Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jboss Portal MEDIUM 5.9
CVE-2014-0245

It was found that the implementation of the GTNSubjectCreatingInterceptor class in gatein-wsrp was not thread safe. For a specific WSRP endpoint, und…

Mitigation only
Fix from $1,600 2020-01-02
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2014-0169

In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could all…

Mitigation only
Fix from $1,600 2020-01-02
Quay MEDIUM 6.3
CVE-2019-10205

A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay …

Mitigation only
Fix from $1,600 2020-01-02
Ansible MEDIUM 6.5
CVE-2019-14864

Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True w…

Fix: 2.7.15 / 2.8.7+
Fix from $1,600 2020-01-02
Decision Manager MEDIUM 6.1
CVE-2019-14862

There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers…

Fix: after 3.4.2
Fix from $1,600 2020-01-02
Decision Manager MEDIUM 6.1
CVE-2019-14863

There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application de…

Fix: after 1.4.14
Fix from $1,600 2020-01-02
Jboss Data Grid CRITICAL 9.8
CVE-2019-10158

A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session inte…

Fix: after 9.4.14
Fix from $2,300 2020-01-02
Ceph Storage CRITICAL 9.1
CVE-2019-14859

A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this ver…

Fix: 0.13.3+
Fix from $2,300 2020-01-02
Mrg Management Console HIGH 7.5
CVE-2013-0264

An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary …

Patch available
Fix from $1,950 2019-12-30
Openshift MEDIUM 6.5
CVE-2013-0196

A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection me…

No fix yet
Fix from $1,600 2019-12-30
Openstack MEDIUM 5.5
CVE-2012-5474

The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2…

Fix: 2012.1.1+
Fix from $1,600 2019-12-30
Ceph Storage MEDIUM 6.5
CVE-2019-19337

A flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An authenticated attacker can abuse …

Mitigation only
Fix from $1,600 2019-12-23
Enterprise Linux HIGH 7.8
CVE-2019-18389

A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS use…

Fix: after 0.8.0
Fix from $1,950 2019-12-23
Enterprise Linux HIGH 7.1
CVE-2019-18390

An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a den…

Fix: after 0.8.0
Fix from $1,950 2019-12-23
Enterprise Linux MEDIUM 5.5
CVE-2019-18391

A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS use…

Fix: after 0.8.0
Fix from $1,600 2019-12-23
Jboss Fuse MEDIUM 6.1
CVE-2016-1000229

swagger-ui has XSS in key names

Mitigation only
Fix from $1,600 2019-12-20
Ansible Tower MEDIUM 5.5
CVE-2019-19341

A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' are left world-readable. These files include both …

Fix: 3.6.2+
Fix from $1,600 2019-12-19
Ansible Tower MEDIUM 5.3
CVE-2019-19342

A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and the password contains the '#'…

Fix: 3.5.4 / 3.6.2+
Fix from $1,600 2019-12-19
Ansible Tower HIGH 8.2
CVE-2019-19340

A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e rabbitm…

Fix: 3.5.3 / 3.6.2+
Fix from $1,950 2019-12-19
Jboss Application Server HIGH 7.8
CVE-2012-2312

An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat …

Mitigation only
Fix from $1,950 2019-12-18
Edeploy CRITICAL 9.8
CVE-2014-3699

eDeploy has RCE via cPickle deserialization of untrusted data

No fix yet
Fix from $2,300 2019-12-15
Edeploy HIGH 8.1
CVE-2014-3701

eDeploy has tmp file race condition flaws

No fix yet
Fix from $1,950 2019-12-15
Keycloak MEDIUM 6.1
CVE-2014-3652

JBoss KeyCloak: Open redirect vulnerability via failure to validate the redirect URL.

Patch available
Fix from $1,600 2019-12-15
Cloudforms Management Engine MEDIUM 5.5
CVE-2014-3536

CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration

Mitigation only
Fix from $1,600 2019-12-15
Satellite MEDIUM 5.5
CVE-2014-0241

rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable

Mitigation only
Fix from $1,600 2019-12-13
Openshift CRITICAL 9.8
CVE-2014-0175

mcollective has a default password set at install

Mitigation only
Fix from $2,300 2019-12-13
Cloudforms HIGH 8.8
CVE-2014-0197

CFME: CSRF protection vulnerability via permissive check of the referrer header

Fix: after 5.9.3.1
Fix from $1,950 2019-12-13
Enterprise Linux MEDIUM 6.5
CVE-2019-16775

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of…

Fix: 6.13.3+
Fix from $1,600 2019-12-13
3scale MEDIUM 5.4
CVE-2019-14849

A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to …

Fix: 2.6+
Fix from $1,600 2019-12-12
Openshift HIGH 8.8
CVE-2014-0163

Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.

Mitigation only
Fix from $1,950 2019-12-11