Vulnerability index

Browse CVEs

813 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux HIGH 7.8
CVE-2016-10730

An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Applicatio…

No fix yet
Fix from $1,950 2018-10-24
Ansible Engine HIGH 7.8
CVE-2018-16837

Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases c…

Mitigation only
Fix from $1,950 2018-10-23
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-5156

A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurring. This can result in stream …

Mitigation only
Fix from $2,300 2018-10-18
Enterprise Linux Desktop HIGH 7.0
CVE-2018-12385

A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile director…

Mitigation only
Fix from $1,950 2018-10-18
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-12378

A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to…

Mitigation only
Fix from $2,300 2018-10-18
Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-12383

If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is…

No fix yet
Fix from $1,600 2018-10-18
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-12376

Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Mitigation only
Fix from $2,300 2018-10-18
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-12377

A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted whi…

Mitigation only
Fix from $2,300 2018-10-18
Enterprise Linux Desktop HIGH 8.8
CVE-2018-12364

NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin POST that does a 307 redirect t…

Mitigation only
Fix from $1,950 2018-10-18
Enterprise Linux Desktop MEDIUM 6.5
CVE-2018-12365

A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or inter…

Mitigation only
Fix from $1,600 2018-10-18
Enterprise Linux Desktop MEDIUM 6.5
CVE-2018-12366

An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds read interpreted as a float value. This could leak p…

Mitigation only
Fix from $1,600 2018-10-18
Enterprise Linux Desktop HIGH 8.8
CVE-2018-12362

An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) scaler, resulting in a potentia…

Mitigation only
Fix from $1,950 2018-10-18
Enterprise Linux Desktop HIGH 8.8
CVE-2018-12363

A use-after-free vulnerability can occur when script uses mutation events to move DOM nodes between documents, resulting in the old document that hel…

Mitigation only
Fix from $1,950 2018-10-18
Enterprise Linux Desktop HIGH 8.8
CVE-2018-12359

A buffer overflow can occur when rendering canvas content while adjusting the height and width of the canvas element dynamically, causing data to be …

Mitigation only
Fix from $1,950 2018-10-18
Enterprise Linux Desktop HIGH 8.8
CVE-2018-12360

A use-after-free vulnerability can occur when deleting an input element during a mutation event handler triggered by focusing that element. This resu…

Mitigation only
Fix from $1,950 2018-10-18
Undertow MEDIUM 6.5
CVE-2018-1114

It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors…

Mitigation only
Fix from $1,600 2018-09-11
Openstack CRITICAL 9.8
CVE-2018-14620

The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could potentially…

Mitigation only
Fix from $2,300 2018-09-10
Jboss Brms MEDIUM 6.5
CVE-2016-7041

Drools Workbench contains a path traversal vulnerability. The vulnerability allows a remote, authenticated attacker to bypass the directory restricti…

Mitigation only
Fix from $1,600 2018-09-10
Openstack HIGH 8.2
CVE-2017-2627

A flaw was found in openstack-tripleo-common as shipped with Red Hat Openstack Enterprise 10 and 11. The sudoers file as installed with OSP's opensta…

Mitigation only
Fix from $1,950 2018-08-22
Ansible Tower MEDIUM 6.5
CVE-2017-7528

Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection. It was found that X-Forwarded-For header allows…

Mitigation only
Fix from $1,600 2018-08-22
Satellite MEDIUM 5.4
CVE-2017-7513

It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fiel…

Mitigation only
Fix from $1,600 2018-08-22
Satellite HIGH 7.5
CVE-2018-1517

A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack w…

Mitigation only
Fix from $1,950 2018-08-20
Virtualization MEDIUM 5.5
CVE-2015-5160

libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sen…

Mitigation only
Fix from $1,600 2018-08-20
Certification MEDIUM 6.2
CVE-2018-10864

An uncontrolled resource consumption flaw has been discovered in redhat-certification in the way documents are loaded. A remote attacker may provide …

Mitigation only
Fix from $1,600 2018-08-13
Jboss A Mq HIGH 7.2
CVE-2016-8648

It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX opera…

Mitigation only
Fix from $1,950 2018-08-01
Jboss Bpm Suite MEDIUM 5.4
CVE-2016-8608

JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via business process editor. The flaw is due to an incomplete fix for CVE-2016-5398. Remo…

Mitigation only
Fix from $1,600 2018-08-01
Jboss A Mq MEDIUM 5.3
CVE-2016-8653

It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this …

Mitigation only
Fix from $1,600 2018-08-01
Openshift HIGH 7.7
CVE-2016-8631

The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routes can pote…

Mitigation only
Fix from $1,950 2018-07-31
Jboss Enterprise Application Platform HIGH 7.8
CVE-2016-8657

It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuratio…

Mitigation only
Fix from $1,950 2018-07-31
Enterprise Linux Desktop MEDIUM 6.7
CVE-2017-15097

Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could…

Mitigation only
Fix from $1,600 2018-07-27