Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.8
CVE-2015-1220
Use-after-free vulnerability in the GIFImageReader::parseData function in platform/image-decoders/gif/GIFImageReader.cpp in Blink, as used in Google …
Enterprise Linux Desktop Supplementary
after 40.0.2214.115
HIGH 7.5
CVE-2015-1214
Integer overflow in the SkAutoSTArray implementation in include/core/SkTemplates.h in the filters implementation in Skia, as used in Google Chrome be…
Enterprise Linux Desktop Supplementary
after 40.0.2214.115
MEDIUM 5.0
CVE-2013-7423EPSS 6%
The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows re…
Enterprise Linux Server Aus
2.20+
HIGH 10.0
CVE-2015-0240EPSS 88%
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc…
Enterprise Linux
Mitigation only
MEDIUM 6.5
CVE-2014-8115
The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitrary files, bypass intended ac…
Kie Workbench
Patch available
MEDIUM 6.8
CVE-2014-8114
The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted conte…
Uberfire
Patch available
HIGH 7.5
CVE-2014-3682
XML external entity (XXE) vulnerability in the JBPMBpmn2ResourceImpl function in designer/bpmn2/resource/JBPMBpmn2ResourceImpl.java in jbpm-designer …
Jbpm Designer
Patch available
MEDIUM 6.8
CVE-2014-0151
Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for …
Ovirt Engine
after 3.5.0
MEDIUM 6.8
CVE-2014-9664
FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of servi…
Enterprise Linux Desktop
Patch available
HIGH 7.5
CVE-2014-9657EPSS 5%
The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers…
Enterprise Linux Desktop
Patch available
HIGH 7.5
CVE-2014-7942
The Fonts implementation in Google Chrome before 40.0.2214.91 does not initialize memory for a data structure, which allows remote attackers to cause…
Enterprise Linux Desktop Supplementary
after 40.0.2214.85
MEDIUM 5.0
CVE-2014-7941
The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner.cc in the UI implementation in Google Chrome before 40.0.2214.91 uses an inco…
Enterprise Linux Desktop Supplementary
after 40.0.2214.85
HIGH 7.5
CVE-2014-7926
The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.221…
Enterprise Linux Desktop Supplementary
after 40.0.2214.85
HIGH 7.5
CVE-2014-7923
The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.221…
Enterprise Linux Desktop Supplementary
55.1+
MEDIUM 6.5
CVE-2014-7814
SQL injection vulnerability in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 allows remote authenticated users to execute arbitrary SQL command…
Cloudforms 3.1 Management Engine
Mitigation only
HIGH 10.0
CVE-2014-3692
The customization template in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 uses a default password for the root account when a password is not…
Cloudforms 3.1 Management Engine
Mitigation only
MEDIUM 5.0
CVE-2014-0171
XML external entity (XXE) vulnerability in StaxXMLFactoryProvider2 in Odata4j, as used in Red Hat JBoss Data Virtualization before 6.0.0 patch 4, all…
Jboss Data Virtualization
after 6.0.0
MEDIUM 5.5
CVE-2014-9493
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete…
Openstack
2014.1.4 / 2014.2.2+
HIGH 7.2
CVE-2014-7300
GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests,…
Enterprise Linux Desktop
Patch available
HIGH 7.5
CVE-2014-8138EPSS 19%
Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or p…
Enterprise Linux
No fix yet
MEDIUM 6.8
CVE-2014-8137EPSS 15%
Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (…
Enterprise Linux
after 1.900.1
MEDIUM 5.0
CVE-2014-8108EPSS 10%
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.7.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial…
Enterprise Linux Desktop
Patch available
MEDIUM 5.0
CVE-2014-3580EPSS 11%
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial o…
Enterprise Linux Desktop
Patch available
HIGH 7.5
CVE-2014-7840
The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers to execute arbitrary code via…
Enterprise Linux Desktop
after 2.1.3
MEDIUM 5.0
CVE-2014-9140EPSS 6%
Buffer overflow in the ppp_hdlc function in print-ppp.c in tcpdump 4.6.2 and earlier allows remote attackers to cause a denial of service (crash) cia…
Tcpdump
after 4.6.2
MEDIUM 5.0
CVE-2014-3703
OpenStack PackStack 2012.2.1, when the Open vSwitch (OVS) monolithic plug-in is not used, does not properly set the libvirt_vif_driver configuration …
Packstack
Mitigation only
MEDIUM 5.0
CVE-2014-7816EPSS 25%
Directory traversal vulnerability in JBoss Undertow 1.0.x before 1.0.17, 1.1.x before 1.1.0.CR5, and 1.2.x before 1.2.0.Beta3, when running on Window…
Undertow
after 1.2.0
MEDIUM 6.4
CVE-2014-7839
DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which …
Resteasy
Mitigation only
MEDIUM 6.4
CVE-2014-8769EPSS 6%
tcpdump 3.8 through 4.6.2 might allow remote attackers to obtain sensitive information from memory or cause a denial of service (packet loss or segme…
Tcpdump
No fix yet
MEDIUM 5.0
CVE-2014-8767EPSS 5%
Integer underflow in the olsr_print function in tcpdump 3.9.6 through 4.6.2, when in verbose mode, allows remote attackers to cause a denial of servi…
Tcpdump
No fix yet