Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux HIGH 8.5
CVE-2021-3682

A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfe…

Fix: 6.1.0+
Fix from $1,950 2021-08-05
Jboss Core Services MEDIUM 6.5
CVE-2021-3541

A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of s…

Fix: 2.9.11+
Fix from $1,600 2021-07-09
Keycloak HIGH 7.5
CVE-2021-3637

A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity …

Fix: 14.0.0+
Fix from $1,950 2021-07-09
Enterprise Linux HIGH 8.8
CVE-2021-3570

A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote att…

Fix: 1.5.1 / 1.6.1+
Fix from $1,950 2021-07-09
Enterprise Linux HIGH 7.1
CVE-2021-3571

A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a …

Fix: 2.0.1 / 3.1.1+
Fix from $1,950 2021-07-09
Enterprise Linux MEDIUM 5.5
CVE-2021-3598

There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an…

Fix: 3.0.5+
Fix from $1,600 2021-07-06
Resteasy MEDIUM 6.1
CVE-2021-20293

A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where it did not properly handle URL…

Fix: after 4.6.0
Fix from $1,600 2021-06-10
Enterprise Linux MEDIUM 5.7
CVE-2021-0129

Improper access control in BlueZ may allow an authenticated user to potentially enable information disclosure via adjacent access.

Fix: 5.57+
Fix from $1,600 2021-06-09
Cloudforms HIGH 8.1
CVE-2020-25716

A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is possible. An attacker with a…

Fix: 5.11.10.1+
Fix from $1,950 2021-06-07
Machine Config Operator MEDIUM 6.5
CVE-2020-1750

A flaw was found in the machine-config-operator that causes an OpenShift node to become unresponsive when a container consumes a large amount of memo…

Fix: 4.2.36 / 4.3.25+
Fix from $1,600 2021-06-07
Openshift Virtualization HIGH 7.0
CVE-2020-1742

An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the containe…

Fix: 2.3.0+
Fix from $1,950 2021-06-07
Openstack Selinux MEDIUM 6.5
CVE-2020-1690

An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root user in a container from pri…

Fix: 0.8.24+
Fix from $1,600 2021-06-07
Wildfly MEDIUM 5.4
CVE-2020-1719

A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Security Domain. The highest th…

Fix: 20.0.0+
Fix from $1,600 2021-06-07
Enterprise Linux MEDIUM 5.9
CVE-2021-3565

A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed AES key for the inner wrapper, potentially allowin…

Fix: 4.3.2 / 5.1.1+
Fix from $1,600 2021-06-04
Enterprise Linux MEDIUM 5.5
CVE-2021-3569

A stack corruption bug was found in libtpms in versions before 0.7.2 and before 0.8.0 while decrypting data using RSA. This flaw could result in a SI…

Fix: 0.7.2 / 0.8.0+
Fix from $1,600 2021-06-03
Noobaa Operator HIGH 7.1
CVE-2021-3529

A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as p…

Fix: 5.7.0+
Fix from $1,950 2021-06-02
Openshift HIGH 7.0
CVE-2020-35514

An insecure modification flaw in the /etc/kubernetes/kubeconfig file was found in OpenShift. This flaw allows an attacker with access to a running co…

Fix: 4.7.0+
Fix from $1,950 2021-06-02
Jboss Remoting MEDIUM 5.9
CVE-2020-35510

A flaw was found in jboss-remoting in versions before 5.0.20.SP1-redhat-00001. A malicious attacker could cause threads to hold up forever in the EJB…

Fix: 5.0.20+
Fix from $1,600 2021-06-02
3scale Api Management MEDIUM 6.3
CVE-2020-14388

A flaw was found in the Red Hat 3scale API Management Platform, where member permissions for an API's admin portal were not properly enforced. This f…

Mitigation only
Fix from $1,600 2021-06-02
Satellite HIGH 7.5
CVE-2020-14380

An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authen…

Mitigation only
Fix from $1,950 2021-06-02
Satellite MEDIUM 6.5
CVE-2020-14371

A credential leak vulnerability was found in Red Hat Satellite. This flaw exposes the compute resources credentials through VMs that are running on t…

Mitigation only
Fix from $1,600 2021-06-02
Xnio MEDIUM 5.9
CVE-2020-14340

A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection c…

Fix: 3.7.9 / 3.8.2+
Fix from $1,600 2021-06-02
Integration Camel K HIGH 7.5
CVE-2020-14326

A vulnerability was found in RESTEasy, where RootNode incorrectly caches routes. This issue results in hash flooding, leading to slower requests with…

Fix: 4.5.6+
Fix from $1,950 2021-06-02
Openshift Container Platform MEDIUM 6.5
CVE-2020-14336

A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets. This flaw allows an atta…

Mitigation only
Fix from $1,600 2021-06-02
Jboss Enterprise Application Platform MEDIUM 5.5
CVE-2020-14317

It was found that the issue for security flaw CVE-2019-3805 appeared again in a further version of JBoss Enterprise Application Platform - Continuous…

Mitigation only
Fix from $1,600 2021-06-02
Satellite MEDIUM 5.5
CVE-2020-14335

A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets through the ISC DHCP of Smart-Proxy. This flaw allows…

Mitigation only
Fix from $1,600 2021-06-02
Data Grid HIGH 7.1
CVE-2020-10771

A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw…

Mitigation only
Fix from $1,950 2021-06-02
Single Sign On MEDIUM 5.3
CVE-2021-3424

A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can register himself…

Mitigation only
Fix from $1,600 2021-06-01
Openshift Service Mesh HIGH 8.8
CVE-2021-3495

An incorrect access control flaw was found in the kiali-operator in versions before 1.33.0 and before 1.24.7. This flaw allows an attacker with a bas…

Fix: 1.24.7 / 1.33.0+
Fix from $1,950 2021-06-01
3scale HIGH 7.3
CVE-2021-3412

It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, an…

Mitigation only
Fix from $1,950 2021-06-01