Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux CRITICAL 9.8
CVE-2021-20232

A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potentia…

Fix: 3.7.1+
Fix from $2,300 2021-03-12
Enterprise Linux MEDIUM 5.5
CVE-2020-35521

A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of servi…

Fix: 4.2.0+
Fix from $1,600 2021-03-09
Enterprise Linux MEDIUM 5.5
CVE-2021-20244

A flaw was found in ImageMagick in MagickCore/visual-effects.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger…

Fix: 7.0.10-62+
Fix from $1,600 2021-03-09
Enterprise Linux MEDIUM 5.5
CVE-2021-20245

A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined beh…

Fix: 6.9.11-62 / 7.0.10-62+
Fix from $1,600 2021-03-09
Enterprise Linux MEDIUM 5.5
CVE-2021-20246

A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undef…

Fix: 6.9.11-62 / 7.0.10-62+
Fix from $1,600 2021-03-09
Keycloak MEDIUM 6.8
CVE-2021-20262

A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows an attacker to take over an …

Mitigation only
Fix from $1,600 2021-03-09
Ansible Tower MEDIUM 6.7
CVE-2021-20253

A flaw was found in ansible-tower. The default installation is vulnerable to Job Isolation escape allowing an attacker to elevate the privilege from …

Fix: 3.6.7 / 3.7.5+
Fix from $1,600 2021-03-09
Keycloak MEDIUM 6.5
CVE-2020-27838EPSS 18%

A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like cli…

Fix: 13.0.0+
Fix from $1,600 2021-03-08
Enterprise Linux HIGH 7.8
CVE-2021-3403

In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) …

No fix yet
Fix from $1,950 2021-03-04
Enterprise Linux HIGH 7.8
CVE-2021-3404

In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a h…

No fix yet
Fix from $1,950 2021-03-04
Enterprise Linux HIGH 8.2
CVE-2021-20233

A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption tha…

Fix: 2.06+
Fix from $1,950 2021-03-03
Enterprise Linux HIGH 8.2
CVE-2020-25632

A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking …

Fix: 2.06+
Fix from $1,950 2021-03-03
Enterprise Linux HIGH 7.6
CVE-2020-25647

A flaw was found in grub2 in versions prior to 2.06. During USB device initialization, descriptors are read with very little bounds checking and assu…

Fix: 2.06+
Fix from $1,950 2021-03-03
Enterprise Linux HIGH 7.5
CVE-2020-14372

A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the ACPI command when Secure Boot is enabled. This fla…

Fix: 2.06+
Fix from $1,950 2021-03-03
Enterprise Linux HIGH 7.5
CVE-2020-27779

A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove …

Fix: 2.06+
Fix from $1,950 2021-03-03
Enterprise Linux MEDIUM 6.7
CVE-2020-27749

A flaw was found in grub2 in versions prior to 2.06. Variable names present are expanded in the supplied command line into their corresponding variab…

Fix: 2.06+
Fix from $1,600 2021-03-03
Enterprise Linux MEDIUM 6.7
CVE-2021-20225

A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-allocated buffer by calling…

Fix: 2.06+
Fix from $1,600 2021-03-03
3scale Api Management MEDIUM 6.5
CVE-2021-20252

A flaw was found in Red Hat 3scale API Management Platform 2. The 3scale backend does not perform preventive handling on user-requested date ranges i…

Mitigation only
Fix from $1,600 2021-02-23
Satellite MEDIUM 5.3
CVE-2021-20256

A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local attacker with view_hosts perm…

Mitigation only
Fix from $1,600 2021-02-23
Openshift Container Platform HIGH 8.8
CVE-2021-20182

A privilege escalation flaw was found in openshift4/ose-docker-builder. The build container runs with high privileges using a chrooted environment in…

Fix: 4.4.33 / 4.5.30+
Fix from $1,950 2021-02-23
Jboss Fuse HIGH 7.5
CVE-2020-27782

A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings…

Mitigation only
Fix from $1,950 2021-02-23
Openshift Installer HIGH 8.1
CVE-2021-20198

A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installation of OpenShift Container Pl…

Fix: 0.9.0-master.0.20210125200451-95101da940b0+
Fix from $1,950 2021-02-23
Louketo Proxy HIGH 7.3
CVE-2020-14359

A vulnerability was found in all versions of Keycloak Gatekeeper, where on using lower case HTTP headers (via cURL) an attacker can bypass our Gateke…

Mitigation only
Fix from $1,950 2021-02-23
Openshift Container Platform HIGH 7.0
CVE-2021-20188

A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not correctly checked. This flaw c…

Fix: 1.7.0+
Fix from $1,950 2021-02-11
Openshift Service Mesh MEDIUM 6.5
CVE-2019-25014

A NULL pointer dereference was found in pkg/proxy/envoy/v2/debug.go getResourceVersion in Istio pilot before 1.5.0-alpha.0. If a particular HTTP GET …

Fix: after 1.4.9
Fix from $1,600 2021-01-29
Mobile Application Platform MEDIUM 6.1
CVE-2020-1723

A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected ver…

Mitigation only
Fix from $1,600 2021-01-28
Keycloak MEDIUM 5.4
CVE-2020-1725

A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycl…

Fix: 13.0.0+
Fix from $1,600 2021-01-28
Virtualization MEDIUM 5.9
CVE-2020-25657

A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the t…

Mitigation only
Fix from $1,600 2021-01-12
Jboss Core Services Httpd MEDIUM 5.4
CVE-2020-25680

A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The v…

Mitigation only
Fix from $1,600 2021-01-07
Enterprise Linux MEDIUM 5.5
CVE-2020-35507

There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit…

Fix: 2.34+
Fix from $1,600 2021-01-04