Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux Eus HIGH 7.5
CVE-2023-6478

A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow wh…

Fix: 21.1.10 / 23.2.3+
Fix from $1,950 2023-12-13
Enterprise Linux Eus HIGH 7.8
CVE-2023-6377

A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory…

Fix: 21.1.10 / 23.2.3+
Fix from $1,950 2023-12-13
Ansible HIGH 7.8
CVE-2023-5764

A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from templa…

Fix: 2.14.12 / 2.15.7+
Fix from $1,950 2023-12-12
Jboss Enterprise Application Platform HIGH 7.5
CVE-2023-5379

A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error…

Mitigation only
Fix from $1,950 2023-12-12
Enterprise Linux MEDIUM 5.4
CVE-2023-6710

A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the…

Mitigation only
Fix from $1,600 2023-12-12
Advanced Cluster Security MEDIUM 6.1
CVE-2023-4958

In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this…

Patch available
Fix from $1,600 2023-12-12
Build Of Quarkus CRITICAL 9.1
CVE-2023-6394

A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operati…

Fix: 3.6.0+
Fix from $2,300 2023-12-09
Build Of Quarkus MEDIUM 5.3
CVE-2023-6393

A flaw was found in the Quarkus Cache Runtime. When request processing utilizes a Uni cached using @CacheResult and the cached Uni reuses the initial…

Mitigation only
Fix from $1,600 2023-12-06
Libnbd MEDIUM 5.3
CVE-2023-5871

A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network. …

Fix: 1.18.2+
Fix from $1,600 2023-11-27
Ansible Automation Platform MEDIUM 6.5
CVE-2023-5189

A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy …

No fix yet
Fix from $1,600 2023-11-14
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2023-4061

A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from…

Fix: 15.0.30+
Fix from $1,600 2023-11-08
Enterprise Linux MEDIUM 6.6
CVE-2023-40660

A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographi…

Fix: after 0.23.0
Fix from $1,600 2023-11-06
Enterprise Linux MEDIUM 6.4
CVE-2023-40661

Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user …

Fix: after 0.23.0
Fix from $1,600 2023-11-06
3scale Api Management MEDIUM 5.5
CVE-2023-4910

A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the browser, the tokens…

Mitigation only
Fix from $1,600 2023-11-06
Storage MEDIUM 6.5
CVE-2023-42669

A vulnerability was found in Samba's "rpcecho" development server, a non-Windows RPC server used to test Samba's DCE/RPC stack elements. This vulnera…

Fix: 4.17.12 / 4.18.8+
Fix from $1,600 2023-11-06
Enterprise Linux HIGH 7.0
CVE-2023-5088

A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead (potentially overw…

Fix: 8.2.0+
Fix from $1,950 2023-11-03
Storage CRITICAL 9.8
CVE-2023-3961

A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory…

Fix: 4.17.12 / 4.18.8+
Fix from $2,300 2023-11-03
Enterprise Linux HIGH 7.5
CVE-2023-46847EPSS 88%

Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to he…

Mitigation only
Fix from $1,950 2023-11-03
Enterprise Linux HIGH 7.5
CVE-2023-46848EPSS 10%

Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ft…

Fix: 6.4+
Fix from $1,950 2023-11-03
Enterprise Linux HIGH 7.5
CVE-2023-5824EPSS 5%

A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HT…

Fix: 6.4+
Fix from $1,950 2023-11-03
Enterprise Linux MEDIUM 5.3
CVE-2023-46846EPSS 6%

SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling pas…

Fix: 6.4+
Fix from $1,600 2023-11-03
Enterprise Linux MEDIUM 5.5
CVE-2023-38473

A vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name() function.

Fix: 0.9+
Fix from $1,600 2023-11-02
Enterprise Linux MEDIUM 5.5
CVE-2023-38469

A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record.

Fix: 0.9+
Fix from $1,600 2023-11-02
Enterprise Linux MEDIUM 5.5
CVE-2023-38470

A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function.

Fix: 0.9+
Fix from $1,600 2023-11-02
Enterprise Linux MEDIUM 5.5
CVE-2023-38471

A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function.

Fix: 0.9+
Fix from $1,600 2023-11-02
Enterprise Linux MEDIUM 5.5
CVE-2023-38472

A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function.

Fix: 0.9+
Fix from $1,600 2023-11-02
Enterprise Linux MEDIUM 5.5
CVE-2023-3164

A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/tiffcrop.c:7801. This flaw all…

Fix: 4.6.0+
Fix from $1,600 2023-11-02
Openshift Container Platform HIGH 7.2
CVE-2023-5408

A privilege escalation flaw was found in the node restriction admission plugin of the kubernetes api server of OpenShift. A remote attacker who modif…

Patch available
Fix from $1,950 2023-11-02
Insights Client HIGH 7.8
CVE-2023-3972

A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files an…

Fix: 3.2.2+
Fix from $1,950 2023-11-01
Openshift Container Platform For Arm64 HIGH 7.5
CVE-2023-5625

A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2…

Patch available
Fix from $1,950 2023-11-01