Vulnerability index

Browse CVEs

80 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Cloudforms 3.0.1 Management Engine MEDIUM 6.5
CVE-2014-3642

vmdb/app/controllers/application_controller/performance.rb in Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated …

Fix: after 5.2.5
Fix from $1,600 2014-10-06
Conga MEDIUM 5.5
CVE-2014-3521

The component in (1) /luci/homebase and (2) /luci/cluster menu in Red Hat Conga 0.12.2 allows remote authenticated users to bypass intended access re…

Mitigation only
Fix from $1,600 2014-10-06
Hibernate Validator MEDIUM 5.0
CVE-2014-3558

ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 …

Fix: 4.3.2 / 5.1.2+
Fix from $1,600 2014-09-30
Jboss Enterprise Application Platform MEDIUM 5.5
CVE-2014-3464

The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not proper…

Mitigation only
Fix from $1,600 2014-08-19
Freeipa MEDIUM 5.0
CVE-2013-0199

The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes,…

Patch available
Fix from $1,600 2014-05-29
Icedtea Web MEDIUM 6.8
CVE-2011-2514

The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and bef…

Fix: after 1.8.8
Fix from $1,600 2014-05-14
Openstack MEDIUM 6.4
CVE-2014-0071

PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass int…

Mitigation only
Fix from $1,600 2014-04-17
Jboss Enterprise Application Platform MEDIUM 5.8
CVE-2014-0093

Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by…

Mitigation only
Fix from $1,600 2014-04-03
Enterprise Virtualization MEDIUM 6.8
CVE-2012-3406

The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the …

Mitigation only
Fix from $1,600 2014-02-10
Libvirt MEDIUM 5.2
CVE-2013-6457

The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver.c) in libvirt before 1.2.1 does not properly initialize the nodemap…

Fix: after 1.2.0
Fix from $1,600 2014-01-24
Jboss Seam 2 Framework MEDIUM 5.0
CVE-2013-6448

The InterfaceGenerator handler in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allows remote …

Fix: after 2.3.1
Fix from $1,600 2014-01-23
Enterprise Mrg MEDIUM 6.5
CVE-2013-4404

cumin in Red Hat Enterprise MRG Grid 2.4 does not properly enforce user roles, which allows remote authenticated users to bypass intended role restri…

Mitigation only
Fix from $1,600 2013-12-23
Libvirt HIGH 7.2
CVE-2013-4400

virt-login-shell in libvirt 1.1.2 through 1.1.3 allows local users to overwrite arbitrary files and possibly gain privileges via unspecified environm…

Patch available
Fix from $1,950 2013-12-09
Jboss Enterprise Application Platform MEDIUM 5.5
CVE-2013-2133

The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly …

Fix: after 6.1.0
Fix from $1,600 2013-12-06
Enterprise Linux HIGH 7.2
CVE-2013-1813

util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows lo…

Fix: after 1.20.2
Fix from $1,950 2013-11-23
Libvirt HIGH 8.5
CVE-2013-4401

The virConnectDomainXMLToNative API function in libvirt 1.1.0 through 1.1.3 checks for the connect:read permission instead of the connect:write permi…

Patch available
Fix from $1,950 2013-11-02
Enterprise Linux HIGH 7.6
CVE-2013-4342EPSS 6%

xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it e…

Patch available
Fix from $1,950 2013-10-10
Libvirt MEDIUM 6.9
CVE-2013-4291

The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the domain has read an uid:gid label, does not properly …

Patch available
Fix from $1,600 2013-09-30
Openstack HIGH 7.5
CVE-2013-4182

app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to acces…

Fix: after 1.2.1
Fix from $1,950 2013-09-16
Openstack MEDIUM 6.0
CVE-2013-2113EPSS 21%

The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or …

Fix: after 1.2.0
Fix from $1,600 2013-07-31
Jboss Enterprise Application Platform HIGH 7.5
CVE-2013-2165EPSS 13%

ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform …

Fix: after 2.2.0
Fix from $1,950 2013-07-23
Enterprise Virtualization Manager MEDIUM 5.0
CVE-2013-2144

Red Hat Enterprise Virtualization Manager (RHEVM) before 3.2 does not properly check permissions for the target storage domain, which allows attacker…

Fix: after 3.1
Fix from $1,600 2013-07-03
Livecd Tools HIGH 7.2
CVE-2013-2069

Red Hat livecd-tools before 13.4.4, 17.x before 17.17, 18.x before 18.16, and 19.x before 19.3, when a rootpw directive is not set in a Kickstart fil…

Fix: 13.4.4 / 17.17+
Fix from $1,950 2013-05-29
Jboss Enterprise Portal Platform MEDIUM 5.0
CVE-2013-0315

The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 allows remote attackers to read arbitrary files via a crafted extern…

Mitigation only
Fix from $1,600 2013-04-12
Jboss Enterprise Application Platform HIGH 7.5
CVE-2012-5629

The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.…

Mitigation only
Fix from $1,950 2013-03-12
Automatic Bug Reporting Tool MEDIUM 6.9
CVE-2012-5660

abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbit…

Fix: after 2.0.9
Fix from $1,600 2013-03-12
Aeolus Conductor MEDIUM 5.5
CVE-2012-6118

The Administer tab in Aeolus Conductor allows remote authenticated users to bypass intended quota restrictions by updating the Maximum Running Instan…

No fix yet
Fix from $1,600 2013-03-12
Jboss Enterprise Application Platform MEDIUM 5.8
CVE-2012-3370

The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platf…

Fix: after 5.3.0
Fix from $1,600 2013-02-05
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2012-4549

A flaw was found in JBoss Enterprise Application Platform. The `processInvocation` function within the `org.jboss.as.ejb3.security.AuthorizationInter…

Fix: after 6.0.0
Fix from $1,600 2013-01-05
Jboss Enterprise Application Platform MEDIUM 5.3
CVE-2012-4550

A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system d…

Mitigation only
Fix from $1,600 2013-01-05