Vulnerability index

Browse CVEs

80 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 8.8 CVE-2019-10132 A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configurati… Libvirt after 4.1.0 Fix from $1,9502019-05-22 MEDIUM 5.5 CVE-2016-2121 A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitive informat… Openstack Mitigation only Fix from $1,6002018-10-31 HIGH 7.8 CVE-2016-10730 An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Applicatio… Enterprise Linux No fix yet Fix from $1,9502018-10-24 HIGH 8.0 CVE-2016-7070 A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trus… Ansible Tower 3.0.3+ Fix from $1,9502018-09-11 HIGH 7.8 CVE-2016-8657 It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuratio… Jboss Enterprise Application Platform Mitigation only Fix from $1,9502018-07-31 HIGH 7.8 CVE-2016-8656 Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local p… Jboss Enterprise Application Platform Mitigation only Fix from $1,9502018-05-22 MEDIUM 6.5 CVE-2016-8629 Red Hat Keycloak before version 2.4.0 did not correctly check permissions when handling service account user deletion requests sent to the rest serve… Keycloak 2.4.0+ Fix from $1,6002018-03-12 HIGH 8.8 CVE-2014-0087 The check_privileges method in vmdb/app/controllers/application_controller.rb in ManageIQ, as used in Red Hat CloudForms Management Engine (CFME), al… Cloudforms Management Engine 5.3+ Fix from $1,9502018-01-11 HIGH 7.5 CVE-2014-7851 oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowle… Ovirt Engine Mitigation only Fix from $1,9502017-10-16 HIGH 7.8 CVE-2015-1795 Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root. Gluster Storage Mitigation only Fix from $1,9502017-06-27 HIGH 8.8 CVE-2016-4471 ManageIQ in CloudForms before 4.1 allows remote authenticated users to execute arbitrary code. Cloudforms after 4.0 Fix from $1,9502017-06-08 HIGH 8.8 CVE-2016-5406 The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by… Jboss Enterprise Application Platform after 7.0.1 Fix from $1,9502016-09-26 HIGH 8.4 CVE-2016-6322 Red Hat QuickStart Cloud Installer (QCI) uses world-readable permissions for /etc/qci/answers, which allows local users to obtain the root password f… Quickstart Cloud Installer Mitigation only Fix from $1,9502016-09-22 HIGH 8.8 CVE-2016-5422 The web console in Red Hat JBoss Operations Network (JON) before 3.3.7 does not properly authorize requests to add users with the super user role, wh… Jboss Operations Network after 3.3.6 Fix from $1,9502016-09-07 HIGH 8.8 CVE-2016-3738 Red Hat OpenShift Enterprise 3.2 does not properly restrict access to STI builds, which allows remote authenticated users to access the Docker socket… Openshift Mitigation only Fix from $1,9502016-06-08 HIGH 8.8 CVE-2016-2160 Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allow remote authenticated users to execute commands with root privileges by changing the root … Openshift Origin Patch available Fix from $1,9502016-06-08 HIGH 7.3 CVE-2015-5329 The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 7.0, do not properly use the configured R… Openstack Mitigation only Fix from $1,9502016-04-11 MEDIUM 6.5 CVE-2015-5323 Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges … Openshift after 3.1 Fix from $1,6002015-11-25 HIGH 7.2 CVE-2015-5157 arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform mishandles IRET faults in processing NMIs that occurred during user… Enterprise Linux Desktop 3.12.47 / 3.14.54+ Fix from $1,9502015-08-31 HIGH 8.5 CVE-2015-5222 Red Hat OpenShift Enterprise 3.0.0.0 does not properly check permissions, which allows remote authenticated users with build permissions to execute a… Openshift Mitigation only Fix from $1,9502015-08-24 HIGH 7.5 CVE-2015-1867 Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command. Enterprise Linux High Availability after 1.1.12 Fix from $1,9502015-08-12 HIGH 7.2 CVE-2015-3246EPSS 7% libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allo… Libuser after 0.56.13-5 Fix from $1,9502015-08-11 MEDIUM 6.0 CVE-2014-8175 Red Hat JBoss Fuse before 6.2.0 allows remote authenticated users to bypass intended restrictions and access the HawtIO console by leveraging an acco… Jboss Fuse after 6.1.0 Fix from $1,6002015-07-08 MEDIUM 6.8 CVE-2015-0237 Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 ignores the permission to deny snapshot creation during live storage migration between … Enterprise Virtualization Manager after 3.5.0 Fix from $1,6002015-05-01 MEDIUM 5.0 CVE-2015-2348EPSS 9% The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a… Enterprise Linux Desktop after 10.10.5 Fix from $1,6002015-03-30 MEDIUM 6.5 CVE-2014-8115 The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitrary files, bypass intended ac… Kie Workbench Patch available Fix from $1,6002015-02-20 MEDIUM 6.8 CVE-2014-8114 The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted conte… Uberfire Patch available Fix from $1,6002015-02-20 MEDIUM 5.5 CVE-2014-9493 The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete… Openstack 2014.1.4 / 2014.2.2+ Fix from $1,6002015-01-07 MEDIUM 5.0 CVE-2014-3703 OpenStack PackStack 2012.2.1, when the Open vSwitch (OVS) monolithic plug-in is not used, does not properly set the libvirt_vif_driver configuration … Packstack Mitigation only Fix from $1,6002014-12-02 HIGH 7.5 CVE-2014-3674 Red Hat OpenShift Enterprise before 2.2 does not properly restrict access to gears, which allows remote attackers to access the network resources of … Openshift after 2.1.8 Fix from $1,9502014-11-13