Vulnerability index

Browse CVEs

231 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Libnbd CRITICAL 9.8
CVE-2019-14842

Structured reply is a feature of the newstyle NBD protocol allowing the server to send a reply in chunks. A bounds check which was supposed to test f…

Fix: 1.0.3+
Fix from $2,300 2019-11-26
Redhat Upgrade Tool CRITICAL 9.8
CVE-2014-3585

redhat-upgrade-tool: Does not check GPG signatures when upgrading versions

Mitigation only
Fix from $2,300 2019-11-22
Edeploy CRITICAL 9.8
CVE-2014-3700

eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data

Fix: after 1.6.0
Fix from $2,300 2019-11-21
Enterprise Mrg CRITICAL 9.8
CVE-2012-3460

cumin: At installation postgresql database user created without password

Mitigation only
Fix from $2,300 2019-11-21
Enterprise Linux CRITICAL 9.8
CVE-2011-2897

gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw

Fix: after 2.31.1
Fix from $2,300 2019-11-12
Enterprise Linux CRITICAL 9.8
CVE-2015-8980EPSS 7%

The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code.

Fix: 1.0.12+
Fix from $2,300 2019-11-04
Icedtea6 CRITICAL 9.1
CVE-2010-2548

IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.

Fix: 1.7.4+
Fix from $2,300 2019-10-31
Icedtea6 CRITICAL 9.1
CVE-2010-2783

IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services.

Fix: 1.7.4+
Fix from $2,300 2019-10-31
Satellite CRITICAL 9.1
CVE-2019-17631

From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privil…

Fix: after 0.16.0
Fix from $2,300 2019-10-17
Undertow CRITICAL 9.8
CVE-2019-10212

A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to o…

Fix: 2.0.20+
Fix from $2,300 2019-10-02
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2019-10202EPSS 5%

A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525…

Mitigation only
Fix from $2,300 2019-10-01
Openshift Container Platform CRITICAL 9.8
CVE-2019-14813EPSS 11%

A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, en…

Patch available
Fix from $2,300 2019-09-06
Openstack CRITICAL 9.1
CVE-2019-10141

A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability wa…

Fix: 5.0.2 / 6.0.3+
Fix from $2,300 2019-07-30
Openshift Container Platform CRITICAL 9.8
CVE-2018-11307EPSS 6%

An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows…

Fix: 2.6.7.3 / 2.7.9.4+
Fix from $2,300 2019-07-09
Satellite CRITICAL 9.8
CVE-2019-10137

A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthen…

Fix: after 2.9
Fix from $2,300 2019-07-02
Undertow CRITICAL 9.8
CVE-2019-3888

A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connector…

Fix: 2.0.21+
Fix from $2,300 2019-06-12
Jboss Enterprise Application Platform CRITICAL 9.0
CVE-2019-3873

It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An att…

Mitigation only
Fix from $2,300 2019-06-12
Kie Server CRITICAL 9.8
CVE-2016-7043

It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any…

Fix: 7.21.0+
Fix from $2,300 2019-05-15
Openshift Container Platform CRITICAL 9.8
CVE-2019-3899

It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This i…

Mitigation only
Fix from $2,300 2019-04-22
Satellite CRITICAL 9.8
CVE-2018-12547

In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects exis…

Fix: 0.12.0+
Fix from $2,300 2019-02-11
Satellite CRITICAL 9.8
CVE-2018-12549

In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when acceleratin…

Mitigation only
Fix from $2,300 2019-02-11
Modulemd CRITICAL 9.8
CVE-2017-1002157

modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.

Fix: after 1.3.1
Fix from $2,300 2019-01-10
Ansible Tower CRITICAL 9.8
CVE-2018-16879

Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging cel…

Fix: 3.3.3+
Fix from $2,300 2019-01-03
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-15981EPSS 10%

Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

Fix: after 31.0.0.148
Fix from $2,300 2018-11-29
Richfaces CRITICAL 9.8
CVE-2018-14667 KEVEPSS 74%

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticate…

Fix: after 3.3.4
Fix from $2,300 2018-11-06
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-5156

A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurring. This can result in stream …

Mitigation only
Fix from $2,300 2018-10-18
Enterprise Linux Desktop CRITICAL 9.1
CVE-2018-12387EPSS 8%

A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by…

Patch available
Fix from $2,300 2018-10-18
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-12378

A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to…

Mitigation only
Fix from $2,300 2018-10-18
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-12376

Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Mitigation only
Fix from $2,300 2018-10-18
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-12377

A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted whi…

Mitigation only
Fix from $2,300 2018-10-18