Vulnerability index

Browse CVEs

80 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.5 CVE-2014-3642 vmdb/app/controllers/application_controller/performance.rb in Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated … Cloudforms 3.0.1 Management Engine after 5.2.5 Fix from $1,6002014-10-06 MEDIUM 5.5 CVE-2014-3521 The component in (1) /luci/homebase and (2) /luci/cluster menu in Red Hat Conga 0.12.2 allows remote authenticated users to bypass intended access re… Conga Mitigation only Fix from $1,6002014-10-06 MEDIUM 5.0 CVE-2014-3558 ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 … Hibernate Validator 4.3.2 / 5.1.2+ Fix from $1,6002014-09-30 MEDIUM 5.5 CVE-2014-3464 The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not proper… Jboss Enterprise Application Platform Mitigation only Fix from $1,6002014-08-19 MEDIUM 5.0 CVE-2013-0199 The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes,… Freeipa Patch available Fix from $1,6002014-05-29 MEDIUM 6.8 CVE-2011-2514 The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and bef… Icedtea Web after 1.8.8 Fix from $1,6002014-05-14 MEDIUM 6.4 CVE-2014-0071 PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass int… Openstack Mitigation only Fix from $1,6002014-04-17 MEDIUM 5.8 CVE-2014-0093 Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by… Jboss Enterprise Application Platform Mitigation only Fix from $1,6002014-04-03 MEDIUM 6.8 CVE-2012-3406 The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the … Enterprise Virtualization Mitigation only Fix from $1,6002014-02-10 MEDIUM 5.2 CVE-2013-6457 The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver.c) in libvirt before 1.2.1 does not properly initialize the nodemap… Libvirt after 1.2.0 Fix from $1,6002014-01-24 MEDIUM 5.0 CVE-2013-6448 The InterfaceGenerator handler in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allows remote … Jboss Seam 2 Framework after 2.3.1 Fix from $1,6002014-01-23 MEDIUM 6.5 CVE-2013-4404 cumin in Red Hat Enterprise MRG Grid 2.4 does not properly enforce user roles, which allows remote authenticated users to bypass intended role restri… Enterprise Mrg Mitigation only Fix from $1,6002013-12-23 HIGH 7.2 CVE-2013-4400 virt-login-shell in libvirt 1.1.2 through 1.1.3 allows local users to overwrite arbitrary files and possibly gain privileges via unspecified environm… Libvirt Patch available Fix from $1,9502013-12-09 MEDIUM 5.5 CVE-2013-2133 The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly … Jboss Enterprise Application Platform after 6.1.0 Fix from $1,6002013-12-06 HIGH 7.2 CVE-2013-1813 util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows lo… Enterprise Linux after 1.20.2 Fix from $1,9502013-11-23 HIGH 8.5 CVE-2013-4401 The virConnectDomainXMLToNative API function in libvirt 1.1.0 through 1.1.3 checks for the connect:read permission instead of the connect:write permi… Libvirt Patch available Fix from $1,9502013-11-02 HIGH 7.6 CVE-2013-4342EPSS 6% xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it e… Enterprise Linux Patch available Fix from $1,9502013-10-10 MEDIUM 6.9 CVE-2013-4291 The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the domain has read an uid:gid label, does not properly … Libvirt Patch available Fix from $1,6002013-09-30 HIGH 7.5 CVE-2013-4182 app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to acces… Openstack after 1.2.1 Fix from $1,9502013-09-16 MEDIUM 6.0 CVE-2013-2113EPSS 21% The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or … Openstack after 1.2.0 Fix from $1,6002013-07-31 HIGH 7.5 CVE-2013-2165EPSS 13% ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform … Jboss Enterprise Application Platform after 2.2.0 Fix from $1,9502013-07-23 MEDIUM 5.0 CVE-2013-2144 Red Hat Enterprise Virtualization Manager (RHEVM) before 3.2 does not properly check permissions for the target storage domain, which allows attacker… Enterprise Virtualization Manager after 3.1 Fix from $1,6002013-07-03 HIGH 7.2 CVE-2013-2069 Red Hat livecd-tools before 13.4.4, 17.x before 17.17, 18.x before 18.16, and 19.x before 19.3, when a rootpw directive is not set in a Kickstart fil… Livecd Tools 13.4.4 / 17.17+ Fix from $1,9502013-05-29 MEDIUM 5.0 CVE-2013-0315 The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 allows remote attackers to read arbitrary files via a crafted extern… Jboss Enterprise Portal Platform Mitigation only Fix from $1,6002013-04-12 HIGH 7.5 CVE-2012-5629 The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.… Jboss Enterprise Application Platform Mitigation only Fix from $1,9502013-03-12 MEDIUM 6.9 CVE-2012-5660 abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbit… Automatic Bug Reporting Tool after 2.0.9 Fix from $1,6002013-03-12 MEDIUM 5.5 CVE-2012-6118 The Administer tab in Aeolus Conductor allows remote authenticated users to bypass intended quota restrictions by updating the Maximum Running Instan… Aeolus Conductor No fix yet Fix from $1,6002013-03-12 MEDIUM 5.8 CVE-2012-3370 The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platf… Jboss Enterprise Application Platform after 5.3.0 Fix from $1,6002013-02-05 MEDIUM 6.5 CVE-2012-4549 A flaw was found in JBoss Enterprise Application Platform. The `processInvocation` function within the `org.jboss.as.ejb3.security.AuthorizationInter… Jboss Enterprise Application Platform after 6.0.0 Fix from $1,6002013-01-05 MEDIUM 5.3 CVE-2012-4550 A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system d… Jboss Enterprise Application Platform Mitigation only Fix from $1,6002013-01-05