Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Linux Desktop MEDIUM 6.5
CVE-2018-6104

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoo…

Fix: 66.0.3359.117+
Fix from $1,600 2018-12-04
Linux Desktop MEDIUM 6.5
CVE-2018-6105

Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing v…

Fix: 66.0.3359.117+
Fix from $1,600 2018-12-04
Linux Desktop MEDIUM 6.5
CVE-2018-6107

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoo…

Fix: 66.0.3359.117+
Fix from $1,600 2018-12-04
Linux Desktop MEDIUM 6.5
CVE-2018-6108

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoo…

Fix: 66.0.3359.117+
Fix from $1,600 2018-12-04
Enterprise Linux Desktop HIGH 7.8
CVE-2018-16863

It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSA…

Patch available
Fix from $1,950 2018-12-03
Keycloak HIGH 8.1
CVE-2018-14637

The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit th…

Fix: 4.6.0+
Fix from $1,950 2018-11-30
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-15981EPSS 12%

Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

Fix: after 31.0.0.148
Fix from $2,300 2018-11-29
Enterprise Linux Desktop HIGH 7.5
CVE-2018-15978EPSS 7%

Flash Player versions 31.0.0.122 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

Fix: after 31.0.0.122
Fix from $1,950 2018-11-29
Keycloak HIGH 8.1
CVE-2018-14657

A flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force detection algorithm will not …

Mitigation only
Fix from $1,950 2018-11-13
Keycloak MEDIUM 6.1
CVE-2018-14658

A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.Red…

Mitigation only
Fix from $1,600 2018-11-13
Keycloak MEDIUM 5.4
CVE-2018-14655

A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible to inject arbitrary Javascrip…

Mitigation only
Fix from $1,600 2018-11-13
Enterprise Linux HIGH 7.8
CVE-2018-19214

Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for insufficient input.

Patch available
Fix from $1,950 2018-11-12
Enterprise Linux HIGH 7.8
CVE-2018-19215

Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for the special cases of the % and $ and !…

No fix yet
Fix from $1,950 2018-11-12
Enterprise Linux MEDIUM 6.5
CVE-2018-19208

In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a d…

No fix yet
Fix from $1,600 2018-11-12
Fedora MEDIUM 5.5
CVE-2018-19139

An issue has been found in JasPer 2.0.14. There is a memory leak in jas_malloc.c when called from jpc_unk_getparms in jpc_cs.c.

No fix yet
Fix from $1,600 2018-11-09
Richfaces CRITICAL 9.8
CVE-2018-14667 KEVEPSS 74%

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticate…

Fix: after 3.3.4
Fix from $2,300 2018-11-06
Openstack Mistral HIGH 7.5
CVE-2018-16849

A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbit…

Fix: 7.0.1+
Fix from $1,950 2018-11-02
Virtualization Host MEDIUM 6.5
CVE-2018-14660

A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated…

Fix: after 4.1.4
Fix from $1,600 2018-11-01
Gluster Storage MEDIUM 6.5
CVE-2016-2125EPSS 9%

It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to wh…

Fix: 4.3.13 / 4.4.8+
Fix from $1,600 2018-10-31
Gluster Storage HIGH 8.8
CVE-2018-14653

The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the '__server_getspec' function via the 'gf_…

Fix: after 4.1.4
Fix from $1,950 2018-10-31
Gluster Storage MEDIUM 6.5
CVE-2018-14652

The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' translator via the code handling t…

Fix: after 4.1.8
Fix from $1,600 2018-10-31
Gluster Storage MEDIUM 6.5
CVE-2018-14654

The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attacker with access to mount volum…

Fix: after 4.1.4
Fix from $1,600 2018-10-31
Gluster File System MEDIUM 6.5
CVE-2018-14659

The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_XATTR_IOSTATS_DUMP_KEY' xattr…

Fix: after 4.1.4
Fix from $1,600 2018-10-31
Cloudforms HIGH 8.8
CVE-2016-5402EPSS 6%

A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with acces…

Mitigation only
Fix from $1,950 2018-10-31
Openstack MEDIUM 5.5
CVE-2016-2121

A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitive informat…

Mitigation only
Fix from $1,600 2018-10-31
Jboss Bpm Suite MEDIUM 5.4
CVE-2016-6343

JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that have privileges to access da…

Fix: 6.4.2+
Fix from $1,600 2018-10-31
Enterprise Linux Desktop MEDIUM 6.6
CVE-2018-14665EPSS 27%

A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server al…

Patch available
Fix from $1,600 2018-10-25
Enterprise Linux HIGH 7.8
CVE-2016-10729

An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binar…

No fix yet
Fix from $1,950 2018-10-24
Enterprise Linux HIGH 7.8
CVE-2016-10730

An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Applicatio…

No fix yet
Fix from $1,950 2018-10-24
Ansible Engine HIGH 7.8
CVE-2018-16837

Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases c…

Mitigation only
Fix from $1,950 2018-10-23