Vulnerability index

Browse CVEs

813 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.3 CVE-2017-2614 When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is ex… Enterprise Virtualization Mitigation only Fix from $1,6002018-07-27 MEDIUM 6.5 CVE-2017-2595 It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path trave… Jboss Enterprise Application Platform Mitigation only Fix from $1,6002018-07-27 MEDIUM 6.5 CVE-2017-2666 It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction w… Undertow Mitigation only Fix from $1,6002018-07-27 CRITICAL 9.8 CVE-2017-7470 It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorizati… Spacewalk Mitigation only Fix from $2,3002018-07-27 HIGH 7.5 CVE-2017-2639 It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communica… Cloudforms Mitigation only Fix from $1,9502018-07-27 MEDIUM 5.5 CVE-2017-2622 An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malic… Openstack Mitigation only Fix from $1,6002018-07-27 CRITICAL 9.8 CVE-2017-7464 It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use thi… Jboss Enterprise Application Platform Mitigation only Fix from $2,3002018-07-27 MEDIUM 6.5 CVE-2017-12171EPSS 8% A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines… Enterprise Linux Mitigation only Fix from $1,6002018-07-26 CRITICAL 9.0 CVE-2017-2589 It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored … Jboss Fuse Mitigation only Fix from $2,3002018-07-26 CRITICAL 10.0 CVE-2017-2637 A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed… Openstack Mitigation only Fix from $2,3002018-07-26 HIGH 8.2 CVE-2017-3224 Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNum… Package Manager No fix yet Fix from $1,9502018-07-24 HIGH 7.8 CVE-2018-10905 CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with access to an… Cloudforms Mitigation only Fix from $1,9502018-07-24 CRITICAL 9.8 CVE-2018-10870EPSS 6% redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any fil… Certification Mitigation only Fix from $2,3002018-07-19 HIGH 7.5 CVE-2018-10869 redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file access… Certification Mitigation only Fix from $1,9502018-07-19 MEDIUM 5.3 CVE-2017-15137 The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a… Openshift Mitigation only Fix from $1,6002018-07-16 HIGH 7.8 CVE-2018-10875 A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module pat… Ansible Engine Mitigation only Fix from $1,9502018-07-13 HIGH 7.8 CVE-2018-10874 In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's con… Ansible Engine Mitigation only Fix from $1,9502018-07-02 CRITICAL 9.8 CVE-2017-7465 It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw … Jboss Enterprise Application Platform Mitigation only Fix from $2,3002018-06-27 CRITICAL 9.8 CVE-2018-5183 Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and… Enterprise Linux Desktop Mitigation only Fix from $2,3002018-06-11 MEDIUM 6.5 CVE-2018-5185 Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird… Enterprise Linux Desktop Mitigation only Fix from $1,6002018-06-11 HIGH 7.5 CVE-2018-5157 Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow th… Enterprise Linux Desktop Mitigation only Fix from $1,9502018-06-11 HIGH 7.5 CVE-2018-5162 Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Th… Enterprise Linux Desktop Mitigation only Fix from $1,9502018-06-11 HIGH 8.8 CVE-2018-5146EPSS 12% An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.… Enterprise Linux Desktop Mitigation only Fix from $1,9502018-06-11 HIGH 7.8 CVE-2016-8656 Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local p… Jboss Enterprise Application Platform Mitigation only Fix from $1,9502018-05-22 HIGH 8.8 CVE-2018-1131 Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticat… Jboss Data Grid Mitigation only Fix from $1,9502018-05-15 MEDIUM 6.5 CVE-2016-8627 admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be available via … Jboss Enterprise Application Platform Mitigation only Fix from $1,6002018-05-11 CRITICAL 9.8 CVE-2018-10683 An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successful… Wildfly No fix yet Fix from $2,3002018-05-09 HIGH 8.8 CVE-2013-0185 Cross-site request forgery (CSRF) vulnerability in ManageIQ Enterprise Virtualization Manager (EVM) allows remote attackers to hijack the authenticat… Manageiq Enterprise Virtualization Manager No fix yet Fix from $1,9502018-05-01 HIGH 7.5 CVE-2013-2049 Red Hat CloudForms 2 Management Engine (CFME) allows remote attackers to conduct session tampering attacks by leveraging use of a static secret_token… Cloudforms Management Engine Mitigation only Fix from $1,9502018-05-01 MEDIUM 5.5 CVE-2018-10534 The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU B… Enterprise Linux Desktop Mitigation only Fix from $1,6002018-04-29