Vulnerability index

Browse CVEs

813 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.4 CVE-2014-7839 DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which … Resteasy Mitigation only Fix from $1,6002014-11-25 MEDIUM 6.4 CVE-2014-8769EPSS 6% tcpdump 3.8 through 4.6.2 might allow remote attackers to obtain sensitive information from memory or cause a denial of service (packet loss or segme… Tcpdump No fix yet Fix from $1,6002014-11-20 MEDIUM 5.0 CVE-2014-8767EPSS 5% Integer underflow in the olsr_print function in tcpdump 3.9.6 through 4.6.2, when in verbose mode, allows remote attackers to cause a denial of servi… Tcpdump No fix yet Fix from $1,6002014-11-20 MEDIUM 6.5 CVE-2014-0233 Red Hat OpenShift Enterprise 2.0 and 2.1 and OpenShift Origin allow remote authenticated users to execute arbitrary commands via shell metacharacters… Openshift No fix yet Fix from $1,6002014-11-16 MEDIUM 5.0 CVE-2014-7968 VDSM allows remote attackers to cause a denial of service (connection blocking) by keeping an SSL connection open. Virtual Desktop Service Manager Mitigation only Fix from $1,6002014-10-22 MEDIUM 5.5 CVE-2014-3521 The component in (1) /luci/homebase and (2) /luci/cluster menu in Red Hat Conga 0.12.2 allows remote authenticated users to bypass intended access re… Conga Mitigation only Fix from $1,6002014-10-06 MEDIUM 5.0 CVE-2013-6496 Red Hat Conga 0.12.2 allows remote attackers to obtain sensitive information via a crafted request to the (1) homebase, (2) cluster, (3) storage, (4)… Conga Mitigation only Fix from $1,6002014-10-06 MEDIUM 5.0 CVE-2014-3562 Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by se… Directory Server Mitigation only Fix from $1,6002014-08-21 MEDIUM 5.5 CVE-2014-3464 The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not proper… Jboss Enterprise Application Platform Mitigation only Fix from $1,6002014-08-19 HIGH 7.5 CVE-2014-3530 The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform … Jboss Enterprise Application Platform Mitigation only Fix from $1,9502014-07-22 MEDIUM 6.8 CVE-2014-3518 jmx-remoting.sar in JBoss Remoting, as used in Red Hat JBoss Enterprise Application Platform (JEAP) 5.2.0, Red Hat JBoss BRMS 5.3.1, Red Hat JBoss Po… Jboss Enterprise Application Platform Mitigation only Fix from $1,6002014-07-22 MEDIUM 5.0 CVE-2012-2682 Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, allows attackers with certain database privileges to cause a denial of ser… Enterprise Mrg Mitigation only Fix from $1,6002014-07-19 MEDIUM 6.8 CVE-2014-0248 org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Ente… Jboss Enterprise Application Platform Mitigation only Fix from $1,6002014-07-07 MEDIUM 5.0 CVE-2013-6470 The default configuration in the standalone controller quickstack manifest in openstack-foreman-installer, as used in Red Hat Enterprise Linux OpenSt… Openstack Mitigation only Fix from $1,6002014-06-02 MEDIUM 5.0 CVE-2013-6445 Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, uses the DES-based crypt function to hash passwords, which makes it easier… Enterprise Mrg Mitigation only Fix from $1,6002014-04-30 MEDIUM 6.5 CVE-2013-6469 JBoss Overlord Run Time Governance (RTGov) 1.0 for JBossAS allows remote authenticated users to execute arbitrary Java code via an MVFLEX Expression … Jboss Fuse Service Works Mitigation only Fix from $1,6002014-04-22 MEDIUM 6.4 CVE-2014-0071 PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass int… Openstack Mitigation only Fix from $1,6002014-04-17 MEDIUM 5.8 CVE-2013-6456 The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDetta… Libvirt Mitigation only Fix from $1,6002014-04-15 MEDIUM 6.5 CVE-2013-6468 JBoss Drools, Red Hat JBoss BRMS before 6.0.1, and Red Hat JBoss BPM Suite before 6.0.1 allows remote authenticated users to execute arbitrary Java c… Jboss Bpm Suite Mitigation only Fix from $1,6002014-04-10 MEDIUM 5.8 CVE-2014-0093 Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by… Jboss Enterprise Application Platform Mitigation only Fix from $1,6002014-04-03 HIGH 7.5 CVE-2014-0057 The x_button method in the ServiceController (vmdb/app/controllers/service_controller.rb) in Red Hat CloudForms 3.0 Management Engine 5.2 allows remo… Cloudforms Mitigation only Fix from $1,9502014-03-18 MEDIUM 6.8 CVE-2012-3406 The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the … Enterprise Virtualization Mitigation only Fix from $1,6002014-02-10 MEDIUM 5.0 CVE-2012-3405 The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer le… Enterprise Virtualization Mitigation only Fix from $1,6002014-02-10 HIGH 7.5 CVE-2013-1886 Format string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System … Certificate System Mitigation only Fix from $1,9502014-01-24 HIGH 7.2 CVE-2013-2151 Unquoted Windows search path vulnerability in Red Hat Enterprise Virtualization (RHEV) 3 and 3.2 allows local users to gain privileges via a crafted … Enterprise Virtualization Mitigation only Fix from $1,9502014-01-21 HIGH 7.2 CVE-2013-2152 Unquoted Windows search path vulnerability in the SPICE service, as used in Red Hat Enterprise Virtualization (RHEV) 3.2, allows local users to gain … Enterprise Virtualization Mitigation only Fix from $1,9502014-01-21 MEDIUM 5.1 CVE-2014-0418EPSS 6% Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown … Enterprise Linux Desktop Supplementary Mitigation only Fix from $1,6002014-01-15 MEDIUM 5.1 CVE-2013-5906EPSS 6% Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via… Enterprise Linux Desktop Supplementary Mitigation only Fix from $1,6002014-01-15 HIGH 9.3 CVE-2013-6439 Candlepin in Red Hat Subscription Asset Manager 1.0 through 1.3 uses a weak authentication scheme when the configuration file does not specify a sche… Subscription Asset Manager No fix yet Fix from $1,9502013-12-23 HIGH 7.5 CVE-2013-4461 SQL injection vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to execute arbitrary SQL comman… Enterprise Mrg Mitigation only Fix from $1,9502013-12-23