Vulnerability index

Browse CVEs

80 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Cloudforms MEDIUM 5.5
CVE-2012-5603

proxies_controller.rb in Katello in Red Hat CloudForms before 1.1 does not properly check permissions, which allows remote authenticated users to rea…

Fix: after 1.0
Fix from $1,600 2013-01-04
Jboss Enterprise Application Platform HIGH 7.5
CVE-2011-4605

The (1) JNDI service, (2) HA-JNDI service, and (3) HAJNDIFactory invoker servlet in JBoss Enterprise Application Platform 4.3.0 CP10 and 5.1.2, Web P…

Fix: after 5.2.0
Fix from $1,950 2012-11-23
Enterprise Mrg MEDIUM 5.0
CVE-2012-2680

Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, does not properly restrict access to resources, which a…

Fix: after 0.1.5192-4
Fix from $1,600 2012-09-28
Jboss Enterprise Application Platform HIGH 7.5
CVE-2011-4608

mod_cluster in JBoss Enterprise Application Platform 5.1.2 for Red Hat Linux allows worker nodes to register with arbitrary virtual hosts, which allo…

Mitigation only
Fix from $1,950 2012-01-27
Jboss Enterprise Application Platform MEDIUM 6.8
CVE-2011-2196

jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP05 and 5.1.0; JBoss E…

Fix: after 2.2.2
Fix from $1,600 2011-07-27
Jboss Enterprise Application Platform MEDIUM 6.8
CVE-2011-1484

jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP04 and 5.1.0 and JBos…

Fix: after 2.2.2
Fix from $1,600 2011-07-27
Satellite MEDIUM 5.5
CVE-2010-1171

Red Hat Network (RHN) Satellite 5.3 and 5.4 exposes a dangerous, obsolete XML-RPC API, which allows remote authenticated users to access arbitrary fi…

Mitigation only
Fix from $1,600 2011-04-18
Libvirt MEDIUM 6.9
CVE-2011-1146

libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only connection, which allows remote attackers to cause…

Patch available
Fix from $1,600 2011-03-15
Policycoreutils MEDIUM 6.9
CVE-2011-1011

The seunshare_mount function in sandbox/seunshare.c in seunshare in certain Red Hat packages of policycoreutils 2.0.83 and earlier in Red Hat Enterpr…

Fix: after 2.0.83
Fix from $1,600 2011-02-24
Directory Server MEDIUM 6.2
CVE-2011-0532

The (1) backup and restore scripts, (2) main initialization script, and (3) ldap-agent script in 389 Directory Server 1.2.x (aka Red Hat Directory Se…

Mitigation only
Fix from $1,600 2011-02-23
Icedtea Web HIGH 7.5
CVE-2011-0706

The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via u…

Patch available
Fix from $1,950 2011-02-19
Icedtea MEDIUM 6.8
CVE-2010-4351

The JNLP SecurityManager in IcedTea (IcedTea.so) 1.7 before 1.7.7, 1.8 before 1.8.4, and 1.9 before 1.9.4 for Java OpenJDK returns from the checkPerm…

Patch available
Fix from $1,600 2011-01-20
Enterprise Mrg HIGH 7.5
CVE-2010-4179

The installation documentation for Red Hat Enterprise Messaging, Realtime and Grid (MRG) 1.3 recommends that Condor should be configured so that the …

Mitigation only
Fix from $1,950 2010-12-07
Enterprise Virtualization MEDIUM 6.6
CVE-2010-2784

The subpage MMIO initialization functionality in the subpage_register function in exec.c in QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor)…

Patch available
Fix from $1,600 2010-08-24
Enterprise Virtualization MEDIUM 6.6
CVE-2010-0429

libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and qspice 0.3.0, does not prop…

Patch available
Fix from $1,600 2010-08-24
Jboss Enterprise Application Platform MEDIUM 5.0
CVE-2010-1429EPSS 54%

Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 allows remote attackers to obt…

Fix: after 4.3.0
Fix from $1,600 2010-04-28
Enterprise Linux MEDIUM 6.0
CVE-2008-4313

A certain Red Hat patch for tog-pegasus in OpenGroup Pegasus 2.7.0 does not properly configure the PAM tty name, which allows remote authenticated us…

Patch available
Fix from $1,600 2008-11-27
Nfs Utils HIGH 7.5
CVE-2008-1376

A certain Red Hat build script for nfs-utils before 1.0.9-35z.el5_2 on Red Hat Enterprise Linux (RHEL) 5 omits TCP wrappers support, which might allo…

Mitigation only
Fix from $1,950 2008-08-01
Directory Server HIGH 7.5
CVE-2008-0893

Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, does not properly restrict access to CGI scripts, which allows re…

Patch available
Fix from $1,950 2008-04-16
Linux HIGH 7.2
CVE-2000-0219

Red Hat 6.0 allows local users to gain root access by booting single user and hitting ^C at the password prompt.

Patch available
Fix from $1,950 2000-02-23