Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Virtualization MEDIUM 6.5
CVE-2020-35497

A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal information, including name, email an…

Fix: after 4.4.3
Fix from $1,600 2020-12-21
Ceph HIGH 7.1
CVE-2020-27781

User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open S…

Fix: 14.2.16 / 15.2.8+
Fix from $1,950 2020-12-18
Keycloak MEDIUM 5.3
CVE-2020-10770EPSS 70%

A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_u…

Fix: 12.0.2+
Fix from $1,600 2020-12-15
Enterprise Linux HIGH 7.8
CVE-2020-25712

A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The …

Fix: 1.20.10+
Fix from $1,950 2020-12-15
Language Support For Java HIGH 7.8
CVE-2020-17159

Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2020-12-10
Enterprise Linux HIGH 7.5
CVE-2020-25692

A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An unauthenticated atta…

Fix: 2.4.55+
Fix from $1,950 2020-12-08
Wildfly MEDIUM 5.9
CVE-2020-27822

A flaw was found in Wildfly affecting versions 19.0.0.Final, 19.1.0.Final, 20.0.0.Final, 20.0.1.Final, and 21.0.0.Final. When an application uses the…

Mitigation only
Fix from $1,600 2020-12-08
Ceph Storage MEDIUM 5.5
CVE-2020-25677

A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any use…

Patch available
Fix from $1,600 2020-12-08
Enterprise Linux HIGH 7.5
CVE-2020-29573

sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on x86 targets has a stack-based buffer overflow if the input to any of…

Fix: 2.23+
Fix from $1,950 2020-12-06
Enterprise Linux HIGH 7.5
CVE-2020-27778

A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious…

Fix: 0.76.0+
Fix from $1,950 2020-12-03
Software Collections MEDIUM 6.1
CVE-2020-27783

A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behavi…

Fix: 4.6.2+
Fix from $1,600 2020-12-03
Libvirt HIGH 8.8
CVE-2020-14339

A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privi…

Fix: 6.7.0+
Fix from $1,950 2020-12-03
Data Grid MEDIUM 6.5
CVE-2020-25711

A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When …

Fix: 11.0.6+
Fix from $1,600 2020-12-03
Cloudforms MEDIUM 6.3
CVE-2020-14369

This release fixes a Cross Site Request Forgery vulnerability was found in Red Hat CloudForms which forces end users to execute unwanted actions on a…

Fix: after 5.11
Fix from $1,600 2020-12-02
Enterprise Linux MEDIUM 6.5
CVE-2020-14383

A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC server, which also serves prot…

Fix: 4.11.15 / 4.12.9+
Fix from $1,600 2020-12-02
Enterprise Linux HIGH 7.5
CVE-2020-25708

A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this flaw to send a specially crafted message that, wh…

Patch available
Fix from $1,950 2020-11-27
Wildfly MEDIUM 5.3
CVE-2020-25640

A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inser…

Fix: 21.0.0+
Fix from $1,600 2020-11-24
Gluster Block MEDIUM 5.5
CVE-2020-10762

An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes …

Fix: 0.5.1+
Fix from $1,600 2020-11-24
Gluster Storage MEDIUM 5.5
CVE-2020-10763

An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access t…

Fix: 10.1.0+
Fix from $1,600 2020-11-24
Ceph HIGH 8.8
CVE-2020-25660

A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly a…

Fix: 14.2.14 / 15.2.6+
Fix from $1,950 2020-11-23
Keycloak HIGH 8.1
CVE-2020-14389

It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, …

Fix: 12.0.0+
Fix from $1,950 2020-11-17
Openstack Platform MEDIUM 5.9
CVE-2020-25658

It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt part…

Fix: 4.7+
Fix from $1,600 2020-11-12
Keycloak HIGH 7.5
CVE-2020-14366

A vulnerability was found in keycloak, where path traversal using URL-encoded path segments in the request is possible because the resources endpoint…

Fix: 12.0.0+
Fix from $1,950 2020-11-09
Advanced Cluster Management For Kubernetes MEDIUM 6.5
CVE-2020-25655

An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created f…

Mitigation only
Fix from $1,600 2020-11-09
Enterprise Linux HIGH 8.8
CVE-2020-25661

A Red Hat only CVE-2020-12351 regression issue was found in the way the Linux kernel's Bluetooth implementation handled L2CAP packets with A2MP CID. …

Mitigation only
Fix from $1,950 2020-11-05
Enterprise Linux MEDIUM 6.5
CVE-2020-25662

A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of s…

Mitigation only
Fix from $1,600 2020-11-05
Wildfly MEDIUM 6.5
CVE-2020-25689

A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connec…

Fix: after 21.0.0
Fix from $1,600 2020-11-02
Fabric8 Maven HIGH 7.8
CVE-2020-10721

A flaw was found in the fabric8-maven-plugin 4.0.0 and later. When using a wildfly-swarm or thorntail custom configuration, a malicious YAML configur…

Fix: after 4.4.1
Fix from $1,950 2020-10-22
Enterprise Linux HIGH 7.5
CVE-2020-25648

A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages,…

Fix: 3.58 / 9.2.6.0+
Fix from $1,950 2020-10-20
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2020-14299

A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox Secur…

Fix: 5.0.3+
Fix from $1,600 2020-10-16