Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openshift Container Platform CRITICAL 9.8
CVE-2018-11307EPSS 6%

An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows…

Fix: 2.6.7.3 / 2.7.9.4+
Fix from $2,300 2019-07-09
Virt Bootstrap HIGH 7.8
CVE-2019-13314

virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password…

No fix yet
Fix from $1,950 2019-07-05
Satellite CRITICAL 9.8
CVE-2019-10137

A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthen…

Fix: after 2.9
Fix from $2,300 2019-07-02
Cloudforms Management Engine MEDIUM 6.5
CVE-2019-10177

A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user input is no…

Mitigation only
Fix from $1,600 2019-06-27
Enterprise Linux HIGH 7.8
CVE-2012-6711

A heap-based buffer overflow exists in GNU Bash before 4.3 when wide characters, not supported by the current locale set in the LC_CTYPE environment …

Fix: after 4.3
Fix from $1,950 2019-06-18
Enterprise Linux Desktop HIGH 8.8
CVE-2019-7845EPSS 6%

Adobe Flash Player versions 32.0.0.192 and earlier, 32.0.0.192 and earlier, and 32.0.0.192 and earlier have an use after free vulnerability. Successf…

Fix: after 32.0.0.192
Fix from $1,950 2019-06-12
Undertow CRITICAL 9.8
CVE-2019-3888

A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connector…

Fix: 2.0.21+
Fix from $2,300 2019-06-12
Jboss Enterprise Application Platform CRITICAL 9.0
CVE-2019-3873

It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An att…

Mitigation only
Fix from $2,300 2019-06-12
Jboss Enterprise Application Platform MEDIUM 5.4
CVE-2019-3872

It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. …

Mitigation only
Fix from $1,600 2019-06-12
Openshift Container Platform MEDIUM 5.9
CVE-2019-10150

It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during…

Fix: after 4.1
Fix from $1,600 2019-06-12
Keycloak MEDIUM 5.5
CVE-2019-10157

It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel l…

Fix: 4.8.3 / 7.3.2+
Fix from $1,600 2019-06-12
Cloudforms Management Engine MEDIUM 5.3
CVE-2017-15123

A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users onl…

Fix: after 5.10
Fix from $1,600 2019-06-12
Enterprise Linux HIGH 7.0
CVE-2019-9755

An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafte…

Mitigation only
Fix from $1,950 2019-06-05
Openstack HIGH 8.0
CVE-2019-3895

An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker c…

Fix: 0.9.0+
Fix from $1,950 2019-06-03
Rkt HIGH 7.7
CVE-2019-10144

rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are given all capab…

Fix: after 1.30.0
Fix from $1,950 2019-06-03
Rkt HIGH 7.7
CVE-2019-10145

rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` do not have seccomp…

Fix: after 1.30.0
Fix from $1,950 2019-06-03
Rkt HIGH 7.7
CVE-2019-10147

rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are not limited by …

Fix: after 1.30.0
Fix from $1,950 2019-06-03
Enterprise Linux Desktop HIGH 8.8
CVE-2019-7837EPSS 10%

Adobe Flash Player versions 32.0.0.171 and earlier, 32.0.0.171 and earlier, and 32.0.0.171 and earlier have a use after free vulnerability. Successfu…

Fix: after 32.0.0.171
Fix from $1,950 2019-05-22
Libvirt HIGH 8.8
CVE-2019-10132

A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configurati…

Fix: after 4.1.0
Fix from $1,950 2019-05-22
Enterprise Linux HIGH 7.5
CVE-2019-0820EPSS 6%

A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial…

Patch available
Fix from $1,950 2019-05-16
Kie Server CRITICAL 9.8
CVE-2016-7043

It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any…

Fix: 7.21.0+
Fix from $2,300 2019-05-15
Wildfly HIGH 8.8
CVE-2019-3894

It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread …

Fix: after 16.0.0
Fix from $1,950 2019-05-03
Enterprise Linux HIGH 7.1
CVE-2019-10131

An off-by-one read vulnerability was discovered in ImageMagick before version 7.0.7-28 in the formatIPTCfromBuffer function in coders/meta.c. A local…

Fix: 6.9.9-40 / 7.0.7-28+
Fix from $1,950 2019-04-30
Openshift Service Mesh HIGH 8.3
CVE-2019-9900

When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers c…

Fix: after 1.9.0
Fix from $1,950 2019-04-25
Openshift Container Platform HIGH 8.1
CVE-2019-2698EPSS 12%

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Diffi…

Patch available
Fix from $1,950 2019-04-23
Openshift Container Platform MEDIUM 5.9
CVE-2019-2684EPSS 38%

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u2…

Patch available
Fix from $1,600 2019-04-23
Openshift Container Platform HIGH 7.5
CVE-2019-2602

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java S…

Patch available
Fix from $1,950 2019-04-23
Openshift Container Platform CRITICAL 9.8
CVE-2019-3899

It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This i…

Mitigation only
Fix from $2,300 2019-04-22
Satellite HIGH 7.5
CVE-2019-10245

In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causi…

Fix: 0.14.0+
Fix from $1,950 2019-04-19
Libvirt HIGH 7.5
CVE-2016-10746

libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was …

Fix: 1.3.1+
Fix from $1,950 2019-04-18