Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux Desktop HIGH 7.5
CVE-2018-12827EPSS 32%

Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

Fix: after 30.0.0.154
Fix from $1,950 2018-08-29
Enterprise Linux Desktop MEDIUM 5.9
CVE-2018-12824EPSS 11%

Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

Fix: after 30.0.0.154
Fix from $1,600 2018-08-29
Enterprise Linux Desktop MEDIUM 6.5
CVE-2017-15419

Insufficient policy enforcement in Resource Timing API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to infer browsing history by …

Fix: 63.0.3239.84+
Fix from $1,600 2018-08-28
Enterprise Linux Desktop MEDIUM 6.5
CVE-2017-15416

Heap buffer overflow in Blob API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafte…

Fix: 63.0.3239.84+
Fix from $1,600 2018-08-28
Enterprise Linux Desktop HIGH 8.8
CVE-2017-15413

Type confusion in WebAssembly in V8 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a cra…

Fix: 63.0.3239.84+
Fix from $1,950 2018-08-28
Enterprise Linux Desktop HIGH 8.8
CVE-2017-15412

Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potentially e…

Fix: 2.9.5 / 63.0.3239.84+
Fix from $1,950 2018-08-28
Openstack HIGH 7.5
CVE-2017-15139

A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configura…

Fix: after 12.0.4-7
Fix from $1,950 2018-08-27
Libvirt MEDIUM 6.5
CVE-2017-2635

A NULL pointer deference flaw was found in the way libvirt from 2.5.0 to 3.0.0 handled empty drives. A remote authenticated attacker could use this f…

Fix: after 3.0.0
Fix from $1,600 2018-08-22
Openstack HIGH 8.2
CVE-2017-2627

A flaw was found in openstack-tripleo-common as shipped with Red Hat Openstack Enterprise 10 and 11. The sudoers file as installed with OSP's opensta…

Mitigation only
Fix from $1,950 2018-08-22
Ansible Tower MEDIUM 6.5
CVE-2017-7528

Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection. It was found that X-Forwarded-For header allows…

Mitigation only
Fix from $1,600 2018-08-22
Satellite MEDIUM 5.4
CVE-2017-7513

It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fiel…

Mitigation only
Fix from $1,600 2018-08-22
Ansible Tower HIGH 8.8
CVE-2018-10884

Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could expl…

Fix: after 3.2.6
Fix from $1,950 2018-08-22
Enterprise Linux Desktop MEDIUM 5.9
CVE-2018-10844

It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to …

Fix: 3.6.12+
Fix from $1,600 2018-08-22
Enterprise Linux Desktop MEDIUM 5.9
CVE-2018-10845

It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to …

Fix: 3.6.12+
Fix from $1,600 2018-08-22
Enterprise Linux Desktop MEDIUM 5.6
CVE-2018-10846

A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a c…

Fix: 3.6.12+
Fix from $1,600 2018-08-22
Satellite HIGH 7.5
CVE-2018-1517

A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack w…

Mitigation only
Fix from $1,950 2018-08-20
Satellite MEDIUM 6.5
CVE-2018-1656

The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Technology Edition 6.0 , 7.0, and 8.0) does not protec…

Patch available
Fix from $1,600 2018-08-20
Virtualization MEDIUM 5.5
CVE-2015-5160

libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sen…

Mitigation only
Fix from $1,600 2018-08-20
Jboss Core Services MEDIUM 6.5
CVE-2016-9596

libxml2, as used in Red Hat JBoss Core Services and when in recovery mode, allows context-dependent attackers to cause a denial of service (stack con…

Fix: 2.9.4+
Fix from $1,600 2018-08-16
Jboss Core Services MEDIUM 6.5
CVE-2016-9598

libxml2, as used in Red Hat JBoss Core Services, allows context-dependent attackers to cause a denial of service (out-of-bounds read and application …

Fix: 2.9.4+
Fix from $1,600 2018-08-16
Certification MEDIUM 6.2
CVE-2018-10864

An uncontrolled resource consumption flaw has been discovered in redhat-certification in the way documents are loaded. A remote attacker may provide …

Mitigation only
Fix from $1,600 2018-08-13
Openshift Container Platform MEDIUM 5.0
CVE-2017-15138

The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook…

Patch available
Fix from $1,600 2018-08-13
Satellite CRITICAL 9.8
CVE-2018-10931EPSS 68%

It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use…

Fix: after 2.6.11
Fix from $2,300 2018-08-09
Openstack HIGH 7.5
CVE-2018-10915EPSS 5%

A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections…

Patch available
Fix from $1,950 2018-08-09
Virtualization MEDIUM 6.3
CVE-2018-10908

It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By uploading a specially crafted image…

Fix: 4.20.37+
Fix from $1,600 2018-08-09
Virtualization HIGH 7.5
CVE-2018-5390EPSS 74%

Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet…

Fix: 4.18+
Fix from $1,950 2018-08-06
Keycloak HIGH 8.1
CVE-2016-8609

It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing …

Fix: 2.3.0+
Fix from $1,950 2018-08-01
Virtualization HIGH 8.1
CVE-2018-10897EPSS 6%

A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration fil…

Fix: after 1.1.31
Fix from $1,950 2018-08-01
Enterprise Linux Desktop HIGH 7.8
CVE-2016-9583

An out-of-bounds heap read vulnerability was found in the jpc_pi_nextpcrl() function of jasper before 2.0.6 when processing crafted input.

Fix: 2.0.6+
Fix from $1,950 2018-08-01
Keycloak MEDIUM 5.4
CVE-2018-10894

It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to acce…

Patch available
Fix from $1,600 2018-08-01