Vulnerability index

Browse CVEs

15 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Cloudforms Management Engine HIGH 7.5
CVE-2016-4457

CloudForms Management Engine before 5.8 includes a default SSL/TLS certificate.

No fix yet
Fix from $1,950 2017-06-08
Enterprise Linux Desktop MEDIUM 5.9
CVE-2016-2107EPSS 89%

The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which …

Fix: after 1.0.1s
Fix from $1,600 2016-05-05
Openstack HIGH 7.5
CVE-2014-3691

Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which allows remot…

Fix: after 1.5.3
Fix from $1,950 2015-03-09
Enterprise Linux Desktop MEDIUM 5.0
CVE-2014-8564

The _gnutls_ecc_ansi_x963_export function in gnutls_ecc.c in GnuTLS 3.x before 3.1.28, 3.2.x before 3.2.20, and 3.3.x before 3.3.10 allows remote att…

Patch available
Fix from $1,600 2014-11-13
Jboss Fuse MEDIUM 6.8
CVE-2014-5075

The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify that the server hostname match…

Fix: after 6.1.0
Fix from $1,600 2014-10-25
Virtual Desktop Service Manager MEDIUM 5.0
CVE-2014-7968

VDSM allows remote attackers to cause a denial of service (connection blocking) by keeping an SSL connection open.

Mitigation only
Fix from $1,600 2014-10-22
Enterprise Mrg MEDIUM 5.0
CVE-2013-6445

Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, uses the DES-based crypt function to hash passwords, which makes it easier…

Mitigation only
Fix from $1,600 2014-04-30
Kexec Tools MEDIUM 5.7
CVE-2011-3588

The SSH configuration in the Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-…

Fix: after 2.0.0-188
Fix from $1,600 2014-02-15
Kexec Tools MEDIUM 5.7
CVE-2011-3589

The Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-209 packages in Red Hat E…

Fix: after 2.0.0-188
Fix from $1,600 2014-02-15
Kexec Tools MEDIUM 5.7
CVE-2011-3590

The Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-209 packages in Red Hat E…

Fix: after 2.0.0-188
Fix from $1,600 2014-02-15
Freeipa HIGH 7.9
CVE-2012-5484

The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows ma…

Mitigation only
Fix from $1,950 2013-01-27
Enterprise Virtualization Manager MEDIUM 6.8
CVE-2012-0861

The vds_installer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, uses the -k curl parameter when downloading d…

Fix: after 3.0
Fix from $1,600 2013-01-04
Jboss Enterprise Portal Platform MEDIUM 5.0
CVE-2011-1096

The W3C XML Encryption Standard, as used in the JBoss Web Services (JBossWS) component in JBoss Enterprise Portal Platform before 5.2.2 and other pro…

Fix: after 5.2.1
Fix from $1,600 2012-11-23
Enterprise Mrg MEDIUM 5.8
CVE-2012-2681

Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, uses predictable random numbers to generate session key…

Fix: after 0.1.5192-4
Fix from $1,600 2012-09-28
Certificate System MEDIUM 5.5
CVE-2012-3367

Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System does not properly check certificate revocation requests made through the…

Fix: after 8.1
Fix from $1,600 2012-08-13