Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Certification HIGH 7.5
CVE-2018-10865

It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated use…

Mitigation only
Fix from $1,950 2021-05-26
Certification HIGH 7.5
CVE-2018-10868

redhat-certification 7 does not properly restrict the number of recursive definitions of entities in XML documents, allowing an unauthenticated user …

Mitigation only
Fix from $1,950 2021-05-26
Ansible MEDIUM 5.5
CVE-2021-20178

A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using…

Fix: 2.9.18+
Fix from $1,600 2021-05-26
3scale HIGH 8.8
CVE-2019-14836

A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to…

Mitigation only
Fix from $1,950 2021-05-26
Libvirt MEDIUM 6.5
CVE-2021-3559

A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with a PCI device and driver that…

Fix: 7.0.0+
Fix from $1,600 2021-05-24
Enterprise Linux CRITICAL 9.8
CVE-2018-25011

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.8
CVE-2018-25014

A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.8
CVE-2020-36328

A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check …

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.8
CVE-2020-36329

A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this…

Fix: 1.0.1 / 14.7+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.1
CVE-2018-25009

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.1
CVE-2018-25010

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.1
CVE-2018-25012

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.1
CVE-2018-25013

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.1
CVE-2020-36331

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulne…

Fix: 1.0.1 / 14.7+
Fix from $2,300 2021-05-21
Enterprise Linux HIGH 7.5
CVE-2020-36332

A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from th…

Fix: 1.0.1+
Fix from $1,950 2021-05-21
Jboss Core Services HIGH 8.6
CVE-2021-3517EPSS 8%

There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be…

Fix: 2.9.11+
Fix from $1,950 2021-05-19
Enterprise Linux MEDIUM 5.5
CVE-2021-3421

A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiab…

Fix: 4.16.1.3+
Fix from $1,600 2021-05-19
Ceph MEDIUM 5.3
CVE-2021-3531

A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift URL that ends with two slashes…

Fix: 14.2.21+
Fix from $1,600 2021-05-18
Ceph MEDIUM 6.5
CVE-2021-3524

A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection …

Fix: 14.2.21+
Fix from $1,600 2021-05-17
Openshift Container Platform HIGH 7.1
CVE-2020-27833

A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by using a specially crafted raw c…

Fix: after 4.7
Fix from $1,950 2021-05-14
Jboss Core Services MEDIUM 5.9
CVE-2021-3537

A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL der…

Fix: 2.9.11+
Fix from $1,600 2021-05-14
Enterprise Linux MEDIUM 6.0
CVE-2021-20221

An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt Controller emulator of QEMU up to and including qemu 4.2.0on aarch64…

Fix: after 4.2.0
Fix from $1,600 2021-05-13
Noobaa Operator HIGH 8.8
CVE-2021-3528

A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator and the noobaa core are leake…

Fix: 5.7.0+
Fix from $1,950 2021-05-13
Enterprise Linux MEDIUM 5.5
CVE-2020-27824

A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input t…

Fix: 2.4.0+
Fix from $1,600 2021-05-13
Keycloak HIGH 7.3
CVE-2021-20202

A flaw was found in keycloak. Directories can be created prior to the Java process creating them in the temporary directory, but with wider user perm…

Fix: 13.0.0+
Fix from $1,950 2021-05-12
Hivex MEDIUM 5.4
CVE-2021-3504

A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the hivex_open function. An attack…

Fix: 1.3.20+
Fix from $1,600 2021-05-11
Openstack HIGH 7.5
CVE-2021-31918

A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update a…

Mitigation only
Fix from $1,950 2021-05-06
Ansible Engine HIGH 7.5
CVE-2021-20228

A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using th…

Patch available
Fix from $1,950 2021-04-29
Enterprise Linux MEDIUM 6.1
CVE-2021-20208

A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credent…

Fix: 6.13+
Fix from $1,600 2021-04-19
Enterprise Linux MEDIUM 5.5
CVE-2021-3505

A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG …

Fix: 0.8.0+
Fix from $1,600 2021-04-19