Vulnerability index

Browse CVEs

813 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-10535

The ignore_section_sym function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, does not vali…

Mitigation only
Fix from $1,600 2018-04-29
Enterprise Linux Desktop MEDIUM 6.5
CVE-2018-10373

concat_filename in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to…

Mitigation only
Fix from $1,600 2018-04-25
Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-10372

process_cu_tu_index in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (heap-based buffer over-read and application…

No fix yet
Fix from $1,600 2018-04-25
Openstack HIGH 7.5
CVE-2016-9599

puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of T…

Mitigation only
Fix from $1,950 2018-04-24
Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-1106

An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed package…

Mitigation only
Fix from $1,600 2018-04-23
Rhn Client Tools MEDIUM 5.9
CVE-2015-1777

rhnreg_ks in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Gluster Storage 2.1 and Enterprise Linux (RHEL) 5, 6, and 7 does not prop…

Mitigation only
Fix from $1,600 2018-04-12
Openshift MEDIUM 5.4
CVE-2017-7534

OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, spec…

Mitigation only
Fix from $1,600 2018-04-11
Spacewalk HIGH 7.5
CVE-2018-1077

Spacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensitive information from the server.

Mitigation only
Fix from $1,950 2018-03-14
Jboss Enterprise Application Platform MEDIUM 5.3
CVE-2016-9585

Red Hat JBoss EAP version 5 is vulnerable to a deserialization of untrusted data in the JMX endpoint when deserializes the credentials passed to it. …

Mitigation only
Fix from $1,600 2018-03-09
Openshift HIGH 7.1
CVE-2018-1069

Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the U…

Mitigation only
Fix from $1,950 2018-03-09
Enterprise Linux Desktop MEDIUM 6.5
CVE-2018-7727

An issue was discovered in ZZIPlib 0.13.68. There is a memory leak triggered in the function zzip_mem_disk_new in memdisk.c, which will lead to a den…

No fix yet
Fix from $1,600 2018-03-06
Enterprise Linux Desktop HIGH 7.8
CVE-2018-7643

The display_debug_ranges function in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (integer overflow and applicat…

Mitigation only
Fix from $1,950 2018-03-02
Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-7642

The swap_std_reloc_in function in aoutx.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remot…

Mitigation only
Fix from $1,600 2018-03-02
Enterprise Linux Desktop HIGH 7.8
CVE-2018-7208

In the coff_pointerize_aux function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, an in…

Mitigation only
Fix from $1,950 2018-02-18
Jboss Enterprise Application Platform HIGH 7.5
CVE-2018-1041EPSS 16%

A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker coul…

No fix yet
Fix from $1,950 2018-02-15
Resteasy HIGH 8.1
CVE-2018-1051

It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yam…

Mitigation only
Fix from $1,950 2018-01-25
Jboss Enterprise Application Platform HIGH 7.5
CVE-2018-1048

It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the…

Mitigation only
Fix from $1,950 2018-01-24
Jboss Wildfly Application Server MEDIUM 5.5
CVE-2018-1047

A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResou…

Mitigation only
Fix from $1,600 2018-01-24
Openshift HIGH 7.8
CVE-2013-4364

(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local u…

Mitigation only
Fix from $1,950 2018-01-08
Enterprise Linux HIGH 7.8
CVE-2017-15104

An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi serv…

Mitigation only
Fix from $1,950 2017-12-18
Enterprise Linux MEDIUM 5.5
CVE-2017-15121

A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not e…

Mitigation only
Fix from $1,600 2017-12-07
Data Grid CRITICAL 9.8
CVE-2015-7501EPSS 86%

Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Pl…

Mitigation only
Fix from $2,300 2017-11-09
Gluster Storage HIGH 7.5
CVE-2017-15087

It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.

Mitigation only
Fix from $1,950 2017-11-08
Gluster Storage HIGH 7.4
CVE-2017-15086

It was discovered that the fix for CVE-2017-12151 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.

Mitigation only
Fix from $1,950 2017-11-08
Gluster Storage MEDIUM 5.9
CVE-2017-15085

It was discovered that the fix for CVE-2017-12150 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.

Mitigation only
Fix from $1,600 2017-11-08
Single Sign On HIGH 7.5
CVE-2017-12159

It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to a…

Mitigation only
Fix from $1,950 2017-10-26
Keycloak HIGH 7.2
CVE-2017-12160

It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permit…

Mitigation only
Fix from $1,950 2017-10-26
Single Sign On MEDIUM 5.4
CVE-2017-12158

It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use …

Mitigation only
Fix from $1,600 2017-10-26
Cloudforms 3.0 Management Engine MEDIUM 6.5
CVE-2014-7813

Red Hat CloudForms 3 Management Engine (CFME) allows remote authenticated users to cause a denial of service (resource consumption) via vectors invol…

Mitigation only
Fix from $1,600 2017-10-18
Enterprise Mrg MEDIUM 5.9
CVE-2014-3706

ovirt-engine, as used in Red Hat MRG 3, allows man-in-the-middle attackers to spoof servers by leveraging failure to verify key attributes in vdsm X.…

Mitigation only
Fix from $1,600 2017-10-18