Vulnerability index

Browse CVEs

817 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2024-6237 A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific ex… Directory Server Mitigation only Fix from $1,6002024-07-09 MEDIUM 6.8 CVE-2024-6505 A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within R… Enterprise Linux Mitigation only Fix from $1,6002024-07-05 HIGH 8.1 CVE-2024-3183 A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new… Enterprise Linux Mitigation only Fix from $1,9502024-06-12 MEDIUM 6.2 CVE-2024-3716 A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the proce… Satellite Mitigation only Fix from $1,6002024-06-05 HIGH 8.8 CVE-2024-3622 A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text format in one of the configurati… Mirror Registry Mitigation only Fix from $1,9502024-04-25 MEDIUM 6.5 CVE-2024-3623 A flaw was found when using mirror-registry to install Quay. It uses a default database secret key, which is stored in plain-text format in one of th… Mirror Registry Mitigation only Fix from $1,6002024-04-25 MEDIUM 5.5 CVE-2023-6725 An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were impr… Openstack Platform Mitigation only Fix from $1,6002024-03-15 MEDIUM 6.5 CVE-2024-1725 A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated atta… Openshift Container Platform Mitigation only Fix from $1,6002024-03-07 MEDIUM 5.3 CVE-2024-1722 A flaw was found in Keycloak. In certain conditions, this issue may allow a remote unauthenticated attacker to block other accounts from logging in. Keycloak Mitigation only Fix from $1,6002024-02-29 MEDIUM 5.3 CVE-2024-1459 A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP reques… Undertow Mitigation only Fix from $1,6002024-02-12 HIGH 7.5 CVE-2023-6356 A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages whe… Codeready Linux Builder Eus Mitigation only Fix from $1,9502024-02-07 HIGH 7.5 CVE-2023-4503 An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created … Jboss Enterprise Application Platform Mitigation only Fix from $1,9502024-02-06 HIGH 7.5 CVE-2023-50781 A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which ma… Enterprise Linux Mitigation only Fix from $1,9502024-02-05 MEDIUM 5.3 CVE-2023-7216 A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a… Enterprise Linux No fix yet Fix from $1,6002024-02-05 MEDIUM 5.9 CVE-2023-5992 A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in th… Enterprise Linux No fix yet Fix from $1,6002024-01-31 MEDIUM 6.8 CVE-2023-4001 An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains… Enterprise Linux Mitigation only Fix from $1,6002024-01-15 HIGH 7.5 CVE-2023-6476 A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get a… Openshift Container Platform Mitigation only Fix from $1,9502024-01-09 HIGH 7.5 CVE-2023-3171 A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources… Jboss Enterprise Application Platform Mitigation only Fix from $1,9502023-12-27 MEDIUM 5.5 CVE-2023-4641 A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, … Codeready Linux Builder Mitigation only Fix from $1,6002023-12-27 HIGH 8.1 CVE-2023-2585 Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validatio… Single Sign On Mitigation only Fix from $1,9502023-12-21 MEDIUM 6.1 CVE-2023-6927 A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM respo… Keycloak Mitigation only Fix from $1,6002023-12-18 MEDIUM 6.3 CVE-2023-5115 An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make … Ansible Automation Platform Mitigation only Fix from $1,6002023-12-18 HIGH 7.5 CVE-2023-5379 A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error… Jboss Enterprise Application Platform Mitigation only Fix from $1,9502023-12-12 MEDIUM 5.4 CVE-2023-6710 A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the… Enterprise Linux Mitigation only Fix from $1,6002023-12-12 MEDIUM 5.3 CVE-2023-6393 A flaw was found in the Quarkus Cache Runtime. When request processing utilizes a Uni cached using @CacheResult and the cached Uni reuses the initial… Build Of Quarkus Mitigation only Fix from $1,6002023-12-06 MEDIUM 6.5 CVE-2023-5189 A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy … Ansible Automation Platform No fix yet Fix from $1,6002023-11-14 MEDIUM 5.5 CVE-2023-4910 A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the browser, the tokens… 3scale Api Management Mitigation only Fix from $1,6002023-11-06 HIGH 7.5 CVE-2023-46847EPSS 88% Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to he… Enterprise Linux Mitigation only Fix from $1,9502023-11-03 HIGH 7.5 CVE-2022-3248 A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the bo… Advanced Cluster Management For Kubernetes Mitigation only Fix from $1,9502023-10-05 MEDIUM 5.3 CVE-2022-4145 A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, e… Openshift Container Platform Mitigation only Fix from $1,6002023-10-05