Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2017-1000253 KEVEPSS 11%
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committ…
Enterprise Linux
3.2.70 / 3.4.109+
CRITICAL 9.8
CVE-2017-12149 KEVEPSS 91%
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessF…
Jboss Enterprise Application Platform
Mitigation only
CRITICAL 9.8
CVE-2017-14491EPSS 85%
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafte…
Enterprise Linux Desktop
after 2.77
CRITICAL 9.8
CVE-2017-7552
A flaw was discovered in the file editor of millicore, affecting versions before 3.19.0 and 4.x before 4.5.0, which allows files to be executed as we…
Mobile Application Platform
after 4.4.3
MEDIUM 6.3
CVE-2017-7553
The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the netwo…
Mobile Application Platform
after 4.4.3
MEDIUM 6.1
CVE-2017-7554
It was found that the App Studio component of RHMAP 4.4 executes javascript provided by a user. An attacker could use this flaw to execute a stored X…
Mobile Application Platform
Patch available
CRITICAL 9.1
CVE-2015-7544
redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the Supe…
Enterprise Virtualization Manager
Mitigation only
HIGH 8.8
CVE-2015-5182
Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ.
Amq
Mitigation only
HIGH 7.5
CVE-2015-5183
Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ.
Amq
6.3+
HIGH 7.5
CVE-2015-5184
Console: CORS headers set to allow all in Red Hat AMQ.
Amq
6.2.1+
MEDIUM 5.4
CVE-2015-5181
The JBoss console in A-MQ allows remote attackers to execute arbitrary JavaScript.
Jboss A Mq
after 6.0
MEDIUM 6.5
CVE-2015-5248
Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform.
Feedhenry Enterprise Mobile Application Platform
No fix yet
MEDIUM 5.9
CVE-2015-1849
AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vect…
Jboss Enterprise Application Platform
after 6.4.0
MEDIUM 5.5
CVE-2015-7837
The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local …
Enterprise Linux
Patch available
CRITICAL 9.8
CVE-2014-8174
eDeploy makes it easier for remote attackers to execute arbitrary code by leveraging use of HTTP to download files.
Edeploy
after 1.11.0
HIGH 7.5
CVE-2017-1002151
Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization
Pagure
after 3.3
HIGH 7.5
CVE-2017-7561
Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component re…
Jboss Enterprise Application Platform
Patch available
MEDIUM 5.5
CVE-2017-7560
It was found that rhnsd PID files are created as world-writable that allows local attackers to fill the disks or to kill selected processes.
Rhnsd
Mitigation only
MEDIUM 6.5
CVE-2014-8163
Directory traversal vulnerability in the XMLRPC interface in Red Hat Satellite 5.
Satellite
No fix yet
MEDIUM 6.1
CVE-2014-0141
Cross-site scripting (XSS) vulnerability in Red Hat Satellite 6.0.3.
Satellite
No fix yet
MEDIUM 6.1
CVE-2014-8168
Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.
Satellite
Mitigation only
MEDIUM 5.9
CVE-2015-5293
Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which m…
Enterprise Virtualization Manager
after 3.6.0
MEDIUM 5.5
CVE-2016-6310
oVirt Engine discloses the ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD in /var/log/ovirt-engine/engine.log file in RHEV before 4.0.
Enterprise Virtualization
after 3.6
MEDIUM 5.3
CVE-2016-6311
Get requests in JBoss Enterprise Application Platform (EAP) 7 disclose internal IP addresses to remote attackers.
Jboss Enterprise Application Platform
Mitigation only
HIGH 8.8
CVE-2017-3106EPSS 22%
Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful exploitation c…
Enterprise Linux
after 26.0.0.137
HIGH 7.4
CVE-2017-3085
Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redi…
Enterprise Linux
after 26.0.0.137
HIGH 7.0
CVE-2014-0143
Multiple integer overflows in the block drivers in QEMU, possibly before 2.0.0, allow local users to cause a denial of service (crash) via a crafted …
Enterprise Linux
after 1.7.1
MEDIUM 6.1
CVE-2016-3113
Cross-site scripting (XSS) vulnerability in ovirt-engine allows remote attackers to inject arbitrary web script or HTML.
Ovirt Engine
Mitigation only
MEDIUM 5.5
CVE-2015-3149
The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitrary files via a symlink attack.
Enterprise Linux Desktop
Mitigation only
HIGH 7.5
CVE-2015-3198
The Undertow module of WildFly 9.x before 9.0.0.CR2 and 10.x before 10.0.0.Alpha1 allows remote attackers to obtain the source code of a JSP page via…
Jboss Wildfly Application Server
Mitigation only