Vulnerability index

Browse CVEs

231 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Satellite CRITICAL 9.0
CVE-2018-3183

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Scripting). Supported versions that are affected a…

Patch available
Fix from $2,300 2018-10-17
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-14649EPSS 12%

It was found that ceph-isci-cli package as shipped by Red Hat Ceph Storage 2 and 3 is using python-werkzeug in debug shell mode. This is done by sett…

Patch available
Fix from $2,300 2018-10-09
Openstack CRITICAL 9.8
CVE-2018-14620

The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could potentially…

Mitigation only
Fix from $2,300 2018-09-10
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-12825EPSS 6%

Adobe Flash Player 30.0.0.134 and earlier have a security bypass vulnerability. Successful exploitation could lead to security mitigation bypass.

Fix: after 30.0.0.154
Fix from $2,300 2018-08-29
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-12828EPSS 6%

Adobe Flash Player 30.0.0.134 and earlier have a "use of a component with a known vulnerability" vulnerability. Successful exploitation could lead to…

Fix: after 30.0.0.154
Fix from $2,300 2018-08-29
Satellite CRITICAL 9.8
CVE-2018-10931EPSS 68%

It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use…

Fix: after 2.6.11
Fix from $2,300 2018-08-09
Ansible CRITICAL 9.1
CVE-2016-8628

Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create speci…

Fix: 2.2.0+
Fix from $2,300 2018-07-31
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-15101

A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a den…

Fix: 2.5.4+
Fix from $2,300 2018-07-27
Spacewalk CRITICAL 9.8
CVE-2017-7470

It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorizati…

Mitigation only
Fix from $2,300 2018-07-27
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-7464

It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use thi…

Mitigation only
Fix from $2,300 2018-07-27
Jboss Fuse CRITICAL 9.0
CVE-2017-2589

It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored …

Mitigation only
Fix from $2,300 2018-07-26
Openstack CRITICAL 10.0
CVE-2017-2637

A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed…

Mitigation only
Fix from $2,300 2018-07-26
Certification CRITICAL 9.8
CVE-2018-10870EPSS 6%

redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any fil…

Mitigation only
Fix from $2,300 2018-07-19
Openshift Container Platform CRITICAL 9.8
CVE-2017-7481

Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of looku…

Fix: 2.3.1.0 / 2.4.0.0+
Fix from $2,300 2018-07-19
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-7465

It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw …

Mitigation only
Fix from $2,300 2018-06-27
Enterprise Virtualization Manager CRITICAL 9.8
CVE-2018-1072

ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the option…

Fix: 4.2.2+
Fix from $2,300 2018-06-26
Enterprise Virtualization CRITICAL 9.8
CVE-2018-1117

ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/Clou…

Fix: 1.0.6+
Fix from $2,300 2018-06-20
Richfaces CRITICAL 9.8
CVE-2018-12532EPSS 6%

JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and exec…

Fix: after 4.5.17
Fix from $2,300 2018-06-18
Richfaces CRITICAL 9.8
CVE-2018-12533EPSS 13%

JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java…

Fix: after 3.3.4
Fix from $2,300 2018-06-18
Openshift Container Platform CRITICAL 9.8
CVE-2018-1085

openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificate authentication to be disabl…

Fix: 3.9.31+
Fix from $2,300 2018-06-15
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-5183

Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and…

Mitigation only
Fix from $2,300 2018-06-11
Enterprise Linux Aus CRITICAL 9.8
CVE-2017-7824

A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. This is due to an incorrect va…

Fix: 52.4.0 / 56.0+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-7818

A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applications (ARIA) elements within containers through …

Fix: 52.4.0 / 56.0+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-7819

A use-after-free vulnerability can occur in design mode when image objects are resized if objects referenced during the resizing have been freed from…

Fix: 52.4.0 / 56.0+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop CRITICAL 9.1
CVE-2017-7758

An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use. This vu…

Fix: 52.2.0 / 54.0+
Fix from $2,300 2018-06-11
Enterprise Linux CRITICAL 9.8
CVE-2017-5456

A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an IPC message. This allows for…

Fix: 52.1.0 / 53.0+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-5459

A buffer overflow in WebGL triggerable by web content, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, F…

Fix: 45.9.0 / 52.1.0+
Fix from $2,300 2018-06-11
Enterprise Linux CRITICAL 9.8
CVE-2017-5428

An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental exten…

Fix: 52.0.1+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-5429

Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory co…

Fix: 45.9.0 / 52.1.0+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-5430

Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we pr…

Fix: 52.1.0 / 53.0+
Fix from $2,300 2018-06-11