Vulnerability index

Browse CVEs

173 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Jboss Enterprise Brms Platform HIGH 7.5
CVE-2013-2186EPSS 13%

The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss …

Fix: after 3.1
Fix from $1,950 2013-10-28
Openstack MEDIUM 5.0
CVE-2013-4180

The (1) power and (2) ipmi_boot actions in the HostController in Foreman before 1.2.2 allow remote attackers to cause a denial of service (memory con…

Fix: after 1.2.1
Fix from $1,600 2013-09-16
Enterprise Mrg MEDIUM 5.8
CVE-2013-1909

The Python client in Apache Qpid before 2.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subje…

Fix: after 0.20
Fix from $1,600 2013-08-23
Enterprise Linux Desktop MEDIUM 5.0
CVE-2012-3411EPSS 5%

Dnsmasq before 2.63test1, when used with certain libvirt configurations, replies to requests from prohibited interfaces, which allows remote attacker…

Fix: after 2.62
Fix from $1,600 2013-03-05
Openshift MEDIUM 5.8
CVE-2012-5647

Open redirect vulnerability in node-util/www/html/restorer.php in Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to redirect users t…

Fix: after 1.0.5
Fix from $1,600 2013-02-24
Openshift HIGH 7.5
CVE-2012-5646

node-util/www/html/restorer.php in the Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to execute arbitrary commands via a crafted uu…

Fix: after 1.0.5
Fix from $1,950 2013-02-24
Enterprise Linux MEDIUM 6.2
CVE-2012-5536

A certain Red Hat build of the pam_ssh_agent_auth module on Red Hat Enterprise Linux (RHEL) 6 and Fedora Rawhide calls the glibc error function inste…

Patch available
Fix from $1,600 2013-02-22
Enterprise Linux Desktop HIGH 7.1
CVE-2012-5689EPSS 12%

ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA …

Mitigation only
Fix from $1,950 2013-01-25
Virtualization HIGH 7.2
CVE-2012-3515

Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users…

Fix: 1.2.0+
Fix from $1,950 2012-11-23
Enterprise Linux Desktop HIGH 7.8
CVE-2012-1535 KEVEPSS 70%

Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers …

Fix: 11.2.202.238 / 11.3.300.271+
Fix from $1,950 2012-08-15
Jboss Enterprise Application Platform MEDIUM 5.8
CVE-2011-4314

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework …

Fix: after 1.0.1
Fix from $1,600 2012-01-27
System Config Printer MEDIUM 5.1
CVE-2011-2899

pysmb.py in system-config-printer 0.6.x and 0.7.x, as used in foomatic-gui and possibly other products, allows remote SMB servers to execute arbitrar…

Patch available
Fix from $1,600 2011-08-31
Directory Server HIGH 7.5
CVE-2011-0019

slapd (aka ns-slapd) in 389 Directory Server 1.2.7.5 (aka Red Hat Directory Server 8.2.x or dirsrv) does not properly handle simple paged result sear…

Mitigation only
Fix from $1,950 2011-02-23
Icedtea MEDIUM 6.8
CVE-2011-0025

IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or…

Patch available
Fix from $1,600 2011-02-04
Evince HIGH 7.6
CVE-2010-2640

Array index error in the PK font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to cause a denial of service …

Fix: after 2.32
Fix from $1,950 2011-01-07
Evince HIGH 7.6
CVE-2010-2641

Array index error in the VF font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to cause a denial of service …

Fix: after 2.32
Fix from $1,950 2011-01-07
Jboss Enterprise Application Platform HIGH 7.5
CVE-2010-3708

The serialization implementation in JBoss Drools in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 and …

Mitigation only
Fix from $1,950 2010-12-30
Enterprise Virtualization MEDIUM 6.6
CVE-2010-0431

QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and KVM 83, does not properly validate gues…

Patch available
Fix from $1,600 2010-08-24
Enterprise Virtualization MEDIUM 6.6
CVE-2010-0428

libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and qspice 0.3.0, does not prop…

Patch available
Fix from $1,600 2010-08-24
Jboss Enterprise Application Platform MEDIUM 5.0
CVE-2009-0027

The request handler in JBossWS in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP06 and 4.3 before 4.3.0.CP04 does…

Patch available
Fix from $1,600 2009-03-09
Cygwin HIGH 7.6
CVE-2008-3323

setup.exe before 2.573.2.3 in Cygwin does not properly verify the authenticity of packages, which allows remote Cygwin mirror servers or man-in-the-m…

Fix: after 1.7
Fix from $1,950 2008-07-28
Directory Server HIGH 9.0
CVE-2008-0892EPSS 14%

The replication monitor CGI script (repl-monitor-cgi.pl) in Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, allow…

Mitigation only
Fix from $1,950 2008-04-16
Enterprise Linux HIGH 7.2
CVE-2007-4130

The Linux kernel 2.6.9 before 2.6.9-67 in Red Hat Enterprise Linux (RHEL) 4 on Itanium (ia64) does not properly handle page faults during NUMA memory…

Patch available
Fix from $1,950 2008-02-05