Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Satellite HIGH 7.8
CVE-2019-3891

It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin da…

No fix yet
Fix from $1,950 2019-04-15
Satellite HIGH 8.0
CVE-2019-3845

A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite…

Fix: 6.2+
Fix from $1,950 2019-04-11
Enterprise Linux HIGH 7.0
CVE-2019-3842

In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is p…

Fix: after 241
Fix from $1,950 2019-04-09
Enterprise Linux Server Aus HIGH 7.5
CVE-2017-3139

A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly w…

Mitigation only
Fix from $1,950 2019-04-09
Enterprise Linux MEDIUM 6.5
CVE-2019-0757

A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package'…

Patch available
Fix from $1,600 2019-04-09
Openstack MEDIUM 6.5
CVE-2019-10876

An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with sep…

Fix: 11.0.7 / 12.0.6+
Fix from $1,600 2019-04-05
Libvirt MEDIUM 5.4
CVE-2019-3886

An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest a…

Fix: 5.3.0+
Fix from $1,600 2019-04-04
Openshift Container Platform MEDIUM 6.3
CVE-2019-3876

A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X…

Fix: after 3.11
Fix from $1,600 2019-04-01
Ansible Tower HIGH 7.2
CVE-2019-3869

When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A mal…

Fix: 3.3.5 / 3.4.3+
Fix from $1,950 2019-03-28
Libvirt MEDIUM 6.3
CVE-2019-3840

A NULL pointer dereference flaw was discovered in libvirt before version 5.0.0 in the way it gets interface information through the QEMU agent. An at…

Fix: 5.0.0+
Fix from $1,600 2019-03-27
Jboss Enterprise Application Platform MEDIUM 5.4
CVE-2018-10934

A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can c…

Mitigation only
Fix from $1,600 2019-03-27
Openstack HIGH 7.8
CVE-2019-3830

A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data t…

Fix: after 2015.1.4
Fix from $1,950 2019-03-26
Openstack HIGH 7.5
CVE-2018-16856

In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.…

Fix: 2.0.2-5 / 3.0.1-0.20181009115732+
Fix from $1,950 2019-03-26
Virtualization HIGH 8.1
CVE-2019-3879

It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission …

Fix: 4.3.2.1+
Fix from $1,950 2019-03-25
Ansible Tower MEDIUM 5.5
CVE-2019-3835

It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file cou…

No fix yet
Fix from $1,600 2019-03-25
Ansible Tower MEDIUM 5.5
CVE-2019-3838

It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript …

Patch available
Fix from $1,600 2019-03-25
Ovirt Engine HIGH 8.8
CVE-2017-7510

In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.

Mitigation only
Fix from $1,950 2019-03-25
Gluster Storage MEDIUM 6.7
CVE-2019-3831

A vulnerability was discovered in vdsm, version 4.19 through 4.30.3 and 4.30.5 through 4.30.8. The systemd_run function exposed to the vdsm system us…

Fix: after 4.30.8
Fix from $1,600 2019-03-25
Enterprise Linux MEDIUM 5.4
CVE-2018-16838

A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the ser…

Mitigation only
Fix from $1,600 2019-03-25
Enterprise Linux HIGH 7.5
CVE-2019-3816EPSS 15%

Openwsman, versions up to and including 2.6.9, are vulnerable to arbitrary file disclosure because the working directory of openwsmand daemon was set…

Mitigation only
Fix from $1,950 2019-03-14
Openstack MEDIUM 6.5
CVE-2019-9735

An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 1…

Fix: 10.0.8 / 11.0.7+
Fix from $1,600 2019-03-13
Satellite CRITICAL 9.8
CVE-2018-12547

In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects exis…

Fix: 0.12.0+
Fix from $2,300 2019-02-11
Satellite CRITICAL 9.8
CVE-2018-12549

In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when acceleratin…

Mitigation only
Fix from $2,300 2019-02-11
Enterprise Linux MEDIUM 5.5
CVE-2019-7664

In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check. Crafted elf in…

No fix yet
Fix from $1,600 2019-02-09
Pagure MEDIUM 5.9
CVE-2019-7628

Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for man-in-the-middle attackers to …

Patch available
Fix from $1,600 2019-02-08
Openshift Container Platform HIGH 7.5
CVE-2019-3818

The kube-rbac-proxy container before version 0.4.1 as used in Red Hat OpenShift Container Platform does not honor TLS configurations, allowing for us…

Fix: 0.4.1+
Fix from $1,950 2019-02-05
Enterprise Linux Desktop HIGH 7.5
CVE-2019-3813

Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a deni…

Mitigation only
Fix from $1,950 2019-02-04
Ceph HIGH 7.5
CVE-2018-16889

Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files …

Fix: after 13.2.4
Fix from $1,950 2019-01-28
Virtualization Manager HIGH 7.5
CVE-2018-16881

A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket,…

Patch available
Fix from $1,950 2019-01-25
Satellite HIGH 7.2
CVE-2018-14666

An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered…

Fix: after 6.4
Fix from $1,950 2019-01-22