Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux MEDIUM 6.7
CVE-2021-3543

A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descri…

Fix: 5.10.0+
Fix from $1,600 2021-06-01
Openstack Platform HIGH 7.1
CVE-2021-20267

A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server inst…

Fix: 16.3.3 / 17.1.3+
Fix from $1,950 2021-05-28
389 Directory Server MEDIUM 6.5
CVE-2021-3514

When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing…

Mitigation only
Fix from $1,600 2021-05-28
Ceph Storage CRITICAL 9.8
CVE-2021-20236

A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by…

Fix: 4.3.3+
Fix from $2,300 2021-05-28
Keycloak CRITICAL 9.6
CVE-2021-20195

A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account takeover is possible due to …

Fix: 12.0.3+
Fix from $2,300 2021-05-28
Jboss Core Services HIGH 7.5
CVE-2020-25710

A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a fa…

Fix: 2.4.56+
Fix from $1,950 2021-05-28
Enterprise Linux MEDIUM 5.3
CVE-2021-20201

A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of service (CPU consumpt…

Fix: 0.14.92+
Fix from $1,600 2021-05-28
Openshift MEDIUM 6.1
CVE-2020-1761

A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attacker can use this flaw to get …

Fix: 4.0+
Fix from $1,600 2021-05-27
Libvirt MEDIUM 6.5
CVE-2020-14301

An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in …

Fix: 6.3.0+
Fix from $1,600 2021-05-27
Ansible Tower MEDIUM 5.5
CVE-2020-14327

A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and before 3.7.2. Functionality on the Tower server is …

Fix: 3.6.5 / 3.7.2+
Fix from $1,600 2021-05-27
Ansible Tower HIGH 7.1
CVE-2020-10709

A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application. Ansible Tower uses the token to provide authen…

Fix: 3.5.6 / 3.6.4+
Fix from $1,950 2021-05-27
Libvirt MEDIUM 6.5
CVE-2020-10701

A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connec…

Fix: 6.2.0+
Fix from $1,600 2021-05-27
Satellite MEDIUM 6.5
CVE-2020-10716

A flaw was found in Red Hat Satellite's Job Invocation, where the "User Input" entry was not properly restricted to the view. This flaw allows a mali…

Fix: 4.0.3.4+
Fix from $1,600 2021-05-27
Fuse MEDIUM 6.1
CVE-2020-10688

A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL …

Fix: 3.11.1 / 4.5.3+
Fix from $1,600 2021-05-27
Ansible Engine MEDIUM 5.5
CVE-2020-10729

A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups of the same length generate the equal value as th…

Fix: 2.9.6+
Fix from $1,600 2021-05-27
Quay CRITICAL 9.0
CVE-2020-27832

A flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a repository's notification. Thi…

Fix: 3.3.2+
Fix from $2,300 2021-05-27
Enterprise Linux HIGH 7.8
CVE-2021-30500

Null pointer dereference was found in upx PackLinuxElf::canUnpack() in p_lx_elf.cpp,in version UPX 4.0.0. That allow attackers to execute arbitrary c…

Patch available
Fix from $1,950 2021-05-27
Ceph Storage MEDIUM 6.1
CVE-2021-3509

A flaw was found in Red Hat Ceph Storage 4, in the Dashboard component. In response to CVE-2020-27839, the JWT token was moved from localStorage to a…

Patch available
Fix from $1,600 2021-05-27
Enterprise Linux MEDIUM 5.5
CVE-2021-30501

An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to cause a denial of service (abor…

Patch available
Fix from $1,600 2021-05-27
Enterprise Linux MEDIUM 5.5
CVE-2021-30470

A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call among PdfTokenizer::ReadArray(), PdfTokenizer::GetNextVariant() and PdfTokenizer::Re…

Patch available
Fix from $1,600 2021-05-26
Enterprise Linux MEDIUM 5.5
CVE-2021-30471

A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call in PdfNamesTree::AddToDictionary function in src/podofo/doc/PdfNamesTree.cpp can lea…

Patch available
Fix from $1,600 2021-05-26
Enterprise Linux MEDIUM 5.5
CVE-2021-3527

A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB packets are combined into a single, large transfer request, to reduce th…

Fix: after 6.0.0
Fix from $1,600 2021-05-26
Single Sign On HIGH 7.8
CVE-2020-10695

An insecure modification flaw in the /etc/passwd file was found in the redhat-sso-7 container. An attacker with access to the container can use this …

Fix: 7.4.4+
Fix from $1,950 2021-05-26
Ceph MEDIUM 5.4
CVE-2020-27839

A flaw was found in ceph-dashboard. The JSON Web Token (JWT) used for user authentication is stored by the frontend application in the browser’s loca…

Fix: 14.2.17 / 15.2.9+
Fix from $1,600 2021-05-26
Ansible MEDIUM 5.5
CVE-2021-20191

A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when usi…

Fix: 1.2.2 / 1.3.2+
Fix from $1,600 2021-05-26
Openshift Container Platform MEDIUM 5.5
CVE-2021-20297

A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat …

Fix: 1.30.0+
Fix from $1,600 2021-05-26
3scale MEDIUM 5.4
CVE-2020-25634

A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attacker to view sensitive informa…

Fix: 2.10.0+
Fix from $1,600 2021-05-26
Certification CRITICAL 9.1
CVE-2018-10866

It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated use…

Mitigation only
Fix from $2,300 2021-05-26
Certification CRITICAL 9.1
CVE-2018-10867

Files are accessible without restrictions from the /update/results page of redhat-certification 7 package, allowing an attacker to remove any file ac…

Mitigation only
Fix from $2,300 2021-05-26
Certification HIGH 7.5
CVE-2018-10863

It was discovered that redhat-certification 7 is not properly configured and it lists all files and directories in the /var/www/rhcert/store/transfer…

Mitigation only
Fix from $1,950 2021-05-26