Vulnerability index

Browse CVEs

231 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Quickstart Cloud Installer CRITICAL 9.8
CVE-2016-5411

/var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created world readable and contains the …

Mitigation only
Fix from $2,300 2017-06-13
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-5405

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server …

Mitigation only
Fix from $2,300 2017-06-08
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-7050

SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and R…

Mitigation only
Fix from $2,300 2017-06-08
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2016-3690

The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.

Mitigation only
Fix from $2,300 2017-06-08
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-7504EPSS 24%

HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Se…

Fix: after 4.0
Fix from $2,300 2017-05-19
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-7503

It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use th…

Mitigation only
Fix from $2,300 2017-05-18
Openstack CRITICAL 9.8
CVE-2008-7313

The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CV…

Fix: after 4.2.3
Fix from $2,300 2017-03-31
Openstack CRITICAL 9.8
CVE-2014-5008

Snoopy allows remote attackers to execute arbitrary commands.

Patch available
Fix from $2,300 2017-03-31
Openstack CRITICAL 9.8
CVE-2014-5009

Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.

Fix: after 4.2.3
Fix from $2,300 2017-03-31
Satellite CRITICAL 9.8
CVE-2017-5929EPSS 8%

QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.

Fix: 1.2.0+
Fix from $2,300 2017-03-13
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-9636EPSS 8%

Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a…

Fix: after 1.10.1
Fix from $2,300 2017-01-27
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-9634EPSS 9%

Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a…

Fix: after 1.10.1
Fix from $2,300 2017-01-27
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-9635EPSS 9%

Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a…

Fix: after 1.10.1
Fix from $2,300 2017-01-27
Enterprise Linux Desktop CRITICAL 9.8
CVE-2014-8241

XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return …

Mitigation only
Fix from $2,300 2016-12-14
Jboss Operations Network CRITICAL 9.8
CVE-2016-6330EPSS 9%

The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote a…

Mitigation only
Fix from $2,300 2016-09-27
Dashbuilder CRITICAL 9.8
CVE-2016-4999

SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuil…

Fix: after 0.5.0
Fix from $2,300 2016-08-05
Jboss Operations Network CRITICAL 9.8
CVE-2016-3737EPSS 6%

The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, relat…

Fix: after 3.3.5
Fix from $2,300 2016-08-02
Libvirt CRITICAL 9.8
CVE-2016-5008

libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers…

Fix: after 1.3.5
Fix from $2,300 2016-07-13
Openshift CRITICAL 9.8
CVE-2016-2074EPSS 6%

Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute …

Patch available
Fix from $2,300 2016-07-03
Jgroups CRITICAL 9.8
CVE-2016-2141

It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use …

Fix: 4.0+
Fix from $2,300 2016-06-30
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-4171 KEVEPSS 20%

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as expl…

Fix: after 21.0.0.242
Fix from $2,300 2016-06-16
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-4138EPSS 25%

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11…

Fix: after 21.0.0.242
Fix from $2,300 2016-06-16
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-4448EPSS 7%

Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.

Mitigation only
Fix from $2,300 2016-06-09
Satellite CRITICAL 9.1
CVE-2015-5041

The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote at…

Fix: 6.0.16.20 / 6.1.8.20+
Fix from $2,300 2016-06-06
Enterprise Linux CRITICAL 9.8
CVE-2015-4602EPSS 10%

The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remot…

Fix: after 5.4.39
Fix from $2,300 2016-05-16
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-4601EPSS 8%

PHP before 5.6.7 might allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected d…

Fix: after 5.6.6
Fix from $2,300 2016-05-16
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-4600EPSS 10%

The SoapClient implementation in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service …

Fix: after 5.4.39
Fix from $2,300 2016-05-16
Enterprise Linux Desktop Supplementary CRITICAL 9.8
CVE-2016-1666

Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.94 allow attackers to cause a denial of service or possibly have other impact …

Fix: after 50.0.2661.87
Fix from $2,300 2016-05-14
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-4117 KEVEPSS 94%

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May …

Fix: after 21.0.0.226
Fix from $2,300 2016-05-11
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-2108EPSS 79%

The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of serv…

Fix: after 1.0.1n
Fix from $2,300 2016-05-05