Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Keycloak MEDIUM 5.0
CVE-2023-0264

A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could ob…

Fix: 7.6.2 / 18.0.6+
Fix from $1,600 2023-08-04
Enterprise Linux MEDIUM 5.5
CVE-2023-38559

A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a den…

Fix: 10.02.0+
Fix from $1,600 2023-08-01
Openstack Platform MEDIUM 6.5
CVE-2023-3637

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security gr…

Mitigation only
Fix from $1,600 2023-07-25
Libvirt MEDIUM 5.3
CVE-2023-3750

A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and de…

Mitigation only
Fix from $1,600 2023-07-24
Enterprise Linux HIGH 7.5
CVE-2023-38200

A flaw was found in Keylime. Due to their blocking nature, the Keylime registrar is subject to a remote denial of service against its SSL connections…

Patch available
Fix from $1,950 2023-07-24
Enterprise Linux MEDIUM 6.5
CVE-2023-3019

A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code in QEMU. This issue could allow a privileged gues…

Fix: 8.2.0+
Fix from $1,600 2023-07-24
Quay MEDIUM 5.4
CVE-2023-3384

A flaw was found in the Quay registry. While the image labels created through Quay undergo validation both in the UI and backend by applying a regex …

Mitigation only
Fix from $1,600 2023-07-24
Enterprise Linux MEDIUM 5.9
CVE-2022-2127

An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentica…

Fix: 4.16.10 / 4.17.9+
Fix from $1,600 2023-07-20
Storage MEDIUM 5.9
CVE-2023-3347

A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = …

Fix: 4.17.10 / 4.18.5+
Fix from $1,600 2023-07-20
Shim HIGH 7.8
CVE-2022-28737

There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into acc…

Fix: 15.6+
Fix from $1,950 2023-07-20
Openstack Platform HIGH 7.5
CVE-2023-3354

A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections cro…

Fix: 8.1.0+
Fix from $1,950 2023-07-11
Keycloak MEDIUM 6.1
CVE-2022-4361

Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The v…

Fix: 7.6.4 / 21.1.2+
Fix from $1,600 2023-07-07
Openshift Container Platform HIGH 7.5
CVE-2023-3089

A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the crypt…

Mitigation only
Fix from $1,950 2023-07-05
Build Of Quarkus HIGH 8.1
CVE-2023-2974

A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enfor…

Fix: 2.13.8+
Fix from $1,950 2023-07-04
Enterprise Linux HIGH 7.5
CVE-2023-3138

A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided …

Fix: 1.8.6+
Fix from $1,950 2023-06-28
Enterprise Linux HIGH 7.8
CVE-2023-2603

A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is cl…

Fix: 2.69+
Fix from $1,950 2023-06-06
Openshift Api For Data Protection MEDIUM 6.5
CVE-2023-2253

A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records retu…

Mitigation only
Fix from $1,600 2023-06-06
Advanced Cluster Management For Kubernetes HIGH 7.8
CVE-2023-3027

The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained value…

Mitigation only
Fix from $1,950 2023-06-05
Enterprise Linux HIGH 7.1
CVE-2023-2977

A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can …

Patch available
Fix from $1,950 2023-06-01
Enterprise Linux HIGH 7.5
CVE-2023-2953

A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.

Fix: 11.7.9 / 12.6.8+
Fix from $1,950 2023-05-30
Build Of Quarkus MEDIUM 6.5
CVE-2023-1664

A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is…

Mitigation only
Fix from $1,600 2023-05-26
Enterprise Linux High Availability CRITICAL 9.8
CVE-2023-2319

It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix…

Mitigation only
Fix from $2,300 2023-05-17
Enterprise Linux HIGH 7.5
CVE-2023-2295

A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptabl…

Mitigation only
Fix from $1,950 2023-05-17
Enterprise Linux HIGH 8.8
CVE-2023-2203

A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers …

Mitigation only
Fix from $1,950 2023-05-17
Enterprise Linux HIGH 7.8
CVE-2023-2491

A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el ca…

Mitigation only
Fix from $1,950 2023-05-17
Libvirt MEDIUM 5.5
CVE-2023-2700

A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory…

Patch available
Fix from $1,600 2023-05-15
Openstack MEDIUM 6.5
CVE-2023-2088

A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, au…

No fix yet
Fix from $1,600 2023-05-12
Enterprise Linux MEDIUM 6.5
CVE-2023-32573

In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg QSvgFont m_unitsPerEm initialization is mishandle…

Fix: 5.15.14 / 6.2.9+
Fix from $1,600 2023-05-10
Device Mapper Multipath HIGH 7.8
CVE-2022-3787

A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in…

Mitigation only
Fix from $1,950 2023-03-29
Keycloak MEDIUM 5.4
CVE-2022-1274

A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak user…

Fix: 7.6.2 / 20.0.5+
Fix from $1,600 2023-03-29