Vulnerability index

Browse CVEs

173 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Satellite CRITICAL 9.8
CVE-2018-12549

In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when acceleratin…

Mitigation only
Fix from $2,300 2019-02-11
Ceph HIGH 7.5
CVE-2018-16889

Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files …

Fix: after 13.2.4
Fix from $1,950 2019-01-28
Modulemd CRITICAL 9.8
CVE-2017-1002157

modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.

Fix: after 1.3.1
Fix from $2,300 2019-01-10
Linux Desktop HIGH 7.5
CVE-2018-6101

A lack of host validation in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML …

Fix: 66.0.3359.117+
Fix from $1,950 2018-12-04
Gluster Storage MEDIUM 6.5
CVE-2016-2125EPSS 9%

It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to wh…

Fix: 4.3.13 / 4.4.8+
Fix from $1,600 2018-10-31
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-5156

A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurring. This can result in stream …

Mitigation only
Fix from $2,300 2018-10-18
Enterprise Linux Desktop CRITICAL 9.1
CVE-2018-12387EPSS 10%

A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by…

Patch available
Fix from $2,300 2018-10-18
Enterprise Linux Desktop HIGH 7.0
CVE-2018-12385

A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile director…

Mitigation only
Fix from $1,950 2018-10-18
389 Directory Server MEDIUM 6.5
CVE-2018-10935

A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.

Fix: 1.3.8.7 / 1.4.0.14+
Fix from $1,600 2018-09-11
Openstack CRITICAL 9.8
CVE-2018-14620

The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could potentially…

Mitigation only
Fix from $2,300 2018-09-10
Openstack MEDIUM 6.5
CVE-2018-14635

When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP add…

Fix: after 12.0.3
Fix from $1,600 2018-09-10
Enterprise Linux Desktop HIGH 7.5
CVE-2018-14624

A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the error log was not correctly u…

Fix: after 1.4.0.16
Fix from $1,950 2018-09-06
Openshift Container Platform MEDIUM 5.3
CVE-2016-1000232

NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial…

Fix: after 5.0.7.2
Fix from $1,600 2018-09-05
Enterprise Linux MEDIUM 6.5
CVE-2018-10930

A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw to write to a destination ou…

Fix: 3.12.14 / 4.1.4+
Fix from $1,600 2018-09-04
Virtualization Host HIGH 8.8
CVE-2018-10926

A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to a…

Fix: 3.12.14 / 4.1.8+
Fix from $1,950 2018-09-04
Virtualization Host HIGH 8.1
CVE-2018-10923

It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker c…

Fix: 3.12.14 / 4.1.8+
Fix from $1,950 2018-09-04
Satellite HIGH 7.5
CVE-2018-1517

A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack w…

Mitigation only
Fix from $1,950 2018-08-20
Virtualization MEDIUM 6.3
CVE-2018-10908

It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By uploading a specially crafted image…

Fix: 4.20.37+
Fix from $1,600 2018-08-09
Ceph Storage HIGH 7.5
CVE-2016-9579

A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A re…

Patch available
Fix from $1,950 2018-08-01
Openshift HIGH 7.7
CVE-2016-8631

The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routes can pote…

Mitigation only
Fix from $1,950 2018-07-31
Ceph MEDIUM 6.5
CVE-2016-8626

A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ceph Object Gateway handles POST object requests permits an authenticated attacker to launc…

Fix: 0.94.3.9-8+
Fix from $1,600 2018-07-31
Openstack HIGH 7.5
CVE-2018-10903

A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user …

Fix: 2.3+
Fix from $1,950 2018-07-30
Cloudforms Management Engine MEDIUM 6.5
CVE-2017-2653

A number of unused delete routes are present in CloudForms before 5.7.2.1 which can be accessed via GET requests instead of just POST requests. This …

Fix: 5.7.2.1+
Fix from $1,600 2018-07-27
Jboss Bpm Suite MEDIUM 6.5
CVE-2017-2658

It was discovered that the Dashbuilder login page as used in Red Hat JBoss BPM Suite before 6.4.2 and Red Hat JBoss Data Virtualization & Services be…

Fix: 6.4.2 / 6.4.3+
Fix from $1,600 2018-07-27
Jboss Bpm Suite MEDIUM 5.4
CVE-2017-2674

JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a stored XSS via several lists in Business Central. The flaw is due to lack of sanitation…

Fix: 6.4.3+
Fix from $1,600 2018-07-27
Enterprise Virtualization MEDIUM 6.3
CVE-2017-2614

When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is ex…

Mitigation only
Fix from $1,600 2018-07-27
Enterprise Linux Desktop HIGH 8.8
CVE-2017-12173

It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulner…

Fix: 1.16.0+
Fix from $1,950 2018-07-27
Ansible Tower HIGH 7.2
CVE-2017-12148

A flaw was found in Ansible Tower's interface before 3.1.5 and 3.2.0 with SCM repositories. If a Tower project (SCM repository) definition does not h…

Fix: 3.1.5 / 3.2.0+
Fix from $1,950 2018-07-27
Enterprise Linux MEDIUM 6.5
CVE-2017-12171EPSS 8%

A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines…

Mitigation only
Fix from $1,600 2018-07-26
Certificate System MEDIUM 6.5
CVE-2017-7509

An input validation error was found in Red Hat Certificate System's handling of client provided certificates before 8.1.20-1. If the certreq field is…

Fix: 8.1.20-1+
Fix from $1,600 2018-07-26