Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2013-1820
tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.
Tuned
2.0.2+
MEDIUM 5.5
CVE-2019-3866
An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world…
Openstack Mistral
Mitigation only
MEDIUM 6.5
CVE-2008-5083
In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBoss ON.
Jboss Operations Network
2.1.2+
HIGH 7.8
CVE-2008-3278
frysk packages through 2008-08-05 as shipped in Red Hat Enterprise Linux 5 are built with an insecure RPATH set in the ELF header of multiple binarie…
Frysk
after 2008-08-05
MEDIUM 6.1
CVE-2016-1000037
Pagure: XSS possible in file attachment endpoint
Pagure
2.3.4+
MEDIUM 5.5
CVE-2014-8181
The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace.
Enterprise Linux
Mitigation only
HIGH 7.5
CVE-2010-2222
The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a denial of service (NULL pointe…
Directory Server
Patch available
MEDIUM 5.9
CVE-2013-5661
Cache Poisoning issue exists in DNS Response Rate Limiting.
Enterprise Linux
1.3.0+
HIGH 7.1
CVE-2013-4374
An insecurity temporary file vulnerability exists in RHQ Mongo DB Drift Server through 2013-09-25 when unpacking zipped files.
Rhq Mongo Db Drift Server
after 2013-09-25
CRITICAL 9.8
CVE-2015-8980EPSS 7%
The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code.
Enterprise Linux
1.0.12+
HIGH 7.8
CVE-2017-5332
The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cau…
Enterprise Linux
Patch available
HIGH 7.8
CVE-2017-5333
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a d…
Enterprise Linux
Patch available
MEDIUM 5.5
CVE-2013-4280
Insecure temporary file vulnerability in RedHat vsdm 4.9.6.
Virtual Desktop Server Manager
No fix yet
MEDIUM 6.1
CVE-2014-3649
JBoss AeroGear has reflected XSS via the password field
Jboss Aerogear
after 2014-09-19
MEDIUM 5.5
CVE-2013-4423
CloudForms stores user passwords in recoverable format
Cloudforms
Mitigation only
MEDIUM 5.5
CVE-2013-4518
RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates
Update Infrastructure
No fix yet
HIGH 7.5
CVE-2019-6470EPSS 9%
There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in …
Enterprise Linux
No fix yet
HIGH 7.3
CVE-2013-0165
cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp.
Openshift
Mitigation only
MEDIUM 6.1
CVE-2013-0186
Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspecified ve…
Cloudforms
Mitigation only
MEDIUM 5.9
CVE-2013-2255
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL cert…
Openstack
Mitigation only
CRITICAL 9.1
CVE-2010-2548
IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.
Icedtea6
1.7.4+
CRITICAL 9.1
CVE-2010-2783
IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services.
Icedtea6
1.7.4+
HIGH 8.0
CVE-2010-0737
A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON u…
Jboss Operations Network
2.3.1+
CRITICAL 9.1
CVE-2019-17631
From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privil…
Satellite
after 0.16.0
MEDIUM 6.8
CVE-2019-2989
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7…
Enterprise Linux Desktop
after 11.50.2
HIGH 7.5
CVE-2019-14832
A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authent…
Keycloak
7.0.1+
HIGH 7.4
CVE-2019-14823
A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly tru…
Enterprise Linux
after 4.6.2
MEDIUM 5.5
CVE-2019-14858
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters mar…
Ansible Engine
after 3.5.0
MEDIUM 5.3
CVE-2019-6465
Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 …
Enterprise Linux
after 9.13.6
HIGH 7.8
CVE-2019-14846
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level whi…
Ansible Engine
2.6.20 / 2.7.14+