Vulnerability index

Browse CVEs

231 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.0 CVE-2018-3183 Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Scripting). Supported versions that are affected a… Satellite Patch available Fix from $2,3002018-10-17 CRITICAL 9.8 CVE-2018-14649EPSS 12% It was found that ceph-isci-cli package as shipped by Red Hat Ceph Storage 2 and 3 is using python-werkzeug in debug shell mode. This is done by sett… Enterprise Linux Desktop Patch available Fix from $2,3002018-10-09 CRITICAL 9.8 CVE-2018-14620 The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could potentially… Openstack Mitigation only Fix from $2,3002018-09-10 CRITICAL 9.8 CVE-2018-12825EPSS 6% Adobe Flash Player 30.0.0.134 and earlier have a security bypass vulnerability. Successful exploitation could lead to security mitigation bypass. Enterprise Linux Desktop after 30.0.0.154 Fix from $2,3002018-08-29 CRITICAL 9.8 CVE-2018-12828EPSS 6% Adobe Flash Player 30.0.0.134 and earlier have a "use of a component with a known vulnerability" vulnerability. Successful exploitation could lead to… Enterprise Linux Desktop after 30.0.0.154 Fix from $2,3002018-08-29 CRITICAL 9.8 CVE-2018-10931EPSS 68% It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use… Satellite after 2.6.11 Fix from $2,3002018-08-09 CRITICAL 9.1 CVE-2016-8628 Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create speci… Ansible 2.2.0+ Fix from $2,3002018-07-31 CRITICAL 9.8 CVE-2017-15101 A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a den… Enterprise Linux Desktop 2.5.4+ Fix from $2,3002018-07-27 CRITICAL 9.8 CVE-2017-7470 It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorizati… Spacewalk Mitigation only Fix from $2,3002018-07-27 CRITICAL 9.8 CVE-2017-7464 It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use thi… Jboss Enterprise Application Platform Mitigation only Fix from $2,3002018-07-27 CRITICAL 9.0 CVE-2017-2589 It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored … Jboss Fuse Mitigation only Fix from $2,3002018-07-26 CRITICAL 10.0 CVE-2017-2637 A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed… Openstack Mitigation only Fix from $2,3002018-07-26 CRITICAL 9.8 CVE-2018-10870EPSS 6% redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any fil… Certification Mitigation only Fix from $2,3002018-07-19 CRITICAL 9.8 CVE-2017-7481 Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of looku… Openshift Container Platform 2.3.1.0 / 2.4.0.0+ Fix from $2,3002018-07-19 CRITICAL 9.8 CVE-2017-7465 It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw … Jboss Enterprise Application Platform Mitigation only Fix from $2,3002018-06-27 CRITICAL 9.8 CVE-2018-1072 ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the option… Enterprise Virtualization Manager 4.2.2+ Fix from $2,3002018-06-26 CRITICAL 9.8 CVE-2018-1117 ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/Clou… Enterprise Virtualization 1.0.6+ Fix from $2,3002018-06-20 CRITICAL 9.8 CVE-2018-12532EPSS 6% JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and exec… Richfaces after 4.5.17 Fix from $2,3002018-06-18 CRITICAL 9.8 CVE-2018-12533EPSS 13% JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java… Richfaces after 3.3.4 Fix from $2,3002018-06-18 CRITICAL 9.8 CVE-2018-1085 openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificate authentication to be disabl… Openshift Container Platform 3.9.31+ Fix from $2,3002018-06-15 CRITICAL 9.8 CVE-2018-5183 Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and… Enterprise Linux Desktop Mitigation only Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-7824 A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. This is due to an incorrect va… Enterprise Linux Aus 52.4.0 / 56.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-7818 A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applications (ARIA) elements within containers through … Enterprise Linux Desktop 52.4.0 / 56.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-7819 A use-after-free vulnerability can occur in design mode when image objects are resized if objects referenced during the resizing have been freed from… Enterprise Linux Desktop 52.4.0 / 56.0+ Fix from $2,3002018-06-11 CRITICAL 9.1 CVE-2017-7758 An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use. This vu… Enterprise Linux Desktop 52.2.0 / 54.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5456 A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an IPC message. This allows for… Enterprise Linux 52.1.0 / 53.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5459 A buffer overflow in WebGL triggerable by web content, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, F… Enterprise Linux Desktop 45.9.0 / 52.1.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5428 An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental exten… Enterprise Linux 52.0.1+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5429 Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory co… Enterprise Linux Desktop 45.9.0 / 52.1.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5430 Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we pr… Enterprise Linux Desktop 52.1.0 / 53.0+ Fix from $2,3002018-06-11