Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jboss Application Server HIGH 7.5
CVE-2012-1094

JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched…

Fix: 7.1.1+
Fix from $1,950 2020-03-10
Ansible Engine HIGH 7.8
CVE-2020-1737

A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as t…

Fix: 2.7.17 / 2.8.9+
Fix from $1,950 2020-03-09
Openshift Container Platform HIGH 7.0
CVE-2020-1706

It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, multiple containers modify th…

Mitigation only
Fix from $1,950 2020-03-09
Decision Manager MEDIUM 6.5
CVE-2019-14886

A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context…

Mitigation only
Fix from $1,600 2020-03-05
Openshift Service Mesh HIGH 7.5
CVE-2020-8659

CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e. 1 byte) chunks.

Fix: after 1.13.0
Fix from $1,950 2020-03-04
Openshift Service Mesh HIGH 7.5
CVE-2020-8661

CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.

Fix: after 1.13.0
Fix from $1,950 2020-03-04
Ansible Engine HIGH 7.4
CVE-2020-1734

A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=…

Fix: after 3.3.4
Fix from $1,950 2020-03-03
Keycloak Operator CRITICAL 9.8
CVE-2020-1731

A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password…

Fix: 8.0.2+
Fix from $2,300 2020-03-02
Decision Manager CRITICAL 9.8
CVE-2019-14892EPSS 6%

A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a mal…

Fix: 2.6.7.3 / 2.8.11.5+
Fix from $2,300 2020-03-02
Enterprise Virtualization HIGH 7.5
CVE-2015-5201

VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as pack…

Fix: 3.5.6 / 6-6.7-20151117.0+
Fix from $1,950 2020-02-25
Ansible CRITICAL 9.8
CVE-2014-4657

The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code vi…

Fix: 1.5.4+
Fix from $2,300 2020-02-20
Ansible MEDIUM 5.5
CVE-2014-4658

The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtai…

Fix: 1.5.5+
Fix from $1,600 2020-02-20
Ansible MEDIUM 5.5
CVE-2014-4659

Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunisti…

Fix: 1.5.5+
Fix from $1,600 2020-02-20
Ansible CRITICAL 9.8
CVE-2014-4678EPSS 5%

The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code vi…

Fix: 1.6.4+
Fix from $2,300 2020-02-20
Ansible MEDIUM 5.5
CVE-2014-4660

Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local user…

Fix: 1.5.5+
Fix from $1,600 2020-02-20
Cloudforms Management Engine HIGH 7.5
CVE-2012-6685

Nokogiri before 1.5.4 is vulnerable to XXE attacks

Fix: 1.5.4+
Fix from $1,950 2020-02-19
Ansible CRITICAL 9.8
CVE-2014-4966

Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which …

Fix: 1.6.7+
Fix from $2,300 2020-02-18
Ansible CRITICAL 9.8
CVE-2014-4967

Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansib…

Fix: 1.6.7+
Fix from $2,300 2020-02-18
Enterprise Linux CRITICAL 9.8
CVE-2014-8089

SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows …

Fix: 1.12.9 / 2.2.8+
Fix from $2,300 2020-02-17
Spacewalk CRITICAL 9.8
CVE-2020-1693

A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An unauthenticated …

Fix: 2.9+
Fix from $2,300 2020-02-17
Openshift Service Mesh HIGH 7.8
CVE-2020-1704

An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1.0.8 in the opens…

Fix: 1.0.8+
Fix from $1,950 2020-02-17
Enterprise Linux Desktop HIGH 8.8
CVE-2020-3757EPSS 10%

Adobe Flash Player versions 32.0.0.321 and earlier, 32.0.0.314 and earlier, 32.0.0.321 and earlier, and 32.0.0.255 and earlier have a type confusion …

Fix: 32.0.0.314 / 32.0.0.321+
Fix from $1,950 2020-02-13
Openshift Service Mesh HIGH 7.3
CVE-2020-8595

Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact…

Fix: after 1.4.3
Fix from $1,950 2020-02-12
Openshift CRITICAL 9.8
CVE-2014-0234

The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows re…

Fix: 2.1+
Fix from $2,300 2020-02-12
Openshift Container Platform MEDIUM 5.9
CVE-2020-1726

A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted …

Patch available
Fix from $1,600 2020-02-11
Openstack MEDIUM 6.0
CVE-2020-1711

An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming f…

Fix: 4.2.1+
Fix from $1,600 2020-02-11
Virtualization HIGH 8.8
CVE-2013-4535

The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm imag…

Fix: 1.7.2+
Fix from $1,950 2020-02-11
Keycloak MEDIUM 5.4
CVE-2020-1697

It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated pro…

Fix: 9.0.0+
Fix from $1,600 2020-02-10
Enterprise Linux HIGH 8.8
CVE-2012-4512EPSS 12%

The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read mem…

No fix yet
Fix from $1,950 2020-02-08
Openshift Container Platform HIGH 7.0
CVE-2020-1708

It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers mod…

Mitigation only
Fix from $1,950 2020-02-07