Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vscode Xml CRITICAL 9.1
CVE-2022-0671

A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large file.

Fix: 0.19.0+
Fix from $2,300 2022-02-18
Enterprise Linux Desktop HIGH 7.5
CVE-2021-4091

A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search r…

Fix: 1.3.10.2+
Fix from $1,950 2022-02-18
Enterprise Linux CRITICAL 9.8
CVE-2021-20325

Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regress…

Mitigation only
Fix from $2,300 2022-02-18
Codeready Linux Builder MEDIUM 6.5
CVE-2021-3930

An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the …

Patch available
Fix from $1,600 2022-02-18
Migration Toolkit MEDIUM 6.3
CVE-2021-3948

An incorrect default permissions vulnerability was found in the mig-controller. Due to an incorrect cluster namespaces handling an attacker may be ab…

Fix: 1.5.2 / 1.6.3+
Fix from $1,600 2022-02-18
Openshift Gitops MEDIUM 6.5
CVE-2021-3557

A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-serve…

Fix: 1.1.1+
Fix from $1,600 2022-02-16
Enterprise Linux MEDIUM 5.5
CVE-2022-0561

Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 …

Fix: after 4.3.0
Fix from $1,600 2022-02-11
Enterprise Linux MEDIUM 5.5
CVE-2022-0529

A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound wri…

No fix yet
Fix from $1,600 2022-02-09
Enterprise Linux MEDIUM 5.5
CVE-2022-0530

A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound wri…

Fix: 10.15.7 / 11.6.6+
Fix from $1,600 2022-02-09
Enterprise Linux Server Update Services For Sap Solutions HIGH 7.8
CVE-2021-4034 KEVEPSS 95%

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileg…

Patch available
Fix from $1,950 2022-01-28
Keycloak HIGH 8.8
CVE-2021-4133

A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default …

Fix: 15.1.1+
Fix from $1,950 2022-01-25
Enterprise Linux MEDIUM 6.5
CVE-2021-4145

A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in mirror…

Patch available
Fix from $1,600 2022-01-25
Ovirt Node HIGH 7.8
CVE-2021-45417

AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of…

Fix: after 0.17.3
Fix from $1,950 2022-01-20
Enterprise Linux HIGH 7.1
CVE-2021-4166

vim is vulnerable to Out-of-bounds Read

Fix: 8.2.3884 / 11.6.6+
Fix from $1,950 2021-12-25
Virtualization HIGH 8.8
CVE-2021-3621

A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This fl…

Patch available
Fix from $1,950 2021-12-23
Satellite HIGH 7.2
CVE-2021-3584

A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to …

Fix: 2.4.1 / 2.5.1+
Fix from $1,950 2021-12-23
Jboss Enterprise Application Platform HIGH 7.2
CVE-2021-20318

The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary …

Mitigation only
Fix from $1,950 2021-12-23
Enterprise Linux HIGH 7.8
CVE-2021-45463

load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by u…

Fix: 0.4.34 / 2.10.30+
Fix from $1,950 2021-12-23
Satellite MEDIUM 6.6
CVE-2021-42550

In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configurat…

Fix: 1.0.3+
Fix from $1,600 2021-12-16
Ceph Storage CRITICAL 9.1
CVE-2021-4048

An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS b…

Fix: 0.3.18+
Fix from $2,300 2021-12-08
Enterprise Linux HIGH 8.1
CVE-2021-3935

When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first e…

Fix: 1.16.1+
Fix from $1,950 2021-11-22
Ansible Automation Platform HIGH 7.1
CVE-2021-3583

A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template i…

Fix: 2.9.23 / 3.7.0+
Fix from $1,950 2021-09-22
Data Grid CRITICAL 9.8
CVE-2021-31917

A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authenticat…

Fix: 11.0.12 / 12.1.4+
Fix from $2,300 2021-09-21
Enterprise Linux CRITICAL 9.0
CVE-2021-40438 KEVEPSS 100%

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP …

Patch available
Fix from $2,300 2021-09-16
Enterprise Linux HIGH 7.8
CVE-2021-33285

In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, a heap buffer overflow…

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Virtualization MEDIUM 6.5
CVE-2021-3634

A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during the lifetime of the session. On…

Fix: 0.9.6+
Fix from $1,600 2021-08-31
Enterprise Linux MEDIUM 5.5
CVE-2021-3605

There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an applicatio…

Fix: 3.0.5+
Fix from $1,600 2021-08-25
Enterprise Linux CRITICAL 9.8
CVE-2021-20314

Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code executio…

Fix: 1.2.11+
Fix from $2,300 2021-08-12
Wildfly Elytron MEDIUM 5.3
CVE-2021-3642

A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susc…

Fix: 1.10.14 / 1.15.5+
Fix from $1,600 2021-08-05
Enterprise Linux HIGH 7.5
CVE-2021-3580

A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a mani…

Fix: 3.7.3+
Fix from $1,950 2021-08-05