Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2017-3072
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the BitmapData class. Successful exploitati…
Enterprise Linux
after 25.0.0.163
HIGH 8.8
CVE-2017-3073
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability when handling multiple mask properties of display…
Enterprise Linux
after 25.0.0.163
HIGH 8.8
CVE-2017-3074
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Graphics class. Successful exploitation…
Enterprise Linux
after 25.0.0.163
HIGH 7.5
CVE-2017-7957
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during…
Fuse
after 1.4.9
HIGH 8.3
CVE-2017-3512
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 7u131 and 8u121. Diff…
Icedtea
3.4.0+
MEDIUM 5.3
CVE-2016-3702
Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext information.
Cloudforms Management Engine
Mitigation only
MEDIUM 5.4
CVE-2016-6519
Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authenticated users to inject arbitr…
Openstack
after 2.5
HIGH 8.8
CVE-2016-5401
Cross-site request forgery (CSRF) vulnerability in Red Hat JBoss BRMS and BPMS 6 allows remote attackers to hijack the authentication of users for re…
Jboss Bpm Suite
Mitigation only
MEDIUM 6.1
CVE-2016-6347
Cross-site scripting (XSS) vulnerability in the default exception handler in RESTEasy allows remote attackers to inject arbitrary web script or HTML …
Resteasy
Mitigation only
HIGH 7.5
CVE-2016-5409
Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which makes it easier for remote atta…
Openshift
Mitigation only
MEDIUM 6.8
CVE-2016-6338
ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate atta…
Enterprise Virtualization
No fix yet
MEDIUM 5.5
CVE-2016-5410
firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations via the (1) addPassthrough, (…
Enterprise Linux Desktop
after 0.4.3.2
HIGH 7.5
CVE-2016-6489EPSS 5%
The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack.
Enterprise Linux Desktop
3.3+
HIGH 7.5
CVE-2016-4970EPSS 11%
handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (…
Jboss Data Grid
4.0.37 / 4.1.1+
MEDIUM 6.1
CVE-2016-2104
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the …
Satellite
Mitigation only
MEDIUM 6.1
CVE-2016-6348
JacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack.
Resteasy
Mitigation only
HIGH 7.5
CVE-2016-4459
Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9.
Mod Cluster
Mitigation only
HIGH 7.0
CVE-2016-4444
The allow_execmod plugin for setroubleshoot before 3.2.23 allows local users to execute arbitrary commands by triggering an execmod SELinux denial wi…
Enterprise Linux Desktop
after 3.2.22
HIGH 7.0
CVE-2016-4445
The fix_lookup_id function in sealert in setroubleshoot before 3.2.23 allows local users to execute arbitrary commands as root by triggering an SELin…
Enterprise Linux Desktop
after 3.2.22
HIGH 7.0
CVE-2016-4446
The allow_execstack plugin for setroubleshoot allows local users to execute arbitrary commands by triggering an execstack SELinux denial with a craft…
Enterprise Linux Desktop
Patch available
HIGH 7.0
CVE-2016-4989
setroubleshoot allows local users to bypass an intended container protection mechanism and execute arbitrary commands by (1) triggering an SELinux de…
Enterprise Linux Desktop
Patch available
CRITICAL 9.8
CVE-2008-7313
The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CV…
Openstack
after 4.2.3
CRITICAL 9.8
CVE-2014-5008
Snoopy allows remote attackers to execute arbitrary commands.
Openstack
Patch available
CRITICAL 9.8
CVE-2014-5009
Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.
Openstack
after 4.2.3
HIGH 7.5
CVE-2016-7797
Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthent…
Enterprise Linux High Availability
after 1.1.14
CRITICAL 9.8
CVE-2017-5929EPSS 8%
QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.
Satellite
1.2.0+
HIGH 8.8
CVE-2016-3616
The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitra…
Enterprise Linux
Mitigation only
HIGH 7.8
CVE-2016-2568
pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters t…
Enterprise Linux
Mitigation only
CRITICAL 9.8
CVE-2016-9636EPSS 9%
Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a…
Enterprise Linux Desktop
after 1.10.1
CRITICAL 9.8
CVE-2016-9634EPSS 9%
Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a…
Enterprise Linux Desktop
after 1.10.1