Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2016-9635EPSS 9%
Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a…
Enterprise Linux Desktop
after 1.10.1
HIGH 7.5
CVE-2016-9446
The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrate…
Enterprise Linux Desktop
1.11.1+
HIGH 7.8
CVE-2016-9675
openjpeg: A heap-based buffer overflow flaw was found in the patch for CVE-2013-6045. A crafted j2k image could cause the application to crash, or po…
Enterprise Linux
1.5.2+
CRITICAL 9.8
CVE-2014-8241
XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return …
Enterprise Linux Desktop
Mitigation only
MEDIUM 5.5
CVE-2016-4443
Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by r…
Enterprise Virtualization
Patch available
MEDIUM 6.0
CVE-2016-7466
Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator), when the xhci uses msix, allows local guest OS administr…
Openstack
after 2.7.1
MEDIUM 6.0
CVE-2016-7422
The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service …
Openstack
after 2.7.1
MEDIUM 6.0
CVE-2016-6835
The vmxnet_tx_pkt_parse_headers function in hw/net/vmxnet_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denia…
Virtualization
2.6.0+
HIGH 8.8
CVE-2016-7865EPSS 7%
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitatio…
Enterprise Linux Desktop
after 23.0.0.205
HIGH 8.8
CVE-2016-7864EPSS 7%
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitatio…
Enterprise Linux Desktop
after 23.0.0.205
HIGH 8.8
CVE-2016-7863EPSS 7%
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitatio…
Enterprise Linux Desktop
after 23.0.0.205
HIGH 8.8
CVE-2016-7862EPSS 7%
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitatio…
Enterprise Linux Desktop
after 23.0.0.205
HIGH 8.8
CVE-2016-7861EPSS 7%
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitatio…
Enterprise Linux Desktop
after 23.0.0.205
HIGH 8.8
CVE-2016-7860EPSS 7%
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitatio…
Enterprise Linux Desktop
after 23.0.0.205
HIGH 8.8
CVE-2016-7859EPSS 7%
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitatio…
Enterprise Linux Desktop
after 23.0.0.205
HIGH 8.8
CVE-2016-7858EPSS 7%
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitatio…
Enterprise Linux Desktop
after 23.0.0.205
HIGH 8.8
CVE-2016-7857EPSS 7%
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitatio…
Enterprise Linux Desktop
after 23.0.0.205
MEDIUM 6.0
CVE-2016-8669
The serial_update_parameters function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of serv…
Openstack
after 2.7.1
MEDIUM 6.0
CVE-2016-8576
The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (inf…
Openstack
after 2.7.1
HIGH 7.5
CVE-2016-8864EPSS 39%
named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (ass…
Enterprise Linux Desktop
9.9.9 / 9.10.4+
HIGH 8.8
CVE-2016-7855 KEVEPSS 25%
Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to …
Enterprise Linux Desktop
after 23.0.0.185
HIGH 8.8
CVE-2016-4286EPSS 6%
Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to…
Enterprise Linux Desktop
after 23.0.0.162
MEDIUM 5.5
CVE-2016-7796
The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received o…
Enterprise Linux Desktop
Patch available
HIGH 8.8
CVE-2016-7065EPSS 12%
The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and pos…
Jboss Enterprise Application Platform
No fix yet
MEDIUM 6.1
CVE-2016-1000007
Pagure 2.2.1 XSS in raw file endpoint
Pagure
Patch available
HIGH 8.8
CVE-2016-7040
Red Hat CloudForms Management Engine 4.1 does not properly handle regular expressions passed to the expression engine via the JSON API and the web-ba…
Cloudforms Management Engine
Mitigation only
MEDIUM 5.9
CVE-2016-7046
Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause …
Jboss Enterprise Application Platform
Mitigation only
HIGH 7.5
CVE-2016-7031
The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL.
Ceph Storage
after 10.0.0
MEDIUM 5.4
CVE-2016-5398
Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6.3.3 allows remote authenticated users to inje…
Jboss Bpm Suite
after 6.3.2
CRITICAL 9.8
CVE-2016-6330EPSS 11%
The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote a…
Jboss Operations Network
Mitigation only