Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openshift Container Storage MEDIUM 6.5
CVE-2020-1700

A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making mult…

Mitigation only
Fix from $1,600 2020-02-07
Enterprise Linux Desktop HIGH 7.5
CVE-2013-4166

The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does…

Fix: after 3.9.5
Fix from $1,950 2020-02-06
Enterprise Linux Desktop HIGH 7.8
CVE-2014-8141EPSS 7%

Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a cra…

Fix: after 6.0
Fix from $1,950 2020-01-31
Enterprise Linux Desktop HIGH 7.8
CVE-2014-8139EPSS 7%

Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafte…

Fix: after 6.0
Fix from $1,950 2020-01-31
Enterprise Linux Desktop HIGH 7.8
CVE-2014-8140EPSS 7%

Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a cr…

Fix: after 6.0
Fix from $1,950 2020-01-31
Openshift CRITICAL 9.8
CVE-2013-2060EPSS 6%

The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a req…

No fix yet
Fix from $2,300 2020-01-28
Jboss Brms HIGH 7.5
CVE-2012-5626

EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and…

Mitigation only
Fix from $1,950 2020-01-23
Undertow HIGH 7.5
CVE-2019-14888

A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to…

Fix: after 2.0.28
Fix from $1,950 2020-01-23
Quay HIGH 8.8
CVE-2019-3864

A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameter which i…

Fix: 3.0.0+
Fix from $1,950 2020-01-21
Enterprise Linux MEDIUM 6.5
CVE-2019-19339

It was found that the Red Hat Enterprise Linux 8 kpatch update did not include the complete fix for CVE-2018-12207. A flaw was found in the way Intel…

Mitigation only
Fix from $1,600 2020-01-17
Enterprise Linux HIGH 8.3
CVE-2019-9503

The Broadcom brcmfmac WiFi driver prior to commit a4176ec356c73a46c07c181c6d04039fafa34a9f is vulnerable to a frame validation bypass. If the brcmfma…

Patch available
Fix from $1,950 2020-01-16
Enterprise Linux HIGH 8.1
CVE-2020-2604

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE…

Fix: after 13.0.1
Fix from $1,950 2020-01-15
Enterprise Linux HIGH 8.8
CVE-2020-0603EPSS 20%

A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfull…

Patch available
Fix from $1,950 2020-01-14
Enterprise Linux HIGH 7.5
CVE-2020-0602EPSS 8%

A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.

Patch available
Fix from $1,950 2020-01-14
Automatic Bug Reporting Tool HIGH 7.8
CVE-2015-1869

The default event handling scripts in Automatic Bug Reporting Tool (ABRT) allow local users to gain privileges as demonstrated by a symlink attack on…

Patch available
Fix from $1,950 2020-01-14
Automatic Bug Reporting Tool HIGH 7.8
CVE-2015-3151

Directory traversal vulnerability in abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to read, write to, or change ownership of ar…

Patch available
Fix from $1,950 2020-01-14
Automatic Bug Reporting Tool HIGH 7.8
CVE-2015-3159

The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) does not properly handle the process environment …

Patch available
Fix from $1,950 2020-01-14
Automatic Bug Reporting Tool HIGH 7.1
CVE-2015-3150

abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory ar…

Patch available
Fix from $1,950 2020-01-14
Automatic Bug Reporting Tool MEDIUM 6.5
CVE-2015-3147

daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to w…

Patch available
Fix from $1,600 2020-01-14
Enterprise Linux Desktop HIGH 7.8
CVE-2014-7844

BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.

Patch available
Fix from $1,950 2020-01-14
Enterprise Linux HIGH 7.8
CVE-2012-2142

The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence…

Fix: 0.21.4+
Fix from $1,950 2020-01-09
Ansible HIGH 7.5
CVE-2014-2686

Ansible prior to 1.5.4 mishandles the evaluation of some strings.

Fix: 1.5.4+
Fix from $1,950 2020-01-09
Enterprise Linux CRITICAL 9.8
CVE-2019-14906

A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL pack…

Fix: after 2.0.9
Fix from $2,300 2020-01-07
Openshift Container Platform HIGH 8.8
CVE-2019-14819

A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to…

No fix yet
Fix from $1,950 2020-01-07
Keycloak CRITICAL 9.1
CVE-2019-14837

A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name …

Fix: 8.0.0+
Fix from $2,300 2020-01-07
Single Sign On HIGH 8.8
CVE-2019-14843

A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a mal…

Patch available
Fix from $1,950 2020-01-07
Enterprise Linux HIGH 7.3
CVE-2019-14866

In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives fro…

Fix: 2.13+
Fix from $1,950 2020-01-07
Openshift Container Platform MEDIUM 6.5
CVE-2019-14854

OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or hig…

No fix yet
Fix from $1,600 2020-01-07
Satellite MEDIUM 6.5
CVE-2014-3590

Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Therefore, an attacker can log …

Mitigation only
Fix from $1,600 2020-01-02
Subscription Asset Manager MEDIUM 6.1
CVE-2014-0183

Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering.

Mitigation only
Fix from $1,600 2020-01-02