Vulnerability index

Browse CVEs

231 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2021-3586 A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed, allo… Openshift Service Mesh Mitigation only Fix from $2,3002022-08-22 CRITICAL 9.8 CVE-2020-27836 A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker… Openshift Container Platform Patch available Fix from $2,3002022-08-22 CRITICAL 9.8 CVE-2022-2457 A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against Administration Console as th… Process Automation Manager 7.13.2+ Fix from $2,3002022-08-10 CRITICAL 9.1 CVE-2022-0670 A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file syste… Ceph Storage 5.2 / 15.2.17+ Fix from $2,3002022-07-25 CRITICAL 9.8 CVE-2022-1245 A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid ac… Keycloak 18.0.0+ Fix from $2,3002022-07-08 CRITICAL 9.1 CVE-2014-8164 A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat Cloud… Cloudforms Management Engine Mitigation only Fix from $2,3002022-07-06 CRITICAL 9.1 CVE-2013-4561 In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to loss of confidentiality and i… Openshift Patch available Fix from $2,3002022-06-30 CRITICAL 9.8 CVE-2021-41411 drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, res… Drools 7.6.0+ Fix from $2,3002022-06-16 CRITICAL 9.1 CVE-2022-1587 An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. Th… Enterprise Linux 10.40+ Fix from $2,3002022-05-16 CRITICAL 9.8 CVE-2021-3762 A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image w… Clair 0.4.8 / 0.5.5+ Fix from $2,3002022-03-03 CRITICAL 9.1 CVE-2022-0671 A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large file. Vscode Xml 0.19.0+ Fix from $2,3002022-02-18 CRITICAL 9.8 CVE-2021-20325 Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regress… Enterprise Linux Mitigation only Fix from $2,3002022-02-18 CRITICAL 9.1 CVE-2021-4048 An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS b… Ceph Storage 0.3.18+ Fix from $2,3002021-12-08 CRITICAL 9.8 CVE-2021-31917 A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authenticat… Data Grid 11.0.12 / 12.1.4+ Fix from $2,3002021-09-21 CRITICAL 9.0 CVE-2021-40438 KEVEPSS 100% A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP … Enterprise Linux Patch available Fix from $2,3002021-09-16 CRITICAL 9.8 CVE-2021-20314 Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code executio… Enterprise Linux 1.2.11+ Fix from $2,3002021-08-12 CRITICAL 9.8 CVE-2021-20236 A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by… Ceph Storage 4.3.3+ Fix from $2,3002021-05-28 CRITICAL 9.6 CVE-2021-20195 A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account takeover is possible due to … Keycloak 12.0.3+ Fix from $2,3002021-05-28 CRITICAL 9.0 CVE-2020-27832 A flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a repository's notification. Thi… Quay 3.3.2+ Fix from $2,3002021-05-27 CRITICAL 9.1 CVE-2018-10866 It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated use… Certification Mitigation only Fix from $2,3002021-05-26 CRITICAL 9.1 CVE-2018-10867 Files are accessible without restrictions from the /update/results page of redhat-certification 7 package, allowing an attacker to remove any file ac… Certification Mitigation only Fix from $2,3002021-05-26 CRITICAL 9.8 CVE-2018-25011 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16(). Enterprise Linux 1.0.1+ Fix from $2,3002021-05-21 CRITICAL 9.8 CVE-2018-25014 A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol(). Enterprise Linux 1.0.1+ Fix from $2,3002021-05-21 CRITICAL 9.8 CVE-2020-36328 A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check … Enterprise Linux 1.0.1+ Fix from $2,3002021-05-21 CRITICAL 9.8 CVE-2020-36329 A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this… Enterprise Linux 1.0.1 / 14.7+ Fix from $2,3002021-05-21 CRITICAL 9.1 CVE-2018-25009 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16(). Enterprise Linux 1.0.1+ Fix from $2,3002021-05-21 CRITICAL 9.1 CVE-2018-25010 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter(). Enterprise Linux 1.0.1+ Fix from $2,3002021-05-21 CRITICAL 9.1 CVE-2018-25012 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24(). Enterprise Linux 1.0.1+ Fix from $2,3002021-05-21 CRITICAL 9.1 CVE-2018-25013 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes(). Enterprise Linux 1.0.1+ Fix from $2,3002021-05-21 CRITICAL 9.1 CVE-2020-36331 A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulne… Enterprise Linux 1.0.1 / 14.7+ Fix from $2,3002021-05-21