Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2018-12827EPSS 32%
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
Enterprise Linux Desktop
after 30.0.0.154
MEDIUM 5.9
CVE-2018-12824EPSS 11%
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
Enterprise Linux Desktop
after 30.0.0.154
MEDIUM 6.5
CVE-2017-15419
Insufficient policy enforcement in Resource Timing API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to infer browsing history by …
Enterprise Linux Desktop
63.0.3239.84+
MEDIUM 6.5
CVE-2017-15416
Heap buffer overflow in Blob API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafte…
Enterprise Linux Desktop
63.0.3239.84+
HIGH 8.8
CVE-2017-15413
Type confusion in WebAssembly in V8 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a cra…
Enterprise Linux Desktop
63.0.3239.84+
HIGH 8.8
CVE-2017-15412
Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potentially e…
Enterprise Linux Desktop
2.9.5 / 63.0.3239.84+
HIGH 7.5
CVE-2017-15139
A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configura…
Openstack
after 12.0.4-7
MEDIUM 6.5
CVE-2017-2635
A NULL pointer deference flaw was found in the way libvirt from 2.5.0 to 3.0.0 handled empty drives. A remote authenticated attacker could use this f…
Libvirt
after 3.0.0
HIGH 8.2
CVE-2017-2627
A flaw was found in openstack-tripleo-common as shipped with Red Hat Openstack Enterprise 10 and 11. The sudoers file as installed with OSP's opensta…
Openstack
Mitigation only
MEDIUM 6.5
CVE-2017-7528
Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection. It was found that X-Forwarded-For header allows…
Ansible Tower
Mitigation only
MEDIUM 5.4
CVE-2017-7513
It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fiel…
Satellite
Mitigation only
HIGH 8.8
CVE-2018-10884
Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could expl…
Ansible Tower
after 3.2.6
MEDIUM 5.9
CVE-2018-10844
It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to …
Enterprise Linux Desktop
3.6.12+
MEDIUM 5.9
CVE-2018-10845
It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to …
Enterprise Linux Desktop
3.6.12+
MEDIUM 5.6
CVE-2018-10846
A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a c…
Enterprise Linux Desktop
3.6.12+
HIGH 7.5
CVE-2018-1517
A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack w…
Satellite
Mitigation only
MEDIUM 6.5
CVE-2018-1656
The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Technology Edition 6.0 , 7.0, and 8.0) does not protec…
Satellite
Patch available
MEDIUM 5.5
CVE-2015-5160
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sen…
Virtualization
Mitigation only
MEDIUM 6.5
CVE-2016-9596
libxml2, as used in Red Hat JBoss Core Services and when in recovery mode, allows context-dependent attackers to cause a denial of service (stack con…
Jboss Core Services
2.9.4+
MEDIUM 6.5
CVE-2016-9598
libxml2, as used in Red Hat JBoss Core Services, allows context-dependent attackers to cause a denial of service (out-of-bounds read and application …
Jboss Core Services
2.9.4+
MEDIUM 6.2
CVE-2018-10864
An uncontrolled resource consumption flaw has been discovered in redhat-certification in the way documents are loaded. A remote attacker may provide …
Certification
Mitigation only
MEDIUM 5.0
CVE-2017-15138
The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook…
Openshift Container Platform
Patch available
CRITICAL 9.8
CVE-2018-10931EPSS 68%
It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use…
Satellite
after 2.6.11
HIGH 7.5
CVE-2018-10915EPSS 5%
A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections…
Openstack
Patch available
MEDIUM 6.3
CVE-2018-10908
It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By uploading a specially crafted image…
Virtualization
4.20.37+
HIGH 7.5
CVE-2018-5390EPSS 74%
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet…
Virtualization
4.18+
HIGH 8.1
CVE-2016-8609
It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing …
Keycloak
2.3.0+
HIGH 8.1
CVE-2018-10897EPSS 6%
A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration fil…
Virtualization
after 1.1.31
HIGH 7.8
CVE-2016-9583
An out-of-bounds heap read vulnerability was found in the jpc_pi_nextpcrl() function of jasper before 2.0.6 when processing crafted input.
Enterprise Linux Desktop
2.0.6+
MEDIUM 5.4
CVE-2018-10894
It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to acce…
Keycloak
Patch available