Vulnerability index

Browse CVEs

41 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Openshift Container Platform HIGH 7.8
CVE-2019-14817

A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged ca…

Fix: 9.50+
Fix from $1,950 2019-09-03
Enterprise Linux HIGH 7.0
CVE-2019-3842

In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is p…

Fix: after 241
Fix from $1,950 2019-04-09
Gluster Storage MEDIUM 6.7
CVE-2019-3831

A vulnerability was discovered in vdsm, version 4.19 through 4.30.3 and 4.30.5 through 4.30.8. The systemd_run function exposed to the vdsm system us…

Fix: after 4.30.8
Fix from $1,600 2019-03-25
Satellite HIGH 7.2
CVE-2018-14666

An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered…

Fix: after 6.4
Fix from $1,950 2019-01-22
Enterprise Linux Desktop MEDIUM 6.6
CVE-2018-14665EPSS 27%

A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server al…

Patch available
Fix from $1,600 2018-10-25
Ansible Tower HIGH 8.8
CVE-2018-1000805

Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in…

Patch available
Fix from $1,950 2018-10-08
Spacewalk CRITICAL 9.8
CVE-2017-7470

It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorizati…

Mitigation only
Fix from $2,300 2018-07-27
Openstack HIGH 7.2
CVE-2017-2673

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user…

Patch available
Fix from $1,950 2018-07-19
Undertow MEDIUM 5.9
CVE-2017-12196

undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that…

Fix: after 1.4.18
Fix from $1,600 2018-04-18
3scale Api Management Platform CRITICAL 9.8
CVE-2017-7512

Red Hat 3scale (aka RH-3scale) API Management Platform (AMP) before 2.0.0 would permit creation of an access token without a client secret. An attack…

Mitigation only
Fix from $2,300 2017-07-07
Enterprise Linux MEDIUM 5.0
CVE-2008-6123

The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does …

Fix: after 5.4.2.1
Fix from $1,600 2009-02-12