Vulnerability index

Browse CVEs

52 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Cloudforms HIGH 7.4
CVE-2017-12191

A flaw was found in the CloudForms account configuration when using VMware. By default, a shared account is used that has privileged access to VMRC (…

Patch available
Fix from $1,950 2018-02-28
Enterprise Linux HIGH 7.8
CVE-2017-15131

It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting…

Fix: 0.15.5+
Fix from $1,950 2018-01-09
Satellite MEDIUM 6.1
CVE-2014-8168

Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.

Mitigation only
Fix from $1,600 2017-08-28
Enterprise Virtualization Manager MEDIUM 5.9
CVE-2015-5293

Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which m…

Fix: after 3.6.0
Fix from $1,600 2017-08-24
Enterprise Virtualization MEDIUM 6.8
CVE-2016-6338

ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate atta…

No fix yet
Fix from $1,600 2017-04-20
Enterprise Linux Desktop HIGH 8.8
CVE-2016-4286EPSS 6%

Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to…

Fix: after 23.0.0.162
Fix from $1,950 2016-10-13
Cloudforms Management Engine HIGH 8.8
CVE-2016-7040

Red Hat CloudForms Management Engine 4.1 does not properly handle regular expressions passed to the expression engine via the JSON API and the web-ba…

Mitigation only
Fix from $1,950 2016-10-07
Cloudforms HIGH 8.8
CVE-2016-5383

The web UI in Red Hat CloudForms 4.1 allows remote authenticated users to execute arbitrary code via vectors involving "Lack of field filters."

Mitigation only
Fix from $1,950 2016-08-26
Enterprise Linux Desktop HIGH 8.1
CVE-2016-5388EPSS 51%

Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not prote…

Patch available
Fix from $1,950 2016-07-19
Libvirt CRITICAL 9.8
CVE-2016-5008

libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers…

Fix: after 1.3.5
Fix from $2,300 2016-07-13
Enterprise Linux Desktop HIGH 8.1
CVE-2016-3698

libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remot…

Patch available
Fix from $1,950 2016-06-13
Enterprise Linux HIGH 7.1
CVE-2016-2150

SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to…

Mitigation only
Fix from $1,950 2016-06-09
Openshift HIGH 7.1
CVE-2016-3708

Red Hat OpenShift Enterprise 3.2, when multi-tenant SDN is enabled and a build is run in a namespace that would normally be isolated from pods in oth…

Mitigation only
Fix from $1,950 2016-06-08
Openshift MEDIUM 5.3
CVE-2016-3703

Red Hat OpenShift Enterprise 3.2 and 3.1 do not properly validate the origin of a request when anonymous access is granted to a service/proxy or pod/…

Mitigation only
Fix from $1,600 2016-06-08
Gluster Storage Management Console MEDIUM 6.5
CVE-2014-8177

The Red Hat gluster-swift package, as used in Red Hat Gluster Storage (formerly Red Hat Storage Server), allows remote authenticated users to bypass …

Mitigation only
Fix from $1,600 2016-06-07
Libvirt MEDIUM 6.5
CVE-2015-5247

The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of s…

Mitigation only
Fix from $1,600 2016-04-14
Openshift HIGH 7.5
CVE-2015-5325

Jenkins before 1.638 and LTS before 1.625.2 allow attackers to bypass intended slave-to-master access restrictions by leveraging a JNLP slave. NOTE: …

Fix: after 3.1
Fix from $1,950 2015-11-25
Satellite MEDIUM 5.3
CVE-2015-4902 KEVEPSS 13%

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployme…

Patch available
Fix from $1,600 2015-10-22
Jboss Operations Network HIGH 9.0
CVE-2015-0297

Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java met…

Mitigation only
Fix from $1,950 2015-04-24
Jboss Enterprise Application Platform MEDIUM 6.4
CVE-2013-4213

Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attacker…

Mitigation only
Fix from $1,600 2013-08-16
Enterprise Linux Desktop CRITICAL 9.8
CVE-2012-4681 KEVEPSS 99%

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute a…

Mitigation only
Fix from $2,300 2012-08-28
Icedtea6 CRITICAL 9.8
CVE-2012-1723 KEVEPSS 94%

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update…

Fix: 1.10.8 / 1.11.3+
Fix from $2,300 2012-06-16