Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux HIGH 8.1
CVE-2024-3183

A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new…

Mitigation only
Fix from $1,950 2024-06-12
Enterprise Linux MEDIUM 5.9
CVE-2024-3049

A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC t…

Fix: 1.1+
Fix from $1,600 2024-06-06
Openshift Container Platform HIGH 7.5
CVE-2024-5037

A flaw was found in OpenShift's Telemeter. If certain conditions are in place, an attacker can use a forged token to bypass the issue ("iss") check d…

Patch available
Fix from $1,950 2024-06-05
Satellite MEDIUM 6.2
CVE-2024-3716

A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the proce…

Mitigation only
Fix from $1,600 2024-06-05
Mirror Registry HIGH 8.8
CVE-2024-3622

A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text format in one of the configurati…

Mitigation only
Fix from $1,950 2024-04-25
Mirror Registry MEDIUM 6.5
CVE-2024-3623

A flaw was found when using mirror-registry to install Quay. It uses a default database secret key, which is stored in plain-text format in one of th…

Mitigation only
Fix from $1,600 2024-04-25
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2024-1102

A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for…

Fix: 2.2.1+
Fix from $1,600 2024-04-25
Build Of Keycloak HIGH 8.8
CVE-2023-6787

A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijack…

Fix: 22.0.10 / 24.0.3+
Fix from $1,950 2024-04-25
Codeready Linux Builder HIGH 7.1
CVE-2023-3758

A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authoriza…

Patch available
Fix from $1,950 2024-04-18
Build Of Keycloak HIGH 8.1
CVE-2024-1132

A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a mali…

Fix: 22.0.10 / 24.0.3+
Fix from $1,950 2024-04-17
Enterprise Linux MEDIUM 5.5
CVE-2024-3567

A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c when trying to calculate the…

Fix: 8.2.3+
Fix from $1,600 2024-04-10
Advanced Cluster Security HIGH 7.8
CVE-2024-0406

A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may a…

Fix: 4.0.0 / 4.18.4+
Fix from $1,950 2024-04-06
Libvirt MEDIUM 5.5
CVE-2024-2496

A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host inter…

Fix: 9.8.0+
Fix from $1,600 2024-03-18
Enterprise Linux HIGH 7.5
CVE-2024-2002

A double-free vulnerability was found in libdwarf. In a multiply-corrupted DWARF object, libdwarf may try to dealloc(free) an allocation twice, poten…

Fix: 0.9.2+
Fix from $1,950 2024-03-18
Enterprise Linux MEDIUM 5.3
CVE-2023-7250

A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less tha…

Fix: 3.15+
Fix from $1,600 2024-03-18
Openstack Platform MEDIUM 5.5
CVE-2023-6725

An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were impr…

Mitigation only
Fix from $1,600 2024-03-15
Openshift Container Platform MEDIUM 6.5
CVE-2024-1725

A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated atta…

Mitigation only
Fix from $1,600 2024-03-07
Keycloak MEDIUM 5.3
CVE-2024-1722

A flaw was found in Keycloak. In certain conditions, this issue may allow a remote unauthenticated attacker to block other accounts from logging in.

Mitigation only
Fix from $1,600 2024-02-29
Enterprise Linux MEDIUM 6.7
CVE-2023-6917

A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services …

Fix: 6.2.0+
Fix from $1,600 2024-02-28
Codeready Linux Builder HIGH 7.3
CVE-2024-1488

A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runti…

Patch available
Fix from $1,950 2024-02-15
Enterprise Linux HIGH 7.5
CVE-2023-50387EPSS 100%

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU…

Patch available
Fix from $1,950 2024-02-14
Enterprise Linux HIGH 7.5
CVE-2023-50868EPSS 82%

The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of se…

Fix: 4.8.5 / 4.9.3+
Fix from $1,950 2024-02-14
Openshift CRITICAL 9.3
CVE-2024-1485

A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user i…

Fix: 0.0.0-20240206+
Fix from $2,300 2024-02-14
Undertow MEDIUM 5.3
CVE-2024-1459

A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP reques…

Mitigation only
Fix from $1,600 2024-02-12
389 Directory Server MEDIUM 5.5
CVE-2024-1062

A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.

Fix: 2.2.0+
Fix from $1,600 2024-02-12
Codeready Linux Builder Eus HIGH 7.5
CVE-2023-6356

A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages whe…

Mitigation only
Fix from $1,950 2024-02-07
Ansible MEDIUM 5.5
CVE-2024-0690

An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information …

Fix: 2.14.4 / 2.15.9+
Fix from $1,600 2024-02-06
Jboss Enterprise Application Platform HIGH 7.5
CVE-2023-4503

An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created …

Mitigation only
Fix from $1,950 2024-02-06
Ansible Automation Platform HIGH 7.5
CVE-2023-50782

A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA …

Fix: 42.0.0+
Fix from $1,950 2024-02-05
Enterprise Linux HIGH 7.5
CVE-2023-50781

A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which ma…

Mitigation only
Fix from $1,950 2024-02-05