Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2017-7465
It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw …
Jboss Enterprise Application Platform
Mitigation only
HIGH 7.5
CVE-2018-3760EPSS 27%
There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially craft…
Cloudforms
after 3.7.1
CRITICAL 9.8
CVE-2018-1072
ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the option…
Enterprise Virtualization Manager
4.2.2+
HIGH 8.0
CVE-2017-7466
Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An attacker with control over a cl…
Ansible
2.3+
MEDIUM 6.5
CVE-2017-2668
389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote…
Enterprise Linux Desktop
1.3.5.17 / 1.3.6.10+
HIGH 8.8
CVE-2017-2672
A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file woul…
Satellite
1.15+
CRITICAL 9.8
CVE-2018-1117
ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/Clou…
Enterprise Virtualization
1.0.6+
MEDIUM 5.3
CVE-2018-1073
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an a…
Virtualization
4.2.3+
CRITICAL 9.8
CVE-2018-12532EPSS 7%
JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and exec…
Richfaces
after 4.5.17
CRITICAL 9.8
CVE-2018-12533EPSS 19%
JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java…
Richfaces
after 3.3.4
CRITICAL 9.8
CVE-2018-1085
openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificate authentication to be disabl…
Openshift Container Platform
3.9.31+
HIGH 7.8
CVE-2018-5848
In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_le…
Virtualization Host
Patch available
MEDIUM 6.5
CVE-2018-1103
Openshift Enterprise source-to-image before version 1.1.10 is vulnerable to an improper validation of user input. An attacker who could trick a user …
Source To Image
1.1.10+
HIGH 7.5
CVE-2018-1070
routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which can cause an entire shard to b…
Openshift Container Platform
3.10+
CRITICAL 9.8
CVE-2018-5183
Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and…
Enterprise Linux Desktop
Mitigation only
MEDIUM 6.5
CVE-2018-5185
Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird…
Enterprise Linux Desktop
Mitigation only
HIGH 7.5
CVE-2018-5157
Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow th…
Enterprise Linux Desktop
Mitigation only
HIGH 7.5
CVE-2018-5162
Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Th…
Enterprise Linux Desktop
Mitigation only
HIGH 8.8
CVE-2018-5146EPSS 12%
An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.…
Enterprise Linux Desktop
Mitigation only
HIGH 7.3
CVE-2018-5144
An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affec…
Enterprise Linux Desktop
52.7.0+
HIGH 8.8
CVE-2018-5127EPSS 8%
A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentially exploitable crash. This vul…
Enterprise Linux Desktop
52.7.0 / 59.0+
HIGH 8.8
CVE-2017-7846
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in th…
Enterprise Linux Desktop
52.5.2+
MEDIUM 5.3
CVE-2017-7848
RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2.
Enterprise Linux
52.5.2+
CRITICAL 9.8
CVE-2017-7824
A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. This is due to an incorrect va…
Enterprise Linux Aus
52.4.0 / 56.0+
MEDIUM 5.4
CVE-2017-7823
The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-ori…
Enterprise Linux Desktop
52.4.0 / 56.0+
MEDIUM 5.3
CVE-2017-7829
It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not d…
Enterprise Linux Aus
52.5.2+
CRITICAL 9.8
CVE-2017-7818
A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applications (ARIA) elements within containers through …
Enterprise Linux Desktop
52.4.0 / 56.0+
CRITICAL 9.8
CVE-2017-7819
A use-after-free vulnerability can occur in design mode when image objects are resized if objects referenced during the resizing have been freed from…
Enterprise Linux Desktop
52.4.0 / 56.0+
HIGH 7.8
CVE-2017-7814
File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature …
Enterprise Linux Desktop
52.4.0 / 56.0+
HIGH 7.5
CVE-2017-7803
When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This results in the incorrect enforc…
Enterprise Linux Desktop
52.3.0 / 55.0+