Vulnerability index

Browse CVEs

173 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2017-7539EPSS 6% An assertion-failure flaw was found in Qemu before 2.10.1, in the Network Block Device (NBD) server's initial connection negotiation, where the I/O c… Openstack 2.10.1+ Fix from $1,9502018-07-26 CRITICAL 9.8 CVE-2018-10870EPSS 6% redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any fil… Certification Mitigation only Fix from $2,3002018-07-19 CRITICAL 9.8 CVE-2017-7481 Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of looku… Openshift Container Platform 2.3.1.0 / 2.4.0.0+ Fix from $2,3002018-07-19 MEDIUM 5.3 CVE-2017-15137 The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a… Openshift Mitigation only Fix from $1,6002018-07-16 HIGH 7.5 CVE-2018-10885 In atomic-openshift before version 3.10.9 a malicious network-policy configuration can cause Openshift Routing to crash when using ovs-networkpolicy … Openshift 3.10.9+ Fix from $1,9502018-07-05 HIGH 8.8 CVE-2018-10843 source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privile… Openshift Container Platform 3.7.53+ Fix from $1,9502018-07-02 HIGH 7.8 CVE-2018-10874 In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's con… Ansible Engine Mitigation only Fix from $1,9502018-07-02 HIGH 8.0 CVE-2017-7466 Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An attacker with control over a cl… Ansible 2.3+ Fix from $1,9502018-06-22 MEDIUM 6.5 CVE-2018-1103 Openshift Enterprise source-to-image before version 1.1.10 is vulnerable to an improper validation of user input. An attacker who could trick a user … Source To Image 1.1.10+ Fix from $1,6002018-06-12 HIGH 7.5 CVE-2018-1070 routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which can cause an entire shard to b… Openshift Container Platform 3.10+ Fix from $1,9502018-06-12 MEDIUM 5.3 CVE-2017-7829 It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not d… Enterprise Linux Aus 52.5.2+ Fix from $1,6002018-06-11 HIGH 7.8 CVE-2017-7814 File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature … Enterprise Linux Desktop 52.4.0 / 56.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-7762 When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing… Enterprise Linux Desktop 54.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-5449 A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS animations. This vulnerabilit… Enterprise Linux 52.1.0 / 53.0+ Fix from $1,9502018-06-11 CRITICAL 9.8 CVE-2016-9901 HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-sa… Enterprise Linux Aus 45.6.0 / 50.1+ Fix from $2,3002018-06-11 HIGH 8.8 CVE-2018-1104 Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrar… Ansible Tower after 3.2.3 Fix from $1,9502018-05-02 HIGH 8.8 CVE-2018-1102 A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFr… Openshift Patch available Fix from $1,9502018-04-30 HIGH 8.1 CVE-2016-9587EPSS 18% Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacke… Ansible 2.1.4 / 2.2.1+ Fix from $1,9502018-04-24 MEDIUM 5.5 CVE-2018-1099 DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser in… Etcd after 3.3.1 Fix from $1,6002018-04-03 MEDIUM 5.5 CVE-2018-8945 The bfd_section_from_shdr function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows rem… Enterprise Linux Desktop Patch available Fix from $1,6002018-03-22 HIGH 8.1 CVE-2016-9606EPSS 6% JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted dat… Resteasy after 3.1.1 Fix from $1,9502018-03-09 HIGH 7.5 CVE-2018-7549 In params.c in zsh through 5.4.2, there is a crash during a copy of an empty hash table, as demonstrated by typeset -p. Enterprise Linux Desktop after 5.4.2 Fix from $1,9502018-02-27 HIGH 7.8 CVE-2018-7208 In the coff_pointerize_aux function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, an in… Enterprise Linux Desktop Mitigation only Fix from $1,9502018-02-18 HIGH 8.1 CVE-2018-1051 It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yam… Resteasy Mitigation only Fix from $1,9502018-01-25 MEDIUM 5.5 CVE-2018-1047 A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResou… Jboss Wildfly Application Server Mitigation only Fix from $1,6002018-01-24 HIGH 8.8 CVE-2017-15103EPSS 5% A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted r… Enterprise Linux Patch available Fix from $1,9502017-12-18 MEDIUM 5.5 CVE-2017-15121 A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not e… Enterprise Linux Mitigation only Fix from $1,6002017-12-07 MEDIUM 6.5 CVE-2015-5248 Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform. Feedhenry Enterprise Mobile Application Platform No fix yet Fix from $1,6002017-09-20 HIGH 7.5 CVE-2015-3215 The NetKVM Windows Virtio driver allows remote attackers to cause a denial of service (guest crash) via a crafted length value in an IP packet, as de… Virtio Win Patch available Fix from $1,9502017-06-26 HIGH 8.8 CVE-2014-3498 The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands. Ansible after 1.6.5 Fix from $1,9502017-06-08