Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2017-7758
An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use. This vu…
Enterprise Linux Desktop
52.2.0 / 54.0+
HIGH 7.5
CVE-2017-7762
When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing…
Enterprise Linux Desktop
54.0+
HIGH 7.5
CVE-2017-5467
A potential memory corruption and crash when using Skia content when drawing content outside of the bounds of a clipping region. This vulnerability a…
Enterprise Linux Desktop
52.1 / 52.1.0+
MEDIUM 6.1
CVE-2017-5466
If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the rel…
Enterprise Linux
52.1.0 / 53.0+
CRITICAL 9.8
CVE-2017-5456
A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an IPC message. This allows for…
Enterprise Linux
52.1.0 / 53.0+
CRITICAL 9.8
CVE-2017-5459
A buffer overflow in WebGL triggerable by web content, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, F…
Enterprise Linux Desktop
45.9.0 / 52.1.0+
HIGH 7.5
CVE-2017-5449
A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS animations. This vulnerabilit…
Enterprise Linux
52.1.0 / 53.0+
HIGH 7.5
CVE-2017-5454
A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file …
Enterprise Linux
52.1.0 / 53.0+
HIGH 7.5
CVE-2017-5455
The internal feed reader APIs that crossed the sandbox barrier allowed for a sandbox escape and escalation of privilege if combined with another vuln…
Enterprise Linux
52.1.0 / 53.0+
CRITICAL 9.8
CVE-2017-5428
An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental exten…
Enterprise Linux
52.0.1+
CRITICAL 9.8
CVE-2017-5429
Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory co…
Enterprise Linux Desktop
45.9.0 / 52.1.0+
CRITICAL 9.8
CVE-2017-5430
Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we pr…
Enterprise Linux Desktop
52.1.0 / 53.0+
CRITICAL 9.8
CVE-2017-5434
A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially exploitable crash. This vulnerability affects Th…
Enterprise Linux Desktop
45.9.0 / 52.1.0+
CRITICAL 9.8
CVE-2017-5400
JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks.…
Enterprise Linux Desktop
45.8.0 / 52.0+
CRITICAL 9.8
CVE-2016-9901
HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-sa…
Enterprise Linux Aus
45.6.0 / 50.1+
CRITICAL 9.8
CVE-2017-5375EPSS 34%
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Thu…
Enterprise Linux Desktop
45.7.0 / 51.0.1+
HIGH 8.8
CVE-2016-9905
A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and …
Enterprise Linux Desktop
45.6.0+
HIGH 7.5
CVE-2016-9897
Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a varying array within libGLES.…
Enterprise Linux Server
45.6 / 45.6.0+
HIGH 7.5
CVE-2016-9902
The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allow…
Enterprise Linux Desktop
45.6.0 / 50.1+
HIGH 7.5
CVE-2016-9904
An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This …
Enterprise Linux Desktop
45.6.0 / 51.0+
HIGH 7.5
CVE-2018-12020EPSS 9%
mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof …
Enterprise Linux Desktop
Patch available
HIGH 7.5
CVE-2016-1000338
In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to…
Satellite
1.56+
MEDIUM 6.1
CVE-2018-11627
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
Cloudforms
2.0.2+
HIGH 7.8
CVE-2016-8656
Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local p…
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 5.5
CVE-2018-3639EPSS 61%
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory write…
Mrg Realtime
Patch available
MEDIUM 6.1
CVE-2018-1067
In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to t…
Undertow
1.4.25 / 2.0.5+
CRITICAL 9.8
CVE-2018-4944EPSS 9%
Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary …
Enterprise Linux Desktop
after 29.0.0.140
CRITICAL 9.8
CVE-2018-11236EPSS 7%
stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath functi…
Virtualization Host
after 2.27
HIGH 7.8
CVE-2018-11237
An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the targ…
Virtualization Host
after 2.27
HIGH 7.5
CVE-2018-5256
CoreOS Tectonic 1.7.x before 1.7.9-tectonic.4 and 1.8.x before 1.8.4-tectonic.3 mounts a direct proxy to the kubernetes cluster at /api/kubernetes/ w…
Tectonic
1.7.9-tectonic.4 / 1.8.4-tectonic.3+