Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ceph Storage CRITICAL 9.1
CVE-2022-0670

A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file syste…

Fix: 5.2 / 15.2.17+
Fix from $2,300 2022-07-25
Openstack MEDIUM 6.5
CVE-2022-1655

An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without …

Mitigation only
Fix from $1,600 2022-07-22
Certificate System MEDIUM 5.7
CVE-2022-2393

A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled.…

Fix: after 10.12.4
Fix from $1,600 2022-07-14
Enterprise Linux MEDIUM 6.5
CVE-2022-2211

A vulnerability was found in libguestfs. This issue occurs while calculating the greatest possible number of matching keys in the get_keys() function…

No fix yet
Fix from $1,600 2022-07-12
Keycloak CRITICAL 9.8
CVE-2022-1245

A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid ac…

Fix: 18.0.0+
Fix from $2,300 2022-07-08
Cloudforms Management Engine CRITICAL 9.1
CVE-2014-8164

A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat Cloud…

Mitigation only
Fix from $2,300 2022-07-06
Developer Tools HIGH 7.0
CVE-2021-3697

A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to …

Mitigation only
Fix from $1,950 2022-07-06
Jboss Aerogear HIGH 7.5
CVE-2014-3648

The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But this is use…

Mitigation only
Fix from $1,950 2022-07-01
Jboss Aerogear MEDIUM 5.4
CVE-2014-3650

Multiple persistent cross-site scripting (XSS) flaws were found in the way Aerogear handled certain user-supplied content. A remote attacker could us…

Mitigation only
Fix from $1,600 2022-07-01
Openshift Origin Node Util MEDIUM 5.5
CVE-2014-0068

It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission.

Mitigation only
Fix from $1,600 2022-06-30
Openshift CRITICAL 9.1
CVE-2013-4561

In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to loss of confidentiality and i…

Patch available
Fix from $2,300 2022-06-30
Amq Broker HIGH 8.8
CVE-2022-1833

A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has access to the namespace where th…

Mitigation only
Fix from $1,950 2022-06-21
Enterprise Linux HIGH 8.2
CVE-2022-1665

A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub in Secure Boot mode even tho…

Mitigation only
Fix from $1,950 2022-06-21
Drools CRITICAL 9.8
CVE-2021-41411

drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, res…

Fix: 7.6.0+
Fix from $2,300 2022-06-16
389 Directory Server HIGH 7.5
CVE-2022-1949

An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progr…

Fix: after 2.0.0
Fix from $1,950 2022-06-02
Jboss Enterprise Application Platform HIGH 7.8
CVE-2021-3717

A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER acces…

Fix: 17.0+
Fix from $1,950 2022-05-24
Fuse MEDIUM 5.9
CVE-2021-3597

A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The h…

Fix: 2.0.35 / 2.2.6+
Fix from $1,600 2022-05-24
Integration MEDIUM 5.9
CVE-2021-3629

A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a deni…

Fix: 2.0.40 / 2.2.11+
Fix from $1,600 2022-05-24
Ignition MEDIUM 6.5
CVE-2022-1706

A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issu…

Fix: 2.14.0+
Fix from $1,600 2022-05-17
Enterprise Linux CRITICAL 9.1
CVE-2022-1587

An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. Th…

Fix: 10.40+
Fix from $2,300 2022-05-16
Enterprise Linux MEDIUM 6.5
CVE-2021-3611

A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use this flaw to crash the QEMU pr…

Fix: 7.0.0+
Fix from $1,600 2022-05-11
Jboss Enterprise Application Platform MEDIUM 5.3
CVE-2022-0866

This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that is configured with a…

Fix: 26.1.1+
Fix from $1,600 2022-05-10
Enterprise Linux HIGH 8.2
CVE-2021-3750

A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO regi…

Fix: 7.0.0+
Fix from $1,950 2022-05-02
Enterprise Linux HIGH 8.2
CVE-2021-4206

A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a smal…

Fix: 7.0.0+
Fix from $1,950 2022-04-29
Enterprise Linux HIGH 8.2
CVE-2021-4207

A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.he…

Fix: 7.0.0+
Fix from $1,950 2022-04-29
Apicast HIGH 7.5
CVE-2021-3523

A flaw was found in 3Scale APICast in versions prior to 2.11.0, where it incorrectly identified connections for reuse. This flaw allows an attacker t…

Fix: 2.11.0+
Fix from $1,950 2022-04-27
Keycloak MEDIUM 6.5
CVE-2022-1466

Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was po…

Fix: 17.0.1+
Fix from $1,600 2022-04-26
Ansible Automation Platform MEDIUM 5.5
CVE-2021-3681

A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly ex…

Mitigation only
Fix from $1,600 2022-04-18
Enterprise Linux HIGH 7.8
CVE-2022-1304

An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code executi…

Mitigation only
Fix from $1,950 2022-04-14
Openshift HIGH 7.5
CVE-2021-4047

The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only aff…

Mitigation only
Fix from $1,950 2022-04-11