Vulnerability index

Browse CVEs

813 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Jboss Bpm Suite HIGH 8.8
CVE-2016-5401

Cross-site request forgery (CSRF) vulnerability in Red Hat JBoss BRMS and BPMS 6 allows remote attackers to hijack the authentication of users for re…

Mitigation only
Fix from $1,950 2017-04-20
Resteasy MEDIUM 6.1
CVE-2016-6347

Cross-site scripting (XSS) vulnerability in the default exception handler in RESTEasy allows remote attackers to inject arbitrary web script or HTML …

Mitigation only
Fix from $1,600 2017-04-20
Openshift HIGH 7.5
CVE-2016-5409

Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which makes it easier for remote atta…

Mitigation only
Fix from $1,950 2017-04-20
Enterprise Virtualization MEDIUM 6.8
CVE-2016-6338

ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate atta…

No fix yet
Fix from $1,600 2017-04-20
Satellite MEDIUM 6.1
CVE-2016-2104

Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the …

Mitigation only
Fix from $1,600 2017-04-13
Resteasy MEDIUM 6.1
CVE-2016-6348

JacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack.

Mitigation only
Fix from $1,600 2017-04-12
Mod Cluster HIGH 7.5
CVE-2016-4459

Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9.

Mitigation only
Fix from $1,950 2017-04-12
Enterprise Linux HIGH 8.8
CVE-2016-3616

The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitra…

Mitigation only
Fix from $1,950 2017-02-13
Enterprise Linux HIGH 7.8
CVE-2016-2568

pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters t…

Mitigation only
Fix from $1,950 2017-02-13
Enterprise Linux Desktop CRITICAL 9.8
CVE-2014-8241

XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return …

Mitigation only
Fix from $2,300 2016-12-14
Jboss Enterprise Application Platform HIGH 8.8
CVE-2016-7065EPSS 12%

The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and pos…

No fix yet
Fix from $1,950 2016-10-13
Cloudforms Management Engine HIGH 8.8
CVE-2016-7040

Red Hat CloudForms Management Engine 4.1 does not properly handle regular expressions passed to the expression engine via the JSON API and the web-ba…

Mitigation only
Fix from $1,950 2016-10-07
Jboss Enterprise Application Platform MEDIUM 5.9
CVE-2016-7046

Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause …

Mitigation only
Fix from $1,600 2016-10-03
Jboss Operations Network CRITICAL 9.8
CVE-2016-6330EPSS 11%

The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote a…

Mitigation only
Fix from $2,300 2016-09-27
Jboss Enterprise Application Platform HIGH 7.5
CVE-2016-3110

mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP mes…

Mitigation only
Fix from $1,950 2016-09-26
Quickstart Cloud Installer HIGH 8.4
CVE-2016-6340

The kickstart file in Red Hat QuickStart Cloud Installer (QCI) forces use of MD5 passwords on deployed systems, which makes it easier for attackers t…

Mitigation only
Fix from $1,950 2016-09-22
Quickstart Cloud Installer HIGH 8.4
CVE-2016-6322

Red Hat QuickStart Cloud Installer (QCI) uses world-readable permissions for /etc/qci/answers, which allows local users to obtain the root password f…

Mitigation only
Fix from $1,950 2016-09-22
Jboss Bpm Suite HIGH 8.8
CVE-2016-7034

The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session and includes them in query s…

Mitigation only
Fix from $1,950 2016-09-07
Jboss Bpm Suite MEDIUM 6.1
CVE-2016-7033

Multiple cross-site scripting (XSS) vulnerabilities in the admin pages in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 allow remote attackers to inje…

Mitigation only
Fix from $1,600 2016-09-07
Resteasy HIGH 7.5
CVE-2016-6346EPSS 6%

RESTEasy enables GZIPInterceptor, which allows remote attackers to cause a denial of service via unspecified vectors.

Mitigation only
Fix from $1,950 2016-09-07
Resteasy MEDIUM 6.5
CVE-2016-6345

RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.

Mitigation only
Fix from $1,600 2016-09-07
Jboss Bpm Suite MEDIUM 5.3
CVE-2016-6344

Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attacke…

Mitigation only
Fix from $1,600 2016-09-07
Cloudforms HIGH 8.8
CVE-2016-5383

The web UI in Red Hat CloudForms 4.1 allows remote authenticated users to execute arbitrary code via vectors involving "Lack of field filters."

Mitigation only
Fix from $1,950 2016-08-26
Openshift MEDIUM 6.5
CVE-2016-5392

The API server in Kubernetes, as used in Red Hat OpenShift Enterprise 3.2, in a multi tenant environment allows remote authenticated users with knowl…

Mitigation only
Fix from $1,600 2016-08-05
Satellite MEDIUM 6.1
CVE-2016-3097

Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML vi…

Mitigation only
Fix from $1,600 2016-08-05
Satellite MEDIUM 6.1
CVE-2016-3080

Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML vi…

Mitigation only
Fix from $1,600 2016-08-05
Openstack HIGH 8.8
CVE-2016-4474

The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterprise Linux OpenStack Platform…

Mitigation only
Fix from $1,950 2016-06-30
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-4448EPSS 7%

Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.

Mitigation only
Fix from $2,300 2016-06-09
Enterprise Linux HIGH 7.1
CVE-2016-2150

SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to…

Mitigation only
Fix from $1,950 2016-06-09
Openshift HIGH 8.8
CVE-2016-3738

Red Hat OpenShift Enterprise 3.2 does not properly restrict access to STI builds, which allows remote authenticated users to access the Docker socket…

Mitigation only
Fix from $1,950 2016-06-08