Vulnerability index

Browse CVEs

128 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Ceph Storage HIGH 7.5
CVE-2016-7031

The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL.

Fix: after 10.0.0
Fix from $1,950 2016-10-03
Resteasy MEDIUM 6.5
CVE-2016-6345

RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.

Mitigation only
Fix from $1,600 2016-09-07
Jboss Bpm Suite MEDIUM 5.3
CVE-2016-6344

Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attacke…

Mitigation only
Fix from $1,600 2016-09-07
Jboss Enterprise Application Platform HIGH 7.5
CVE-2016-2183EPSS 96%

The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately…

Fix: 0.10.47 / 0.12.16+
Fix from $1,950 2016-09-01
Openshift MEDIUM 6.5
CVE-2016-5392

The API server in Kubernetes, as used in Red Hat OpenShift Enterprise 3.2, in a multi tenant environment allows remote authenticated users with knowl…

Mitigation only
Fix from $1,600 2016-08-05
Openstack HIGH 7.5
CVE-2016-4985

The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive informati…

Fix: after 4.2.4
Fix from $1,950 2016-07-12
Openstack HIGH 8.8
CVE-2016-4474

The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterprise Linux OpenStack Platform…

Mitigation only
Fix from $1,950 2016-06-30
Openshift MEDIUM 6.5
CVE-2016-2149

Red Hat OpenShift Enterprise 3.2 allows remote authenticated users to read log files from another namespace by using the same name as a previously de…

Mitigation only
Fix from $1,600 2016-06-08
Openshift MEDIUM 5.5
CVE-2016-2142

Red Hat OpenShift Enterprise 3.1 uses world-readable permissions on the /etc/origin/master/master-config.yaml configuration file, which allows local …

Mitigation only
Fix from $1,600 2016-06-08
Satellite CRITICAL 9.1
CVE-2015-5041

The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote at…

Fix: 6.0.16.20 / 6.1.8.20+
Fix from $2,300 2016-06-06
Openshift MEDIUM 6.5
CVE-2016-3724

Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with extended read access to obtain sensitive password information by read…

Fix: after 1.651.1
Fix from $1,600 2016-05-17
Jboss Middleware HIGH 7.5
CVE-2016-3674EPSS 8%

Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) Stand…

Fix: 1.4.9+
Fix from $1,950 2016-05-17
Enterprise Linux Desktop MEDIUM 5.9
CVE-2016-2107EPSS 89%

The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which …

Fix: after 1.0.1s
Fix from $1,600 2016-05-05
Openstack HIGH 7.5
CVE-2015-5271

The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift)…

Patch available
Fix from $1,950 2016-04-15
Enterprise Linux MEDIUM 5.9
CVE-2016-0739

libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange me…

Fix: after 0.7.2
Fix from $1,600 2016-04-13
Enterprise Linux MEDIUM 6.5
CVE-2015-8553

Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and I/O decodi…

Patch available
Fix from $1,600 2016-04-13
Cloudforms Management Engine MEDIUM 5.1
CVE-2015-7502

Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.5.0 do not properly encrypt data in the backend P…

Mitigation only
Fix from $1,600 2016-04-11
Openshift CRITICAL 9.8
CVE-2016-0791

Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to…

Fix: after 1.649
Fix from $2,300 2016-04-07
Jboss Wildfly Application Server HIGH 7.5
CVE-2016-0793EPSS 16%

Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Server) before 10.0.0.Final on …

No fix yet
Fix from $1,950 2016-04-01
Libreport MEDIUM 5.0
CVE-2015-5302

libreport 2.0.7 before 2.6.3 only saves changes to the first file when editing a crash report, which allows remote attackers to obtain sensitive info…

Patch available
Fix from $1,600 2015-12-07
Openshift MEDIUM 5.0
CVE-2015-5321

The sidepanel widgets in the CLI command overview and help pages in Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sens…

Fix: after 3.1
Fix from $1,600 2015-11-25
Openshift MEDIUM 5.0
CVE-2015-5320

Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, which allows remote attackers to…

Fix: after 3.1
Fix from $1,600 2015-11-25
Enterprise Linux Desktop Supplementary MEDIUM 5.0
CVE-2015-1285

The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, d…

Fix: after 43.0.2357.134
Fix from $1,600 2015-07-23
Enterprise Linux Desktop Supplementary MEDIUM 5.0
CVE-2015-3044EPSS 9%

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to…

Patch available
Fix from $1,600 2015-04-14
Enterprise Linux Desktop Supplementary MEDIUM 5.0
CVE-2015-3040

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux does not properly r…

Fix: after 13.0.0.264
Fix from $1,600 2015-04-14
Conga MEDIUM 5.0
CVE-2013-6496

Red Hat Conga 0.12.2 allows remote attackers to obtain sensitive information via a crafted request to the (1) homebase, (2) cluster, (3) storage, (4)…

Mitigation only
Fix from $1,600 2014-10-06
Directory Server MEDIUM 5.0
CVE-2014-3562

Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by se…

Mitigation only
Fix from $1,600 2014-08-21
Openstack MEDIUM 5.0
CVE-2014-4615

The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014…

Fix: after 0.5.0
Fix from $1,600 2014-08-19
Jboss Enterprise Application Platform HIGH 7.5
CVE-2014-3530

The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform …

Mitigation only
Fix from $1,950 2014-07-22
Jboss Enterprise Application Platform MEDIUM 5.0
CVE-2014-3481

org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion…

Fix: after 6.2.3
Fix from $1,600 2014-07-07