Vulnerability index

Browse CVEs

231 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-5434

A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially exploitable crash. This vulnerability affects Th…

Fix: 45.9.0 / 52.1.0+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-5400

JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks.…

Fix: 45.8.0 / 52.0+
Fix from $2,300 2018-06-11
Enterprise Linux Aus CRITICAL 9.8
CVE-2016-9901

HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-sa…

Fix: 45.6.0 / 50.1+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-5375EPSS 20%

JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Thu…

Fix: 45.7.0 / 51.0.1+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-4944EPSS 8%

Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary …

Fix: after 29.0.0.140
Fix from $2,300 2018-05-19
Virtualization Host CRITICAL 9.8
CVE-2018-11236EPSS 6%

stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath functi…

Fix: after 2.27
Fix from $2,300 2018-05-18
Wildfly CRITICAL 9.8
CVE-2018-10683

An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successful…

No fix yet
Fix from $2,300 2018-05-09
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2018-8088EPSS 15%

org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via…

Patch available
Fix from $2,300 2018-03-20
Ansible Engine CRITICAL 9.8
CVE-2018-7750EPSS 27%

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2…

Patch available
Fix from $2,300 2018-03-13
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-4877EPSS 8%

A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Pri…

Fix: 28.0.0.161+
Fix from $2,300 2018-02-06
Virtualization Host CRITICAL 9.8
CVE-2018-6485

An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier coul…

Fix: after 2.26
Fix from $2,300 2018-02-01
Jboss Fuse CRITICAL 9.8
CVE-2014-0121

The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.

Fix: after 1.2.2
Fix from $2,300 2017-12-29
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-3112EPSS 5%

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data…

Fix: after 27.0.0.183
Fix from $2,300 2017-12-09
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-3114EPSS 5%

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data…

Fix: after 27.0.0.183
Fix from $2,300 2017-12-09
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-11213EPSS 5%

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data…

Fix: after 27.0.0.183
Fix from $2,300 2017-12-09
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-11215EPSS 6%

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in…

Fix: after 27.0.0.183
Fix from $2,300 2017-12-09
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-11225EPSS 6%

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in…

Fix: after 27.0.0.183
Fix from $2,300 2017-12-09
Openstack CRITICAL 9.8
CVE-2017-10906

Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitr…

Patch available
Fix from $2,300 2017-12-08
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-11281EPSS 33%

Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploitation could lead to arbitrary …

Fix: after 26.0.0.151
Fix from $2,300 2017-12-01
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-11282EPSS 36%

Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code ex…

Fix: after 26.0.0.151
Fix from $2,300 2017-12-01
Ansible CRITICAL 9.8
CVE-2017-7550

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attac…

Fix: 2.3.3 / 2.4.1+
Fix from $2,300 2017-11-21
Data Grid CRITICAL 9.8
CVE-2015-7501EPSS 70%

Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Pl…

Mitigation only
Fix from $2,300 2017-11-09
Satellite CRITICAL 9.6
CVE-2017-10346

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE:…

Patch available
Fix from $2,300 2017-10-19
Edeploy CRITICAL 9.1
CVE-2014-3702

Directory traversal vulnerability in eNovance eDeploy allows remote attackers to create arbitrary directories and files and consequently cause a deni…

Mitigation only
Fix from $2,300 2017-10-16
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-12149 KEVEPSS 91%

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessF…

Mitigation only
Fix from $2,300 2017-10-04
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-14491EPSS 85%

Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafte…

Fix: after 2.77
Fix from $2,300 2017-10-04
Mobile Application Platform CRITICAL 9.8
CVE-2017-7552

A flaw was discovered in the file editor of millicore, affecting versions before 3.19.0 and 4.x before 4.5.0, which allows files to be executed as we…

Fix: after 4.4.3
Fix from $2,300 2017-09-29
Enterprise Virtualization Manager CRITICAL 9.1
CVE-2015-7544

redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the Supe…

Mitigation only
Fix from $2,300 2017-09-25
Edeploy CRITICAL 9.8
CVE-2014-8174

eDeploy makes it easier for remote attackers to execute arbitrary code by leveraging use of HTTP to download files.

Fix: after 1.11.0
Fix from $2,300 2017-09-19
3scale Api Management Platform CRITICAL 9.8
CVE-2017-7512

Red Hat 3scale (aka RH-3scale) API Management Platform (AMP) before 2.0.0 would permit creation of an access token without a client secret. An attack…

Mitigation only
Fix from $2,300 2017-07-07