Vulnerability index

Browse CVEs

813 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Openshift MEDIUM 5.4
CVE-2019-3884

A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namesp…

Mitigation only
Fix from $1,600 2019-08-01
Virtualization Manager MEDIUM 5.5
CVE-2019-10194

Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could b…

Mitigation only
Fix from $1,600 2019-07-11
Virt Bootstrap HIGH 7.8
CVE-2019-13314

virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password…

No fix yet
Fix from $1,950 2019-07-05
Cloudforms Management Engine MEDIUM 6.5
CVE-2019-10177

A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user input is no…

Mitigation only
Fix from $1,600 2019-06-27
Jboss Enterprise Application Platform CRITICAL 9.0
CVE-2019-3873

It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An att…

Mitigation only
Fix from $2,300 2019-06-12
Jboss Enterprise Application Platform MEDIUM 5.4
CVE-2019-3872

It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. …

Mitigation only
Fix from $1,600 2019-06-12
Enterprise Linux HIGH 7.0
CVE-2019-9755

An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafte…

Mitigation only
Fix from $1,950 2019-06-05
Openshift Container Platform CRITICAL 9.8
CVE-2019-3899

It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This i…

Mitigation only
Fix from $2,300 2019-04-22
Satellite HIGH 7.8
CVE-2019-3891

It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin da…

No fix yet
Fix from $1,950 2019-04-15
Enterprise Linux Server Aus HIGH 7.5
CVE-2017-3139

A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly w…

Mitigation only
Fix from $1,950 2019-04-09
Jboss Enterprise Application Platform MEDIUM 5.4
CVE-2018-10934

A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can c…

Mitigation only
Fix from $1,600 2019-03-27
Ansible Tower MEDIUM 5.5
CVE-2019-3835

It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file cou…

No fix yet
Fix from $1,600 2019-03-25
Ovirt Engine HIGH 8.8
CVE-2017-7510

In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.

Mitigation only
Fix from $1,950 2019-03-25
Enterprise Linux MEDIUM 5.4
CVE-2018-16838

A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the ser…

Mitigation only
Fix from $1,600 2019-03-25
Enterprise Linux HIGH 7.5
CVE-2019-3816EPSS 15%

Openwsman, versions up to and including 2.6.9, are vulnerable to arbitrary file disclosure because the working directory of openwsmand daemon was set…

Mitigation only
Fix from $1,950 2019-03-14
Satellite CRITICAL 9.8
CVE-2018-12549

In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when acceleratin…

Mitigation only
Fix from $2,300 2019-02-11
Enterprise Linux MEDIUM 5.5
CVE-2019-7664

In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check. Crafted elf in…

No fix yet
Fix from $1,600 2019-02-09
Enterprise Linux Desktop HIGH 7.5
CVE-2019-3813

Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a deni…

Mitigation only
Fix from $1,950 2019-02-04
Enterprise Linux Desktop HIGH 7.5
CVE-2017-3137EPSS 9%

Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a sit…

Mitigation only
Fix from $1,950 2019-01-16
Enterprise Linux Desktop HIGH 7.5
CVE-2017-3144EPSS 73%

A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors availabl…

Mitigation only
Fix from $1,950 2019-01-16
Enterprise Linux Desktop MEDIUM 5.9
CVE-2017-3135EPSS 17%

Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to eithe…

Mitigation only
Fix from $1,600 2019-01-16
Keycloak HIGH 8.1
CVE-2018-14657

A flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force detection algorithm will not …

Mitigation only
Fix from $1,950 2018-11-13
Keycloak MEDIUM 6.1
CVE-2018-14658

A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.Red…

Mitigation only
Fix from $1,600 2018-11-13
Keycloak MEDIUM 5.4
CVE-2018-14655

A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible to inject arbitrary Javascrip…

Mitigation only
Fix from $1,600 2018-11-13
Enterprise Linux HIGH 7.8
CVE-2018-19215

Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for the special cases of the % and $ and !…

No fix yet
Fix from $1,950 2018-11-12
Enterprise Linux MEDIUM 6.5
CVE-2018-19208

In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a d…

No fix yet
Fix from $1,600 2018-11-12
Fedora MEDIUM 5.5
CVE-2018-19139

An issue has been found in JasPer 2.0.14. There is a memory leak in jas_malloc.c when called from jpc_unk_getparms in jpc_cs.c.

No fix yet
Fix from $1,600 2018-11-09
Cloudforms HIGH 8.8
CVE-2016-5402EPSS 6%

A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with acces…

Mitigation only
Fix from $1,950 2018-10-31
Openstack MEDIUM 5.5
CVE-2016-2121

A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitive informat…

Mitigation only
Fix from $1,600 2018-10-31
Enterprise Linux HIGH 7.8
CVE-2016-10729

An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binar…

No fix yet
Fix from $1,950 2018-10-24