Vulnerability index

Browse CVEs

231 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux CRITICAL 9.8
CVE-2021-3466EPSS 9%

A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attac…

Patch available
Fix from $2,300 2021-03-25
Enterprise Linux CRITICAL 9.8
CVE-2021-20231

A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.

Fix: 3.7.1+
Fix from $2,300 2021-03-12
Enterprise Linux CRITICAL 9.8
CVE-2021-20232

A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potentia…

Fix: 3.7.1+
Fix from $2,300 2021-03-12
Cloudforms Management Engine CRITICAL 9.1
CVE-2020-14324

A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS command injection vulnerabil…

Fix: 5.11.7.0+
Fix from $2,300 2020-08-11
Cloudforms CRITICAL 9.1
CVE-2020-14325

Red Hat CloudForms before 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious attacker to create existent and…

Fix: 5.11.7.0+
Fix from $2,300 2020-08-11
Openstack Platform CRITICAL 9.9
CVE-2020-10731

A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux enabled. This flaw cause…

Mitigation only
Fix from $2,300 2020-07-31
Undertow CRITICAL 9.8
CVE-2020-1745

A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.29.Final …

Fix: after 2.0.29
Fix from $2,300 2020-04-28
Jboss Data Grid CRITICAL 9.1
CVE-2019-14887

A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An…

Mitigation only
Fix from $2,300 2020-03-16
Keycloak Operator CRITICAL 9.8
CVE-2020-1731

A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password…

Fix: 8.0.2+
Fix from $2,300 2020-03-02
Decision Manager CRITICAL 9.8
CVE-2019-14892EPSS 6%

A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a mal…

Fix: 2.6.7.3 / 2.8.11.5+
Fix from $2,300 2020-03-02
Ansible CRITICAL 9.8
CVE-2014-4657

The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code vi…

Fix: 1.5.4+
Fix from $2,300 2020-02-20
Ansible CRITICAL 9.8
CVE-2014-4678EPSS 5%

The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code vi…

Fix: 1.6.4+
Fix from $2,300 2020-02-20
Ansible CRITICAL 9.8
CVE-2014-4966

Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which …

Fix: 1.6.7+
Fix from $2,300 2020-02-18
Ansible CRITICAL 9.8
CVE-2014-4967

Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansib…

Fix: 1.6.7+
Fix from $2,300 2020-02-18
Enterprise Linux CRITICAL 9.8
CVE-2014-8089

SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows …

Fix: 1.12.9 / 2.2.8+
Fix from $2,300 2020-02-17
Spacewalk CRITICAL 9.8
CVE-2020-1693

A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An unauthenticated …

Fix: 2.9+
Fix from $2,300 2020-02-17
Openshift CRITICAL 9.8
CVE-2014-0234

The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows re…

Fix: 2.1+
Fix from $2,300 2020-02-12
Openshift CRITICAL 9.8
CVE-2013-2060EPSS 6%

The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a req…

No fix yet
Fix from $2,300 2020-01-28
Enterprise Linux CRITICAL 9.8
CVE-2019-14906

A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL pack…

Fix: after 2.0.9
Fix from $2,300 2020-01-07
Keycloak CRITICAL 9.1
CVE-2019-14837

A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name …

Fix: 8.0.0+
Fix from $2,300 2020-01-07
Jboss Data Grid CRITICAL 9.8
CVE-2019-10158

A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session inte…

Fix: after 9.4.14
Fix from $2,300 2020-01-02
Ceph Storage CRITICAL 9.1
CVE-2019-14859

A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this ver…

Fix: 0.13.3+
Fix from $2,300 2020-01-02
Edeploy CRITICAL 9.8
CVE-2014-3699

eDeploy has RCE via cPickle deserialization of untrusted data

No fix yet
Fix from $2,300 2019-12-15
Openshift CRITICAL 9.8
CVE-2014-0175

mcollective has a default password set at install

Mitigation only
Fix from $2,300 2019-12-13
Openstack CRITICAL 9.8
CVE-2013-2166

python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass

Fix: after 0.2.5
Fix from $2,300 2019-12-10
Openstack CRITICAL 9.8
CVE-2013-2167

python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass

Fix: after 0.2.5
Fix from $2,300 2019-12-10
Enterprise Linux CRITICAL 9.8
CVE-2019-19333

In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "bits…

Patch available
Fix from $2,300 2019-12-06
Enterprise Linux CRITICAL 9.8
CVE-2019-19334

In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "iden…

Patch available
Fix from $2,300 2019-12-06
Keycloak CRITICAL 9.8
CVE-2019-14910

A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDA…

Mitigation only
Fix from $2,300 2019-12-05
Zanata CRITICAL 9.8
CVE-2013-4486

Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging

Fix: after 3.1.2
Fix from $2,300 2019-12-03