Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux HIGH 7.8
CVE-2023-5367

A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data s…

Patch available
Fix from $1,950 2023-10-25
Enterprise Linux HIGH 7.0
CVE-2023-5574

A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setu…

Patch available
Fix from $1,950 2023-10-25
Enterprise Linux HIGH 7.8
CVE-2023-4692

An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesys…

Fix: 2.12+
Fix from $1,950 2023-10-25
Enterprise Linux HIGH 7.7
CVE-2023-5557

A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if th…

Fix: 3.3.2 / 3.4.5+
Fix from $1,950 2023-10-13
Enterprise Linux MEDIUM 5.5
CVE-2023-43789

A vulnerability was found in libXpm where a vulnerability exists due to a boundary condition, a local user can trigger an out-of-bounds read error an…

Fix: 3.5.17+
Fix from $1,600 2023-10-12
Enterprise Linux HIGH 7.8
CVE-2023-43787

A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an intege…

Fix: 1.8.7+
Fix from $1,950 2023-10-10
Enterprise Linux MEDIUM 5.5
CVE-2023-43786

A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to consume all available…

Fix: 1.8.7+
Fix from $1,600 2023-10-10
Enterprise Linux MEDIUM 5.5
CVE-2023-43785

A vulnerability was found in libX11 due to a boundary condition within the _XkbReadKeySyms() function. This flaw allows a local user to trigger an ou…

Fix: 1.8.7+
Fix from $1,600 2023-10-10
Openshift Container Platform MEDIUM 5.5
CVE-2023-5366

A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may …

Fix: 2023-02-28+
Fix from $1,600 2023-10-06
Advanced Cluster Management For Kubernetes HIGH 7.5
CVE-2022-3248

A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the bo…

Mitigation only
Fix from $1,950 2023-10-05
Openshift Container Platform MEDIUM 5.3
CVE-2022-4145

A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, e…

Mitigation only
Fix from $1,600 2023-10-05
Ansible Automation Platform HIGH 7.8
CVE-2023-4237

A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the stand…

Mitigation only
Fix from $1,950 2023-10-04
Ansible Automation Platform MEDIUM 6.3
CVE-2023-4380

A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. T…

Mitigation only
Fix from $1,600 2023-10-04
Ansible Automation Controller MEDIUM 5.4
CVE-2023-3971

An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a cust…

Fix: 4.3.11+
Fix from $1,600 2023-10-04
Satellite HIGH 8.1
CVE-2023-1832

An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of…

Fix: 4.3.7-3+
Fix from $1,950 2023-10-04
Openshift Data Science HIGH 7.5
CVE-2023-3361

A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads…

Fix: 1.28.1+
Fix from $1,950 2023-10-04
Enterprise Linux MEDIUM 5.9
CVE-2022-4132

A flaw was found in JSS. A memory leak in JSS requires non-standard configuration but is a low-effort DoS vector if configured that way (repeatedly h…

Fix: 5.5.0+
Fix from $1,600 2023-10-04
Openshift Container Platform MEDIUM 5.3
CVE-2023-3153

A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could allow an attacker to cause a de…

Fix: 22.03.3 / 22.09.2+
Fix from $1,600 2023-10-04
Data Grid HIGH 7.4
CVE-2023-4586

A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS,…

Mitigation only
Fix from $1,950 2023-10-04
Keycloak HIGH 7.1
CVE-2023-2422

A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the clien…

Mitigation only
Fix from $1,950 2023-10-04
Enterprise Linux HIGH 7.5
CVE-2023-44488

VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.

Fix: 1.13.1+
Fix from $1,950 2023-09-30
Libnbd MEDIUM 6.5
CVE-2023-5215

A flaw was found in libnbd. A server can reply with a block size larger than 2^63 (the NBD spec states the size is a 64-bit unsigned value). This iss…

Fix: 1.18.0+
Fix from $1,600 2023-09-28
Jboss A Mq MEDIUM 5.5
CVE-2023-4066

A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecur…

Mitigation only
Fix from $1,600 2023-09-27
Jboss A Mq MEDIUM 5.5
CVE-2023-4065

A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Opera…

Mitigation only
Fix from $1,600 2023-09-27
Undertow HIGH 7.5
CVE-2023-3223

A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow u…

Fix: 2.2.24+
Fix from $1,950 2023-09-27
Apicast HIGH 7.5
CVE-2023-0456

A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token from a separate realm. This coul…

Fix: 2.12.2 / 2.13.2+
Fix from $1,950 2023-09-27
A Mq Streams MEDIUM 5.5
CVE-2023-0833

A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception trigger…

Fix: 2.2.1 / 2.4.0+
Fix from $1,600 2023-09-27
Integration Camel K HIGH 7.5
CVE-2022-4244

A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outsid…

Fix: 1.10.1 / 3.0.24+
Fix from $1,950 2023-09-25
Keycloak MEDIUM 6.1
CVE-2022-4137

A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte handling. This issue allows a m…

Mitigation only
Fix from $1,600 2023-09-25
Enterprise Linux HIGH 7.1
CVE-2023-4156

A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive informa…

Fix: 5.1.1+
Fix from $1,950 2023-09-25