Vulnerability index

Browse CVEs

173 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Fuse HIGH 7.5
CVE-2017-7957

XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during…

Fix: after 1.4.9
Fix from $1,950 2017-04-29
Enterprise Linux Desktop MEDIUM 5.5
CVE-2016-7796

The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received o…

Patch available
Fix from $1,600 2016-10-13
Jboss Enterprise Application Platform HIGH 7.5
CVE-2016-3110

mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP mes…

Mitigation only
Fix from $1,950 2016-09-26
Enterprise Linux Desktop HIGH 7.5
CVE-2016-5418

The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to …

Patch available
Fix from $1,950 2016-09-21
Enterprise Linux Desktop HIGH 7.5
CVE-2016-4809

The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a…

Patch available
Fix from $1,950 2016-09-21
Jboss Operations Network CRITICAL 9.8
CVE-2016-3737EPSS 7%

The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, relat…

Fix: after 3.3.5
Fix from $2,300 2016-08-02
Ceph Storage Mon MEDIUM 6.5
CVE-2016-5009

The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph mon…

Fix: after 0.94.6
Fix from $1,600 2016-07-12
Enterprise Linux MEDIUM 6.5
CVE-2016-6170EPSS 41%

ISC BIND through 9.9.9-P1, 9.10.x through 9.10.4-P1, and 9.11.x through 9.11.0b1 allows primary DNS servers to cause a denial of service (secondary D…

Fix: after 9.10.3
Fix from $1,600 2016-07-06
Satellite HIGH 8.1
CVE-2016-0363

The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 be…

Mitigation only
Fix from $1,950 2016-06-03
Enterprise Linux Desktop MEDIUM 6.5
CVE-2015-4598

PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not ensure that pathnames lack %00 sequences, which might allow remote attackers…

Fix: after 5.4.41
Fix from $1,600 2016-05-16
Enterprise Linux MEDIUM 6.5
CVE-2015-3411

PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers …

Fix: after 5.4.39
Fix from $1,600 2016-05-16
Enterprise Linux Desktop Supplementary MEDIUM 6.5
CVE-2016-1665

The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrome before 50.0.2661.94, mishandles comparison oper…

Fix: after 50.0.2661.87
Fix from $1,600 2016-05-14
Enterprise Linux Desktop Supplementary HIGH 8.0
CVE-2016-1661

Blink, as used in Google Chrome before 50.0.2661.94, does not ensure that frames satisfy a check for the same renderer process in addition to a Same …

Fix: after 50.0.2661.87
Fix from $1,950 2016-05-14
Enterprise Linux Desktop Supplementary HIGH 8.8
CVE-2016-1660

Blink, as used in Google Chrome before 50.0.2661.94, mishandles assertions in the WTF::BitArray and WTF::double_conversion::Vector classes, which all…

Fix: after 50.0.2661.87
Fix from $1,950 2016-05-14
Openshift CRITICAL 9.8
CVE-2015-5254EPSS 38%

Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitr…

Mitigation only
Fix from $2,300 2016-01-08
Enterprise Linux Desktop MEDIUM 6.8
CVE-2015-5234

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .app…

Fix: after 1.5.2
Fix from $1,600 2015-10-09
Enterprise Linux Desktop MEDIUM 6.8
CVE-2014-9751

The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP addr…

Fix: 4.2.8+
Fix from $1,600 2015-10-06
Enterprise Linux Desktop MEDIUM 5.8
CVE-2014-9750EPSS 6%

ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtain sensitive information from …

Fix: 4.2.8+
Fix from $1,600 2015-10-06
Enterprise Linux Desktop MEDIUM 5.0
CVE-2015-4148EPSS 20%

The do_soap_call function in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that the uri property …

Fix: after 10.10.4
Fix from $1,600 2015-06-09
Enterprise Linux Desktop HIGH 7.5
CVE-2014-7840

The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers to execute arbitrary code via…

Fix: after 2.1.3
Fix from $1,950 2014-12-12
Resteasy MEDIUM 6.4
CVE-2014-7839

DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which …

Mitigation only
Fix from $1,600 2014-11-25
Freeipa MEDIUM 5.0
CVE-2013-0336

The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_extop.c in the directory server (dirsrv) in FreeIPA before 3.2.0 allows…

Fix: after 3.1.5
Fix from $1,600 2014-11-03
Cloudforms 3.0 Management Engine MEDIUM 5.0
CVE-2014-0136

The (1) get and (2) log methods in the AgentController in Red Hat CloudForms 3.0 Management Engine (CFME) 5.x allow remote attackers to insert arbitr…

Fix: after 5.2.5.3
Fix from $1,600 2014-10-27
Enterprise Virtualization Manager MEDIUM 6.5
CVE-2014-3573

The oVirt Engine backend module, as used in Red Hat Enterprise Virtualization Manager before 3.4.2, uses an "insecure DocumentBuilderFactory," which …

Fix: after 3.4.1
Fix from $1,600 2014-10-18
Enterprise Mrg MEDIUM 5.0
CVE-2012-2682

Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, allows attackers with certain database privileges to cause a denial of ser…

Mitigation only
Fix from $1,600 2014-07-19
Network Satellite MEDIUM 6.5
CVE-2013-2143EPSS 48%

The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows r…

Fix: after 1.5.0-14
Fix from $1,600 2014-04-17
Network Proxy MEDIUM 6.0
CVE-2010-2236

The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and …

Fix: after 2.1.147-1
Fix from $1,600 2014-04-15
Jboss Enterprise Portal Platform MEDIUM 5.8
CVE-2011-2941

Open redirect vulnerability in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allows remote attackers to redirect users to arbitrary web sites…

Fix: after 5.1.1
Fix from $1,600 2014-02-26
Jboss Operations Network MEDIUM 5.8
CVE-2012-0052

Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 does not check the JON agent key, which allows remote attackers to spoof t…

Fix: after 2.4.1
Fix from $1,600 2014-02-14
Network Satellite MEDIUM 6.5
CVE-2011-1594

A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to ar…

Patch available
Fix from $1,600 2014-02-05