Vulnerability index

Browse CVEs

231 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2016-5411 /var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created world readable and contains the … Quickstart Cloud Installer Mitigation only Fix from $2,3002017-06-13 CRITICAL 9.8 CVE-2016-5405 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server … Enterprise Linux Desktop Mitigation only Fix from $2,3002017-06-08 CRITICAL 9.8 CVE-2016-7050 SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and R… Enterprise Linux Desktop Mitigation only Fix from $2,3002017-06-08 CRITICAL 9.8 CVE-2016-3690 The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload. Jboss Enterprise Application Platform Mitigation only Fix from $2,3002017-06-08 CRITICAL 9.8 CVE-2017-7504EPSS 24% HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Se… Jboss Enterprise Application Platform after 4.0 Fix from $2,3002017-05-19 CRITICAL 9.8 CVE-2017-7503 It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use th… Jboss Enterprise Application Platform Mitigation only Fix from $2,3002017-05-18 CRITICAL 9.8 CVE-2008-7313 The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CV… Openstack after 4.2.3 Fix from $2,3002017-03-31 CRITICAL 9.8 CVE-2014-5008 Snoopy allows remote attackers to execute arbitrary commands. Openstack Patch available Fix from $2,3002017-03-31 CRITICAL 9.8 CVE-2014-5009 Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008. Openstack after 4.2.3 Fix from $2,3002017-03-31 CRITICAL 9.8 CVE-2017-5929EPSS 8% QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components. Satellite 1.2.0+ Fix from $2,3002017-03-13 CRITICAL 9.8 CVE-2016-9636EPSS 8% Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a… Enterprise Linux Desktop after 1.10.1 Fix from $2,3002017-01-27 CRITICAL 9.8 CVE-2016-9634EPSS 9% Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a… Enterprise Linux Desktop after 1.10.1 Fix from $2,3002017-01-27 CRITICAL 9.8 CVE-2016-9635EPSS 9% Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a… Enterprise Linux Desktop after 1.10.1 Fix from $2,3002017-01-27 CRITICAL 9.8 CVE-2014-8241 XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return … Enterprise Linux Desktop Mitigation only Fix from $2,3002016-12-14 CRITICAL 9.8 CVE-2016-6330EPSS 9% The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote a… Jboss Operations Network Mitigation only Fix from $2,3002016-09-27 CRITICAL 9.8 CVE-2016-4999 SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuil… Dashbuilder after 0.5.0 Fix from $2,3002016-08-05 CRITICAL 9.8 CVE-2016-3737EPSS 6% The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, relat… Jboss Operations Network after 3.3.5 Fix from $2,3002016-08-02 CRITICAL 9.8 CVE-2016-5008 libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers… Libvirt after 1.3.5 Fix from $2,3002016-07-13 CRITICAL 9.8 CVE-2016-2074EPSS 6% Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute … Openshift Patch available Fix from $2,3002016-07-03 CRITICAL 9.8 CVE-2016-2141 It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use … Jgroups 4.0+ Fix from $2,3002016-06-30 CRITICAL 9.8 CVE-2016-4171 KEVEPSS 20% Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as expl… Enterprise Linux Desktop after 21.0.0.242 Fix from $2,3002016-06-16 CRITICAL 9.8 CVE-2016-4138EPSS 25% Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11… Enterprise Linux Desktop after 21.0.0.242 Fix from $2,3002016-06-16 CRITICAL 9.8 CVE-2016-4448EPSS 7% Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors. Enterprise Linux Desktop Mitigation only Fix from $2,3002016-06-09 CRITICAL 9.1 CVE-2015-5041 The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote at… Satellite 6.0.16.20 / 6.1.8.20+ Fix from $2,3002016-06-06 CRITICAL 9.8 CVE-2015-4602EPSS 10% The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remot… Enterprise Linux after 5.4.39 Fix from $2,3002016-05-16 CRITICAL 9.8 CVE-2015-4601EPSS 8% PHP before 5.6.7 might allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected d… Enterprise Linux Desktop after 5.6.6 Fix from $2,3002016-05-16 CRITICAL 9.8 CVE-2015-4600EPSS 10% The SoapClient implementation in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service … Enterprise Linux Desktop after 5.4.39 Fix from $2,3002016-05-16 CRITICAL 9.8 CVE-2016-1666 Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.94 allow attackers to cause a denial of service or possibly have other impact … Enterprise Linux Desktop Supplementary after 50.0.2661.87 Fix from $2,3002016-05-14 CRITICAL 9.8 CVE-2016-4117 KEVEPSS 94% Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May … Enterprise Linux Desktop after 21.0.0.226 Fix from $2,3002016-05-11 CRITICAL 9.8 CVE-2016-2108EPSS 79% The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of serv… Enterprise Linux Desktop after 1.0.1n Fix from $2,3002016-05-05