Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Ceph Storage HIGH 7.5
CVE-2016-9579

A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A re…

Patch available
Fix from $1,950 2018-08-01
Distribution For Python HIGH 7.8
CVE-2018-3650

Insufficient Input Validation in Bleach module in INTEL Distribution for Python versions prior to IDP 2018 Update 2 allows unprivileged user to bypas…

Fix: 2018+
Fix from $1,950 2018-08-01
Ubuntu Linux MEDIUM 6.5
CVE-2018-10916

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on th…

Fix: after 4.8.3
Fix from $1,600 2018-08-01
Curl HIGH 7.5
CVE-2016-8625

curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users to potentially and unknowing…

Fix: 7.51.0+
Fix from $1,950 2018-08-01
OpenBSD MEDIUM 5.5
CVE-2018-14775

tss_alloc in sys/arch/i386/i386/gdt.c in OpenBSD 6.2 and 6.3 has a Local Denial of Service (system crash) due to incorrect I/O port access control on…

Patch available
Fix from $1,600 2018-08-01
Curl HIGH 7.5
CVE-2016-8624EPSS 6%

curl before version 7.51.0 doesn't parse the authority component of the URL correctly when the host name part ends with a '#' character, and could in…

Fix: 7.51.0+
Fix from $1,950 2018-07-31
Foxit Reader HIGH 8.8
CVE-2018-14280

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is requ…

Fix: after 9.1.0.5096
Fix from $1,950 2018-07-31
Foxit Reader HIGH 8.8
CVE-2018-14281

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is requ…

Fix: after 9.1.0.5096
Fix from $1,950 2018-07-31
Glance MEDIUM 6.5
CVE-2016-8611

A vulnerability was found in Openstack Glance. No limits are enforced within the Glance image service for both v1 and v2 `/images` API POST method fo…

Mitigation only
Fix from $1,600 2018-07-31
Openshift HIGH 7.7
CVE-2016-8631

The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routes can pote…

Mitigation only
Fix from $1,950 2018-07-31
Ceph MEDIUM 6.5
CVE-2016-8626

A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ceph Object Gateway handles POST object requests permits an authenticated attacker to launc…

Fix: 0.94.3.9-8+
Fix from $1,600 2018-07-31
Oncommand Insight MEDIUM 6.5
CVE-2017-13652

NetApp OnCommand Insight version 7.3.0 and versions prior to 7.2.0 are susceptible to clickjacking attacks which could cause a user to perform an uni…

Fix: 7.2.0+
Fix from $1,600 2018-07-31
Seeddms HIGH 8.8
CVE-2018-12941

This vulnerability allows remote attackers to execute arbitrary code in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 by adding a system command …

Fix: 5.1.8+
Fix from $1,950 2018-07-31
.net Reflector HIGH 7.8
CVE-2018-14581

Redgate .NET Reflector before 10.0.7.774 and SmartAssembly before 6.12.5 allow attackers to execute code by decompiling a compiled .NET object (such …

Fix: 6.12.5 / 10.0.7.774+
Fix from $1,950 2018-07-31
Mate 10 Pro Firmware MEDIUM 5.5
CVE-2018-7934

Some Huawei mobile phone with the versions before BLA-L29 8.0.0.145(C432) have a denial of service (DoS) vulnerability because they do not adapt to s…

Mitigation only
Fix from $1,600 2018-07-31
Debian Linux CRITICAL 9.8
CVE-2018-14767EPSS 24%

In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag causes a segmentation fault an…

Fix: 5.0.7 / 5.1.4+
Fix from $2,300 2018-07-31
Whereis CRITICAL 9.8
CVE-2018-3772

Concatenating unsanitized user input in the `whereis` npm module < 0.4.1 allowed an attacker to execute arbitrary commands. The `whereis` module is d…

Fix: 0.4.1+
Fix from $2,300 2018-07-30
Openstack HIGH 7.5
CVE-2018-10903

A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user …

Fix: 2.3+
Fix from $1,950 2018-07-30
Xclarity Administrator HIGH 8.8
CVE-2018-9066

In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user can, under specific circumstances, inject additional paramet…

Fix: 2.1.0+
Fix from $1,950 2018-07-30
Ubuntu Linux MEDIUM 6.5
CVE-2018-14680

An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM filenames.

Fix: after 1.5
Fix from $1,600 2018-07-28
Debian Linux HIGH 7.5
CVE-2016-9578

A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send …

Fix: 0.13.90+
Fix from $1,950 2018-07-27
Debian Linux HIGH 8.8
CVE-2016-9577

A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to th…

Fix: 0.13.90+
Fix from $1,950 2018-07-27
Cloudforms Management Engine MEDIUM 6.5
CVE-2017-2653

A number of unused delete routes are present in CloudForms before 5.7.2.1 which can be accessed via GET requests instead of just POST requests. This …

Fix: 5.7.2.1+
Fix from $1,600 2018-07-27
Jboss Bpm Suite MEDIUM 6.5
CVE-2017-2658

It was discovered that the Dashbuilder login page as used in Red Hat JBoss BPM Suite before 6.4.2 and Red Hat JBoss Data Virtualization & Services be…

Fix: 6.4.2 / 6.4.3+
Fix from $1,600 2018-07-27
Jboss Bpm Suite MEDIUM 5.4
CVE-2017-2674

JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a stored XSS via several lists in Business Central. The flaw is due to lack of sanitation…

Fix: 6.4.3+
Fix from $1,600 2018-07-27
Enterprise Virtualization MEDIUM 6.3
CVE-2017-2614

When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is ex…

Mitigation only
Fix from $1,600 2018-07-27
Ansible Tower HIGH 7.2
CVE-2017-12148

A flaw was found in Ansible Tower's interface before 3.1.5 and 3.2.0 with SCM repositories. If a Tower project (SCM repository) definition does not h…

Fix: 3.1.5 / 3.2.0+
Fix from $1,950 2018-07-27
Enterprise Linux Desktop HIGH 8.8
CVE-2017-12173

It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulner…

Fix: 1.16.0+
Fix from $1,950 2018-07-27
Enterprise Linux MEDIUM 6.5
CVE-2017-12171EPSS 8%

A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines…

Mitigation only
Fix from $1,600 2018-07-26
Certificate System MEDIUM 6.5
CVE-2017-7509

An input validation error was found in Red Hat Certificate System's handling of client provided certificates before 8.1.20-1. If the certreq field is…

Fix: 8.1.20-1+
Fix from $1,600 2018-07-26