Vulnerability index

Browse CVEs

813 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Resteasy MEDIUM 6.4
CVE-2014-7839

DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which …

Mitigation only
Fix from $1,600 2014-11-25
Tcpdump MEDIUM 6.4
CVE-2014-8769EPSS 6%

tcpdump 3.8 through 4.6.2 might allow remote attackers to obtain sensitive information from memory or cause a denial of service (packet loss or segme…

No fix yet
Fix from $1,600 2014-11-20
Tcpdump MEDIUM 5.0
CVE-2014-8767EPSS 5%

Integer underflow in the olsr_print function in tcpdump 3.9.6 through 4.6.2, when in verbose mode, allows remote attackers to cause a denial of servi…

No fix yet
Fix from $1,600 2014-11-20
Openshift MEDIUM 6.5
CVE-2014-0233

Red Hat OpenShift Enterprise 2.0 and 2.1 and OpenShift Origin allow remote authenticated users to execute arbitrary commands via shell metacharacters…

No fix yet
Fix from $1,600 2014-11-16
Virtual Desktop Service Manager MEDIUM 5.0
CVE-2014-7968

VDSM allows remote attackers to cause a denial of service (connection blocking) by keeping an SSL connection open.

Mitigation only
Fix from $1,600 2014-10-22
Conga MEDIUM 5.5
CVE-2014-3521

The component in (1) /luci/homebase and (2) /luci/cluster menu in Red Hat Conga 0.12.2 allows remote authenticated users to bypass intended access re…

Mitigation only
Fix from $1,600 2014-10-06
Conga MEDIUM 5.0
CVE-2013-6496

Red Hat Conga 0.12.2 allows remote attackers to obtain sensitive information via a crafted request to the (1) homebase, (2) cluster, (3) storage, (4)…

Mitigation only
Fix from $1,600 2014-10-06
Directory Server MEDIUM 5.0
CVE-2014-3562

Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by se…

Mitigation only
Fix from $1,600 2014-08-21
Jboss Enterprise Application Platform MEDIUM 5.5
CVE-2014-3464

The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not proper…

Mitigation only
Fix from $1,600 2014-08-19
Jboss Enterprise Application Platform HIGH 7.5
CVE-2014-3530

The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform …

Mitigation only
Fix from $1,950 2014-07-22
Jboss Enterprise Application Platform MEDIUM 6.8
CVE-2014-3518

jmx-remoting.sar in JBoss Remoting, as used in Red Hat JBoss Enterprise Application Platform (JEAP) 5.2.0, Red Hat JBoss BRMS 5.3.1, Red Hat JBoss Po…

Mitigation only
Fix from $1,600 2014-07-22
Enterprise Mrg MEDIUM 5.0
CVE-2012-2682

Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, allows attackers with certain database privileges to cause a denial of ser…

Mitigation only
Fix from $1,600 2014-07-19
Jboss Enterprise Application Platform MEDIUM 6.8
CVE-2014-0248

org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Ente…

Mitigation only
Fix from $1,600 2014-07-07
Openstack MEDIUM 5.0
CVE-2013-6470

The default configuration in the standalone controller quickstack manifest in openstack-foreman-installer, as used in Red Hat Enterprise Linux OpenSt…

Mitigation only
Fix from $1,600 2014-06-02
Enterprise Mrg MEDIUM 5.0
CVE-2013-6445

Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, uses the DES-based crypt function to hash passwords, which makes it easier…

Mitigation only
Fix from $1,600 2014-04-30
Jboss Fuse Service Works MEDIUM 6.5
CVE-2013-6469

JBoss Overlord Run Time Governance (RTGov) 1.0 for JBossAS allows remote authenticated users to execute arbitrary Java code via an MVFLEX Expression …

Mitigation only
Fix from $1,600 2014-04-22
Openstack MEDIUM 6.4
CVE-2014-0071

PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass int…

Mitigation only
Fix from $1,600 2014-04-17
Libvirt MEDIUM 5.8
CVE-2013-6456

The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDetta…

Mitigation only
Fix from $1,600 2014-04-15
Jboss Bpm Suite MEDIUM 6.5
CVE-2013-6468

JBoss Drools, Red Hat JBoss BRMS before 6.0.1, and Red Hat JBoss BPM Suite before 6.0.1 allows remote authenticated users to execute arbitrary Java c…

Mitigation only
Fix from $1,600 2014-04-10
Jboss Enterprise Application Platform MEDIUM 5.8
CVE-2014-0093

Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by…

Mitigation only
Fix from $1,600 2014-04-03
Cloudforms HIGH 7.5
CVE-2014-0057

The x_button method in the ServiceController (vmdb/app/controllers/service_controller.rb) in Red Hat CloudForms 3.0 Management Engine 5.2 allows remo…

Mitigation only
Fix from $1,950 2014-03-18
Enterprise Virtualization MEDIUM 6.8
CVE-2012-3406

The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the …

Mitigation only
Fix from $1,600 2014-02-10
Enterprise Virtualization MEDIUM 5.0
CVE-2012-3405

The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer le…

Mitigation only
Fix from $1,600 2014-02-10
Certificate System HIGH 7.5
CVE-2013-1886

Format string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System …

Mitigation only
Fix from $1,950 2014-01-24
Enterprise Virtualization HIGH 7.2
CVE-2013-2151

Unquoted Windows search path vulnerability in Red Hat Enterprise Virtualization (RHEV) 3 and 3.2 allows local users to gain privileges via a crafted …

Mitigation only
Fix from $1,950 2014-01-21
Enterprise Virtualization HIGH 7.2
CVE-2013-2152

Unquoted Windows search path vulnerability in the SPICE service, as used in Red Hat Enterprise Virtualization (RHEV) 3.2, allows local users to gain …

Mitigation only
Fix from $1,950 2014-01-21
Enterprise Linux Desktop Supplementary MEDIUM 5.1
CVE-2014-0418EPSS 6%

Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown …

Mitigation only
Fix from $1,600 2014-01-15
Enterprise Linux Desktop Supplementary MEDIUM 5.1
CVE-2013-5906EPSS 6%

Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via…

Mitigation only
Fix from $1,600 2014-01-15
Subscription Asset Manager HIGH 9.3
CVE-2013-6439

Candlepin in Red Hat Subscription Asset Manager 1.0 through 1.3 uses a weak authentication scheme when the configuration file does not specify a sche…

No fix yet
Fix from $1,950 2013-12-23
Enterprise Mrg HIGH 7.5
CVE-2013-4461

SQL injection vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to execute arbitrary SQL comman…

Mitigation only
Fix from $1,950 2013-12-23