Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2015-8553
Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and I/O decodi…
Enterprise Linux
Patch available
HIGH 8.8
CVE-2016-1568
Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service…
Openstack
after 2.5.1.1
MEDIUM 5.1
CVE-2015-7502
Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.5.0 do not properly encrypt data in the backend P…
Cloudforms Management Engine
Mitigation only
HIGH 7.3
CVE-2015-5329
The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 7.0, do not properly use the configured R…
Openstack
Mitigation only
HIGH 7.5
CVE-2015-5229
The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 and 7.2 does not properly initialize memory areas, which might allow …
Enterprise Linux
Mitigation only
CRITICAL 9.8
CVE-2016-0791
Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to…
Openshift
after 1.649
HIGH 8.1
CVE-2016-1714EPSS 6%
The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware Configuration device emulati…
Openstack
after 2.3.0
HIGH 7.5
CVE-2016-0793EPSS 16%
Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Server) before 10.0.0.Final on …
Jboss Wildfly Application Server
No fix yet
HIGH 8.1
CVE-2016-0636EPSS 6%
Unspecified vulnerability in Oracle Java SE 7u97, 8u73, and 8u74 allows remote attackers to affect confidentiality, integrity, and availability via u…
Enterprise Linux Desktop
after 2.6.6
HIGH 8.8
CVE-2015-7537
Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication o…
Openshift
after 3.1
MEDIUM 6.8
CVE-2016-0505EPSS 8%
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.…
Enterprise Linux Desktop
after 5.7.9
MEDIUM 5.4
CVE-2015-5295
The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticat…
Openstack
5.0.1 / 2015.1.3+
CRITICAL 9.0
CVE-2015-7512EPSS 8%
Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial…
Enterprise Linux Desktop
Mitigation only
CRITICAL 9.8
CVE-2015-5254EPSS 38%
Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitr…
Openshift
Mitigation only
HIGH 8.8
CVE-2015-8651 KEVEPSS 68%
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Ad…
Enterprise Linux Desktop
11.2.202.559 / 18.0.0.324+
HIGH 7.5
CVE-2015-8327EPSS 10%
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows rem…
Enterprise Linux Desktop
Mitigation only
HIGH 7.2
CVE-2015-5277
The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow loc…
Enterprise Linux Desktop
after 2.19
MEDIUM 5.0
CVE-2015-5302
libreport 2.0.7 before 2.6.3 only saves changes to the first file when editing a crash report, which allows remote attackers to obtain sensitive info…
Libreport
Patch available
MEDIUM 6.9
CVE-2015-5287
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges vi…
Automatic Bug Reporting Tool
after 2.7.0
CRITICAL 9.8
CVE-2015-8103EPSS 87%
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized J…
Openshift Container Platform
1.625.2 / 1.638+
HIGH 7.5
CVE-2015-5325
Jenkins before 1.638 and LTS before 1.625.2 allow attackers to bypass intended slave-to-master access restrictions by leveraging a JNLP slave. NOTE: …
Openshift
after 3.1
MEDIUM 6.5
CVE-2015-5323
Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges …
Openshift
after 3.1
MEDIUM 5.0
CVE-2015-5322
Directory traversal vulnerability in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to list directory contents and read arbitrar…
Openshift
after 3.1
MEDIUM 5.0
CVE-2015-5321
The sidepanel widgets in the CLI command overview and help pages in Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sens…
Openshift
after 3.1
MEDIUM 5.0
CVE-2015-5320
Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, which allows remote attackers to…
Openshift
after 3.1
MEDIUM 5.0
CVE-2015-5319
XML external entity (XXE) vulnerability in the create-job CLI command in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to read …
Openshift
after 3.1
MEDIUM 6.0
CVE-2015-5242
OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authe…
Gluster Storage
Mitigation only
HIGH 7.2
CVE-2015-5225
Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of s…
Openstack
after 2.4.0
MEDIUM 6.4
CVE-2015-5305
Directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift Enterprise 3.0, allows attackers to write to arbitrary files via a craf…
Openshift
Mitigation only
MEDIUM 5.0
CVE-2015-5220
The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers…
Jboss Enterprise Application Platform
after 6.4.3