Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Satellite MEDIUM 5.5
CVE-2014-0241

rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable

Mitigation only
Fix from $1,600 2019-12-13
Openshift CRITICAL 9.8
CVE-2014-0175

mcollective has a default password set at install

Mitigation only
Fix from $2,300 2019-12-13
Cloudforms HIGH 8.8
CVE-2014-0197

CFME: CSRF protection vulnerability via permissive check of the referrer header

Fix: after 5.9.3.1
Fix from $1,950 2019-12-13
Enterprise Linux MEDIUM 6.5
CVE-2019-16775

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of…

Fix: 6.13.3+
Fix from $1,600 2019-12-13
3scale MEDIUM 5.4
CVE-2019-14849

A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to …

Fix: 2.6+
Fix from $1,600 2019-12-12
Openshift HIGH 8.8
CVE-2014-0163

Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.

Mitigation only
Fix from $1,950 2019-12-11
Subscription Asset Manager MEDIUM 6.5
CVE-2014-0026

katello-headpin is vulnerable to CSRF in REST API

No fix yet
Fix from $1,600 2019-12-11
Jboss Enterprise Application Platform MEDIUM 6.1
CVE-2013-6495

JBossWeb Bayeux has reflected XSS

Fix: 6.1.0 / 6.1.1+
Fix from $1,600 2019-12-11
Openshift MEDIUM 6.1
CVE-2013-7370

node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware

Fix: 2.8.1+
Fix from $1,600 2019-12-11
Openstack CRITICAL 9.8
CVE-2013-2166

python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass

Fix: after 0.2.5
Fix from $2,300 2019-12-10
Openstack CRITICAL 9.8
CVE-2013-2167

python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass

Fix: after 0.2.5
Fix from $2,300 2019-12-10
Jboss Keycloak MEDIUM 6.1
CVE-2014-3656

JBoss KeyCloak: XSS in login-status-iframe.html

No fix yet
Fix from $1,600 2019-12-10
Openstack HIGH 7.5
CVE-2013-1793

openstack-utils openstack-db has insecure password creation

Mitigation only
Fix from $1,950 2019-12-10
Enterprise Linux CRITICAL 9.8
CVE-2019-19333

In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "bits…

Patch available
Fix from $2,300 2019-12-06
Enterprise Linux CRITICAL 9.8
CVE-2019-19334

In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "iden…

Patch available
Fix from $2,300 2019-12-06
Enterprise Linux MEDIUM 6.5
CVE-2019-19624

An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifically, variable coarsest_scale is assumed to be greater than or equal to finest_s…

Fix: 4.1.1+
Fix from $1,600 2019-12-06
Keycloak CRITICAL 9.8
CVE-2019-14910

A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDA…

Mitigation only
Fix from $2,300 2019-12-05
Openshift MEDIUM 5.5
CVE-2013-0163

OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS

Mitigation only
Fix from $1,600 2019-12-05
Keycloak HIGH 8.3
CVE-2019-14909

A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will…

Mitigation only
Fix from $1,950 2019-12-04
Enterprise Linux MEDIUM 6.5
CVE-2019-13456

In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iteratio…

Fix: after 3.0.19
Fix from $1,600 2019-12-03
Zanata CRITICAL 9.8
CVE-2013-4486

Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging

Fix: after 3.1.2
Fix from $2,300 2019-12-03
Openshift HIGH 8.1
CVE-2013-2103

OpenShift cartridge allows remote URL retrieval

Mitigation only
Fix from $1,950 2019-12-03
Satellite MEDIUM 5.4
CVE-2013-2101

Katello has multiple XSS issues in various entities

No fix yet
Fix from $1,600 2019-12-03
Satellite HIGH 8.6
CVE-2012-5562

A flaw was found in rhn-proxy. This vulnerability may allow the rhn-proxy to transmit user credentials in clear-text when it accesses RHN Satellite. …

Fix: 5.6+
Fix from $1,950 2019-12-02
Enterprise Linux MEDIUM 5.3
CVE-2011-2207

dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafte…

Fix: 2.1.0+
Fix from $1,600 2019-11-27
3scale Api Management HIGH 7.8
CVE-2019-10216

In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` rest…

Patch available
Fix from $1,950 2019-11-27
Libnbd CRITICAL 9.8
CVE-2019-14842

Structured reply is a feature of the newstyle NBD protocol allowing the server to send a reply in chunks. A bounds check which was supposed to test f…

Fix: 1.0.3+
Fix from $2,300 2019-11-26
Ansible MEDIUM 6.5
CVE-2019-14856

ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None

Fix: 2.6.20 / 2.7.14+
Fix from $1,600 2019-11-26
Ansible Tower HIGH 8.4
CVE-2019-14890

A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from …

Mitigation only
Fix from $1,950 2019-11-26
Jboss Application Server MEDIUM 6.5
CVE-2011-3609

A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for …

Mitigation only
Fix from $1,600 2019-11-26