Vulnerability index

Browse CVEs

60 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Certification HIGH 7.5
CVE-2018-10868

redhat-certification 7 does not properly restrict the number of recursive definitions of entities in XML documents, allowing an unauthenticated user …

Mitigation only
Fix from $1,950 2021-05-26
Enterprise Linux HIGH 7.5
CVE-2020-36332

A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from th…

Fix: 1.0.1+
Fix from $1,950 2021-05-21
Jboss Remoting HIGH 7.5
CVE-2019-19343

A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holdi…

Fix: 2.0.25 / 5.0.14+
Fix from $1,950 2021-03-23
Openshift Container Platform HIGH 7.5
CVE-2020-27827

A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle speci…

Fix: 1.0.8 / 2.6.9+
Fix from $1,950 2021-03-18
Jboss Fuse HIGH 7.5
CVE-2020-27782

A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings…

Mitigation only
Fix from $1,950 2021-02-23
Jboss Enterprise Application Platform HIGH 7.5
CVE-2020-14384

A flaw was found in JBossWeb in versions before 7.5.31.Final-redhat-3. The fix for CVE-2020-13935 was incomplete in JBossWeb, leaving it vulnerable t…

Fix: 7.5.31.final-redhat-3+
Fix from $1,950 2020-09-09
Etcd HIGH 7.7
CVE-2020-15114

In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is pos…

Fix: 3.3.23 / 3.4.10+
Fix from $1,950 2020-08-06
Amq MEDIUM 6.5
CVE-2020-14297

A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated ov…

Fix: 4.0.34+
Fix from $1,600 2020-07-24
Openstack Mistral MEDIUM 6.5
CVE-2018-16848

A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow d…

Fix: after 7.0.3
Fix from $1,600 2020-06-15
Enterprise Linux MEDIUM 5.3
CVE-2020-1722

A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password has…

Fix: after 4.8.0
Fix from $1,600 2020-04-27
Openshift Service Mesh HIGH 7.5
CVE-2020-8661

CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.

Fix: after 1.13.0
Fix from $1,950 2020-03-04
Openshift Container Storage MEDIUM 6.5
CVE-2020-1700

A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making mult…

Mitigation only
Fix from $1,600 2020-02-07
Undertow HIGH 7.5
CVE-2019-14888

A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to…

Fix: after 2.0.28
Fix from $1,950 2020-01-23
Enterprise Linux HIGH 7.5
CVE-2019-0820EPSS 6%

A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial…

Patch available
Fix from $1,950 2019-05-16
Openshift Container Platform HIGH 7.5
CVE-2019-2602

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java S…

Patch available
Fix from $1,950 2019-04-23
Enterprise Linux Desktop HIGH 7.5
CVE-2017-3144EPSS 73%

A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors availabl…

Mitigation only
Fix from $1,950 2019-01-16
Virtualization Host MEDIUM 6.5
CVE-2018-14660

A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated…

Fix: after 4.1.4
Fix from $1,600 2018-11-01
Gluster File System MEDIUM 6.5
CVE-2018-14659

The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_XATTR_IOSTATS_DUMP_KEY' xattr…

Fix: after 4.1.4
Fix from $1,600 2018-10-31
Enterprise Linux Aus HIGH 7.5
CVE-2018-14638

A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function when persistent search connec…

Fix: 1.3.8.4+
Fix from $1,950 2018-09-14
389 Directory Server MEDIUM 6.5
CVE-2018-10935

A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.

Fix: 1.3.8.7 / 1.4.0.14+
Fix from $1,600 2018-09-11
Undertow MEDIUM 6.5
CVE-2018-1114

It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors…

Mitigation only
Fix from $1,600 2018-09-11
Jboss Core Services MEDIUM 6.5
CVE-2016-9596

libxml2, as used in Red Hat JBoss Core Services and when in recovery mode, allows context-dependent attackers to cause a denial of service (stack con…

Fix: 2.9.4+
Fix from $1,600 2018-08-16
Certification MEDIUM 6.2
CVE-2018-10864

An uncontrolled resource consumption flaw has been discovered in redhat-certification in the way documents are loaded. A remote attacker may provide …

Mitigation only
Fix from $1,600 2018-08-13
Virtualization HIGH 7.5
CVE-2018-5390EPSS 74%

Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet…

Fix: 4.18+
Fix from $1,950 2018-08-06
Virtualization HIGH 8.6
CVE-2017-15119

The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a client sen…

Fix: 2.11.0+
Fix from $1,950 2018-07-27
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2016-8627

admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be available via …

Mitigation only
Fix from $1,600 2018-05-11
Jboss Wildfly Application Server HIGH 7.5
CVE-2016-9589

Undertow in Red Hat wildfly before version 11.0.0.Beta1 is vulnerable to a resource exhaustion resulting in a denial of service. Undertow keeps a cac…

Fix: after 10.1.0
Fix from $1,950 2018-03-12
Libvirt HIGH 7.5
CVE-2018-5748

qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply.

Patch available
Fix from $1,950 2018-01-25
Cloudforms 3.0 Management Engine MEDIUM 6.5
CVE-2014-7813

Red Hat CloudForms 3 Management Engine (CFME) allows remote authenticated users to cause a denial of service (resource consumption) via vectors invol…

Mitigation only
Fix from $1,600 2017-10-18
Libvirt MEDIUM 6.5
CVE-2014-3672

The qemu implementation in libvirt before 1.3.0 and Xen allows local guest OS users to cause a denial of service (host disk consumption) by writing t…

Fix: after 1.2.21
Fix from $1,600 2016-05-25