Vulnerability index

Browse CVEs

231 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2019-14842 Structured reply is a feature of the newstyle NBD protocol allowing the server to send a reply in chunks. A bounds check which was supposed to test f… Libnbd 1.0.3+ Fix from $2,3002019-11-26 CRITICAL 9.8 CVE-2014-3585 redhat-upgrade-tool: Does not check GPG signatures when upgrading versions Redhat Upgrade Tool Mitigation only Fix from $2,3002019-11-22 CRITICAL 9.8 CVE-2014-3700 eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data Edeploy after 1.6.0 Fix from $2,3002019-11-21 CRITICAL 9.8 CVE-2012-3460 cumin: At installation postgresql database user created without password Enterprise Mrg Mitigation only Fix from $2,3002019-11-21 CRITICAL 9.8 CVE-2011-2897 gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw Enterprise Linux after 2.31.1 Fix from $2,3002019-11-12 CRITICAL 9.8 CVE-2015-8980EPSS 7% The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code. Enterprise Linux 1.0.12+ Fix from $2,3002019-11-04 CRITICAL 9.1 CVE-2010-2548 IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files. Icedtea6 1.7.4+ Fix from $2,3002019-10-31 CRITICAL 9.1 CVE-2010-2783 IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services. Icedtea6 1.7.4+ Fix from $2,3002019-10-31 CRITICAL 9.1 CVE-2019-17631 From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privil… Satellite after 0.16.0 Fix from $2,3002019-10-17 CRITICAL 9.8 CVE-2019-10212 A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to o… Undertow 2.0.20+ Fix from $2,3002019-10-02 CRITICAL 9.8 CVE-2019-10202EPSS 5% A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525… Jboss Enterprise Application Platform Mitigation only Fix from $2,3002019-10-01 CRITICAL 9.8 CVE-2019-14813EPSS 11% A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, en… Openshift Container Platform Patch available Fix from $2,3002019-09-06 CRITICAL 9.1 CVE-2019-10141 A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability wa… Openstack 5.0.2 / 6.0.3+ Fix from $2,3002019-07-30 CRITICAL 9.8 CVE-2018-11307EPSS 6% An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows… Openshift Container Platform 2.6.7.3 / 2.7.9.4+ Fix from $2,3002019-07-09 CRITICAL 9.8 CVE-2019-10137 A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthen… Satellite after 2.9 Fix from $2,3002019-07-02 CRITICAL 9.8 CVE-2019-3888 A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connector… Undertow 2.0.21+ Fix from $2,3002019-06-12 CRITICAL 9.0 CVE-2019-3873 It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An att… Jboss Enterprise Application Platform Mitigation only Fix from $2,3002019-06-12 CRITICAL 9.8 CVE-2016-7043 It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any… Kie Server 7.21.0+ Fix from $2,3002019-05-15 CRITICAL 9.8 CVE-2019-3899 It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This i… Openshift Container Platform Mitigation only Fix from $2,3002019-04-22 CRITICAL 9.8 CVE-2018-12547 In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects exis… Satellite 0.12.0+ Fix from $2,3002019-02-11 CRITICAL 9.8 CVE-2018-12549 In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when acceleratin… Satellite Mitigation only Fix from $2,3002019-02-11 CRITICAL 9.8 CVE-2017-1002157 modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution. Modulemd after 1.3.1 Fix from $2,3002019-01-10 CRITICAL 9.8 CVE-2018-16879 Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging cel… Ansible Tower 3.3.3+ Fix from $2,3002019-01-03 CRITICAL 9.8 CVE-2018-15981EPSS 10% Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution. Enterprise Linux Desktop after 31.0.0.148 Fix from $2,3002018-11-29 CRITICAL 9.8 CVE-2018-14667 KEVEPSS 74% The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticate… Richfaces after 3.3.4 Fix from $2,3002018-11-06 CRITICAL 9.8 CVE-2018-5156 A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurring. This can result in stream … Enterprise Linux Desktop Mitigation only Fix from $2,3002018-10-18 CRITICAL 9.1 CVE-2018-12387EPSS 8% A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by… Enterprise Linux Desktop Patch available Fix from $2,3002018-10-18 CRITICAL 9.8 CVE-2018-12378 A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to… Enterprise Linux Desktop Mitigation only Fix from $2,3002018-10-18 CRITICAL 9.8 CVE-2018-12376 Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of memory corruption and we presume that with enoug… Enterprise Linux Desktop Mitigation only Fix from $2,3002018-10-18 CRITICAL 9.8 CVE-2018-12377 A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted whi… Enterprise Linux Desktop Mitigation only Fix from $2,3002018-10-18