Vulnerability index

Browse CVEs

813 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux Desktop CRITICAL 9.8
CVE-2012-4681 KEVEPSS 99%

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute a…

Mitigation only
Fix from $2,300 2012-08-28
Enterprise Linux MEDIUM 5.6
CVE-2012-3440

A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary files via a symlink attack on …

No fix yet
Fix from $1,600 2012-08-08
Satellite MEDIUM 5.0
CVE-2012-1145

spacewalk-backend in Red Hat Network Satellite 5.4 on Red Hat Enterprise Linux 6 does not properly authorize or authenticate uploads to the NULL orga…

Mitigation only
Fix from $1,600 2012-06-16
Jboss Enterprise Application Platform HIGH 7.5
CVE-2011-4608

mod_cluster in JBoss Enterprise Application Platform 5.1.2 for Red Hat Linux allows worker nodes to register with arbitrary virtual hosts, which allo…

Mitigation only
Fix from $1,950 2012-01-27
Network Satellite Server MEDIUM 6.4
CVE-2009-0788

Red Hat Network (RHN) Satellite Server 5.3 and 5.4 does not properly rewrite unspecified URLs, which allows remote attackers to (1) obtain unspecifie…

No fix yet
Fix from $1,600 2011-04-18
Satellite MEDIUM 5.5
CVE-2010-1171

Red Hat Network (RHN) Satellite 5.3 and 5.4 exposes a dangerous, obsolete XML-RPC API, which allows remote authenticated users to access arbitrary fi…

Mitigation only
Fix from $1,600 2011-04-18
Network Satellite Server MEDIUM 5.8
CVE-2011-0717

Session fixation vulnerability in Red Hat Network (RHN) Satellite Server 5.4 allows remote attackers to hijack web sessions via unspecified vectors r…

Mitigation only
Fix from $1,600 2011-02-25
Network Satellite Server MEDIUM 5.8
CVE-2011-0718

Red Hat Network (RHN) Satellite Server 5.4 does not use a time delay after a failed login attempt, which makes it easier for remote attackers to cond…

Mitigation only
Fix from $1,600 2011-02-25
Directory Server HIGH 7.5
CVE-2011-0019

slapd (aka ns-slapd) in 389 Directory Server 1.2.7.5 (aka Red Hat Directory Server 8.2.x or dirsrv) does not properly handle simple paged result sear…

Mitigation only
Fix from $1,950 2011-02-23
Directory Server MEDIUM 6.2
CVE-2011-0532

The (1) backup and restore scripts, (2) main initialization script, and (3) ldap-agent script in 389 Directory Server 1.2.x (aka Red Hat Directory Se…

Mitigation only
Fix from $1,600 2011-02-23
Conga HIGH 7.5
CVE-2011-0720

Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain administra…

Mitigation only
Fix from $1,950 2011-02-03
Jboss Enterprise Application Platform HIGH 7.5
CVE-2010-3708

The serialization implementation in JBoss Drools in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 and …

Mitigation only
Fix from $1,950 2010-12-30
Enterprise Mrg HIGH 7.5
CVE-2010-4179

The installation documentation for Red Hat Enterprise Messaging, Realtime and Grid (MRG) 1.3 recommends that Condor should be configured so that the …

Mitigation only
Fix from $1,950 2010-12-07
Jboss Enterprise Application Platform HIGH 8.8
CVE-2010-1871 KEVEPSS 83%

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Exp…

Mitigation only
Fix from $1,950 2010-08-05
Jboss Enterprise Application Platform HIGH 7.5
CVE-2010-1428 KEVEPSS 62%

The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 …

Mitigation only
Fix from $1,950 2010-04-28
Jboss Enterprise Application Platform MEDIUM 5.3
CVE-2010-0738 KEVEPSS 79%

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 be…

Mitigation only
Fix from $1,600 2010-04-28
Enterprise Mrg MEDIUM 6.5
CVE-2009-4133

Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and Grid Execute Node for MRG, allows remote authenticated users to queue…

Mitigation only
Fix from $1,600 2009-12-23
Enterprise Linux MEDIUM 6.9
CVE-2009-1893

The configtest function in the Red Hat dhcpd init script for DHCP 3.0.1 in Red Hat Enterprise Linux (RHEL) 3 allows local users to overwrite arbitrar…

Mitigation only
Fix from $1,600 2009-07-17
Cluster Project MEDIUM 6.9
CVE-2008-6552

Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified com…

Mitigation only
Fix from $1,600 2009-03-30
Dogtag Certificate System MEDIUM 6.0
CVE-2008-5082

The verifyProof function in the Token Processing System (TPS) component in Red Hat Certificate System (RHCS) 7.1 through 7.3 and Dogtag Certificate S…

Mitigation only
Fix from $1,600 2009-01-30
Enterprise Linux MEDIUM 6.8
CVE-2008-4315

tog-pegasus in OpenGroup Pegasus 2.7.0 on Red Hat Enterprise Linux (RHEL) 5, Fedora 9, and Fedora 10 does not log failed authentication attempts to t…

Mitigation only
Fix from $1,600 2008-11-27
Enterprise Virtualization HIGH 10.0
CVE-2008-3522

Buffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c in JasPer 1.900.1 might allow context-dependent attackers to have an…

No fix yet
Fix from $1,950 2008-10-02
Cman MEDIUM 6.9
CVE-2008-4192

The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack…

Mitigation only
Fix from $1,600 2008-09-29
Adminutil HIGH 7.5
CVE-2008-2932

Heap-based buffer overflow in Red Hat adminutil 1.1.6 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitra…

Mitigation only
Fix from $1,950 2008-09-12
Nfs Utils HIGH 7.5
CVE-2008-1376

A certain Red Hat build script for nfs-utils before 1.0.9-35z.el5_2 on Red Hat Enterprise Linux (RHEL) 5 omits TCP wrappers support, which might allo…

Mitigation only
Fix from $1,950 2008-08-01
Vsftpd HIGH 7.1
CVE-2008-2375

Memory leak in a certain Red Hat deployment of vsftpd before 2.0.5 on Red Hat Enterprise Linux (RHEL) 3 and 4, when PAM is used, allows remote attack…

No fix yet
Fix from $1,950 2008-07-09
Fedora 8 HIGH 7.2
CVE-2008-2359

The default configuration of consolehelper in system-config-network before 1.5.10-1 on Fedora 8 lacks the USER=root directive, which allows local use…

Mitigation only
Fix from $1,950 2008-06-02
Desktop HIGH 7.5
CVE-2008-1767EPSS 13%

Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent attackers to cause a denial of service (crash) and possibly execute ar…

No fix yet
Fix from $1,950 2008-05-23
Directory Server HIGH 7.5
CVE-2008-1677

Buffer overflow in the regular expression handler in Red Hat Directory Server 8.0 and 7.1 before SP6 allows remote attackers to cause a denial of ser…

Mitigation only
Fix from $1,950 2008-05-12
Enterprise Linux HIGH 7.1
CVE-2007-6282

The IPsec implementation in Linux kernel before 2.6.25 allows remote routers to cause a denial of service (crash) via a fragmented ESP packet in whic…

No fix yet
Fix from $1,950 2008-05-08