Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2018-14638
A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function when persistent search connec…
Enterprise Linux Aus
1.3.8.4+
MEDIUM 5.4
CVE-2018-10937
A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods…
Openshift Container Platform
Patch available
HIGH 8.1
CVE-2018-1127
Tendrl API in Red Hat Gluster Storage before 3.4.0 does not immediately remove session tokens after a user logs out. Session tokens remain active for…
Gluster Storage
3.4+
MEDIUM 6.5
CVE-2018-10935
A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.
389 Directory Server
1.3.8.7 / 1.4.0.14+
MEDIUM 6.5
CVE-2018-1114
It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors…
Undertow
Mitigation only
HIGH 7.8
CVE-2016-7066
It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local u…
Jboss Enterprise Application Platform
7.1.0+
HIGH 8.0
CVE-2016-7070
A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trus…
Ansible Tower
3.0.3+
CRITICAL 9.8
CVE-2018-14620
The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could potentially…
Openstack
Mitigation only
MEDIUM 6.5
CVE-2018-14635
When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP add…
Openstack
after 12.0.3
HIGH 7.8
CVE-2016-7035
An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged accou…
Enterprise Linux Server
after 1.1.16
MEDIUM 6.5
CVE-2016-7041
Drools Workbench contains a path traversal vulnerability. The vulnerability allows a remote, authenticated attacker to bypass the directory restricti…
Jboss Brms
Mitigation only
MEDIUM 6.5
CVE-2016-7061
An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC…
Jboss Enterprise Application Platform
7.0.4+
HIGH 8.8
CVE-2016-7071
It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authent…
Cloudforms Management Engine
5.6.2.2 / 5.7.0.7+
HIGH 7.7
CVE-2018-14632
An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An a…
Openshift Container Platform
after 3.7
HIGH 7.5
CVE-2018-14624
A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the error log was not correctly u…
Enterprise Linux Desktop
after 1.4.0.16
HIGH 7.8
CVE-2018-16540
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in co…
Openshift Container Platform
Patch available
MEDIUM 5.5
CVE-2018-16542
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use insufficient interpreter stack-size checking during e…
Enterprise Linux
9.24+
MEDIUM 5.3
CVE-2016-1000232
NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial…
Openshift Container Platform
after 5.0.7.2
MEDIUM 6.5
CVE-2018-10930
A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw to write to a destination ou…
Enterprise Linux
3.12.14 / 4.1.4+
HIGH 8.8
CVE-2018-10926
A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to a…
Virtualization Host
3.12.14 / 4.1.8+
HIGH 8.1
CVE-2018-10923
It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker c…
Virtualization Host
3.12.14 / 4.1.8+
HIGH 7.5
CVE-2018-10911
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read…
Virtualization Host
3.12.14 / 4.1.8+
MEDIUM 6.5
CVE-2018-10913
An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine t…
Virtualization Host
3.12.14 / 4.1.8+
MEDIUM 6.5
CVE-2018-10914
It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote de…
Virtualization Host
3.12.14 / 4.1.8+
HIGH 8.8
CVE-2018-10907
It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size…
Virtualization Host
3.12.14 / 4.1.4+
HIGH 8.8
CVE-2018-10904
It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debu…
Virtualization Host
3.12.14 / 4.1.8+
MEDIUM 5.9
CVE-2018-14627
The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version…
Wildfly
14.0.0+
CRITICAL 9.8
CVE-2018-12825EPSS 7%
Adobe Flash Player 30.0.0.134 and earlier have a security bypass vulnerability. Successful exploitation could lead to security mitigation bypass.
Enterprise Linux Desktop
after 30.0.0.154
CRITICAL 9.8
CVE-2018-12828EPSS 7%
Adobe Flash Player 30.0.0.134 and earlier have a "use of a component with a known vulnerability" vulnerability. Successful exploitation could lead to…
Enterprise Linux Desktop
after 30.0.0.154
HIGH 7.5
CVE-2018-12826EPSS 7%
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
Enterprise Linux Desktop
after 30.0.0.154