Vulnerability index

Browse CVEs

231 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2021-3466EPSS 9% A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attac… Enterprise Linux Patch available Fix from $2,3002021-03-25 CRITICAL 9.8 CVE-2021-20231 A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences. Enterprise Linux 3.7.1+ Fix from $2,3002021-03-12 CRITICAL 9.8 CVE-2021-20232 A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potentia… Enterprise Linux 3.7.1+ Fix from $2,3002021-03-12 CRITICAL 9.1 CVE-2020-14324 A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS command injection vulnerabil… Cloudforms Management Engine 5.11.7.0+ Fix from $2,3002020-08-11 CRITICAL 9.1 CVE-2020-14325 Red Hat CloudForms before 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious attacker to create existent and… Cloudforms 5.11.7.0+ Fix from $2,3002020-08-11 CRITICAL 9.9 CVE-2020-10731 A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux enabled. This flaw cause… Openstack Platform Mitigation only Fix from $2,3002020-07-31 CRITICAL 9.8 CVE-2020-1745 A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.29.Final … Undertow after 2.0.29 Fix from $2,3002020-04-28 CRITICAL 9.1 CVE-2019-14887 A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An… Jboss Data Grid Mitigation only Fix from $2,3002020-03-16 CRITICAL 9.8 CVE-2020-1731 A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password… Keycloak Operator 8.0.2+ Fix from $2,3002020-03-02 CRITICAL 9.8 CVE-2019-14892EPSS 6% A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a mal… Decision Manager 2.6.7.3 / 2.8.11.5+ Fix from $2,3002020-03-02 CRITICAL 9.8 CVE-2014-4657 The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code vi… Ansible 1.5.4+ Fix from $2,3002020-02-20 CRITICAL 9.8 CVE-2014-4678EPSS 5% The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code vi… Ansible 1.6.4+ Fix from $2,3002020-02-20 CRITICAL 9.8 CVE-2014-4966 Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which … Ansible 1.6.7+ Fix from $2,3002020-02-18 CRITICAL 9.8 CVE-2014-4967 Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansib… Ansible 1.6.7+ Fix from $2,3002020-02-18 CRITICAL 9.8 CVE-2014-8089 SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows … Enterprise Linux 1.12.9 / 2.2.8+ Fix from $2,3002020-02-17 CRITICAL 9.8 CVE-2020-1693 A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An unauthenticated … Spacewalk 2.9+ Fix from $2,3002020-02-17 CRITICAL 9.8 CVE-2014-0234 The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows re… Openshift 2.1+ Fix from $2,3002020-02-12 CRITICAL 9.8 CVE-2013-2060EPSS 6% The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a req… Openshift No fix yet Fix from $2,3002020-01-28 CRITICAL 9.8 CVE-2019-14906 A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL pack… Enterprise Linux after 2.0.9 Fix from $2,3002020-01-07 CRITICAL 9.1 CVE-2019-14837 A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name … Keycloak 8.0.0+ Fix from $2,3002020-01-07 CRITICAL 9.8 CVE-2019-10158 A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session inte… Jboss Data Grid after 9.4.14 Fix from $2,3002020-01-02 CRITICAL 9.1 CVE-2019-14859 A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this ver… Ceph Storage 0.13.3+ Fix from $2,3002020-01-02 CRITICAL 9.8 CVE-2014-3699 eDeploy has RCE via cPickle deserialization of untrusted data Edeploy No fix yet Fix from $2,3002019-12-15 CRITICAL 9.8 CVE-2014-0175 mcollective has a default password set at install Openshift Mitigation only Fix from $2,3002019-12-13 CRITICAL 9.8 CVE-2013-2166 python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass Openstack after 0.2.5 Fix from $2,3002019-12-10 CRITICAL 9.8 CVE-2013-2167 python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass Openstack after 0.2.5 Fix from $2,3002019-12-10 CRITICAL 9.8 CVE-2019-19333 In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "bits… Enterprise Linux Patch available Fix from $2,3002019-12-06 CRITICAL 9.8 CVE-2019-19334 In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "iden… Enterprise Linux Patch available Fix from $2,3002019-12-06 CRITICAL 9.8 CVE-2019-14910 A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDA… Keycloak Mitigation only Fix from $2,3002019-12-05 CRITICAL 9.8 CVE-2013-4486 Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging Zanata after 3.1.2 Fix from $2,3002019-12-03