Vulnerability index

Browse CVEs

57 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Enterprise Linux Desktop MEDIUM 6.5
CVE-2019-10182

It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a vi…

Fix: after 1.7.2
Fix from $1,600 2019-07-31
Libvirt HIGH 7.8
CVE-2019-10161

It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specif…

Fix: 4.10.1 / 5.4.1+
Fix from $1,950 2019-07-30
Satellite CRITICAL 9.8
CVE-2019-10137

A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthen…

Fix: after 2.9
Fix from $2,300 2019-07-02
Enterprise Linux HIGH 7.5
CVE-2019-3816EPSS 15%

Openwsman, versions up to and including 2.6.9, are vulnerable to arbitrary file disclosure because the working directory of openwsmand daemon was set…

Mitigation only
Fix from $1,950 2019-03-14
Gluster Storage MEDIUM 6.5
CVE-2018-14654

The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attacker with access to mount volum…

Fix: after 4.1.4
Fix from $1,600 2018-10-31
Jboss Brms MEDIUM 6.5
CVE-2016-7041

Drools Workbench contains a path traversal vulnerability. The vulnerability allows a remote, authenticated attacker to bypass the directory restricti…

Mitigation only
Fix from $1,600 2018-09-10
Virtualization Host HIGH 8.8
CVE-2018-10926

A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to a…

Fix: 3.12.14 / 4.1.8+
Fix from $1,950 2018-09-04
Openstack HIGH 8.2
CVE-2017-2627

A flaw was found in openstack-tripleo-common as shipped with Red Hat Openstack Enterprise 10 and 11. The sudoers file as installed with OSP's opensta…

Mitigation only
Fix from $1,950 2018-08-22
Satellite MEDIUM 6.5
CVE-2018-1656

The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Technology Edition 6.0 , 7.0, and 8.0) does not protec…

Patch available
Fix from $1,600 2018-08-20
Virtualization HIGH 8.1
CVE-2018-10897EPSS 6%

A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration fil…

Fix: after 1.1.31
Fix from $1,950 2018-08-01
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2017-2595

It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path trave…

Mitigation only
Fix from $1,600 2018-07-27
Virtualization MEDIUM 5.5
CVE-2018-10862

WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives…

Fix: after 5.0.0
Fix from $1,600 2018-07-27
Certification CRITICAL 9.8
CVE-2018-10870EPSS 6%

redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any fil…

Mitigation only
Fix from $2,300 2018-07-19
Cloudforms HIGH 7.5
CVE-2018-3760EPSS 27%

There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially craft…

Fix: after 3.7.1
Fix from $1,950 2018-06-26
Source To Image MEDIUM 6.5
CVE-2018-1103

Openshift Enterprise source-to-image before version 1.1.10 is vulnerable to an improper validation of user input. An attacker who could trick a user …

Fix: 1.1.10+
Fix from $1,600 2018-06-12
Openshift HIGH 8.8
CVE-2018-1102

A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFr…

Patch available
Fix from $1,950 2018-04-30
Enterprise Linux MEDIUM 6.5
CVE-2018-1079

pcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call. The REST interface of the pcsd s…

Fix: after 0.9.164
Fix from $1,600 2018-04-12
Jboss Enterprise Application Platform HIGH 7.5
CVE-2018-1048

It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the…

Mitigation only
Fix from $1,950 2018-01-24
Jboss Wildfly Application Server MEDIUM 5.5
CVE-2018-1047

A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResou…

Mitigation only
Fix from $1,600 2018-01-24
Edeploy CRITICAL 9.1
CVE-2014-3702

Directory traversal vulnerability in eNovance eDeploy allows remote attackers to create arbitrary directories and files and consequently cause a deni…

Mitigation only
Fix from $2,300 2017-10-16
Satellite MEDIUM 6.5
CVE-2014-8163

Directory traversal vulnerability in the XMLRPC interface in Red Hat Satellite 5.

No fix yet
Fix from $1,600 2017-08-28
Openshift MEDIUM 5.0
CVE-2015-5322

Directory traversal vulnerability in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to list directory contents and read arbitrar…

Fix: after 3.1
Fix from $1,600 2015-11-25
Openshift MEDIUM 6.4
CVE-2015-5305

Directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift Enterprise 3.0, allows attackers to write to arbitrary files via a craf…

Mitigation only
Fix from $1,600 2015-11-06
Undertow MEDIUM 5.0
CVE-2014-7816EPSS 25%

Directory traversal vulnerability in JBoss Undertow 1.0.x before 1.0.17, 1.1.x before 1.1.0.CR5, and 1.2.x before 1.2.0.Beta3, when running on Window…

Fix: after 1.2.0
Fix from $1,600 2014-12-01
Subscription Asset Manager HIGH 7.5
CVE-2014-0130 KEVEPSS 54%

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18,…

Fix: 3.2.18 / 4.0.5+
Fix from $1,950 2014-05-07
Cloudforms Management Engine HIGH 9.4
CVE-2013-2068EPSS 59%

Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow remote attackers to create and …

No fix yet
Fix from $1,950 2013-09-28
Fedora MEDIUM 6.8
CVE-2007-4134

Directory traversal vulnerability in extract.c in star before 1.5a84 allows user-assisted remote attackers to overwrite arbitrary files via certain /…

Patch available
Fix from $1,600 2007-08-30