Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2016-5406
The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by…
Jboss Enterprise Application Platform
after 7.0.1
MEDIUM 6.1
CVE-2016-4993
CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before …
Jboss Enterprise Application Platform
after 7.0.1
HIGH 7.5
CVE-2016-3110
mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP mes…
Jboss Enterprise Application Platform
Mitigation only
HIGH 8.4
CVE-2016-6340
The kickstart file in Red Hat QuickStart Cloud Installer (QCI) forces use of MD5 passwords on deployed systems, which makes it easier for attackers t…
Quickstart Cloud Installer
Mitigation only
HIGH 8.4
CVE-2016-6322
Red Hat QuickStart Cloud Installer (QCI) uses world-readable permissions for /etc/qci/answers, which allows local users to obtain the root password f…
Quickstart Cloud Installer
Mitigation only
MEDIUM 5.5
CVE-2016-7166
libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory con…
Enterprise Linux Desktop
Patch available
MEDIUM 6.5
CVE-2016-5844
Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a crafted …
Enterprise Linux Desktop
Patch available
HIGH 7.5
CVE-2016-5418
The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to …
Enterprise Linux Desktop
Patch available
HIGH 7.5
CVE-2016-4809
The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a…
Enterprise Linux Desktop
Patch available
HIGH 7.8
CVE-2016-4302
Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to exe…
Enterprise Linux Desktop
after 3.2.0
HIGH 7.8
CVE-2016-4300
Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to exec…
Enterprise Linux Desktop
after 3.2.0
HIGH 8.8
CVE-2016-5422
The web console in Red Hat JBoss Operations Network (JON) before 3.3.7 does not properly authorize requests to add users with the super user role, wh…
Jboss Operations Network
after 3.3.6
HIGH 8.8
CVE-2016-7034
The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session and includes them in query s…
Jboss Bpm Suite
Mitigation only
MEDIUM 6.1
CVE-2016-7033
Multiple cross-site scripting (XSS) vulnerabilities in the admin pages in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 allow remote attackers to inje…
Jboss Bpm Suite
Mitigation only
HIGH 7.5
CVE-2016-6346EPSS 6%
RESTEasy enables GZIPInterceptor, which allows remote attackers to cause a denial of service via unspecified vectors.
Resteasy
Mitigation only
MEDIUM 6.5
CVE-2016-6345
RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.
Resteasy
Mitigation only
MEDIUM 5.3
CVE-2016-6344
Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attacke…
Jboss Bpm Suite
Mitigation only
HIGH 7.5
CVE-2016-2183EPSS 96%
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately…
Jboss Enterprise Application Platform
0.10.47 / 0.12.16+
HIGH 8.8
CVE-2016-5383
The web UI in Red Hat CloudForms 4.1 allows remote authenticated users to execute arbitrary code via vectors involving "Lack of field filters."
Cloudforms
Mitigation only
HIGH 8.8
CVE-2016-5766EPSS 7%
Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x b…
Openshift
Patch available
MEDIUM 6.5
CVE-2016-5392
The API server in Kubernetes, as used in Red Hat OpenShift Enterprise 3.2, in a multi tenant environment allows remote authenticated users with knowl…
Openshift
Mitigation only
CRITICAL 9.8
CVE-2016-4999
SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuil…
Dashbuilder
after 0.5.0
MEDIUM 6.1
CVE-2016-3097
Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML vi…
Satellite
Mitigation only
MEDIUM 6.1
CVE-2016-3080
Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML vi…
Satellite
Mitigation only
CRITICAL 9.8
CVE-2016-3737EPSS 7%
The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, relat…
Jboss Operations Network
after 3.3.5
HIGH 8.1
CVE-2016-5388EPSS 51%
Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not prote…
Enterprise Linux Desktop
Patch available
CRITICAL 9.8
CVE-2016-5008
libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers…
Libvirt
after 1.3.5
MEDIUM 6.5
CVE-2016-5009
The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph mon…
Ceph Storage Mon
after 0.94.6
HIGH 7.5
CVE-2016-4985
The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive informati…
Openstack
after 4.2.4
MEDIUM 5.4
CVE-2016-4428
Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allows remote authenticated users…
Openstack
after 8.0.1