Vulnerability index

Browse CVEs

813 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Enterprise Virtualization MEDIUM 6.3
CVE-2017-2614

When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is ex…

Mitigation only
Fix from $1,600 2018-07-27
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2017-2595

It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path trave…

Mitigation only
Fix from $1,600 2018-07-27
Undertow MEDIUM 6.5
CVE-2017-2666

It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction w…

Mitigation only
Fix from $1,600 2018-07-27
Spacewalk CRITICAL 9.8
CVE-2017-7470

It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorizati…

Mitigation only
Fix from $2,300 2018-07-27
Cloudforms HIGH 7.5
CVE-2017-2639

It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communica…

Mitigation only
Fix from $1,950 2018-07-27
Openstack MEDIUM 5.5
CVE-2017-2622

An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malic…

Mitigation only
Fix from $1,600 2018-07-27
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-7464

It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use thi…

Mitigation only
Fix from $2,300 2018-07-27
Enterprise Linux MEDIUM 6.5
CVE-2017-12171EPSS 8%

A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines…

Mitigation only
Fix from $1,600 2018-07-26
Jboss Fuse CRITICAL 9.0
CVE-2017-2589

It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored …

Mitigation only
Fix from $2,300 2018-07-26
Openstack CRITICAL 10.0
CVE-2017-2637

A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed…

Mitigation only
Fix from $2,300 2018-07-26
Package Manager HIGH 8.2
CVE-2017-3224

Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNum…

No fix yet
Fix from $1,950 2018-07-24
Cloudforms HIGH 7.8
CVE-2018-10905

CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with access to an…

Mitigation only
Fix from $1,950 2018-07-24
Certification CRITICAL 9.8
CVE-2018-10870EPSS 6%

redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any fil…

Mitigation only
Fix from $2,300 2018-07-19
Certification HIGH 7.5
CVE-2018-10869

redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file access…

Mitigation only
Fix from $1,950 2018-07-19
Openshift MEDIUM 5.3
CVE-2017-15137

The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a…

Mitigation only
Fix from $1,600 2018-07-16
Ansible Engine HIGH 7.8
CVE-2018-10875

A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module pat…

Mitigation only
Fix from $1,950 2018-07-13
Ansible Engine HIGH 7.8
CVE-2018-10874

In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's con…

Mitigation only
Fix from $1,950 2018-07-02
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-7465

It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw …

Mitigation only
Fix from $2,300 2018-06-27
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-5183

Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and…

Mitigation only
Fix from $2,300 2018-06-11
Enterprise Linux Desktop MEDIUM 6.5
CVE-2018-5185

Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird…

Mitigation only
Fix from $1,600 2018-06-11
Enterprise Linux Desktop HIGH 7.5
CVE-2018-5157

Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow th…

Mitigation only
Fix from $1,950 2018-06-11
Enterprise Linux Desktop HIGH 7.5
CVE-2018-5162

Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Th…

Mitigation only
Fix from $1,950 2018-06-11
Enterprise Linux Desktop HIGH 8.8
CVE-2018-5146EPSS 12%

An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.…

Mitigation only
Fix from $1,950 2018-06-11
Jboss Enterprise Application Platform HIGH 7.8
CVE-2016-8656

Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local p…

Mitigation only
Fix from $1,950 2018-05-22
Jboss Data Grid HIGH 8.8
CVE-2018-1131

Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticat…

Mitigation only
Fix from $1,950 2018-05-15
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2016-8627

admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be available via …

Mitigation only
Fix from $1,600 2018-05-11
Wildfly CRITICAL 9.8
CVE-2018-10683

An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successful…

No fix yet
Fix from $2,300 2018-05-09
Manageiq Enterprise Virtualization Manager HIGH 8.8
CVE-2013-0185

Cross-site request forgery (CSRF) vulnerability in ManageIQ Enterprise Virtualization Manager (EVM) allows remote attackers to hijack the authenticat…

No fix yet
Fix from $1,950 2018-05-01
Cloudforms Management Engine HIGH 7.5
CVE-2013-2049

Red Hat CloudForms 2 Management Engine (CFME) allows remote attackers to conduct session tampering attacks by leveraging use of a static secret_token…

Mitigation only
Fix from $1,950 2018-05-01
Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-10534

The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU B…

Mitigation only
Fix from $1,600 2018-04-29