Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2023-39976 log_blackbox.c in libqb before 2.0.8 allows a buffer overflow via long log messages because the header size is not considered. Libqb 2.0.8+ Fix from $2,3002023-08-08 HIGH 8.8 CVE-2021-3020 An issue was discovered in ClusterLabs Hawk (aka HA Web Konsole) through 2.3.0-15. It ships the binary hawk_invoke (built from tools/hawk_invoke.c), … Hawk after 2.3.0-15 Fix from $1,9502022-08-26 MEDIUM 5.5 CVE-2010-2496 stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwor… Cluster Glue 1.0.6 / 1.1.3+ Fix from $1,6002021-10-18 CRITICAL 9.8 CVE-2020-35458EPSS 5% An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawk_remember_me_id parameter in … Hawk Patch available Fix from $2,3002021-01-12 MEDIUM 5.9 CVE-2014-0104 In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-mid… Fence Agents 4.0.17+ Fix from $1,6002020-01-02 MEDIUM 5.5 CVE-2011-5271 Pacemaker before 1.1.6 configure script creates temporary files insecurely Pacemaker 1.1.6+ Fix from $1,6002019-11-12 HIGH 7.1 CVE-2019-12779 libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /t… Libqb 1.0.5+ Fix from $1,9502019-06-07 MEDIUM 6.1 CVE-2017-2661 ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field when creat… Pcs 0.9.157+ Fix from $1,6002018-03-12