562
A flaw was found in rhn-proxy. This vulnerability may allow the rhn-proxy to transmit user credentials in clear-text when it accesses RHN Satellite. …
Satellite
5.6+
MEDIUM 5.3
CVE-2011-2207
dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafte…
Enterprise Linux
2.1.0+
HIGH 7.8
CVE-2019-10216
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` rest…
3scale Api Management
Patch available
CRITICAL 9.8
CVE-2019-14842
Structured reply is a feature of the newstyle NBD protocol allowing the server to send a reply in chunks. A bounds check which was supposed to test f…
Libnbd
1.0.3+
MEDIUM 6.5
CVE-2019-14856
ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
Ansible
2.6.20 / 2.7.14+
HIGH 8.4
CVE-2019-14890
A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from …
Ansible Tower
Mitigation only
MEDIUM 6.5
CVE-2011-3609
A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for …
Jboss Application Server
Mitigation only