Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2014-3464
The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not proper…
Jboss Enterprise Application Platform
Mitigation only
HIGH 7.5
CVE-2014-3530
The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform …
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 6.8
CVE-2014-3518
jmx-remoting.sar in JBoss Remoting, as used in Red Hat JBoss Enterprise Application Platform (JEAP) 5.2.0, Red Hat JBoss BRMS 5.3.1, Red Hat JBoss Po…
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 5.0
CVE-2014-4341EPSS 7%
MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting in…
Enterprise Linux Desktop
Patch available
MEDIUM 5.0
CVE-2012-2682
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, allows attackers with certain database privileges to cause a denial of ser…
Enterprise Mrg
Mitigation only
MEDIUM 6.9
CVE-2014-3486
The (1) shell_exec function in lib/util/MiqSshUtilV1.rb and (2) temp_cmd_file function in lib/util/MiqSshUtilV2.rb in Red Hat CloudForms 3.0 Manageme…
Cloudforms 3.0 Management Engine
after 5.2.4
MEDIUM 6.8
CVE-2014-0248
org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Ente…
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 5.0
CVE-2014-0180
The wait_for_task function in app/controllers/application_controller.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allows remo…
Cloudforms 3.0 Management Engine
after 5.2.4
MEDIUM 5.0
CVE-2014-3481
org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion…
Jboss Enterprise Application Platform
after 6.2.3
HIGH 10.0
CVE-2014-3496EPSS 5%
cartridge_repository.rb in OpenShift Origin and Enterprise 1.2.8 through 2.1.1 allows remote attackers to execute arbitrary commands via shell metach…
Openshift
Patch available
HIGH 7.5
CVE-2014-3468
The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows con…
Virtualization
Patch available
MEDIUM 5.0
CVE-2014-3467EPSS 7%
Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of se…
Virtualization
Patch available
MEDIUM 5.0
CVE-2014-3469
The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of ser…
Virtualization
Patch available
MEDIUM 5.0
CVE-2013-6470
The default configuration in the standalone controller quickstack manifest in openstack-foreman-installer, as used in Red Hat Enterprise Linux OpenSt…
Openstack
Mitigation only
MEDIUM 5.0
CVE-2013-0199
The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes,…
Freeipa
Patch available
MEDIUM 6.5
CVE-2014-0137
SQL injection vulnerability in the saved_report_delete action in the ReportController in Red Hat CloudForms Management Engine (CFME) before 5.2.3.2 a…
Cloudforms 3.0 Management Engine
after 5.2.3
MEDIUM 6.8
CVE-2011-2514
The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and bef…
Icedtea Web
after 1.8.8
MEDIUM 5.0
CVE-2011-2513
The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and bef…
Icedtea Web
after 1.8.8
HIGH 7.5
CVE-2014-0130 KEVEPSS 54%
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18,…
Subscription Asset Manager
3.2.18 / 4.0.5+
MEDIUM 5.0
CVE-2013-6445
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, uses the DES-based crypt function to hash passwords, which makes it easier…
Enterprise Mrg
Mitigation only
HIGH 7.5
CVE-2014-0188
The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remot…
Openshift
after 2.0.5
MEDIUM 6.5
CVE-2013-6469
JBoss Overlord Run Time Governance (RTGov) 1.0 for JBossAS allows remote authenticated users to execute arbitrary Java code via an MVFLEX Expression …
Jboss Fuse Service Works
Mitigation only
MEDIUM 6.4
CVE-2014-0071
PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass int…
Openstack
Mitigation only
MEDIUM 6.5
CVE-2013-2143EPSS 48%
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows r…
Network Satellite
after 1.5.0-14
MEDIUM 5.8
CVE-2013-6456
The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDetta…
Libvirt
Mitigation only
MEDIUM 6.0
CVE-2010-2236
The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and …
Network Proxy
after 2.1.147-1
MEDIUM 6.5
CVE-2013-6468
JBoss Drools, Red Hat JBoss BRMS before 6.0.1, and Red Hat JBoss BPM Suite before 6.0.1 allows remote authenticated users to execute arbitrary Java c…
Jboss Bpm Suite
Mitigation only
MEDIUM 5.8
CVE-2014-0093
Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by…
Jboss Enterprise Application Platform
Mitigation only
HIGH 7.5
CVE-2014-0057
The x_button method in the ServiceController (vmdb/app/controllers/service_controller.rb) in Red Hat CloudForms 3.0 Management Engine 5.2 allows remo…
Cloudforms
Mitigation only
MEDIUM 6.8
CVE-2011-4111
Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote…
Enterprise Linux
after 0.15.1