Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ceph Storage HIGH 7.5
CVE-2016-9579

A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A re…

Patch available
Fix from $1,950 2018-08-01
Jboss A Mq HIGH 7.2
CVE-2016-8648

It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX opera…

Mitigation only
Fix from $1,950 2018-08-01
Jboss Bpm Suite MEDIUM 5.4
CVE-2016-8608

JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via business process editor. The flaw is due to an incomplete fix for CVE-2016-5398. Remo…

Mitigation only
Fix from $1,600 2018-08-01
Jboss A Mq MEDIUM 5.3
CVE-2016-8653

It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this …

Mitigation only
Fix from $1,600 2018-08-01
Enterprise Linux Desktop MEDIUM 5.9
CVE-2016-8635

It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement attack. An attacker could us…

Fix: after 3.21.4
Fix from $1,600 2018-08-01
Satellite MEDIUM 5.4
CVE-2016-8639

It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privile…

Fix: 1.13.0+
Fix from $1,600 2018-08-01
Enterprise Linux Desktop HIGH 8.1
CVE-2016-9573

An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to another fo…

Patch available
Fix from $1,950 2018-08-01
Ansible HIGH 7.5
CVE-2016-8614

A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create a…

Fix: 2.2.0+
Fix from $1,950 2018-07-31
Ansible CRITICAL 9.1
CVE-2016-8628

Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create speci…

Fix: 2.2.0+
Fix from $2,300 2018-07-31
Openshift HIGH 7.7
CVE-2016-8631

The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routes can pote…

Mitigation only
Fix from $1,950 2018-07-31
Jboss Enterprise Application Platform HIGH 7.8
CVE-2016-8657

It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuratio…

Mitigation only
Fix from $1,950 2018-07-31
Ceph MEDIUM 6.5
CVE-2016-8626

A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ceph Object Gateway handles POST object requests permits an authenticated attacker to launc…

Fix: 0.94.3.9-8+
Fix from $1,600 2018-07-31
Openstack HIGH 8.8
CVE-2018-10898

A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Open…

Fix: 8.0.2-40+
Fix from $1,950 2018-07-30
Openstack HIGH 7.5
CVE-2018-10903

A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user …

Fix: 2.3+
Fix from $1,950 2018-07-30
Enterprise Linux HIGH 7.8
CVE-2017-7518

A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the trap flag(TF) bit in EFLAGS during emulation of the …

Patch available
Fix from $1,950 2018-07-30
Satellite MEDIUM 5.4
CVE-2017-7514

A cross-site scripting (XSS) flaw was found in how the failed action entry is processed in Red Hat Satellite before version 5.8.0. A user able to spe…

Fix: 5.8.0+
Fix from $1,600 2018-07-30
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-15101

A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a den…

Fix: 2.5.4+
Fix from $2,300 2018-07-27
Subscription Manager HIGH 7.8
CVE-2017-2663

It was found that subscription-manager's DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1.Facts.GetFacts and com.redhat…

Fix: 1.19.4+
Fix from $1,950 2018-07-27
Enterprise Linux Desktop MEDIUM 6.7
CVE-2017-15097

Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could…

Mitigation only
Fix from $1,600 2018-07-27
Enterprise Linux Desktop MEDIUM 6.5
CVE-2017-2633

An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshin…

Fix: 1.7.2+
Fix from $1,600 2018-07-27
Enterprise Linux Desktop MEDIUM 5.5
CVE-2017-2626

It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijac…

Fix: after 1.0.9
Fix from $1,600 2018-07-27
Keycloak HIGH 7.5
CVE-2017-2646

It was found that when Keycloak before 2.5.5 receives a Logout request with a Extensions in the middle of the request, the SAMLSloRequestParser.parse…

Fix: 2.5.5+
Fix from $1,950 2018-07-27
Cloudforms Management Engine MEDIUM 6.5
CVE-2017-2653

A number of unused delete routes are present in CloudForms before 5.7.2.1 which can be accessed via GET requests instead of just POST requests. This …

Fix: 5.7.2.1+
Fix from $1,600 2018-07-27
Jboss Bpm Suite MEDIUM 6.5
CVE-2017-2658

It was discovered that the Dashbuilder login page as used in Red Hat JBoss BPM Suite before 6.4.2 and Red Hat JBoss Data Virtualization & Services be…

Fix: 6.4.2 / 6.4.3+
Fix from $1,600 2018-07-27
Jboss Bpm Suite MEDIUM 6.1
CVE-2017-7463

JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a reflected XSS via artifact upload. A malformed XML file, if uploaded, causes an error m…

Fix: 6.4.3+
Fix from $1,600 2018-07-27
Jboss Bpm Suite MEDIUM 5.4
CVE-2017-2674

JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a stored XSS via several lists in Business Central. The flaw is due to lack of sanitation…

Fix: 6.4.3+
Fix from $1,600 2018-07-27
Enterprise Linux HIGH 8.1
CVE-2017-2590

A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while mod…

Fix: 4.4.0+
Fix from $1,950 2018-07-27
Enterprise Virtualization MEDIUM 6.3
CVE-2017-2614

When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is ex…

Mitigation only
Fix from $1,600 2018-07-27
Satellite MEDIUM 5.5
CVE-2016-9595

A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this fla…

Fix: 3.4.0+
Fix from $1,600 2018-07-27
Openstack MEDIUM 5.5
CVE-2017-2621

An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improp…

Fix: 8.0.0+
Fix from $1,600 2018-07-27