Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tuned MEDIUM 5.5
CVE-2013-1820

tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.

Fix: 2.0.2+
Fix from $1,600 2019-11-08
Openstack Mistral MEDIUM 5.5
CVE-2019-3866

An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world…

Mitigation only
Fix from $1,600 2019-11-08
Jboss Operations Network MEDIUM 6.5
CVE-2008-5083

In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBoss ON.

Fix: 2.1.2+
Fix from $1,600 2019-11-08
Frysk HIGH 7.8
CVE-2008-3278

frysk packages through 2008-08-05 as shipped in Red Hat Enterprise Linux 5 are built with an insecure RPATH set in the ELF header of multiple binarie…

Fix: after 2008-08-05
Fix from $1,950 2019-11-07
Pagure MEDIUM 6.1
CVE-2016-1000037

Pagure: XSS possible in file attachment endpoint

Fix: 2.3.4+
Fix from $1,600 2019-11-06
Enterprise Linux MEDIUM 5.5
CVE-2014-8181

The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace.

Mitigation only
Fix from $1,600 2019-11-06
Directory Server HIGH 7.5
CVE-2010-2222

The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a denial of service (NULL pointe…

Patch available
Fix from $1,950 2019-11-05
Enterprise Linux MEDIUM 5.9
CVE-2013-5661

Cache Poisoning issue exists in DNS Response Rate Limiting.

Fix: 1.3.0+
Fix from $1,600 2019-11-05
Rhq Mongo Db Drift Server HIGH 7.1
CVE-2013-4374

An insecurity temporary file vulnerability exists in RHQ Mongo DB Drift Server through 2013-09-25 when unpacking zipped files.

Fix: after 2013-09-25
Fix from $1,950 2019-11-04
Enterprise Linux CRITICAL 9.8
CVE-2015-8980EPSS 7%

The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code.

Fix: 1.0.12+
Fix from $2,300 2019-11-04
Enterprise Linux HIGH 7.8
CVE-2017-5332

The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cau…

Patch available
Fix from $1,950 2019-11-04
Enterprise Linux HIGH 7.8
CVE-2017-5333

Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a d…

Patch available
Fix from $1,950 2019-11-04
Virtual Desktop Server Manager MEDIUM 5.5
CVE-2013-4280

Insecure temporary file vulnerability in RedHat vsdm 4.9.6.

No fix yet
Fix from $1,600 2019-11-04
Jboss Aerogear MEDIUM 6.1
CVE-2014-3649

JBoss AeroGear has reflected XSS via the password field

Fix: after 2014-09-19
Fix from $1,600 2019-11-04
Cloudforms MEDIUM 5.5
CVE-2013-4423

CloudForms stores user passwords in recoverable format

Mitigation only
Fix from $1,600 2019-11-04
Update Infrastructure MEDIUM 5.5
CVE-2013-4518

RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates

No fix yet
Fix from $1,600 2019-11-04
Enterprise Linux HIGH 7.5
CVE-2019-6470EPSS 9%

There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in …

No fix yet
Fix from $1,950 2019-11-01
Openshift HIGH 7.3
CVE-2013-0165

cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp.

Mitigation only
Fix from $1,950 2019-11-01
Cloudforms MEDIUM 6.1
CVE-2013-0186

Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspecified ve…

Mitigation only
Fix from $1,600 2019-11-01
Openstack MEDIUM 5.9
CVE-2013-2255

HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL cert…

Mitigation only
Fix from $1,600 2019-11-01
Icedtea6 CRITICAL 9.1
CVE-2010-2548

IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.

Fix: 1.7.4+
Fix from $2,300 2019-10-31
Icedtea6 CRITICAL 9.1
CVE-2010-2783

IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services.

Fix: 1.7.4+
Fix from $2,300 2019-10-31
Jboss Operations Network HIGH 8.0
CVE-2010-0737

A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON u…

Fix: 2.3.1+
Fix from $1,950 2019-10-30
Satellite CRITICAL 9.1
CVE-2019-17631

From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privil…

Fix: after 0.16.0
Fix from $2,300 2019-10-17
Enterprise Linux Desktop MEDIUM 6.8
CVE-2019-2989

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7…

Fix: after 11.50.2
Fix from $1,600 2019-10-16
Keycloak HIGH 7.5
CVE-2019-14832

A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authent…

Fix: 7.0.1+
Fix from $1,950 2019-10-15
Enterprise Linux HIGH 7.4
CVE-2019-14823

A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly tru…

Fix: after 4.6.2
Fix from $1,950 2019-10-14
Ansible Engine MEDIUM 5.5
CVE-2019-14858

A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters mar…

Fix: after 3.5.0
Fix from $1,600 2019-10-14
Enterprise Linux MEDIUM 5.3
CVE-2019-6465

Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 …

Fix: after 9.13.6
Fix from $1,600 2019-10-09
Ansible Engine HIGH 7.8
CVE-2019-14846

In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level whi…

Fix: 2.6.20 / 2.7.14+
Fix from $1,950 2019-10-08