Vulnerability index

Browse CVEs

128 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Openstack HIGH 7.5
CVE-2018-10915EPSS 5%

A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections…

Patch available
Fix from $1,950 2018-08-09
Enterprise Linux Desktop HIGH 8.8
CVE-2017-12173

It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulner…

Fix: 1.16.0+
Fix from $1,950 2018-07-27
Openstack MEDIUM 5.5
CVE-2017-2622

An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malic…

Mitigation only
Fix from $1,600 2018-07-27
Keycloak MEDIUM 6.5
CVE-2017-2582

It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute …

Fix: 2.5.1+
Fix from $1,600 2018-07-26
Jboss Enterprise Application Platform MEDIUM 5.5
CVE-2017-12167

It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role ma…

Fix: 7.0.9+
Fix from $1,600 2018-07-26
Enterprise Linux Desktop HIGH 7.1
CVE-2017-12163EPSS 8%

An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A ma…

Fix: 4.4.16 / 4.5.14+
Fix from $1,950 2018-07-26
Cloudforms HIGH 7.5
CVE-2018-3760EPSS 27%

There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially craft…

Fix: after 3.7.1
Fix from $1,950 2018-06-26
Virtualization MEDIUM 5.3
CVE-2018-1073

The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an a…

Fix: 4.2.3+
Fix from $1,600 2018-06-19
Enterprise Linux Desktop HIGH 7.5
CVE-2018-5157

Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow th…

Mitigation only
Fix from $1,950 2018-06-11
Enterprise Linux HIGH 7.5
CVE-2017-5454

A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file …

Fix: 52.1.0 / 53.0+
Fix from $1,950 2018-06-11
Enterprise Linux Desktop HIGH 7.5
CVE-2016-9904

An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This …

Fix: 45.6.0 / 51.0+
Fix from $1,950 2018-06-11
Tectonic HIGH 7.5
CVE-2018-5256

CoreOS Tectonic 1.7.x before 1.7.9-tectonic.4 and 1.8.x before 1.8.4-tectonic.3 mounts a direct proxy to the kubernetes cluster at /api/kubernetes/ w…

Fix: 1.7.9-tectonic.4 / 1.8.4-tectonic.3+
Fix from $1,950 2018-05-18
Enterprise Virtualization HIGH 7.2
CVE-2018-1074

ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, includ…

Fix: after 4.1.11.1
Fix from $1,950 2018-04-26
Openstack MEDIUM 6.5
CVE-2016-9590

puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object …

Fix: 8.2.1 / 9.4.4+
Fix from $1,600 2018-04-26
Satellite HIGH 8.8
CVE-2018-1097

A flaw was found in foreman before 1.16.1. The issue allows users with limited permissions for powering oVirt/RHV hosts on and off to discover the us…

Fix: 1.6.1+
Fix from $1,950 2018-04-04
Keycloak MEDIUM 5.9
CVE-2017-2585

Red Hat Keycloak before version 2.5.1 has an implementation of HMAC verification for JWS tokens that uses a method that runs in non-constant time, po…

Fix: 2.5.1+
Fix from $1,600 2018-03-12
Enterprise Linux HIGH 7.8
CVE-2017-15104

An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi serv…

Mitigation only
Fix from $1,950 2017-12-18
Gluster Storage HIGH 7.5
CVE-2017-15087

It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.

Mitigation only
Fix from $1,950 2017-11-08
Gluster Storage MEDIUM 5.9
CVE-2017-15085

It was discovered that the fix for CVE-2017-12150 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.

Mitigation only
Fix from $1,600 2017-11-08
Enterprise Linux Desktop MEDIUM 6.5
CVE-2017-16541

Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vec…

Fix: 7.0.9+
Fix from $1,600 2017-11-04
Jboss Enterprise Application Platform MEDIUM 5.9
CVE-2015-1849

AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vect…

Fix: after 6.4.0
Fix from $1,600 2017-09-19
Edeploy CRITICAL 9.8
CVE-2014-8174

eDeploy makes it easier for remote attackers to execute arbitrary code by leveraging use of HTTP to download files.

Fix: after 1.11.0
Fix from $2,300 2017-09-19
Enterprise Virtualization MEDIUM 5.5
CVE-2016-6310

oVirt Engine discloses the ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD in /var/log/ovirt-engine/engine.log file in RHEV before 4.0.

Fix: after 3.6
Fix from $1,600 2017-08-22
Jboss Enterprise Application Platform MEDIUM 5.3
CVE-2016-6311

Get requests in JBoss Enterprise Application Platform (EAP) 7 disclose internal IP addresses to remote attackers.

Mitigation only
Fix from $1,600 2017-08-22
Jboss Wildfly Application Server HIGH 7.5
CVE-2015-3198

The Undertow module of WildFly 9.x before 9.0.0.CR2 and 10.x before 10.0.0.Alpha1 allows remote attackers to obtain the source code of a JSP page via…

Mitigation only
Fix from $1,950 2017-07-21
Automatic Bug Reporting Tool MEDIUM 5.5
CVE-2015-1870

The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which all…

Fix: after 2.1.11
Fix from $1,600 2017-06-26
Enterprise Linux Desktop HIGH 7.5
CVE-2016-4992

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server …

Patch available
Fix from $1,950 2017-06-08
Enterprise Linux Desktop HIGH 7.5
CVE-2016-5416

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server …

Mitigation only
Fix from $1,950 2017-06-08
Cloudforms Management Engine MEDIUM 5.3
CVE-2016-3702

Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext information.

Mitigation only
Fix from $1,600 2017-04-21
Openshift HIGH 7.5
CVE-2016-5409

Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which makes it easier for remote atta…

Mitigation only
Fix from $1,950 2017-04-20