Vulnerability index

Browse CVEs

813 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2016-5401 Cross-site request forgery (CSRF) vulnerability in Red Hat JBoss BRMS and BPMS 6 allows remote attackers to hijack the authentication of users for re… Jboss Bpm Suite Mitigation only Fix from $1,9502017-04-20 MEDIUM 6.1 CVE-2016-6347 Cross-site scripting (XSS) vulnerability in the default exception handler in RESTEasy allows remote attackers to inject arbitrary web script or HTML … Resteasy Mitigation only Fix from $1,6002017-04-20 HIGH 7.5 CVE-2016-5409 Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which makes it easier for remote atta… Openshift Mitigation only Fix from $1,9502017-04-20 MEDIUM 6.8 CVE-2016-6338 ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate atta… Enterprise Virtualization No fix yet Fix from $1,6002017-04-20 MEDIUM 6.1 CVE-2016-2104 Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the … Satellite Mitigation only Fix from $1,6002017-04-13 MEDIUM 6.1 CVE-2016-6348 JacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack. Resteasy Mitigation only Fix from $1,6002017-04-12 HIGH 7.5 CVE-2016-4459 Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9. Mod Cluster Mitigation only Fix from $1,9502017-04-12 HIGH 8.8 CVE-2016-3616 The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitra… Enterprise Linux Mitigation only Fix from $1,9502017-02-13 HIGH 7.8 CVE-2016-2568 pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters t… Enterprise Linux Mitigation only Fix from $1,9502017-02-13 CRITICAL 9.8 CVE-2014-8241 XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return … Enterprise Linux Desktop Mitigation only Fix from $2,3002016-12-14 HIGH 8.8 CVE-2016-7065EPSS 12% The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and pos… Jboss Enterprise Application Platform No fix yet Fix from $1,9502016-10-13 HIGH 8.8 CVE-2016-7040 Red Hat CloudForms Management Engine 4.1 does not properly handle regular expressions passed to the expression engine via the JSON API and the web-ba… Cloudforms Management Engine Mitigation only Fix from $1,9502016-10-07 MEDIUM 5.9 CVE-2016-7046 Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause … Jboss Enterprise Application Platform Mitigation only Fix from $1,6002016-10-03 CRITICAL 9.8 CVE-2016-6330EPSS 11% The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote a… Jboss Operations Network Mitigation only Fix from $2,3002016-09-27 HIGH 7.5 CVE-2016-3110 mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP mes… Jboss Enterprise Application Platform Mitigation only Fix from $1,9502016-09-26 HIGH 8.4 CVE-2016-6340 The kickstart file in Red Hat QuickStart Cloud Installer (QCI) forces use of MD5 passwords on deployed systems, which makes it easier for attackers t… Quickstart Cloud Installer Mitigation only Fix from $1,9502016-09-22 HIGH 8.4 CVE-2016-6322 Red Hat QuickStart Cloud Installer (QCI) uses world-readable permissions for /etc/qci/answers, which allows local users to obtain the root password f… Quickstart Cloud Installer Mitigation only Fix from $1,9502016-09-22 HIGH 8.8 CVE-2016-7034 The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session and includes them in query s… Jboss Bpm Suite Mitigation only Fix from $1,9502016-09-07 MEDIUM 6.1 CVE-2016-7033 Multiple cross-site scripting (XSS) vulnerabilities in the admin pages in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 allow remote attackers to inje… Jboss Bpm Suite Mitigation only Fix from $1,6002016-09-07 HIGH 7.5 CVE-2016-6346EPSS 6% RESTEasy enables GZIPInterceptor, which allows remote attackers to cause a denial of service via unspecified vectors. Resteasy Mitigation only Fix from $1,9502016-09-07 MEDIUM 6.5 CVE-2016-6345 RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs. Resteasy Mitigation only Fix from $1,6002016-09-07 MEDIUM 5.3 CVE-2016-6344 Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attacke… Jboss Bpm Suite Mitigation only Fix from $1,6002016-09-07 HIGH 8.8 CVE-2016-5383 The web UI in Red Hat CloudForms 4.1 allows remote authenticated users to execute arbitrary code via vectors involving "Lack of field filters." Cloudforms Mitigation only Fix from $1,9502016-08-26 MEDIUM 6.5 CVE-2016-5392 The API server in Kubernetes, as used in Red Hat OpenShift Enterprise 3.2, in a multi tenant environment allows remote authenticated users with knowl… Openshift Mitigation only Fix from $1,6002016-08-05 MEDIUM 6.1 CVE-2016-3097 Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML vi… Satellite Mitigation only Fix from $1,6002016-08-05 MEDIUM 6.1 CVE-2016-3080 Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML vi… Satellite Mitigation only Fix from $1,6002016-08-05 HIGH 8.8 CVE-2016-4474 The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterprise Linux OpenStack Platform… Openstack Mitigation only Fix from $1,9502016-06-30 CRITICAL 9.8 CVE-2016-4448EPSS 7% Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors. Enterprise Linux Desktop Mitigation only Fix from $2,3002016-06-09 HIGH 7.1 CVE-2016-2150 SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to… Enterprise Linux Mitigation only Fix from $1,9502016-06-09 HIGH 8.8 CVE-2016-3738 Red Hat OpenShift Enterprise 3.2 does not properly restrict access to STI builds, which allows remote authenticated users to access the Docker socket… Openshift Mitigation only Fix from $1,9502016-06-08