Vulnerability index

Browse CVEs

813 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Openshift HIGH 7.1
CVE-2016-3708

Red Hat OpenShift Enterprise 3.2, when multi-tenant SDN is enabled and a build is run in a namespace that would normally be isolated from pods in oth…

Mitigation only
Fix from $1,950 2016-06-08
Openshift MEDIUM 5.3
CVE-2016-3703

Red Hat OpenShift Enterprise 3.2 and 3.1 do not properly validate the origin of a request when anonymous access is granted to a service/proxy or pod/…

Mitigation only
Fix from $1,600 2016-06-08
Openshift MEDIUM 6.5
CVE-2016-2149

Red Hat OpenShift Enterprise 3.2 allows remote authenticated users to read log files from another namespace by using the same name as a previously de…

Mitigation only
Fix from $1,600 2016-06-08
Openshift MEDIUM 5.5
CVE-2016-2142

Red Hat OpenShift Enterprise 3.1 uses world-readable permissions on the /etc/origin/master/master-config.yaml configuration file, which allows local …

Mitigation only
Fix from $1,600 2016-06-08
Enterprise Linux Desktop HIGH 7.8
CVE-2015-5260

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash…

Mitigation only
Fix from $1,950 2016-06-07
Gluster Storage Management Console MEDIUM 6.5
CVE-2014-8177

The Red Hat gluster-swift package, as used in Red Hat Gluster Storage (formerly Red Hat Storage Server), allows remote authenticated users to bypass …

Mitigation only
Fix from $1,600 2016-06-07
Satellite HIGH 8.1
CVE-2016-0376EPSS 6%

The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), …

Mitigation only
Fix from $1,950 2016-06-03
Satellite HIGH 8.1
CVE-2016-0363

The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 be…

Mitigation only
Fix from $1,950 2016-06-03
Satellite MEDIUM 5.6
CVE-2016-0264

Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25)…

Mitigation only
Fix from $1,600 2016-05-24
Libvirt MEDIUM 6.5
CVE-2015-5247

The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of s…

Mitigation only
Fix from $1,600 2016-04-14
Satellite MEDIUM 6.1
CVE-2016-2103

Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the …

Mitigation only
Fix from $1,600 2016-04-14
Cloudforms Management Engine MEDIUM 5.1
CVE-2015-7502

Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.5.0 do not properly encrypt data in the backend P…

Mitigation only
Fix from $1,600 2016-04-11
Openstack HIGH 7.3
CVE-2015-5329

The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 7.0, do not properly use the configured R…

Mitigation only
Fix from $1,950 2016-04-11
Enterprise Linux HIGH 7.5
CVE-2015-5229

The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 and 7.2 does not properly initialize memory areas, which might allow …

Mitigation only
Fix from $1,950 2016-04-08
Jboss Wildfly Application Server HIGH 7.5
CVE-2016-0793EPSS 16%

Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Server) before 10.0.0.Final on …

No fix yet
Fix from $1,950 2016-04-01
Enterprise Linux Desktop CRITICAL 9.0
CVE-2015-7512EPSS 8%

Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial…

Mitigation only
Fix from $2,300 2016-01-08
Openshift CRITICAL 9.8
CVE-2015-5254EPSS 38%

Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitr…

Mitigation only
Fix from $2,300 2016-01-08
Enterprise Linux Desktop HIGH 7.5
CVE-2015-8327EPSS 10%

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows rem…

Mitigation only
Fix from $1,950 2015-12-17
Gluster Storage MEDIUM 6.0
CVE-2015-5242

OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authe…

Mitigation only
Fix from $1,600 2015-11-25
Openshift MEDIUM 6.4
CVE-2015-5305

Directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift Enterprise 3.0, allows attackers to write to arbitrary files via a craf…

Mitigation only
Fix from $1,600 2015-11-06
Openshift MEDIUM 6.5
CVE-2015-5274

rubygem-openshift-origin-console in Red Hat OpenShift 2.2 allows remote authenticated users to execute arbitrary commands via a crafted request to th…

Mitigation only
Fix from $1,600 2015-09-18
Enterprise Linux MEDIUM 6.9
CVE-2015-3247

Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (h…

Mitigation only
Fix from $1,600 2015-09-08
Openshift HIGH 8.5
CVE-2015-5222

Red Hat OpenShift Enterprise 3.0.0.0 does not properly check permissions, which allows remote authenticated users with build permissions to execute a…

Mitigation only
Fix from $1,950 2015-08-24
Jboss Portal MEDIUM 5.8
CVE-2015-5176

The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets,…

Mitigation only
Fix from $1,600 2015-08-11
Jboss Operations Network HIGH 9.0
CVE-2015-0297

Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java met…

Mitigation only
Fix from $1,950 2015-04-24
Enterprise Linux HIGH 10.0
CVE-2015-0240EPSS 88%

The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc…

Mitigation only
Fix from $1,950 2015-02-24
Cloudforms 3.1 Management Engine MEDIUM 6.5
CVE-2014-7814

SQL injection vulnerability in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 allows remote authenticated users to execute arbitrary SQL command…

Mitigation only
Fix from $1,600 2015-01-16
Cloudforms 3.1 Management Engine HIGH 10.0
CVE-2014-3692

The customization template in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 uses a default password for the root account when a password is not…

Mitigation only
Fix from $1,950 2015-01-16
Enterprise Linux HIGH 7.5
CVE-2014-8138EPSS 19%

Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or p…

No fix yet
Fix from $1,950 2014-12-24
Packstack MEDIUM 5.0
CVE-2014-3703

OpenStack PackStack 2012.2.1, when the Open vSwitch (OVS) monolithic plug-in is not used, does not properly set the libvirt_vif_driver configuration …

Mitigation only
Fix from $1,600 2014-12-02