Vulnerability index

Browse CVEs

813 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Enterprise Mrg MEDIUM 6.8
CVE-2013-4405

Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allow remote attackers t…

Mitigation only
Fix from $1,600 2013-12-23
Enterprise Mrg MEDIUM 6.5
CVE-2013-4404

cumin in Red Hat Enterprise MRG Grid 2.4 does not properly enforce user roles, which allows remote authenticated users to bypass intended role restri…

Mitigation only
Fix from $1,600 2013-12-23
Enterprise Linux MEDIUM 6.3
CVE-2013-2561

OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet…

No fix yet
Fix from $1,600 2013-11-23
Openstack MEDIUM 6.3
CVE-2013-2029

nagios.upgrade_to_v3.sh, as distributed by Red Hat and possibly others for Nagios Core 3.4.4, 3.5.1, and earlier, allows local users to overwrite arb…

Mitigation only
Fix from $1,600 2013-11-23
Enterprise Linux MEDIUM 6.2
CVE-2013-4482

Untrusted search path vulnerability in python-paste-script (aka paster) in Luci 0.26.0, when started using the initscript, allows local users to gain…

Mitigation only
Fix from $1,600 2013-11-23
Enterprise Linux Desktop HIGH 10.0
CVE-2013-5842EPSS 18%

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and ear…

Mitigation only
Fix from $1,950 2013-10-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-5829EPSS 7%

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and ear…

Mitigation only
Fix from $1,950 2013-10-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-5830EPSS 7%

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRoc…

Mitigation only
Fix from $1,950 2013-10-16
Enterprise Mrg MEDIUM 5.0
CVE-2013-4284

Cumin, as used in Red Hat Enterprise MRG 2.4, allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted Ajax up…

Mitigation only
Fix from $1,600 2013-10-09
Enterprise Linux HIGH 7.2
CVE-2013-2231

Unquoted Windows search path vulnerability in the QEMU Guest Agent service for Red Hat Enterprise Linux Desktop 6, HPC Node 6, Server 6, Workstation …

Mitigation only
Fix from $1,950 2013-10-01
Jboss Enterprise Application Platform MEDIUM 5.0
CVE-2013-4210

The org.jboss.remoting.transport.socket.ServerThread class in Red Hat JBoss Remoting for Red Hat JBoss SOA Platform 5.3.1 GA, Web Platform 5.2.0, Ent…

Mitigation only
Fix from $1,600 2013-10-01
Jboss Enterprise Application Platform MEDIUM 5.4
CVE-2013-4112

The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (di…

Mitigation only
Fix from $1,600 2013-09-28
Cloudforms Management Engine HIGH 9.4
CVE-2013-2068EPSS 59%

Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow remote attackers to create and …

No fix yet
Fix from $1,950 2013-09-28
Enterprise Virtualization HIGH 7.2
CVE-2013-2176

Unquoted Windows search path vulnerability in the Red Hat Enterprise Virtualization Application Provisioning Tool (RHEV-APT) in the rhev-guest-tools-…

Mitigation only
Fix from $1,950 2013-08-28
Cloudforms Management Engine HIGH 8.5
CVE-2013-4172

The Red Hat CloudForms Management Engine 5.1 allow remote administrators to execute arbitrary Ruby code via unspecified vectors.

Mitigation only
Fix from $1,950 2013-08-23
Jboss Enterprise Application Platform MEDIUM 6.4
CVE-2013-4213

Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attacker…

Mitigation only
Fix from $1,600 2013-08-16
Jboss Enterprise Application Platform MEDIUM 6.4
CVE-2013-4128

Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by remote-naming, which allows remote attackers to …

Mitigation only
Fix from $1,600 2013-08-16
Satellite MEDIUM 5.0
CVE-2013-2056

The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5.3, 5.4, and 5.5 does not properly check client "authenticity," which al…

Mitigation only
Fix from $1,600 2013-07-31
Jboss Enterprise Web Server MEDIUM 6.9
CVE-2013-1976

The (1) tomcat5, (2) tomcat6, and (3) tomcat7 init scripts, as used in the RPM distribution of Tomcat for JBoss Enterprise Web Server 1.0.2 and 2.0.0…

Mitigation only
Fix from $1,600 2013-07-09
Libvirt MEDIUM 5.0
CVE-2013-1962

The remoteDispatchStoragePoolListAllVolumes function in the storage pool manager in libvirt 1.0.5 allows remote attackers to cause a denial of servic…

Mitigation only
Fix from $1,600 2013-05-29
Jboss Enterprise Portal Platform HIGH 7.5
CVE-2013-0314

The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 does not properly check authentication when importing Zip files, whi…

Mitigation only
Fix from $1,950 2013-04-12
Jboss Enterprise Portal Platform MEDIUM 5.0
CVE-2013-0315

The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 allows remote attackers to read arbitrary files via a crafted extern…

Mitigation only
Fix from $1,600 2013-04-12
Openstack Essex MEDIUM 6.1
CVE-2013-1815

A flaw was found in PackStack. This vulnerability allows a local user to modify deployed systems by changing the answer file, which is created in ins…

No fix yet
Fix from $1,600 2013-04-10
Jboss Enterprise Application Platform HIGH 7.5
CVE-2012-5629

The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.…

Mitigation only
Fix from $1,950 2013-03-12
Aeolus Conductor MEDIUM 5.5
CVE-2012-6118

The Administer tab in Aeolus Conductor allows remote authenticated users to bypass intended quota restrictions by updating the Maximum Running Instan…

No fix yet
Fix from $1,600 2013-03-12
Freeipa HIGH 7.9
CVE-2012-5484

The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows ma…

Mitigation only
Fix from $1,950 2013-01-27
Enterprise Linux Desktop HIGH 7.1
CVE-2012-5689EPSS 12%

ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA …

Mitigation only
Fix from $1,950 2013-01-25
Enterprise Linux MEDIUM 5.0
CVE-2012-2124

functions/imap_general.php in SquirrelMail, as used in Red Hat Enterprise Linux (RHEL) 4 and 5, does not properly handle 8-bit characters in password…

Mitigation only
Fix from $1,600 2013-01-18
Jboss Enterprise Application Platform MEDIUM 5.3
CVE-2012-4550

A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system d…

Mitigation only
Fix from $1,600 2013-01-05
Icedtea Web MEDIUM 6.8
CVE-2012-4540

Off-by-one error in the invoke function in IcedTeaScriptablePluginObject.cc in IcedTea-Web 1.1.x before 1.1.7, 1.2.x before 1.2.2, 1.3.x before 1.3.1…

Mitigation only
Fix from $1,600 2012-11-11