Vulnerability index

Browse CVEs

173 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2017-7957 XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during… Fuse after 1.4.9 Fix from $1,9502017-04-29 MEDIUM 5.5 CVE-2016-7796 The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received o… Enterprise Linux Desktop Patch available Fix from $1,6002016-10-13 HIGH 7.5 CVE-2016-3110 mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP mes… Jboss Enterprise Application Platform Mitigation only Fix from $1,9502016-09-26 HIGH 7.5 CVE-2016-5418 The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to … Enterprise Linux Desktop Patch available Fix from $1,9502016-09-21 HIGH 7.5 CVE-2016-4809 The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a… Enterprise Linux Desktop Patch available Fix from $1,9502016-09-21 CRITICAL 9.8 CVE-2016-3737EPSS 7% The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, relat… Jboss Operations Network after 3.3.5 Fix from $2,3002016-08-02 MEDIUM 6.5 CVE-2016-5009 The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph mon… Ceph Storage Mon after 0.94.6 Fix from $1,6002016-07-12 MEDIUM 6.5 CVE-2016-6170EPSS 41% ISC BIND through 9.9.9-P1, 9.10.x through 9.10.4-P1, and 9.11.x through 9.11.0b1 allows primary DNS servers to cause a denial of service (secondary D… Enterprise Linux after 9.10.3 Fix from $1,6002016-07-06 HIGH 8.1 CVE-2016-0363 The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 be… Satellite Mitigation only Fix from $1,9502016-06-03 MEDIUM 6.5 CVE-2015-4598 PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not ensure that pathnames lack %00 sequences, which might allow remote attackers… Enterprise Linux Desktop after 5.4.41 Fix from $1,6002016-05-16 MEDIUM 6.5 CVE-2015-3411 PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers … Enterprise Linux after 5.4.39 Fix from $1,6002016-05-16 MEDIUM 6.5 CVE-2016-1665 The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrome before 50.0.2661.94, mishandles comparison oper… Enterprise Linux Desktop Supplementary after 50.0.2661.87 Fix from $1,6002016-05-14 HIGH 8.0 CVE-2016-1661 Blink, as used in Google Chrome before 50.0.2661.94, does not ensure that frames satisfy a check for the same renderer process in addition to a Same … Enterprise Linux Desktop Supplementary after 50.0.2661.87 Fix from $1,9502016-05-14 HIGH 8.8 CVE-2016-1660 Blink, as used in Google Chrome before 50.0.2661.94, mishandles assertions in the WTF::BitArray and WTF::double_conversion::Vector classes, which all… Enterprise Linux Desktop Supplementary after 50.0.2661.87 Fix from $1,9502016-05-14 CRITICAL 9.8 CVE-2015-5254EPSS 38% Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitr… Openshift Mitigation only Fix from $2,3002016-01-08 MEDIUM 6.8 CVE-2015-5234 IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .app… Enterprise Linux Desktop after 1.5.2 Fix from $1,6002015-10-09 MEDIUM 6.8 CVE-2014-9751 The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP addr… Enterprise Linux Desktop 4.2.8+ Fix from $1,6002015-10-06 MEDIUM 5.8 CVE-2014-9750EPSS 6% ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtain sensitive information from … Enterprise Linux Desktop 4.2.8+ Fix from $1,6002015-10-06 MEDIUM 5.0 CVE-2015-4148EPSS 20% The do_soap_call function in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that the uri property … Enterprise Linux Desktop after 10.10.4 Fix from $1,6002015-06-09 HIGH 7.5 CVE-2014-7840 The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers to execute arbitrary code via… Enterprise Linux Desktop after 2.1.3 Fix from $1,9502014-12-12 MEDIUM 6.4 CVE-2014-7839 DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which … Resteasy Mitigation only Fix from $1,6002014-11-25 MEDIUM 5.0 CVE-2013-0336 The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_extop.c in the directory server (dirsrv) in FreeIPA before 3.2.0 allows… Freeipa after 3.1.5 Fix from $1,6002014-11-03 MEDIUM 5.0 CVE-2014-0136 The (1) get and (2) log methods in the AgentController in Red Hat CloudForms 3.0 Management Engine (CFME) 5.x allow remote attackers to insert arbitr… Cloudforms 3.0 Management Engine after 5.2.5.3 Fix from $1,6002014-10-27 MEDIUM 6.5 CVE-2014-3573 The oVirt Engine backend module, as used in Red Hat Enterprise Virtualization Manager before 3.4.2, uses an "insecure DocumentBuilderFactory," which … Enterprise Virtualization Manager after 3.4.1 Fix from $1,6002014-10-18 MEDIUM 5.0 CVE-2012-2682 Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, allows attackers with certain database privileges to cause a denial of ser… Enterprise Mrg Mitigation only Fix from $1,6002014-07-19 MEDIUM 6.5 CVE-2013-2143EPSS 48% The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows r… Network Satellite after 1.5.0-14 Fix from $1,6002014-04-17 MEDIUM 6.0 CVE-2010-2236 The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and … Network Proxy after 2.1.147-1 Fix from $1,6002014-04-15 MEDIUM 5.8 CVE-2011-2941 Open redirect vulnerability in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allows remote attackers to redirect users to arbitrary web sites… Jboss Enterprise Portal Platform after 5.1.1 Fix from $1,6002014-02-26 MEDIUM 5.8 CVE-2012-0052 Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 does not check the JON agent key, which allows remote attackers to spoof t… Jboss Operations Network after 2.4.1 Fix from $1,6002014-02-14 MEDIUM 6.5 CVE-2011-1594 A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to ar… Network Satellite Patch available Fix from $1,6002014-02-05