Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux Aus HIGH 7.5
CVE-2018-14638

A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function when persistent search connec…

Fix: 1.3.8.4+
Fix from $1,950 2018-09-14
Openshift Container Platform MEDIUM 5.4
CVE-2018-10937

A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods…

Patch available
Fix from $1,600 2018-09-11
Gluster Storage HIGH 8.1
CVE-2018-1127

Tendrl API in Red Hat Gluster Storage before 3.4.0 does not immediately remove session tokens after a user logs out. Session tokens remain active for…

Fix: 3.4+
Fix from $1,950 2018-09-11
389 Directory Server MEDIUM 6.5
CVE-2018-10935

A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.

Fix: 1.3.8.7 / 1.4.0.14+
Fix from $1,600 2018-09-11
Undertow MEDIUM 6.5
CVE-2018-1114

It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors…

Mitigation only
Fix from $1,600 2018-09-11
Jboss Enterprise Application Platform HIGH 7.8
CVE-2016-7066

It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local u…

Fix: 7.1.0+
Fix from $1,950 2018-09-11
Ansible Tower HIGH 8.0
CVE-2016-7070

A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trus…

Fix: 3.0.3+
Fix from $1,950 2018-09-11
Openstack CRITICAL 9.8
CVE-2018-14620

The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could potentially…

Mitigation only
Fix from $2,300 2018-09-10
Openstack MEDIUM 6.5
CVE-2018-14635

When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP add…

Fix: after 12.0.3
Fix from $1,600 2018-09-10
Enterprise Linux Server HIGH 7.8
CVE-2016-7035

An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged accou…

Fix: after 1.1.16
Fix from $1,950 2018-09-10
Jboss Brms MEDIUM 6.5
CVE-2016-7041

Drools Workbench contains a path traversal vulnerability. The vulnerability allows a remote, authenticated attacker to bypass the directory restricti…

Mitigation only
Fix from $1,600 2018-09-10
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2016-7061

An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC…

Fix: 7.0.4+
Fix from $1,600 2018-09-10
Cloudforms Management Engine HIGH 8.8
CVE-2016-7071

It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authent…

Fix: 5.6.2.2 / 5.7.0.7+
Fix from $1,950 2018-09-10
Openshift Container Platform HIGH 7.7
CVE-2018-14632

An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An a…

Fix: after 3.7
Fix from $1,950 2018-09-06
Enterprise Linux Desktop HIGH 7.5
CVE-2018-14624

A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the error log was not correctly u…

Fix: after 1.4.0.16
Fix from $1,950 2018-09-06
Openshift Container Platform HIGH 7.8
CVE-2018-16540

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in co…

Patch available
Fix from $1,950 2018-09-05
Enterprise Linux MEDIUM 5.5
CVE-2018-16542

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use insufficient interpreter stack-size checking during e…

Fix: 9.24+
Fix from $1,600 2018-09-05
Openshift Container Platform MEDIUM 5.3
CVE-2016-1000232

NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial…

Fix: after 5.0.7.2
Fix from $1,600 2018-09-05
Enterprise Linux MEDIUM 6.5
CVE-2018-10930

A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw to write to a destination ou…

Fix: 3.12.14 / 4.1.4+
Fix from $1,600 2018-09-04
Virtualization Host HIGH 8.8
CVE-2018-10926

A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to a…

Fix: 3.12.14 / 4.1.8+
Fix from $1,950 2018-09-04
Virtualization Host HIGH 8.1
CVE-2018-10923

It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker c…

Fix: 3.12.14 / 4.1.8+
Fix from $1,950 2018-09-04
Virtualization Host HIGH 7.5
CVE-2018-10911

A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read…

Fix: 3.12.14 / 4.1.8+
Fix from $1,950 2018-09-04
Virtualization Host MEDIUM 6.5
CVE-2018-10913

An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine t…

Fix: 3.12.14 / 4.1.8+
Fix from $1,600 2018-09-04
Virtualization Host MEDIUM 6.5
CVE-2018-10914

It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote de…

Fix: 3.12.14 / 4.1.8+
Fix from $1,600 2018-09-04
Virtualization Host HIGH 8.8
CVE-2018-10907

It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size…

Fix: 3.12.14 / 4.1.4+
Fix from $1,950 2018-09-04
Virtualization Host HIGH 8.8
CVE-2018-10904

It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debu…

Fix: 3.12.14 / 4.1.8+
Fix from $1,950 2018-09-04
Wildfly MEDIUM 5.9
CVE-2018-14627

The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version…

Fix: 14.0.0+
Fix from $1,600 2018-09-04
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-12825EPSS 7%

Adobe Flash Player 30.0.0.134 and earlier have a security bypass vulnerability. Successful exploitation could lead to security mitigation bypass.

Fix: after 30.0.0.154
Fix from $2,300 2018-08-29
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-12828EPSS 7%

Adobe Flash Player 30.0.0.134 and earlier have a "use of a component with a known vulnerability" vulnerability. Successful exploitation could lead to…

Fix: after 30.0.0.154
Fix from $2,300 2018-08-29
Enterprise Linux Desktop HIGH 7.5
CVE-2018-12826EPSS 7%

Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

Fix: after 30.0.0.154
Fix from $1,950 2018-08-29