Vulnerability index

Browse CVEs

128 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2018-10915EPSS 5% A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections… Openstack Patch available Fix from $1,9502018-08-09 HIGH 8.8 CVE-2017-12173 It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulner… Enterprise Linux Desktop 1.16.0+ Fix from $1,9502018-07-27 MEDIUM 5.5 CVE-2017-2622 An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malic… Openstack Mitigation only Fix from $1,6002018-07-27 MEDIUM 6.5 CVE-2017-2582 It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute … Keycloak 2.5.1+ Fix from $1,6002018-07-26 MEDIUM 5.5 CVE-2017-12167 It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role ma… Jboss Enterprise Application Platform 7.0.9+ Fix from $1,6002018-07-26 HIGH 7.1 CVE-2017-12163EPSS 8% An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A ma… Enterprise Linux Desktop 4.4.16 / 4.5.14+ Fix from $1,9502018-07-26 HIGH 7.5 CVE-2018-3760EPSS 27% There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially craft… Cloudforms after 3.7.1 Fix from $1,9502018-06-26 MEDIUM 5.3 CVE-2018-1073 The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an a… Virtualization 4.2.3+ Fix from $1,6002018-06-19 HIGH 7.5 CVE-2018-5157 Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow th… Enterprise Linux Desktop Mitigation only Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-5454 A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file … Enterprise Linux 52.1.0 / 53.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2016-9904 An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This … Enterprise Linux Desktop 45.6.0 / 51.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2018-5256 CoreOS Tectonic 1.7.x before 1.7.9-tectonic.4 and 1.8.x before 1.8.4-tectonic.3 mounts a direct proxy to the kubernetes cluster at /api/kubernetes/ w… Tectonic 1.7.9-tectonic.4 / 1.8.4-tectonic.3+ Fix from $1,9502018-05-18 HIGH 7.2 CVE-2018-1074 ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, includ… Enterprise Virtualization after 4.1.11.1 Fix from $1,9502018-04-26 MEDIUM 6.5 CVE-2016-9590 puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object … Openstack 8.2.1 / 9.4.4+ Fix from $1,6002018-04-26 HIGH 8.8 CVE-2018-1097 A flaw was found in foreman before 1.16.1. The issue allows users with limited permissions for powering oVirt/RHV hosts on and off to discover the us… Satellite 1.6.1+ Fix from $1,9502018-04-04 MEDIUM 5.9 CVE-2017-2585 Red Hat Keycloak before version 2.5.1 has an implementation of HMAC verification for JWS tokens that uses a method that runs in non-constant time, po… Keycloak 2.5.1+ Fix from $1,6002018-03-12 HIGH 7.8 CVE-2017-15104 An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi serv… Enterprise Linux Mitigation only Fix from $1,9502017-12-18 HIGH 7.5 CVE-2017-15087 It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6. Gluster Storage Mitigation only Fix from $1,9502017-11-08 MEDIUM 5.9 CVE-2017-15085 It was discovered that the fix for CVE-2017-12150 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6. Gluster Storage Mitigation only Fix from $1,6002017-11-08 MEDIUM 6.5 CVE-2017-16541 Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vec… Enterprise Linux Desktop 7.0.9+ Fix from $1,6002017-11-04 MEDIUM 5.9 CVE-2015-1849 AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vect… Jboss Enterprise Application Platform after 6.4.0 Fix from $1,6002017-09-19 CRITICAL 9.8 CVE-2014-8174 eDeploy makes it easier for remote attackers to execute arbitrary code by leveraging use of HTTP to download files. Edeploy after 1.11.0 Fix from $2,3002017-09-19 MEDIUM 5.5 CVE-2016-6310 oVirt Engine discloses the ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD in /var/log/ovirt-engine/engine.log file in RHEV before 4.0. Enterprise Virtualization after 3.6 Fix from $1,6002017-08-22 MEDIUM 5.3 CVE-2016-6311 Get requests in JBoss Enterprise Application Platform (EAP) 7 disclose internal IP addresses to remote attackers. Jboss Enterprise Application Platform Mitigation only Fix from $1,6002017-08-22 HIGH 7.5 CVE-2015-3198 The Undertow module of WildFly 9.x before 9.0.0.CR2 and 10.x before 10.0.0.Alpha1 allows remote attackers to obtain the source code of a JSP page via… Jboss Wildfly Application Server Mitigation only Fix from $1,9502017-07-21 MEDIUM 5.5 CVE-2015-1870 The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which all… Automatic Bug Reporting Tool after 2.1.11 Fix from $1,6002017-06-26 HIGH 7.5 CVE-2016-4992 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server … Enterprise Linux Desktop Patch available Fix from $1,9502017-06-08 HIGH 7.5 CVE-2016-5416 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server … Enterprise Linux Desktop Mitigation only Fix from $1,9502017-06-08 MEDIUM 5.3 CVE-2016-3702 Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext information. Cloudforms Management Engine Mitigation only Fix from $1,6002017-04-21 HIGH 7.5 CVE-2016-5409 Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which makes it easier for remote atta… Openshift Mitigation only Fix from $1,9502017-04-20