Vulnerability index

Browse CVEs

128 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.5 CVE-2020-1753 A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2… Ansible Engine 2.7.18 / 2.8.11+ Fix from $1,6002020-03-16 HIGH 7.5 CVE-2012-1094 JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched… Jboss Application Server 7.1.1+ Fix from $1,9502020-03-10 CRITICAL 9.8 CVE-2019-14892EPSS 6% A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a mal… Decision Manager 2.6.7.3 / 2.8.11.5+ Fix from $2,3002020-03-02 MEDIUM 5.5 CVE-2014-4658 The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtai… Ansible 1.5.5+ Fix from $1,6002020-02-20 HIGH 7.5 CVE-2013-4166 The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does… Enterprise Linux Desktop after 3.9.5 Fix from $1,9502020-02-06 MEDIUM 6.5 CVE-2019-10217 A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP m… Ansible 2.8.4+ Fix from $1,6002019-11-25 MEDIUM 6.5 CVE-2008-5083 In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBoss ON. Jboss Operations Network 2.1.2+ Fix from $1,6002019-11-08 MEDIUM 5.5 CVE-2013-4518 RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates Update Infrastructure No fix yet Fix from $1,6002019-11-04 CRITICAL 9.1 CVE-2010-2783 IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services. Icedtea6 1.7.4+ Fix from $2,3002019-10-31 MEDIUM 5.4 CVE-2019-10156 A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of informati… Ansible 2.6.18 / 2.7.12+ Fix from $1,6002019-07-30 HIGH 7.8 CVE-2019-13314 virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password… Virt Bootstrap No fix yet Fix from $1,9502019-07-05 HIGH 7.2 CVE-2019-3869 When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A mal… Ansible Tower 3.3.5 / 3.4.3+ Fix from $1,9502019-03-28 HIGH 8.8 CVE-2017-7510 In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface. Ovirt Engine Mitigation only Fix from $1,9502019-03-25 MEDIUM 5.9 CVE-2019-7628 Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for man-in-the-middle attackers to … Pagure Patch available Fix from $1,6002019-02-08 HIGH 7.5 CVE-2018-16889 Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files … Ceph after 13.2.4 Fix from $1,9502019-01-28 MEDIUM 5.3 CVE-2018-16876 ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of … Ansible 2.5.14 / 2.6.11+ Fix from $1,6002019-01-03 MEDIUM 6.5 CVE-2018-6095 Inappropriate dismissal of file picker on keyboard events in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to read local fi… Linux Desktop 66.0.3359.117+ Fix from $1,6002018-12-04 MEDIUM 6.5 CVE-2018-6099 A lack of CORS checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML… Linux Desktop 66.0.3359.117+ Fix from $1,6002018-12-04 HIGH 7.5 CVE-2018-16849 A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbit… Openstack Mistral 7.0.1+ Fix from $1,9502018-11-02 MEDIUM 6.5 CVE-2018-12373 dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward. This vulnerability affect… Enterprise Linux 52.9.0+ Fix from $1,6002018-10-18 MEDIUM 6.5 CVE-2018-12372 Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward. This vulnerability a… Enterprise Linux 52.9.0+ Fix from $1,6002018-10-18 MEDIUM 6.5 CVE-2018-12365 A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or inter… Enterprise Linux Desktop Mitigation only Fix from $1,6002018-10-18 HIGH 7.5 CVE-2018-15967EPSS 8% Adobe Flash Player versions 30.0.0.154 and earlier have a privilege escalation vulnerability. Successful exploitation could lead to information discl… Enterprise Linux Desktop after 31.0.0.108 Fix from $1,9502018-09-25 MEDIUM 5.3 CVE-2018-14642 An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flus… Undertow Patch available Fix from $1,6002018-09-18 MEDIUM 6.5 CVE-2016-7061 An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC… Jboss Enterprise Application Platform 7.0.4+ Fix from $1,6002018-09-10 HIGH 7.5 CVE-2018-10911 A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read… Virtualization Host 3.12.14 / 4.1.8+ Fix from $1,9502018-09-04 MEDIUM 6.5 CVE-2018-10913 An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine t… Virtualization Host 3.12.14 / 4.1.8+ Fix from $1,6002018-09-04 HIGH 7.5 CVE-2017-15139 A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configura… Openstack after 12.0.4-7 Fix from $1,9502018-08-27 MEDIUM 5.5 CVE-2015-5160 libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sen… Virtualization Mitigation only Fix from $1,6002018-08-20 MEDIUM 5.0 CVE-2017-15138 The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook… Openshift Container Platform Patch available Fix from $1,6002018-08-13