Vulnerability index

Browse CVEs

813 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Edeploy CRITICAL 9.1
CVE-2014-3702

Directory traversal vulnerability in eNovance eDeploy allows remote attackers to create arbitrary directories and files and consequently cause a deni…

Mitigation only
Fix from $2,300 2017-10-16
Ovirt Engine HIGH 7.5
CVE-2014-7851

oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowle…

Mitigation only
Fix from $1,950 2017-10-16
Subscription Asset Manager MEDIUM 6.1
CVE-2014-0029

Multiple cross-site scripting (XSS) vulnerabilities in the SAM web application in Red Hat katello-headpin allow remote attackers to inject arbitrary …

Mitigation only
Fix from $1,600 2017-10-16
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-12149 KEVEPSS 91%

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessF…

Mitigation only
Fix from $2,300 2017-10-04
Enterprise Virtualization Manager CRITICAL 9.1
CVE-2015-7544

redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the Supe…

Mitigation only
Fix from $2,300 2017-09-25
Amq HIGH 8.8
CVE-2015-5182

Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ.

Mitigation only
Fix from $1,950 2017-09-25
Feedhenry Enterprise Mobile Application Platform MEDIUM 6.5
CVE-2015-5248

Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform.

No fix yet
Fix from $1,600 2017-09-20
Rhnsd MEDIUM 5.5
CVE-2017-7560

It was found that rhnsd PID files are created as world-writable that allows local attackers to fill the disks or to kill selected processes.

Mitigation only
Fix from $1,600 2017-09-13
Satellite MEDIUM 6.5
CVE-2014-8163

Directory traversal vulnerability in the XMLRPC interface in Red Hat Satellite 5.

No fix yet
Fix from $1,600 2017-08-28
Satellite MEDIUM 6.1
CVE-2014-0141

Cross-site scripting (XSS) vulnerability in Red Hat Satellite 6.0.3.

No fix yet
Fix from $1,600 2017-08-28
Satellite MEDIUM 6.1
CVE-2014-8168

Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.

Mitigation only
Fix from $1,600 2017-08-28
Jboss Enterprise Application Platform MEDIUM 5.3
CVE-2016-6311

Get requests in JBoss Enterprise Application Platform (EAP) 7 disclose internal IP addresses to remote attackers.

Mitigation only
Fix from $1,600 2017-08-22
Ovirt Engine MEDIUM 6.1
CVE-2016-3113

Cross-site scripting (XSS) vulnerability in ovirt-engine allows remote attackers to inject arbitrary web script or HTML.

Mitigation only
Fix from $1,600 2017-08-07
Enterprise Linux Desktop MEDIUM 5.5
CVE-2015-3149

The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitrary files via a symlink attack.

Mitigation only
Fix from $1,600 2017-07-25
Jboss Wildfly Application Server HIGH 7.5
CVE-2015-3198

The Undertow module of WildFly 9.x before 9.0.0.CR2 and 10.x before 10.0.0.Alpha1 allows remote attackers to obtain the source code of a JSP page via…

Mitigation only
Fix from $1,950 2017-07-21
Satellite HIGH 7.0
CVE-2016-4996

discovery-debug in Foreman before 6.2 when the ssh service has been enabled on discovered nodes displays the root password in plaintext in the system…

Mitigation only
Fix from $1,950 2017-07-17
3scale Api Management Platform CRITICAL 9.8
CVE-2017-7512

Red Hat 3scale (aka RH-3scale) API Management Platform (AMP) before 2.0.0 would permit creation of an access token without a client secret. An attack…

Mitigation only
Fix from $2,300 2017-07-07
Gluster Storage HIGH 7.8
CVE-2015-1795

Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root.

Mitigation only
Fix from $1,950 2017-06-27
Storage Console HIGH 7.8
CVE-2016-7062

rhscon-ceph in Red Hat Storage Console 2 x86_64 and Red Hat Storage Console Node 2 x86_64 allows local users to obtain the password as cleartext.

Mitigation only
Fix from $1,950 2017-06-27
Enterprise Linux HIGH 7.5
CVE-2017-9953

There is an invalid free in Image::printIFDStructure that leads to a Segmentation fault in Exiv2 0.26. A crafted input will lead to a remote denial o…

No fix yet
Fix from $1,950 2017-06-26
Quickstart Cloud Installer CRITICAL 9.8
CVE-2016-5411

/var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created world readable and contains the …

Mitigation only
Fix from $2,300 2017-06-13
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-5405

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server …

Mitigation only
Fix from $2,300 2017-06-08
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-7050EPSS 5%

SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and R…

Mitigation only
Fix from $2,300 2017-06-08
Enterprise Linux Desktop HIGH 7.5
CVE-2016-3099

mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Wo…

Mitigation only
Fix from $1,950 2017-06-08
Enterprise Linux Desktop HIGH 7.5
CVE-2016-5416

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server …

Mitigation only
Fix from $1,950 2017-06-08
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2016-3690EPSS 5%

The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.

Mitigation only
Fix from $2,300 2017-06-08
Cloudforms Management Engine HIGH 7.5
CVE-2016-4457

CloudForms Management Engine before 5.8 includes a default SSL/TLS certificate.

No fix yet
Fix from $1,950 2017-06-08
Ovirt Engine MEDIUM 6.5
CVE-2016-3077

The VersionMapper.fromKernelVersionString method in oVirt Engine allows remote authenticated users to cause a denial of service (process crash) for a…

Mitigation only
Fix from $1,600 2017-06-06
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-7503

It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use th…

Mitigation only
Fix from $2,300 2017-05-18
Cloudforms Management Engine MEDIUM 5.3
CVE-2016-3702

Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext information.

Mitigation only
Fix from $1,600 2017-04-21