Vulnerability index

Browse CVEs

128 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2016-7031 The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL. Ceph Storage after 10.0.0 Fix from $1,9502016-10-03 MEDIUM 6.5 CVE-2016-6345 RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs. Resteasy Mitigation only Fix from $1,6002016-09-07 MEDIUM 5.3 CVE-2016-6344 Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attacke… Jboss Bpm Suite Mitigation only Fix from $1,6002016-09-07 HIGH 7.5 CVE-2016-2183EPSS 96% The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately… Jboss Enterprise Application Platform 0.10.47 / 0.12.16+ Fix from $1,9502016-09-01 MEDIUM 6.5 CVE-2016-5392 The API server in Kubernetes, as used in Red Hat OpenShift Enterprise 3.2, in a multi tenant environment allows remote authenticated users with knowl… Openshift Mitigation only Fix from $1,6002016-08-05 HIGH 7.5 CVE-2016-4985 The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive informati… Openstack after 4.2.4 Fix from $1,9502016-07-12 HIGH 8.8 CVE-2016-4474 The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterprise Linux OpenStack Platform… Openstack Mitigation only Fix from $1,9502016-06-30 MEDIUM 6.5 CVE-2016-2149 Red Hat OpenShift Enterprise 3.2 allows remote authenticated users to read log files from another namespace by using the same name as a previously de… Openshift Mitigation only Fix from $1,6002016-06-08 MEDIUM 5.5 CVE-2016-2142 Red Hat OpenShift Enterprise 3.1 uses world-readable permissions on the /etc/origin/master/master-config.yaml configuration file, which allows local … Openshift Mitigation only Fix from $1,6002016-06-08 CRITICAL 9.1 CVE-2015-5041 The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote at… Satellite 6.0.16.20 / 6.1.8.20+ Fix from $2,3002016-06-06 MEDIUM 6.5 CVE-2016-3724 Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with extended read access to obtain sensitive password information by read… Openshift after 1.651.1 Fix from $1,6002016-05-17 HIGH 7.5 CVE-2016-3674EPSS 8% Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) Stand… Jboss Middleware 1.4.9+ Fix from $1,9502016-05-17 MEDIUM 5.9 CVE-2016-2107EPSS 89% The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which … Enterprise Linux Desktop after 1.0.1s Fix from $1,6002016-05-05 HIGH 7.5 CVE-2015-5271 The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift)… Openstack Patch available Fix from $1,9502016-04-15 MEDIUM 5.9 CVE-2016-0739 libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange me… Enterprise Linux after 0.7.2 Fix from $1,6002016-04-13 MEDIUM 6.5 CVE-2015-8553 Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and I/O decodi… Enterprise Linux Patch available Fix from $1,6002016-04-13 MEDIUM 5.1 CVE-2015-7502 Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.5.0 do not properly encrypt data in the backend P… Cloudforms Management Engine Mitigation only Fix from $1,6002016-04-11 CRITICAL 9.8 CVE-2016-0791 Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to… Openshift after 1.649 Fix from $2,3002016-04-07 HIGH 7.5 CVE-2016-0793EPSS 16% Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Server) before 10.0.0.Final on … Jboss Wildfly Application Server No fix yet Fix from $1,9502016-04-01 MEDIUM 5.0 CVE-2015-5302 libreport 2.0.7 before 2.6.3 only saves changes to the first file when editing a crash report, which allows remote attackers to obtain sensitive info… Libreport Patch available Fix from $1,6002015-12-07 MEDIUM 5.0 CVE-2015-5321 The sidepanel widgets in the CLI command overview and help pages in Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sens… Openshift after 3.1 Fix from $1,6002015-11-25 MEDIUM 5.0 CVE-2015-5320 Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, which allows remote attackers to… Openshift after 3.1 Fix from $1,6002015-11-25 MEDIUM 5.0 CVE-2015-1285 The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, d… Enterprise Linux Desktop Supplementary after 43.0.2357.134 Fix from $1,6002015-07-23 MEDIUM 5.0 CVE-2015-3044EPSS 9% Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to… Enterprise Linux Desktop Supplementary Patch available Fix from $1,6002015-04-14 MEDIUM 5.0 CVE-2015-3040 Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux does not properly r… Enterprise Linux Desktop Supplementary after 13.0.0.264 Fix from $1,6002015-04-14 MEDIUM 5.0 CVE-2013-6496 Red Hat Conga 0.12.2 allows remote attackers to obtain sensitive information via a crafted request to the (1) homebase, (2) cluster, (3) storage, (4)… Conga Mitigation only Fix from $1,6002014-10-06 MEDIUM 5.0 CVE-2014-3562 Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by se… Directory Server Mitigation only Fix from $1,6002014-08-21 MEDIUM 5.0 CVE-2014-4615 The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014… Openstack after 0.5.0 Fix from $1,6002014-08-19 HIGH 7.5 CVE-2014-3530 The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform … Jboss Enterprise Application Platform Mitigation only Fix from $1,9502014-07-22 MEDIUM 5.0 CVE-2014-3481 org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion… Jboss Enterprise Application Platform after 6.2.3 Fix from $1,6002014-07-07