Vulnerability index

Browse CVEs

813 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2012-4681 KEVEPSS 99% Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute a… Enterprise Linux Desktop Mitigation only Fix from $2,3002012-08-28 MEDIUM 5.6 CVE-2012-3440 A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary files via a symlink attack on … Enterprise Linux No fix yet Fix from $1,6002012-08-08 MEDIUM 5.0 CVE-2012-1145 spacewalk-backend in Red Hat Network Satellite 5.4 on Red Hat Enterprise Linux 6 does not properly authorize or authenticate uploads to the NULL orga… Satellite Mitigation only Fix from $1,6002012-06-16 HIGH 7.5 CVE-2011-4608 mod_cluster in JBoss Enterprise Application Platform 5.1.2 for Red Hat Linux allows worker nodes to register with arbitrary virtual hosts, which allo… Jboss Enterprise Application Platform Mitigation only Fix from $1,9502012-01-27 MEDIUM 6.4 CVE-2009-0788 Red Hat Network (RHN) Satellite Server 5.3 and 5.4 does not properly rewrite unspecified URLs, which allows remote attackers to (1) obtain unspecifie… Network Satellite Server No fix yet Fix from $1,6002011-04-18 MEDIUM 5.5 CVE-2010-1171 Red Hat Network (RHN) Satellite 5.3 and 5.4 exposes a dangerous, obsolete XML-RPC API, which allows remote authenticated users to access arbitrary fi… Satellite Mitigation only Fix from $1,6002011-04-18 MEDIUM 5.8 CVE-2011-0717 Session fixation vulnerability in Red Hat Network (RHN) Satellite Server 5.4 allows remote attackers to hijack web sessions via unspecified vectors r… Network Satellite Server Mitigation only Fix from $1,6002011-02-25 MEDIUM 5.8 CVE-2011-0718 Red Hat Network (RHN) Satellite Server 5.4 does not use a time delay after a failed login attempt, which makes it easier for remote attackers to cond… Network Satellite Server Mitigation only Fix from $1,6002011-02-25 HIGH 7.5 CVE-2011-0019 slapd (aka ns-slapd) in 389 Directory Server 1.2.7.5 (aka Red Hat Directory Server 8.2.x or dirsrv) does not properly handle simple paged result sear… Directory Server Mitigation only Fix from $1,9502011-02-23 MEDIUM 6.2 CVE-2011-0532 The (1) backup and restore scripts, (2) main initialization script, and (3) ldap-agent script in 389 Directory Server 1.2.x (aka Red Hat Directory Se… Directory Server Mitigation only Fix from $1,6002011-02-23 HIGH 7.5 CVE-2011-0720 Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain administra… Conga Mitigation only Fix from $1,9502011-02-03 HIGH 7.5 CVE-2010-3708 The serialization implementation in JBoss Drools in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 and … Jboss Enterprise Application Platform Mitigation only Fix from $1,9502010-12-30 HIGH 7.5 CVE-2010-4179 The installation documentation for Red Hat Enterprise Messaging, Realtime and Grid (MRG) 1.3 recommends that Condor should be configured so that the … Enterprise Mrg Mitigation only Fix from $1,9502010-12-07 HIGH 8.8 CVE-2010-1871 KEVEPSS 83% JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Exp… Jboss Enterprise Application Platform Mitigation only Fix from $1,9502010-08-05 HIGH 7.5 CVE-2010-1428 KEVEPSS 62% The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 … Jboss Enterprise Application Platform Mitigation only Fix from $1,9502010-04-28 MEDIUM 5.3 CVE-2010-0738 KEVEPSS 79% The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 be… Jboss Enterprise Application Platform Mitigation only Fix from $1,6002010-04-28 MEDIUM 6.5 CVE-2009-4133 Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and Grid Execute Node for MRG, allows remote authenticated users to queue… Enterprise Mrg Mitigation only Fix from $1,6002009-12-23 MEDIUM 6.9 CVE-2009-1893 The configtest function in the Red Hat dhcpd init script for DHCP 3.0.1 in Red Hat Enterprise Linux (RHEL) 3 allows local users to overwrite arbitrar… Enterprise Linux Mitigation only Fix from $1,6002009-07-17 MEDIUM 6.9 CVE-2008-6552 Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified com… Cluster Project Mitigation only Fix from $1,6002009-03-30 MEDIUM 6.0 CVE-2008-5082 The verifyProof function in the Token Processing System (TPS) component in Red Hat Certificate System (RHCS) 7.1 through 7.3 and Dogtag Certificate S… Dogtag Certificate System Mitigation only Fix from $1,6002009-01-30 MEDIUM 6.8 CVE-2008-4315 tog-pegasus in OpenGroup Pegasus 2.7.0 on Red Hat Enterprise Linux (RHEL) 5, Fedora 9, and Fedora 10 does not log failed authentication attempts to t… Enterprise Linux Mitigation only Fix from $1,6002008-11-27 HIGH 10.0 CVE-2008-3522 Buffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c in JasPer 1.900.1 might allow context-dependent attackers to have an… Enterprise Virtualization No fix yet Fix from $1,9502008-10-02 MEDIUM 6.9 CVE-2008-4192 The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack… Cman Mitigation only Fix from $1,6002008-09-29 HIGH 7.5 CVE-2008-2932 Heap-based buffer overflow in Red Hat adminutil 1.1.6 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitra… Adminutil Mitigation only Fix from $1,9502008-09-12 HIGH 7.5 CVE-2008-1376 A certain Red Hat build script for nfs-utils before 1.0.9-35z.el5_2 on Red Hat Enterprise Linux (RHEL) 5 omits TCP wrappers support, which might allo… Nfs Utils Mitigation only Fix from $1,9502008-08-01 HIGH 7.1 CVE-2008-2375 Memory leak in a certain Red Hat deployment of vsftpd before 2.0.5 on Red Hat Enterprise Linux (RHEL) 3 and 4, when PAM is used, allows remote attack… Vsftpd No fix yet Fix from $1,9502008-07-09 HIGH 7.2 CVE-2008-2359 The default configuration of consolehelper in system-config-network before 1.5.10-1 on Fedora 8 lacks the USER=root directive, which allows local use… Fedora 8 Mitigation only Fix from $1,9502008-06-02 HIGH 7.5 CVE-2008-1767EPSS 13% Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent attackers to cause a denial of service (crash) and possibly execute ar… Desktop No fix yet Fix from $1,9502008-05-23 HIGH 7.5 CVE-2008-1677 Buffer overflow in the regular expression handler in Red Hat Directory Server 8.0 and 7.1 before SP6 allows remote attackers to cause a denial of ser… Directory Server Mitigation only Fix from $1,9502008-05-12 HIGH 7.1 CVE-2007-6282 The IPsec implementation in Linux kernel before 2.6.25 allows remote routers to cause a denial of service (crash) via a fragmented ESP packet in whic… Enterprise Linux No fix yet Fix from $1,9502008-05-08