Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openshift MEDIUM 5.3
CVE-2019-14845

A vulnerability was found in OpenShift builds, versions 4.1 up to 4.3. Builds that extract source from a container image, bypass the TLS hostname ver…

Fix: after 4.3
Fix from $1,600 2019-10-08
Jboss Operations Network HIGH 7.3
CVE-2019-3834

It was found that the fix for CVE-2014-0114 had been reverted in JBoss Operations Network 3 (JON). This flaw allows attackers to manipulate ClassLoad…

Fix: 3.3.11+
Fix from $1,950 2019-10-03
Undertow CRITICAL 9.8
CVE-2019-10212

A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to o…

Fix: 2.0.20+
Fix from $2,300 2019-10-02
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2019-10202EPSS 5%

A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525…

Mitigation only
Fix from $2,300 2019-10-01
Tectonic MEDIUM 6.1
CVE-2018-9090

CoreOS Tectonic 1.7.x and 1.8.x before 1.8.7-tectonic.2 deploys the Grafana web application using default credentials (admin/admin) for the administr…

Fix: 1.8.7-tectonic.2+
Fix from $1,600 2019-09-24
Openshift Container Platform CRITICAL 9.8
CVE-2019-14813EPSS 11%

A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, en…

Patch available
Fix from $2,300 2019-09-06
Virtualization Host MEDIUM 5.6
CVE-2019-1125

An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully …

Patch available
Fix from $1,600 2019-09-03
Openshift Container Platform HIGH 7.8
CVE-2019-14811

A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls…

Fix: 9.50+
Fix from $1,950 2019-09-03
Openshift Container Platform HIGH 7.8
CVE-2019-14817

A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged ca…

Fix: 9.50+
Fix from $1,950 2019-09-03
Keycloak HIGH 8.8
CVE-2019-10199

It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw t…

Fix: after 6.0.1
Fix from $1,950 2019-08-14
Keycloak HIGH 8.1
CVE-2019-10201

It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response …

Fix: after 6.0.1
Fix from $1,950 2019-08-14
Openshift Container Platform MEDIUM 5.4
CVE-2019-10176

A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found …

Mitigation only
Fix from $1,600 2019-08-02
Enterprise Linux Server Eus HIGH 7.5
CVE-2019-10171

It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would…

Fix: 1.4.0.17+
Fix from $1,950 2019-08-02
Libvirt HIGH 7.8
CVE-2019-10166

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDe…

Fix: 4.10.1 / 5.4.1+
Fix from $1,950 2019-08-02
Libvirt HIGH 7.8
CVE-2019-10167

The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify …

Fix: 4.10.1 / 5.4.1+
Fix from $1,950 2019-08-02
Libvirt HIGH 7.8
CVE-2019-10168

The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emula…

Fix: 4.10.1 / 5.4.1+
Fix from $1,950 2019-08-02
Enterprise Linux HIGH 8.1
CVE-2019-3890

It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential …

Fix: 3.31.3+
Fix from $1,950 2019-08-01
Openshift MEDIUM 5.4
CVE-2019-3884

A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namesp…

Mitigation only
Fix from $1,600 2019-08-01
Openstack HIGH 8.8
CVE-2018-10899

A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly c…

Fix: 1.6.1+
Fix from $1,950 2019-08-01
Satellite HIGH 7.4
CVE-2014-8183

It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker wi…

Fix: 1.15.6+
Fix from $1,950 2019-08-01
Enterprise Linux Desktop MEDIUM 6.5
CVE-2019-10182

It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a vi…

Fix: after 1.7.2
Fix from $1,600 2019-07-31
Satellite MEDIUM 6.5
CVE-2019-10198

An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, w…

Fix: 0.15.7+
Fix from $1,600 2019-07-31
Libvirt HIGH 7.8
CVE-2019-10161

It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specif…

Fix: 4.10.1 / 5.4.1+
Fix from $1,950 2019-07-30
Ansible MEDIUM 5.4
CVE-2019-10156

A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of informati…

Fix: 2.6.18 / 2.7.12+
Fix from $1,600 2019-07-30
Enterprise Linux MEDIUM 5.0
CVE-2019-10153

A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment or other fields would cause f…

Fix: 4.3.4+
Fix from $1,600 2019-07-30
Openstack CRITICAL 9.1
CVE-2019-10141

A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability wa…

Fix: 5.0.2 / 6.0.3+
Fix from $2,300 2019-07-30
Satellite HIGH 7.4
CVE-2019-11775

All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by ver…

Fix: 0.15.0+
Fix from $1,950 2019-07-30
Undertow HIGH 7.5
CVE-2019-10184

undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through reque…

Fix: 2.0.23+
Fix from $1,950 2019-07-25
Openshift Container Platform MEDIUM 5.4
CVE-2019-3889

A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 thr…

Fix: after 3.11
Fix from $1,600 2019-07-11
Virtualization Manager MEDIUM 5.5
CVE-2019-10194

Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could b…

Mitigation only
Fix from $1,600 2019-07-11