Vulnerability index

Browse CVEs

128 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Ansible Engine MEDIUM 5.5
CVE-2020-1753

A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2…

Fix: 2.7.18 / 2.8.11+
Fix from $1,600 2020-03-16
Jboss Application Server HIGH 7.5
CVE-2012-1094

JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched…

Fix: 7.1.1+
Fix from $1,950 2020-03-10
Decision Manager CRITICAL 9.8
CVE-2019-14892EPSS 6%

A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a mal…

Fix: 2.6.7.3 / 2.8.11.5+
Fix from $2,300 2020-03-02
Ansible MEDIUM 5.5
CVE-2014-4658

The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtai…

Fix: 1.5.5+
Fix from $1,600 2020-02-20
Enterprise Linux Desktop HIGH 7.5
CVE-2013-4166

The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does…

Fix: after 3.9.5
Fix from $1,950 2020-02-06
Ansible MEDIUM 6.5
CVE-2019-10217

A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP m…

Fix: 2.8.4+
Fix from $1,600 2019-11-25
Jboss Operations Network MEDIUM 6.5
CVE-2008-5083

In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBoss ON.

Fix: 2.1.2+
Fix from $1,600 2019-11-08
Update Infrastructure MEDIUM 5.5
CVE-2013-4518

RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates

No fix yet
Fix from $1,600 2019-11-04
Icedtea6 CRITICAL 9.1
CVE-2010-2783

IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services.

Fix: 1.7.4+
Fix from $2,300 2019-10-31
Ansible MEDIUM 5.4
CVE-2019-10156

A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of informati…

Fix: 2.6.18 / 2.7.12+
Fix from $1,600 2019-07-30
Virt Bootstrap HIGH 7.8
CVE-2019-13314

virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password…

No fix yet
Fix from $1,950 2019-07-05
Ansible Tower HIGH 7.2
CVE-2019-3869

When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A mal…

Fix: 3.3.5 / 3.4.3+
Fix from $1,950 2019-03-28
Ovirt Engine HIGH 8.8
CVE-2017-7510

In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.

Mitigation only
Fix from $1,950 2019-03-25
Pagure MEDIUM 5.9
CVE-2019-7628

Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for man-in-the-middle attackers to …

Patch available
Fix from $1,600 2019-02-08
Ceph HIGH 7.5
CVE-2018-16889

Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files …

Fix: after 13.2.4
Fix from $1,950 2019-01-28
Ansible MEDIUM 5.3
CVE-2018-16876

ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of …

Fix: 2.5.14 / 2.6.11+
Fix from $1,600 2019-01-03
Linux Desktop MEDIUM 6.5
CVE-2018-6095

Inappropriate dismissal of file picker on keyboard events in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to read local fi…

Fix: 66.0.3359.117+
Fix from $1,600 2018-12-04
Linux Desktop MEDIUM 6.5
CVE-2018-6099

A lack of CORS checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML…

Fix: 66.0.3359.117+
Fix from $1,600 2018-12-04
Openstack Mistral HIGH 7.5
CVE-2018-16849

A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbit…

Fix: 7.0.1+
Fix from $1,950 2018-11-02
Enterprise Linux MEDIUM 6.5
CVE-2018-12373

dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward. This vulnerability affect…

Fix: 52.9.0+
Fix from $1,600 2018-10-18
Enterprise Linux MEDIUM 6.5
CVE-2018-12372

Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward. This vulnerability a…

Fix: 52.9.0+
Fix from $1,600 2018-10-18
Enterprise Linux Desktop MEDIUM 6.5
CVE-2018-12365

A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or inter…

Mitigation only
Fix from $1,600 2018-10-18
Enterprise Linux Desktop HIGH 7.5
CVE-2018-15967EPSS 8%

Adobe Flash Player versions 30.0.0.154 and earlier have a privilege escalation vulnerability. Successful exploitation could lead to information discl…

Fix: after 31.0.0.108
Fix from $1,950 2018-09-25
Undertow MEDIUM 5.3
CVE-2018-14642

An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flus…

Patch available
Fix from $1,600 2018-09-18
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2016-7061

An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC…

Fix: 7.0.4+
Fix from $1,600 2018-09-10
Virtualization Host HIGH 7.5
CVE-2018-10911

A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read…

Fix: 3.12.14 / 4.1.8+
Fix from $1,950 2018-09-04
Virtualization Host MEDIUM 6.5
CVE-2018-10913

An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine t…

Fix: 3.12.14 / 4.1.8+
Fix from $1,600 2018-09-04
Openstack HIGH 7.5
CVE-2017-15139

A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configura…

Fix: after 12.0.4-7
Fix from $1,950 2018-08-27
Virtualization MEDIUM 5.5
CVE-2015-5160

libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sen…

Mitigation only
Fix from $1,600 2018-08-20
Openshift Container Platform MEDIUM 5.0
CVE-2017-15138

The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook…

Patch available
Fix from $1,600 2018-08-13