Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux MEDIUM 5.3
CVE-2023-7216

A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a…

No fix yet
Fix from $1,600 2024-02-05
Enterprise Linux MEDIUM 5.9
CVE-2023-5992

A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in th…

No fix yet
Fix from $1,600 2024-01-31
Enterprise Linux MEDIUM 5.9
CVE-2024-0914

A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw co…

Fix: 3.23.0+
Fix from $1,600 2024-01-31
Shim MEDIUM 5.5
CVE-2023-40546

A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it tries to print an err…

Fix: 15.8+
Fix from $1,600 2024-01-29
Shim MEDIUM 5.5
CVE-2023-40549

An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw allows an atta…

Fix: 15.8+
Fix from $1,600 2024-01-29
Shim MEDIUM 5.5
CVE-2023-40550

An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensitive data during the system's…

Fix: 15.8+
Fix from $1,600 2024-01-29
Shim MEDIUM 5.1
CVE-2023-40551

A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during t…

Fix: 15.8+
Fix from $1,600 2024-01-29
Shim HIGH 7.4
CVE-2023-40548

A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a user-controlled value parsed …

Fix: 15.8+
Fix from $1,950 2024-01-29
Keycloak HIGH 7.1
CVE-2023-6291

A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful …

Fix: 22.0.7+
Fix from $1,950 2024-01-26
Enterprise Linux HIGH 7.5
CVE-2023-52356

A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw a…

Patch available
Fix from $1,950 2024-01-25
Enterprise Linux HIGH 7.5
CVE-2023-52355

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw al…

Fix: 4.6.0+
Fix from $1,950 2024-01-25
Shim HIGH 8.3
CVE-2023-40547

A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This …

Fix: 15.8+
Fix from $1,950 2024-01-25
Enterprise Linux MEDIUM 6.8
CVE-2023-4001

An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains…

Mitigation only
Fix from $1,600 2024-01-15
Enterprise Linux MEDIUM 5.5
CVE-2024-23301

Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to syst…

Fix: after 2.7
Fix from $1,600 2024-01-12
Enterprise Linux MEDIUM 6.5
CVE-2023-6683

A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before…

Fix: 8.2.2+
Fix from $1,600 2024-01-12
Openshift Container Platform HIGH 7.5
CVE-2023-6476

A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get a…

Mitigation only
Fix from $1,950 2024-01-09
Red Hat Developer Hub MEDIUM 5.7
CVE-2023-6944

A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded …

Fix: 1.21.0+
Fix from $1,600 2024-01-04
Codeready Linux Builder For Eus MEDIUM 6.7
CVE-2024-0193

A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is r…

Patch available
Fix from $1,600 2024-01-02
Enterprise Linux MEDIUM 5.3
CVE-2023-6693

A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virtio_net_flush_tx function if g…

Fix: 8.2.1+
Fix from $1,600 2024-01-02
Jboss Enterprise Application Platform HIGH 7.5
CVE-2023-3171

A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources…

Mitigation only
Fix from $1,950 2023-12-27
Codeready Linux Builder MEDIUM 5.5
CVE-2023-4641

A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, …

Mitigation only
Fix from $1,600 2023-12-27
Single Sign On HIGH 8.1
CVE-2023-2585

Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validatio…

Mitigation only
Fix from $1,950 2023-12-21
Keycloak MEDIUM 6.1
CVE-2023-6927

A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM respo…

Mitigation only
Fix from $1,600 2023-12-18
Data Grid MEDIUM 6.5
CVE-2023-5236

A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permis…

Fix: 8.4.4+
Fix from $1,600 2023-12-18
Ansible Automation Platform MEDIUM 6.3
CVE-2023-5115

An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make …

Mitigation only
Fix from $1,600 2023-12-18
Satellite HIGH 7.5
CVE-2023-4320

An arithmetic overflow flaw was found in Satellite when creating a new personal access token. This flaw allows an attacker who uses this arithmetic o…

Fix: 6.13+
Fix from $1,950 2023-12-18
Jboss Data Grid MEDIUM 6.5
CVE-2023-3628

A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation. This issue could allow an aut…

Fix: 8.4.4+
Fix from $1,600 2023-12-18
Data Grid MEDIUM 6.5
CVE-2023-3629

A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This iss…

Fix: 8.4.4+
Fix from $1,600 2023-12-18
Single Sign On MEDIUM 5.4
CVE-2023-6134

A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could al…

Fix: 7.6 / 22.0.7+
Fix from $1,600 2023-12-14
Keycloak HIGH 7.7
CVE-2023-6563

An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline toke…

Fix: 21.0.0+
Fix from $1,950 2023-12-14