Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2016-9579
A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A re…
Ceph Storage
Patch available
HIGH 7.2
CVE-2016-8648
It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX opera…
Jboss A Mq
Mitigation only
MEDIUM 5.4
CVE-2016-8608
JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via business process editor. The flaw is due to an incomplete fix for CVE-2016-5398. Remo…
Jboss Bpm Suite
Mitigation only
MEDIUM 5.3
CVE-2016-8653
It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this …
Jboss A Mq
Mitigation only
MEDIUM 5.9
CVE-2016-8635
It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement attack. An attacker could us…
Enterprise Linux Desktop
after 3.21.4
MEDIUM 5.4
CVE-2016-8639
It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privile…
Satellite
1.13.0+
HIGH 8.1
CVE-2016-9573
An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to another fo…
Enterprise Linux Desktop
Patch available
HIGH 7.5
CVE-2016-8614
A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create a…
Ansible
2.2.0+
CRITICAL 9.1
CVE-2016-8628
Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create speci…
Ansible
2.2.0+
HIGH 7.7
CVE-2016-8631
The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routes can pote…
Openshift
Mitigation only
HIGH 7.8
CVE-2016-8657
It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuratio…
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 6.5
CVE-2016-8626
A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ceph Object Gateway handles POST object requests permits an authenticated attacker to launc…
Ceph
0.94.3.9-8+
HIGH 8.8
CVE-2018-10898
A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Open…
Openstack
8.0.2-40+
HIGH 7.5
CVE-2018-10903
A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user …
Openstack
2.3+
HIGH 7.8
CVE-2017-7518
A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the trap flag(TF) bit in EFLAGS during emulation of the …
Enterprise Linux
Patch available
MEDIUM 5.4
CVE-2017-7514
A cross-site scripting (XSS) flaw was found in how the failed action entry is processed in Red Hat Satellite before version 5.8.0. A user able to spe…
Satellite
5.8.0+
CRITICAL 9.8
CVE-2017-15101
A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a den…
Enterprise Linux Desktop
2.5.4+
HIGH 7.8
CVE-2017-2663
It was found that subscription-manager's DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1.Facts.GetFacts and com.redhat…
Subscription Manager
1.19.4+
MEDIUM 6.7
CVE-2017-15097
Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could…
Enterprise Linux Desktop
Mitigation only
MEDIUM 6.5
CVE-2017-2633
An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshin…
Enterprise Linux Desktop
1.7.2+
MEDIUM 5.5
CVE-2017-2626
It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijac…
Enterprise Linux Desktop
after 1.0.9
HIGH 7.5
CVE-2017-2646
It was found that when Keycloak before 2.5.5 receives a Logout request with a Extensions in the middle of the request, the SAMLSloRequestParser.parse…
Keycloak
2.5.5+
MEDIUM 6.5
CVE-2017-2653
A number of unused delete routes are present in CloudForms before 5.7.2.1 which can be accessed via GET requests instead of just POST requests. This …
Cloudforms Management Engine
5.7.2.1+
MEDIUM 6.5
CVE-2017-2658
It was discovered that the Dashbuilder login page as used in Red Hat JBoss BPM Suite before 6.4.2 and Red Hat JBoss Data Virtualization & Services be…
Jboss Bpm Suite
6.4.2 / 6.4.3+
MEDIUM 6.1
CVE-2017-7463
JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a reflected XSS via artifact upload. A malformed XML file, if uploaded, causes an error m…
Jboss Bpm Suite
6.4.3+
MEDIUM 5.4
CVE-2017-2674
JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a stored XSS via several lists in Business Central. The flaw is due to lack of sanitation…
Jboss Bpm Suite
6.4.3+
HIGH 8.1
CVE-2017-2590
A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while mod…
Enterprise Linux
4.4.0+
MEDIUM 6.3
CVE-2017-2614
When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is ex…
Enterprise Virtualization
Mitigation only
MEDIUM 5.5
CVE-2016-9595
A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this fla…
Satellite
3.4.0+
MEDIUM 5.5
CVE-2017-2621
An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improp…
Openstack
8.0.0+