Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2018-6104
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoo…
Linux Desktop
66.0.3359.117+
MEDIUM 6.5
CVE-2018-6105
Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing v…
Linux Desktop
66.0.3359.117+
MEDIUM 6.5
CVE-2018-6107
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoo…
Linux Desktop
66.0.3359.117+
MEDIUM 6.5
CVE-2018-6108
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoo…
Linux Desktop
66.0.3359.117+
HIGH 7.8
CVE-2018-16863
It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSA…
Enterprise Linux Desktop
Patch available
HIGH 8.1
CVE-2018-14637
The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit th…
Keycloak
4.6.0+
CRITICAL 9.8
CVE-2018-15981EPSS 12%
Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
Enterprise Linux Desktop
after 31.0.0.148
HIGH 7.5
CVE-2018-15978EPSS 7%
Flash Player versions 31.0.0.122 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
Enterprise Linux Desktop
after 31.0.0.122
HIGH 8.1
CVE-2018-14657
A flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force detection algorithm will not …
Keycloak
Mitigation only
MEDIUM 6.1
CVE-2018-14658
A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.Red…
Keycloak
Mitigation only
MEDIUM 5.4
CVE-2018-14655
A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible to inject arbitrary Javascrip…
Keycloak
Mitigation only
HIGH 7.8
CVE-2018-19214
Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for insufficient input.
Enterprise Linux
Patch available
HIGH 7.8
CVE-2018-19215
Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for the special cases of the % and $ and !…
Enterprise Linux
No fix yet
MEDIUM 6.5
CVE-2018-19208
In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a d…
Enterprise Linux
No fix yet
MEDIUM 5.5
CVE-2018-19139
An issue has been found in JasPer 2.0.14. There is a memory leak in jas_malloc.c when called from jpc_unk_getparms in jpc_cs.c.
Fedora
No fix yet
CRITICAL 9.8
CVE-2018-14667 KEVEPSS 74%
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticate…
Richfaces
after 3.3.4
HIGH 7.5
CVE-2018-16849
A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbit…
Openstack Mistral
7.0.1+
MEDIUM 6.5
CVE-2018-14660
A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated…
Virtualization Host
after 4.1.4
MEDIUM 6.5
CVE-2016-2125EPSS 9%
It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to wh…
Gluster Storage
4.3.13 / 4.4.8+
HIGH 8.8
CVE-2018-14653
The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the '__server_getspec' function via the 'gf_…
Gluster Storage
after 4.1.4
MEDIUM 6.5
CVE-2018-14652
The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' translator via the code handling t…
Gluster Storage
after 4.1.8
MEDIUM 6.5
CVE-2018-14654
The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attacker with access to mount volum…
Gluster Storage
after 4.1.4
MEDIUM 6.5
CVE-2018-14659
The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_XATTR_IOSTATS_DUMP_KEY' xattr…
Gluster File System
after 4.1.4
HIGH 8.8
CVE-2016-5402EPSS 6%
A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with acces…
Cloudforms
Mitigation only
MEDIUM 5.5
CVE-2016-2121
A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitive informat…
Openstack
Mitigation only
MEDIUM 5.4
CVE-2016-6343
JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that have privileges to access da…
Jboss Bpm Suite
6.4.2+
MEDIUM 6.6
CVE-2018-14665EPSS 27%
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server al…
Enterprise Linux Desktop
Patch available
HIGH 7.8
CVE-2016-10729
An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binar…
Enterprise Linux
No fix yet
HIGH 7.8
CVE-2016-10730
An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Applicatio…
Enterprise Linux
No fix yet
HIGH 7.8
CVE-2018-16837
Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases c…
Ansible Engine
Mitigation only