Vulnerability index

Browse CVEs

173 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
3scale Api Management MEDIUM 6.5
CVE-2021-20252

A flaw was found in Red Hat 3scale API Management Platform 2. The 3scale backend does not perform preventive handling on user-requested date ranges i…

Mitigation only
Fix from $1,600 2021-02-23
Ceph Storage MEDIUM 6.1
CVE-2020-25626

A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails…

Fix: 3.12.0+
Fix from $1,600 2020-09-30
Xerces MEDIUM 5.3
CVE-2020-14338

A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforce…

Fix: 2.12.0+
Fix from $1,600 2020-09-17
Ansible HIGH 7.3
CVE-2019-14904

A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name…

Fix: 2.7.15 / 2.8.7+
Fix from $1,950 2020-08-26
Keycloak MEDIUM 5.4
CVE-2020-1727

A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks proper input validation as it al…

Fix: 9.0.2+
Fix from $1,600 2020-06-22
Cloudforms Management Engine HIGH 7.2
CVE-2019-14894

A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution throu…

Mitigation only
Fix from $1,950 2020-06-22
Resteasy HIGH 7.5
CVE-2020-1695

A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input v…

Fix: 3.12.0 / 4.6.0+
Fix from $1,950 2020-05-19
Keycloak HIGH 8.8
CVE-2020-1714

A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an…

Fix: 11.0.0+
Fix from $1,950 2020-05-13
Hibernate Validator MEDIUM 5.3
CVE-2020-10693

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evalua…

Fix: 6.0.20 / 6.1.5+
Fix from $1,600 2020-05-06
Undertow HIGH 8.1
CVE-2020-1757

A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.…

Fix: 2.1.0+
Fix from $1,950 2020-04-21
Ansible Engine MEDIUM 5.6
CVE-2019-14905

A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos…

Fix: 2.7.16 / 2.8.8+
Fix from $1,600 2020-03-31
Libvirt MEDIUM 5.7
CVE-2019-20485

qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a…

Fix: 6.0.0+
Fix from $1,600 2020-03-19
Ansible CRITICAL 9.8
CVE-2014-4657

The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code vi…

Fix: 1.5.4+
Fix from $2,300 2020-02-20
Virtualization HIGH 8.8
CVE-2013-4535

The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm imag…

Fix: 1.7.2+
Fix from $1,950 2020-02-11
Enterprise Linux HIGH 8.3
CVE-2019-9503

The Broadcom brcmfmac WiFi driver prior to commit a4176ec356c73a46c07c181c6d04039fafa34a9f is vulnerable to a frame validation bypass. If the brcmfma…

Patch available
Fix from $1,950 2020-01-16
Automatic Bug Reporting Tool HIGH 7.1
CVE-2015-3150

abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory ar…

Patch available
Fix from $1,950 2020-01-14
Enterprise Linux HIGH 7.3
CVE-2019-14866

In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives fro…

Fix: 2.13+
Fix from $1,950 2020-01-07
Ceph Storage MEDIUM 6.5
CVE-2019-19337

A flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An authenticated attacker can abuse …

Mitigation only
Fix from $1,600 2019-12-23
Openshift HIGH 8.1
CVE-2013-2103

OpenShift cartridge allows remote URL retrieval

Mitigation only
Fix from $1,950 2019-12-03
Enterprise Mrg CRITICAL 9.8
CVE-2012-3460

cumin: At installation postgresql database user created without password

Mitigation only
Fix from $2,300 2019-11-21
Openshift Origin MEDIUM 5.5
CVE-2014-0084

Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of service in cron.daily and cron.…

Fix: 2014-02-14+
Fix from $1,600 2019-11-21
Enterprise Linux HIGH 7.5
CVE-2011-4967

tog-Pegasus has a package hash collision DoS vulnerability

Fix: 2.12+
Fix from $1,950 2019-11-19
Enterprise Linux MEDIUM 5.5
CVE-2014-5118

Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability

Fix: 1.8.2+
Fix from $1,600 2019-11-18
Enterprise Linux CRITICAL 9.8
CVE-2011-2897

gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw

Fix: after 2.31.1
Fix from $2,300 2019-11-12
Tuned MEDIUM 5.5
CVE-2013-1820

tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.

Fix: 2.0.2+
Fix from $1,600 2019-11-08
Enterprise Linux CRITICAL 9.8
CVE-2015-8980EPSS 7%

The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code.

Fix: 1.0.12+
Fix from $2,300 2019-11-04
Openshift HIGH 7.3
CVE-2013-0165

cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp.

Mitigation only
Fix from $1,950 2019-11-01
Openstack HIGH 8.8
CVE-2018-10899

A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly c…

Fix: 1.6.1+
Fix from $1,950 2019-08-01
Satellite HIGH 7.5
CVE-2019-10245

In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causi…

Fix: 0.14.0+
Fix from $1,950 2019-04-19
Satellite CRITICAL 9.8
CVE-2018-12547

In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects exis…

Fix: 0.12.0+
Fix from $2,300 2019-02-11