Vulnerability index

Browse CVEs

173 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 6.5 CVE-2021-20252 A flaw was found in Red Hat 3scale API Management Platform 2. The 3scale backend does not perform preventive handling on user-requested date ranges i… 3scale Api Management Mitigation only Fix from $1,6002021-02-23 MEDIUM 6.1 CVE-2020-25626 A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails… Ceph Storage 3.12.0+ Fix from $1,6002020-09-30 MEDIUM 5.3 CVE-2020-14338 A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforce… Xerces 2.12.0+ Fix from $1,6002020-09-17 HIGH 7.3 CVE-2019-14904 A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name… Ansible 2.7.15 / 2.8.7+ Fix from $1,9502020-08-26 MEDIUM 5.4 CVE-2020-1727 A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks proper input validation as it al… Keycloak 9.0.2+ Fix from $1,6002020-06-22 HIGH 7.2 CVE-2019-14894 A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution throu… Cloudforms Management Engine Mitigation only Fix from $1,9502020-06-22 HIGH 7.5 CVE-2020-1695 A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input v… Resteasy 3.12.0 / 4.6.0+ Fix from $1,9502020-05-19 HIGH 8.8 CVE-2020-1714 A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an… Keycloak 11.0.0+ Fix from $1,9502020-05-13 MEDIUM 5.3 CVE-2020-10693 A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evalua… Hibernate Validator 6.0.20 / 6.1.5+ Fix from $1,6002020-05-06 HIGH 8.1 CVE-2020-1757 A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.… Undertow 2.1.0+ Fix from $1,9502020-04-21 MEDIUM 5.6 CVE-2019-14905 A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos… Ansible Engine 2.7.16 / 2.8.8+ Fix from $1,6002020-03-31 MEDIUM 5.7 CVE-2019-20485 qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a… Libvirt 6.0.0+ Fix from $1,6002020-03-19 CRITICAL 9.8 CVE-2014-4657 The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code vi… Ansible 1.5.4+ Fix from $2,3002020-02-20 HIGH 8.8 CVE-2013-4535 The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm imag… Virtualization 1.7.2+ Fix from $1,9502020-02-11 HIGH 8.3 CVE-2019-9503 The Broadcom brcmfmac WiFi driver prior to commit a4176ec356c73a46c07c181c6d04039fafa34a9f is vulnerable to a frame validation bypass. If the brcmfma… Enterprise Linux Patch available Fix from $1,9502020-01-16 HIGH 7.1 CVE-2015-3150 abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory ar… Automatic Bug Reporting Tool Patch available Fix from $1,9502020-01-14 HIGH 7.3 CVE-2019-14866 In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives fro… Enterprise Linux 2.13+ Fix from $1,9502020-01-07 MEDIUM 6.5 CVE-2019-19337 A flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An authenticated attacker can abuse … Ceph Storage Mitigation only Fix from $1,6002019-12-23 HIGH 8.1 CVE-2013-2103 OpenShift cartridge allows remote URL retrieval Openshift Mitigation only Fix from $1,9502019-12-03 CRITICAL 9.8 CVE-2012-3460 cumin: At installation postgresql database user created without password Enterprise Mrg Mitigation only Fix from $2,3002019-11-21 MEDIUM 5.5 CVE-2014-0084 Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of service in cron.daily and cron.… Openshift Origin 2014-02-14+ Fix from $1,6002019-11-21 HIGH 7.5 CVE-2011-4967 tog-Pegasus has a package hash collision DoS vulnerability Enterprise Linux 2.12+ Fix from $1,9502019-11-19 MEDIUM 5.5 CVE-2014-5118 Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability Enterprise Linux 1.8.2+ Fix from $1,6002019-11-18 CRITICAL 9.8 CVE-2011-2897 gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw Enterprise Linux after 2.31.1 Fix from $2,3002019-11-12 MEDIUM 5.5 CVE-2013-1820 tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service. Tuned 2.0.2+ Fix from $1,6002019-11-08 CRITICAL 9.8 CVE-2015-8980EPSS 7% The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code. Enterprise Linux 1.0.12+ Fix from $2,3002019-11-04 HIGH 7.3 CVE-2013-0165 cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp. Openshift Mitigation only Fix from $1,9502019-11-01 HIGH 8.8 CVE-2018-10899 A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly c… Openstack 1.6.1+ Fix from $1,9502019-08-01 HIGH 7.5 CVE-2019-10245 In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causi… Satellite 0.14.0+ Fix from $1,9502019-04-19 CRITICAL 9.8 CVE-2018-12547 In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects exis… Satellite 0.12.0+ Fix from $2,3002019-02-11