Vulnerability index

Browse CVEs

231 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Openshift Service Mesh CRITICAL 9.8
CVE-2021-3586

A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed, allo…

Mitigation only
Fix from $2,300 2022-08-22
Openshift Container Platform CRITICAL 9.8
CVE-2020-27836

A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker…

Patch available
Fix from $2,300 2022-08-22
Process Automation Manager CRITICAL 9.8
CVE-2022-2457

A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against Administration Console as th…

Fix: 7.13.2+
Fix from $2,300 2022-08-10
Ceph Storage CRITICAL 9.1
CVE-2022-0670

A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file syste…

Fix: 5.2 / 15.2.17+
Fix from $2,300 2022-07-25
Keycloak CRITICAL 9.8
CVE-2022-1245

A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid ac…

Fix: 18.0.0+
Fix from $2,300 2022-07-08
Cloudforms Management Engine CRITICAL 9.1
CVE-2014-8164

A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat Cloud…

Mitigation only
Fix from $2,300 2022-07-06
Openshift CRITICAL 9.1
CVE-2013-4561

In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to loss of confidentiality and i…

Patch available
Fix from $2,300 2022-06-30
Drools CRITICAL 9.8
CVE-2021-41411

drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, res…

Fix: 7.6.0+
Fix from $2,300 2022-06-16
Enterprise Linux CRITICAL 9.1
CVE-2022-1587

An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. Th…

Fix: 10.40+
Fix from $2,300 2022-05-16
Clair CRITICAL 9.8
CVE-2021-3762

A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image w…

Fix: 0.4.8 / 0.5.5+
Fix from $2,300 2022-03-03
Vscode Xml CRITICAL 9.1
CVE-2022-0671

A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large file.

Fix: 0.19.0+
Fix from $2,300 2022-02-18
Enterprise Linux CRITICAL 9.8
CVE-2021-20325

Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regress…

Mitigation only
Fix from $2,300 2022-02-18
Ceph Storage CRITICAL 9.1
CVE-2021-4048

An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS b…

Fix: 0.3.18+
Fix from $2,300 2021-12-08
Data Grid CRITICAL 9.8
CVE-2021-31917

A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authenticat…

Fix: 11.0.12 / 12.1.4+
Fix from $2,300 2021-09-21
Enterprise Linux CRITICAL 9.0
CVE-2021-40438 KEVEPSS 100%

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP …

Patch available
Fix from $2,300 2021-09-16
Enterprise Linux CRITICAL 9.8
CVE-2021-20314

Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code executio…

Fix: 1.2.11+
Fix from $2,300 2021-08-12
Ceph Storage CRITICAL 9.8
CVE-2021-20236

A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by…

Fix: 4.3.3+
Fix from $2,300 2021-05-28
Keycloak CRITICAL 9.6
CVE-2021-20195

A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account takeover is possible due to …

Fix: 12.0.3+
Fix from $2,300 2021-05-28
Quay CRITICAL 9.0
CVE-2020-27832

A flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a repository's notification. Thi…

Fix: 3.3.2+
Fix from $2,300 2021-05-27
Certification CRITICAL 9.1
CVE-2018-10866

It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated use…

Mitigation only
Fix from $2,300 2021-05-26
Certification CRITICAL 9.1
CVE-2018-10867

Files are accessible without restrictions from the /update/results page of redhat-certification 7 package, allowing an attacker to remove any file ac…

Mitigation only
Fix from $2,300 2021-05-26
Enterprise Linux CRITICAL 9.8
CVE-2018-25011

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.8
CVE-2018-25014

A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.8
CVE-2020-36328

A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check …

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.8
CVE-2020-36329

A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this…

Fix: 1.0.1 / 14.7+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.1
CVE-2018-25009

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.1
CVE-2018-25010

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.1
CVE-2018-25012

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.1
CVE-2018-25013

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.1
CVE-2020-36331

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulne…

Fix: 1.0.1 / 14.7+
Fix from $2,300 2021-05-21