Vulnerability index

Browse CVEs

173 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Openstack HIGH 7.5
CVE-2017-7539EPSS 6%

An assertion-failure flaw was found in Qemu before 2.10.1, in the Network Block Device (NBD) server's initial connection negotiation, where the I/O c…

Fix: 2.10.1+
Fix from $1,950 2018-07-26
Certification CRITICAL 9.8
CVE-2018-10870EPSS 6%

redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any fil…

Mitigation only
Fix from $2,300 2018-07-19
Openshift Container Platform CRITICAL 9.8
CVE-2017-7481

Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of looku…

Fix: 2.3.1.0 / 2.4.0.0+
Fix from $2,300 2018-07-19
Openshift MEDIUM 5.3
CVE-2017-15137

The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a…

Mitigation only
Fix from $1,600 2018-07-16
Openshift HIGH 7.5
CVE-2018-10885

In atomic-openshift before version 3.10.9 a malicious network-policy configuration can cause Openshift Routing to crash when using ovs-networkpolicy …

Fix: 3.10.9+
Fix from $1,950 2018-07-05
Openshift Container Platform HIGH 8.8
CVE-2018-10843

source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privile…

Fix: 3.7.53+
Fix from $1,950 2018-07-02
Ansible Engine HIGH 7.8
CVE-2018-10874

In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's con…

Mitigation only
Fix from $1,950 2018-07-02
Ansible HIGH 8.0
CVE-2017-7466

Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An attacker with control over a cl…

Fix: 2.3+
Fix from $1,950 2018-06-22
Source To Image MEDIUM 6.5
CVE-2018-1103

Openshift Enterprise source-to-image before version 1.1.10 is vulnerable to an improper validation of user input. An attacker who could trick a user …

Fix: 1.1.10+
Fix from $1,600 2018-06-12
Openshift Container Platform HIGH 7.5
CVE-2018-1070

routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which can cause an entire shard to b…

Fix: 3.10+
Fix from $1,950 2018-06-12
Enterprise Linux Aus MEDIUM 5.3
CVE-2017-7829

It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not d…

Fix: 52.5.2+
Fix from $1,600 2018-06-11
Enterprise Linux Desktop HIGH 7.8
CVE-2017-7814

File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature …

Fix: 52.4.0 / 56.0+
Fix from $1,950 2018-06-11
Enterprise Linux Desktop HIGH 7.5
CVE-2017-7762

When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing…

Fix: 54.0+
Fix from $1,950 2018-06-11
Enterprise Linux HIGH 7.5
CVE-2017-5449

A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS animations. This vulnerabilit…

Fix: 52.1.0 / 53.0+
Fix from $1,950 2018-06-11
Enterprise Linux Aus CRITICAL 9.8
CVE-2016-9901

HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-sa…

Fix: 45.6.0 / 50.1+
Fix from $2,300 2018-06-11
Ansible Tower HIGH 8.8
CVE-2018-1104

Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrar…

Fix: after 3.2.3
Fix from $1,950 2018-05-02
Openshift HIGH 8.8
CVE-2018-1102

A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFr…

Patch available
Fix from $1,950 2018-04-30
Ansible HIGH 8.1
CVE-2016-9587EPSS 18%

Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacke…

Fix: 2.1.4 / 2.2.1+
Fix from $1,950 2018-04-24
Etcd MEDIUM 5.5
CVE-2018-1099

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser in…

Fix: after 3.3.1
Fix from $1,600 2018-04-03
Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-8945

The bfd_section_from_shdr function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows rem…

Patch available
Fix from $1,600 2018-03-22
Resteasy HIGH 8.1
CVE-2016-9606EPSS 6%

JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted dat…

Fix: after 3.1.1
Fix from $1,950 2018-03-09
Enterprise Linux Desktop HIGH 7.5
CVE-2018-7549

In params.c in zsh through 5.4.2, there is a crash during a copy of an empty hash table, as demonstrated by typeset -p.

Fix: after 5.4.2
Fix from $1,950 2018-02-27
Enterprise Linux Desktop HIGH 7.8
CVE-2018-7208

In the coff_pointerize_aux function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, an in…

Mitigation only
Fix from $1,950 2018-02-18
Resteasy HIGH 8.1
CVE-2018-1051

It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yam…

Mitigation only
Fix from $1,950 2018-01-25
Jboss Wildfly Application Server MEDIUM 5.5
CVE-2018-1047

A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResou…

Mitigation only
Fix from $1,600 2018-01-24
Enterprise Linux HIGH 8.8
CVE-2017-15103EPSS 5%

A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted r…

Patch available
Fix from $1,950 2017-12-18
Enterprise Linux MEDIUM 5.5
CVE-2017-15121

A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not e…

Mitigation only
Fix from $1,600 2017-12-07
Feedhenry Enterprise Mobile Application Platform MEDIUM 6.5
CVE-2015-5248

Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform.

No fix yet
Fix from $1,600 2017-09-20
Virtio Win HIGH 7.5
CVE-2015-3215

The NetKVM Windows Virtio driver allows remote attackers to cause a denial of service (guest crash) via a crafted length value in an IP packet, as de…

Patch available
Fix from $1,950 2017-06-26
Ansible HIGH 8.8
CVE-2014-3498

The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands.

Fix: after 1.6.5
Fix from $1,950 2017-06-08