Vulnerability index

Browse CVEs

21 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Jboss Enterprise Application Platform MEDIUM 5.9
CVE-2016-7046

Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause …

Mitigation only
Fix from $1,600 2016-10-03
Enterprise Linux Desktop MEDIUM 5.5
CVE-2016-7166

libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory con…

Patch available
Fix from $1,600 2016-09-21
Enterprise Linux HIGH 7.5
CVE-2016-0741

slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1.3.4.x before 1.3.4.7 allows remote attackers to cause a denial of ser…

Patch available
Fix from $1,950 2016-04-19
Enterprise Linux MEDIUM 5.0
CVE-2015-4024EPSS 50%

Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x …

Fix: after 5.4.40
Fix from $1,600 2015-06-09
Slapi Nis HIGH 7.8
CVE-2015-0283

The slapi-nis plug-in before 0.54.2 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denia…

Fix: after 0.54.1
Fix from $1,950 2015-03-30
Enterprise Linux Desktop Supplementary HIGH 7.5
CVE-2014-7942

The Fonts implementation in Google Chrome before 40.0.2214.91 does not initialize memory for a data structure, which allows remote attackers to cause…

Fix: after 40.0.2214.85
Fix from $1,950 2015-01-22
Enterprise Linux Desktop HIGH 7.2
CVE-2014-7300

GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests,…

Patch available
Fix from $1,950 2014-12-25
Enterprise Linux Desktop HIGH 9.4
CVE-2014-8567

The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request …

Fix: 0.8.1+
Fix from $1,950 2014-11-14
Openshift MEDIUM 5.0
CVE-2014-3661

Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to cause a denial of service (thread consumption) via vectors related to a CLI ha…

Fix: after 3.1
Fix from $1,600 2014-10-16
Enterprise Linux Desktop Supplementary MEDIUM 5.0
CVE-2014-3199

The wrap function in bindings/core/v8/custom/V8EventCustom.cpp in the V8 bindings in Blink, as used in Google Chrome before 38.0.2125.101, has an err…

Fix: after 38.0.2125.7
Fix from $1,600 2014-10-08
Enterprise Linux Desktop HIGH 7.8
CVE-2014-7145

The SMB2_tcon function in fs/cifs/smb2pdu.c in the Linux kernel before 3.16.3 allows remote CIFS servers to cause a denial of service (NULL pointer d…

Fix: 3.10.55 / 3.12.29+
Fix from $1,950 2014-09-28
Cloudforms 3.0 Management Engine MEDIUM 5.0
CVE-2014-0180

The wait_for_task function in app/controllers/application_controller.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allows remo…

Fix: after 5.2.4
Fix from $1,600 2014-07-07
Enterprise Mrg MEDIUM 5.0
CVE-2013-4284

Cumin, as used in Red Hat Enterprise MRG 2.4, allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted Ajax up…

Mitigation only
Fix from $1,600 2013-10-09
Enterprise Linux HIGH 7.2
CVE-2013-2231

Unquoted Windows search path vulnerability in the QEMU Guest Agent service for Red Hat Enterprise Linux Desktop 6, HPC Node 6, Server 6, Workstation …

Mitigation only
Fix from $1,950 2013-10-01
Libvirt MEDIUM 5.0
CVE-2013-4153

Double free vulnerability in the qemuAgentGetVCPUs function in qemu/qemu_agent.c in libvirt 1.0.6 through 1.1.0 allows remote attackers to cause a de…

Patch available
Fix from $1,600 2013-09-30
Libvirt MEDIUM 5.0
CVE-2013-2218EPSS 8%

Double free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_netcf.c in libvirt 1.0.6 allows remote attackers t…

Patch available
Fix from $1,600 2013-09-30
Enterprise Virtualization HIGH 7.2
CVE-2013-2176

Unquoted Windows search path vulnerability in the Red Hat Enterprise Virtualization Application Provisioning Tool (RHEV-APT) in the rhev-guest-tools-…

Mitigation only
Fix from $1,950 2013-08-28
Libvirt MEDIUM 5.0
CVE-2013-1962

The remoteDispatchStoragePoolListAllVolumes function in the storage pool manager in libvirt 1.0.5 allows remote attackers to cause a denial of servic…

Mitigation only
Fix from $1,600 2013-05-29
Enterprise Linux MEDIUM 5.0
CVE-2012-2124

functions/imap_general.php in SquirrelMail, as used in Red Hat Enterprise Linux (RHEL) 4 and 5, does not properly handle 8-bit characters in password…

Mitigation only
Fix from $1,600 2013-01-18
Vsftpd HIGH 7.1
CVE-2008-2375

Memory leak in a certain Red Hat deployment of vsftpd before 2.0.5 on Red Hat Enterprise Linux (RHEL) 3 and 4, when PAM is used, allows remote attack…

No fix yet
Fix from $1,950 2008-07-09
Enterprise Linux HIGH 7.1
CVE-2007-5962EPSS 12%

Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux a…

Patch available
Fix from $1,950 2008-05-22