Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2017-2625
It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attack…
Enterprise Linux
1.1.2+
MEDIUM 5.3
CVE-2017-2623
It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages…
Enterprise Linux
2017.3+
HIGH 8.8
CVE-2017-12173
It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulner…
Enterprise Linux Desktop
1.16.0+
HIGH 8.6
CVE-2017-15119
The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a client sen…
Virtualization
2.11.0+
HIGH 7.2
CVE-2017-12148
A flaw was found in Ansible Tower's interface before 3.1.5 and 3.2.0 with SCM repositories. If a Tower project (SCM repository) definition does not h…
Ansible Tower
3.1.5 / 3.2.0+
MEDIUM 6.6
CVE-2017-15113
ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change th…
Virtualization
4.1.7.6+
HIGH 7.5
CVE-2017-12165
It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http…
Undertow
1.3.31 / 1.4.17+
HIGH 7.5
CVE-2017-2670
It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively ca…
Undertow
1.3.28+
MEDIUM 6.5
CVE-2017-2595
It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path trave…
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 5.4
CVE-2017-15125
A flaw was found in CloudForms before 5.9.0.22 in the self-service UI snapshot feature where the name field is not properly sanitized for HTML and Ja…
Cloudforms Management Engine
5.9.0.22+
MEDIUM 6.5
CVE-2017-2666
It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction w…
Undertow
Mitigation only
MEDIUM 5.5
CVE-2018-10862
WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives…
Virtualization
after 5.0.0
CRITICAL 9.8
CVE-2017-7470
It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorizati…
Spacewalk
Mitigation only
HIGH 7.5
CVE-2017-2639
It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communica…
Cloudforms
Mitigation only
MEDIUM 5.5
CVE-2017-2622
An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malic…
Openstack
Mitigation only
CRITICAL 9.8
CVE-2017-7464
It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use thi…
Jboss Enterprise Application Platform
Mitigation only
HIGH 7.4
CVE-2017-12150EPSS 13%
It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options w…
Enterprise Linux Desktop
4.4.16 / 4.5.14+
MEDIUM 6.5
CVE-2017-12171EPSS 8%
A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines…
Enterprise Linux
Mitigation only
MEDIUM 6.5
CVE-2017-2582
It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute …
Keycloak
2.5.1+
MEDIUM 5.5
CVE-2017-12167
It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role ma…
Jboss Enterprise Application Platform
7.0.9+
MEDIUM 5.4
CVE-2017-12175
Red Hat Satellite before 6.5 is vulnerable to a XSS in discovery rule when you are entering filter and you use autocomplete functionality.
Satellite
6.5+
HIGH 7.1
CVE-2017-12163EPSS 8%
An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A ma…
Enterprise Linux Desktop
4.4.16 / 4.5.14+
MEDIUM 6.5
CVE-2017-7509
An input validation error was found in Red Hat Certificate System's handling of client provided certificates before 8.1.20-1. If the certreq field is…
Certificate System
8.1.20-1+
CRITICAL 9.0
CVE-2017-2589
It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored …
Jboss Fuse
Mitigation only
MEDIUM 6.5
CVE-2017-7545
It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote a…
Decision Manager
Patch available
MEDIUM 6.5
CVE-2017-7562
An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A remote at…
Enterprise Linux
1.16.1+
MEDIUM 5.4
CVE-2017-7538
A cross-site scripting (XSS) flaw was found in how an organization name is displayed in Satellite 5, before 5.8. A user able to change an organizatio…
Satellite
5.8+
HIGH 7.5
CVE-2017-7539EPSS 6%
An assertion-failure flaw was found in Qemu before 2.10.1, in the Network Block Device (NBD) server's initial connection negotiation, where the I/O c…
Openstack
2.10.1+
MEDIUM 6.5
CVE-2017-2664
CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the rails application portion of Cl…
Cloudforms
5.7.3 / 5.8.1+
MEDIUM 5.9
CVE-2017-7543
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1,…
Openstack
7.2.0-12.1 / 8.3.0-11.1+