Vulnerability index

Browse CVEs

813 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux CRITICAL 9.8
CVE-2021-20325

Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regress…

Mitigation only
Fix from $2,300 2022-02-18
Enterprise Linux MEDIUM 5.5
CVE-2022-0529

A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound wri…

No fix yet
Fix from $1,600 2022-02-09
Jboss Enterprise Application Platform HIGH 7.2
CVE-2021-20318

The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary …

Mitigation only
Fix from $1,950 2021-12-23
3scale Api Management MEDIUM 6.3
CVE-2020-14388

A flaw was found in the Red Hat 3scale API Management Platform, where member permissions for an API's admin portal were not properly enforced. This f…

Mitigation only
Fix from $1,600 2021-06-02
Satellite HIGH 7.5
CVE-2020-14380

An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authen…

Mitigation only
Fix from $1,950 2021-06-02
Satellite MEDIUM 6.5
CVE-2020-14371

A credential leak vulnerability was found in Red Hat Satellite. This flaw exposes the compute resources credentials through VMs that are running on t…

Mitigation only
Fix from $1,600 2021-06-02
Openshift Container Platform MEDIUM 6.5
CVE-2020-14336

A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets. This flaw allows an atta…

Mitigation only
Fix from $1,600 2021-06-02
Jboss Enterprise Application Platform MEDIUM 5.5
CVE-2020-14317

It was found that the issue for security flaw CVE-2019-3805 appeared again in a further version of JBoss Enterprise Application Platform - Continuous…

Mitigation only
Fix from $1,600 2021-06-02
Satellite MEDIUM 5.5
CVE-2020-14335

A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets through the ISC DHCP of Smart-Proxy. This flaw allows…

Mitigation only
Fix from $1,600 2021-06-02
Data Grid HIGH 7.1
CVE-2020-10771

A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw…

Mitigation only
Fix from $1,950 2021-06-02
Single Sign On MEDIUM 5.3
CVE-2021-3424

A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can register himself…

Mitigation only
Fix from $1,600 2021-06-01
3scale HIGH 7.3
CVE-2021-3412

It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, an…

Mitigation only
Fix from $1,950 2021-06-01
389 Directory Server MEDIUM 6.5
CVE-2021-3514

When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing…

Mitigation only
Fix from $1,600 2021-05-28
Certification CRITICAL 9.1
CVE-2018-10866

It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated use…

Mitigation only
Fix from $2,300 2021-05-26
Certification CRITICAL 9.1
CVE-2018-10867

Files are accessible without restrictions from the /update/results page of redhat-certification 7 package, allowing an attacker to remove any file ac…

Mitigation only
Fix from $2,300 2021-05-26
Certification HIGH 7.5
CVE-2018-10863

It was discovered that redhat-certification 7 is not properly configured and it lists all files and directories in the /var/www/rhcert/store/transfer…

Mitigation only
Fix from $1,950 2021-05-26
Certification HIGH 7.5
CVE-2018-10865

It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated use…

Mitigation only
Fix from $1,950 2021-05-26
Certification HIGH 7.5
CVE-2018-10868

redhat-certification 7 does not properly restrict the number of recursive definitions of entities in XML documents, allowing an unauthenticated user …

Mitigation only
Fix from $1,950 2021-05-26
3scale HIGH 8.8
CVE-2019-14836

A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to…

Mitigation only
Fix from $1,950 2021-05-26
Openstack HIGH 7.5
CVE-2021-31918

A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update a…

Mitigation only
Fix from $1,950 2021-05-06
Openshift Container Platform HIGH 7.0
CVE-2019-19352

An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/presto as shipped in Red Hat Openshift 4. An attac…

Mitigation only
Fix from $1,950 2021-03-24
Openshift Container Platform HIGH 7.0
CVE-2019-19353

An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hive as shipped in Red Hat Openshift 4. An attacke…

No fix yet
Fix from $1,950 2021-03-24
Openshift HIGH 7.8
CVE-2019-19349

An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-metering as shipped in Red Hat …

No fix yet
Fix from $1,950 2021-03-24
Openshift HIGH 7.8
CVE-2019-19350

An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as shipped in Red Hat Openshift 4 an…

No fix yet
Fix from $1,950 2021-03-24
Openshift MEDIUM 6.3
CVE-2019-10225

A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the…

Mitigation only
Fix from $1,600 2021-03-19
3scale Api Management HIGH 7.5
CVE-2019-14852

A flaw was found in 3scale’s APIcast gateway that enabled the TLS 1.0 protocol. An attacker could target traffic using this weaker protocol and break…

Mitigation only
Fix from $1,950 2021-03-18
Certification MEDIUM 5.3
CVE-2019-3897

It has been discovered in redhat-certification that any unauthorized user may download any file under /var/www/rhcert, provided they know its name. R…

Mitigation only
Fix from $1,600 2021-03-16
Keycloak MEDIUM 6.8
CVE-2021-20262

A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows an attacker to take over an …

Mitigation only
Fix from $1,600 2021-03-09
Enterprise Linux HIGH 7.8
CVE-2021-3403

In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) …

No fix yet
Fix from $1,950 2021-03-04
Enterprise Linux HIGH 7.8
CVE-2021-3404

In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a h…

No fix yet
Fix from $1,950 2021-03-04