Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jboss Application Server MEDIUM 5.4
CVE-2011-3606

A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could…

Mitigation only
Fix from $1,600 2019-11-26
Ansible MEDIUM 6.5
CVE-2019-10217

A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP m…

Fix: 2.8.4+
Fix from $1,600 2019-11-25
Openshift Container Platform MEDIUM 6.5
CVE-2019-10213

OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set t…

Patch available
Fix from $1,600 2019-11-25
Enterprise Linux HIGH 7.1
CVE-2019-14822

A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another…

Fix: 1.5.22+
Fix from $1,950 2019-11-25
Openshift Container Platform MEDIUM 5.9
CVE-2019-10214

The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Con…

Patch available
Fix from $1,600 2019-11-25
Fuse HIGH 8.8
CVE-2019-10174

A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to in…

Fix: 8.2.12 / 9.4.17+
Fix from $1,950 2019-11-25
Enterprise Linux Openstack Platform MEDIUM 6.5
CVE-2015-5694

Designate does not enforce the DNS protocol limit concerning record set sizes

Mitigation only
Fix from $1,600 2019-11-22
Redhat Upgrade Tool CRITICAL 9.8
CVE-2014-3585

redhat-upgrade-tool: Does not check GPG signatures when upgrading versions

Mitigation only
Fix from $2,300 2019-11-22
Ovirt Engine MEDIUM 6.5
CVE-2015-1780

oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center

Mitigation only
Fix from $1,600 2019-11-22
Ansible MEDIUM 6.5
CVE-2019-10206

ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by …

Fix: 2.6.19 / 2.7.13+
Fix from $1,600 2019-11-22
Cloudforms Management Engine MEDIUM 5.4
CVE-2018-10854

cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in CloudForms's v2v infrastructure m…

Mitigation only
Fix from $1,600 2019-11-22
Edeploy CRITICAL 9.8
CVE-2014-3700

eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data

Fix: after 1.6.0
Fix from $2,300 2019-11-21
Enterprise Mrg CRITICAL 9.8
CVE-2012-3460

cumin: At installation postgresql database user created without password

Mitigation only
Fix from $2,300 2019-11-21
Openshift Origin MEDIUM 5.5
CVE-2014-0084

Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of service in cron.daily and cron.…

Fix: 2014-02-14+
Fix from $1,600 2019-11-21
Tuned MEDIUM 5.5
CVE-2012-6136

tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.

Mitigation only
Fix from $1,600 2019-11-20
Enterprise Linux HIGH 7.5
CVE-2011-4967

tog-Pegasus has a package hash collision DoS vulnerability

Fix: 2.12+
Fix from $1,950 2019-11-19
Enterprise Linux MEDIUM 5.5
CVE-2014-5118

Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability

Fix: 1.8.2+
Fix from $1,600 2019-11-18
Jboss Enterprise Application Platform HIGH 7.5
CVE-2019-10172EPSS 17%

A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects c…

Fix: after 1.9.13
Fix from $1,950 2019-11-18
Openshift HIGH 7.8
CVE-2014-0023

OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution

Mitigation only
Fix from $1,950 2019-11-15
Enterprise Linux Server Aus HIGH 7.8
CVE-2019-0155

Insufficient access control in a subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;…

Fix: 4.4.201 / 4.9.201+
Fix from $1,950 2019-11-14
Enterprise Linux Fast Datapath HIGH 7.5
CVE-2019-14818

A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious…

Fix: 16.11.10 / 17.11.8+
Fix from $1,950 2019-11-14
Enterprise Virtualization MEDIUM 5.9
CVE-2014-8167

vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack

Mitigation only
Fix from $1,600 2019-11-13
Openshift Origin MEDIUM 6.1
CVE-2014-3592

OpenShift Origin: Improperly validated team names could allow stored XSS attacks

Fix: after 2014-08-13
Fix from $1,600 2019-11-13
Jboss Business Rules Management System MEDIUM 6.1
CVE-2010-3857

JBoss BRMS before 5.1.0 has a XSS vulnerability via asset=UUID parameter.

Fix: 5.1.0+
Fix from $1,600 2019-11-12
Hornetq MEDIUM 6.5
CVE-2014-3599

HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy

Fix: after 2.4.5
Fix from $1,600 2019-11-12
Enterprise Linux CRITICAL 9.8
CVE-2011-2897

gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw

Fix: after 2.31.1
Fix from $2,300 2019-11-12
Ceph Storage HIGH 7.5
CVE-2019-10222

A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph…

Patch available
Fix from $1,950 2019-11-08
Enterprise Linux MEDIUM 6.5
CVE-2019-14824

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations,…

Mitigation only
Fix from $1,600 2019-11-08
Fuse MEDIUM 6.5
CVE-2019-14860

It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of prote…

Fix: 7.5.0+
Fix from $1,600 2019-11-08
Hibernate Validator MEDIUM 6.1
CVE-2019-10219

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially mal…

Fix: 6.0.18+
Fix from $1,600 2019-11-08