Vulnerability index

Browse CVEs

80 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Libvirt HIGH 8.8
CVE-2019-10132

A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configurati…

Fix: after 4.1.0
Fix from $1,950 2019-05-22
Openstack MEDIUM 5.5
CVE-2016-2121

A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitive informat…

Mitigation only
Fix from $1,600 2018-10-31
Enterprise Linux HIGH 7.8
CVE-2016-10730

An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Applicatio…

No fix yet
Fix from $1,950 2018-10-24
Ansible Tower HIGH 8.0
CVE-2016-7070

A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trus…

Fix: 3.0.3+
Fix from $1,950 2018-09-11
Jboss Enterprise Application Platform HIGH 7.8
CVE-2016-8657

It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuratio…

Mitigation only
Fix from $1,950 2018-07-31
Jboss Enterprise Application Platform HIGH 7.8
CVE-2016-8656

Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local p…

Mitigation only
Fix from $1,950 2018-05-22
Keycloak MEDIUM 6.5
CVE-2016-8629

Red Hat Keycloak before version 2.4.0 did not correctly check permissions when handling service account user deletion requests sent to the rest serve…

Fix: 2.4.0+
Fix from $1,600 2018-03-12
Cloudforms Management Engine HIGH 8.8
CVE-2014-0087

The check_privileges method in vmdb/app/controllers/application_controller.rb in ManageIQ, as used in Red Hat CloudForms Management Engine (CFME), al…

Fix: 5.3+
Fix from $1,950 2018-01-11
Ovirt Engine HIGH 7.5
CVE-2014-7851

oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowle…

Mitigation only
Fix from $1,950 2017-10-16
Gluster Storage HIGH 7.8
CVE-2015-1795

Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root.

Mitigation only
Fix from $1,950 2017-06-27
Cloudforms HIGH 8.8
CVE-2016-4471

ManageIQ in CloudForms before 4.1 allows remote authenticated users to execute arbitrary code.

Fix: after 4.0
Fix from $1,950 2017-06-08
Jboss Enterprise Application Platform HIGH 8.8
CVE-2016-5406

The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by…

Fix: after 7.0.1
Fix from $1,950 2016-09-26
Quickstart Cloud Installer HIGH 8.4
CVE-2016-6322

Red Hat QuickStart Cloud Installer (QCI) uses world-readable permissions for /etc/qci/answers, which allows local users to obtain the root password f…

Mitigation only
Fix from $1,950 2016-09-22
Jboss Operations Network HIGH 8.8
CVE-2016-5422

The web console in Red Hat JBoss Operations Network (JON) before 3.3.7 does not properly authorize requests to add users with the super user role, wh…

Fix: after 3.3.6
Fix from $1,950 2016-09-07
Openshift HIGH 8.8
CVE-2016-3738

Red Hat OpenShift Enterprise 3.2 does not properly restrict access to STI builds, which allows remote authenticated users to access the Docker socket…

Mitigation only
Fix from $1,950 2016-06-08
Openshift Origin HIGH 8.8
CVE-2016-2160

Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allow remote authenticated users to execute commands with root privileges by changing the root …

Patch available
Fix from $1,950 2016-06-08
Openstack HIGH 7.3
CVE-2015-5329

The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 7.0, do not properly use the configured R…

Mitigation only
Fix from $1,950 2016-04-11
Openshift MEDIUM 6.5
CVE-2015-5323

Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges …

Fix: after 3.1
Fix from $1,600 2015-11-25
Enterprise Linux Desktop HIGH 7.2
CVE-2015-5157

arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform mishandles IRET faults in processing NMIs that occurred during user…

Fix: 3.12.47 / 3.14.54+
Fix from $1,950 2015-08-31
Openshift HIGH 8.5
CVE-2015-5222

Red Hat OpenShift Enterprise 3.0.0.0 does not properly check permissions, which allows remote authenticated users with build permissions to execute a…

Mitigation only
Fix from $1,950 2015-08-24
Enterprise Linux High Availability HIGH 7.5
CVE-2015-1867

Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.

Fix: after 1.1.12
Fix from $1,950 2015-08-12
Libuser HIGH 7.2
CVE-2015-3246EPSS 7%

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allo…

Fix: after 0.56.13-5
Fix from $1,950 2015-08-11
Jboss Fuse MEDIUM 6.0
CVE-2014-8175

Red Hat JBoss Fuse before 6.2.0 allows remote authenticated users to bypass intended restrictions and access the HawtIO console by leveraging an acco…

Fix: after 6.1.0
Fix from $1,600 2015-07-08
Enterprise Virtualization Manager MEDIUM 6.8
CVE-2015-0237

Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 ignores the permission to deny snapshot creation during live storage migration between …

Fix: after 3.5.0
Fix from $1,600 2015-05-01
Enterprise Linux Desktop MEDIUM 5.0
CVE-2015-2348EPSS 9%

The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a…

Fix: after 10.10.5
Fix from $1,600 2015-03-30
Kie Workbench MEDIUM 6.5
CVE-2014-8115

The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitrary files, bypass intended ac…

Patch available
Fix from $1,600 2015-02-20
Uberfire MEDIUM 6.8
CVE-2014-8114

The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted conte…

Patch available
Fix from $1,600 2015-02-20
Openstack MEDIUM 5.5
CVE-2014-9493

The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete…

Fix: 2014.1.4 / 2014.2.2+
Fix from $1,600 2015-01-07
Packstack MEDIUM 5.0
CVE-2014-3703

OpenStack PackStack 2012.2.1, when the Open vSwitch (OVS) monolithic plug-in is not used, does not properly set the libvirt_vif_driver configuration …

Mitigation only
Fix from $1,600 2014-12-02
Openshift HIGH 7.5
CVE-2014-3674

Red Hat OpenShift Enterprise before 2.2 does not properly restrict access to gears, which allows remote attackers to access the network resources of …

Fix: after 2.1.8
Fix from $1,950 2014-11-13