Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.0
CVE-2016-4996
discovery-debug in Foreman before 6.2 when the ssh service has been enabled on discovered nodes displays the root password in plaintext in the system…
Satellite
Mitigation only
MEDIUM 6.2
CVE-2016-0764
Race condition in Network Manager before 1.0.12 as packaged in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enter…
Networkmanager
after 1.0.8
CRITICAL 9.8
CVE-2017-7512
Red Hat 3scale (aka RH-3scale) API Management Platform (AMP) before 2.0.0 would permit creation of an access token without a client secret. An attack…
3scale Api Management Platform
Mitigation only
HIGH 7.8
CVE-2015-1795
Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root.
Gluster Storage
Mitigation only
HIGH 7.8
CVE-2016-7062
rhscon-ceph in Red Hat Storage Console 2 x86_64 and Red Hat Storage Console Node 2 x86_64 allows local users to obtain the password as cleartext.
Storage Console
Mitigation only
HIGH 7.5
CVE-2017-9953
There is an invalid free in Image::printIFDStructure that leads to a Segmentation fault in Exiv2 0.26. A crafted input will lead to a remote denial o…
Enterprise Linux
No fix yet
HIGH 7.8
CVE-2015-3315
Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impact on arbitrary files via a sy…
Automatic Bug Reporting Tool
Patch available
HIGH 7.5
CVE-2015-3215
The NetKVM Windows Virtio driver allows remote attackers to cause a denial of service (guest crash) via a crafted length value in an IP packet, as de…
Virtio Win
Patch available
MEDIUM 5.5
CVE-2015-1870
The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which all…
Automatic Bug Reporting Tool
after 2.1.11
HIGH 7.8
CVE-2017-1000366
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially …
Enterprise Linux
Patch available
HIGH 7.0
CVE-2017-1000376
libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting the stack. Please note that lib…
Enterprise Virtualization Server
3.2+
CRITICAL 9.8
CVE-2016-5411
/var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created world readable and contains the …
Quickstart Cloud Installer
Mitigation only
CRITICAL 9.8
CVE-2016-5405
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server …
Enterprise Linux Desktop
Mitigation only
CRITICAL 9.8
CVE-2016-7050EPSS 5%
SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and R…
Enterprise Linux Desktop
Mitigation only
HIGH 7.5
CVE-2016-3099
mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Wo…
Enterprise Linux Desktop
Mitigation only
HIGH 7.5
CVE-2016-4992
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server …
Enterprise Linux Desktop
Patch available
HIGH 7.5
CVE-2016-5416
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server …
Enterprise Linux Desktop
Mitigation only
CRITICAL 9.8
CVE-2016-3690EPSS 5%
The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.
Jboss Enterprise Application Platform
Mitigation only
HIGH 8.8
CVE-2014-3498
The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands.
Ansible
after 1.6.5
HIGH 8.8
CVE-2016-4471
ManageIQ in CloudForms before 4.1 allows remote authenticated users to execute arbitrary code.
Cloudforms
after 4.0
HIGH 7.5
CVE-2016-4457
CloudForms Management Engine before 5.8 includes a default SSL/TLS certificate.
Cloudforms Management Engine
No fix yet
HIGH 7.8
CVE-2015-6240
The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow local users to escape a restricted environment via a symlink attack.
Ansible
after 1.9.1
MEDIUM 6.5
CVE-2017-9461
smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory…
Enterprise Linux Desktop
after 4.4.9
MEDIUM 6.5
CVE-2016-3077
The VersionMapper.fromKernelVersionString method in oVirt Engine allows remote authenticated users to cause a denial of service (process crash) for a…
Ovirt Engine
Mitigation only
CRITICAL 9.8
CVE-2017-7504EPSS 29%
HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Se…
Jboss Enterprise Application Platform
after 4.0
CRITICAL 9.8
CVE-2017-7503
It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use th…
Jboss Enterprise Application Platform
Mitigation only
HIGH 8.8
CVE-2017-3068EPSS 20%
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Advanced Video Coding engine. Successfu…
Enterprise Linux
after 25.0.0.163
HIGH 8.8
CVE-2017-3069
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the BlendMode class. Successful exploitatio…
Enterprise Linux
after 25.0.0.163
HIGH 8.8
CVE-2017-3070
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the ConvolutionFilter class. Successful exp…
Enterprise Linux
after 25.0.0.163
HIGH 8.8
CVE-2017-3071EPSS 6%
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability when masking display objects. Successful exploita…
Enterprise Linux
after 25.0.0.163