Vulnerability index

Browse CVEs

13 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Openshift Container Platform MEDIUM 5.3
CVE-2022-4145

A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, e…

Mitigation only
Fix from $1,600 2023-10-05
Ceph MEDIUM 6.5
CVE-2021-3524

A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection …

Fix: 14.2.21+
Fix from $1,600 2021-05-17
Ceph Storage MEDIUM 6.5
CVE-2020-10753

A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS …

Fix: 14.2.21+
Fix from $1,600 2020-06-26
Ansible CRITICAL 9.8
CVE-2014-4678EPSS 5%

The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code vi…

Fix: 1.6.4+
Fix from $2,300 2020-02-20
Ansible CRITICAL 9.8
CVE-2014-4966

Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which …

Fix: 1.6.7+
Fix from $2,300 2020-02-18
Ansible CRITICAL 9.8
CVE-2014-4967

Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansib…

Fix: 1.6.7+
Fix from $2,300 2020-02-18
Enterprise Linux Desktop HIGH 7.8
CVE-2014-7844

BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.

Patch available
Fix from $1,950 2020-01-14
Zanata CRITICAL 9.8
CVE-2013-4486

Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging

Fix: after 3.1.2
Fix from $2,300 2019-12-03
Edeploy CRITICAL 9.8
CVE-2014-3700

eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data

Fix: after 1.6.0
Fix from $2,300 2019-11-21
Openshift Service Mesh HIGH 8.3
CVE-2019-9900

When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers c…

Fix: after 1.9.0
Fix from $1,950 2019-04-25
Enterprise Linux Desktop HIGH 8.8
CVE-2017-7846

It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in th…

Fix: 52.5.2+
Fix from $1,950 2018-06-11
Enterprise Linux MEDIUM 5.3
CVE-2017-7848

RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2.

Fix: 52.5.2+
Fix from $1,600 2018-06-11
Enterprise Virtualization Manager CRITICAL 9.1
CVE-2015-7544

redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the Supe…

Mitigation only
Fix from $2,300 2017-09-25