Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux MEDIUM 5.5
CVE-2017-2625

It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attack…

Fix: 1.1.2+
Fix from $1,600 2018-07-27
Enterprise Linux MEDIUM 5.3
CVE-2017-2623

It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages…

Fix: 2017.3+
Fix from $1,600 2018-07-27
Enterprise Linux Desktop HIGH 8.8
CVE-2017-12173

It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulner…

Fix: 1.16.0+
Fix from $1,950 2018-07-27
Virtualization HIGH 8.6
CVE-2017-15119

The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a client sen…

Fix: 2.11.0+
Fix from $1,950 2018-07-27
Ansible Tower HIGH 7.2
CVE-2017-12148

A flaw was found in Ansible Tower's interface before 3.1.5 and 3.2.0 with SCM repositories. If a Tower project (SCM repository) definition does not h…

Fix: 3.1.5 / 3.2.0+
Fix from $1,950 2018-07-27
Virtualization MEDIUM 6.6
CVE-2017-15113

ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change th…

Fix: 4.1.7.6+
Fix from $1,600 2018-07-27
Undertow HIGH 7.5
CVE-2017-12165

It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http…

Fix: 1.3.31 / 1.4.17+
Fix from $1,950 2018-07-27
Undertow HIGH 7.5
CVE-2017-2670

It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively ca…

Fix: 1.3.28+
Fix from $1,950 2018-07-27
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2017-2595

It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path trave…

Mitigation only
Fix from $1,600 2018-07-27
Cloudforms Management Engine MEDIUM 5.4
CVE-2017-15125

A flaw was found in CloudForms before 5.9.0.22 in the self-service UI snapshot feature where the name field is not properly sanitized for HTML and Ja…

Fix: 5.9.0.22+
Fix from $1,600 2018-07-27
Undertow MEDIUM 6.5
CVE-2017-2666

It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction w…

Mitigation only
Fix from $1,600 2018-07-27
Virtualization MEDIUM 5.5
CVE-2018-10862

WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives…

Fix: after 5.0.0
Fix from $1,600 2018-07-27
Spacewalk CRITICAL 9.8
CVE-2017-7470

It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorizati…

Mitigation only
Fix from $2,300 2018-07-27
Cloudforms HIGH 7.5
CVE-2017-2639

It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communica…

Mitigation only
Fix from $1,950 2018-07-27
Openstack MEDIUM 5.5
CVE-2017-2622

An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malic…

Mitigation only
Fix from $1,600 2018-07-27
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-7464

It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use thi…

Mitigation only
Fix from $2,300 2018-07-27
Enterprise Linux Desktop HIGH 7.4
CVE-2017-12150EPSS 13%

It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options w…

Fix: 4.4.16 / 4.5.14+
Fix from $1,950 2018-07-26
Enterprise Linux MEDIUM 6.5
CVE-2017-12171EPSS 8%

A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines…

Mitigation only
Fix from $1,600 2018-07-26
Keycloak MEDIUM 6.5
CVE-2017-2582

It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute …

Fix: 2.5.1+
Fix from $1,600 2018-07-26
Jboss Enterprise Application Platform MEDIUM 5.5
CVE-2017-12167

It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role ma…

Fix: 7.0.9+
Fix from $1,600 2018-07-26
Satellite MEDIUM 5.4
CVE-2017-12175

Red Hat Satellite before 6.5 is vulnerable to a XSS in discovery rule when you are entering filter and you use autocomplete functionality.

Fix: 6.5+
Fix from $1,600 2018-07-26
Enterprise Linux Desktop HIGH 7.1
CVE-2017-12163EPSS 8%

An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A ma…

Fix: 4.4.16 / 4.5.14+
Fix from $1,950 2018-07-26
Certificate System MEDIUM 6.5
CVE-2017-7509

An input validation error was found in Red Hat Certificate System's handling of client provided certificates before 8.1.20-1. If the certreq field is…

Fix: 8.1.20-1+
Fix from $1,600 2018-07-26
Jboss Fuse CRITICAL 9.0
CVE-2017-2589

It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored …

Mitigation only
Fix from $2,300 2018-07-26
Decision Manager MEDIUM 6.5
CVE-2017-7545

It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote a…

Patch available
Fix from $1,600 2018-07-26
Enterprise Linux MEDIUM 6.5
CVE-2017-7562

An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A remote at…

Fix: 1.16.1+
Fix from $1,600 2018-07-26
Satellite MEDIUM 5.4
CVE-2017-7538

A cross-site scripting (XSS) flaw was found in how an organization name is displayed in Satellite 5, before 5.8. A user able to change an organizatio…

Fix: 5.8+
Fix from $1,600 2018-07-26
Openstack HIGH 7.5
CVE-2017-7539EPSS 6%

An assertion-failure flaw was found in Qemu before 2.10.1, in the Network Block Device (NBD) server's initial connection negotiation, where the I/O c…

Fix: 2.10.1+
Fix from $1,950 2018-07-26
Cloudforms MEDIUM 6.5
CVE-2017-2664

CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the rails application portion of Cl…

Fix: 5.7.3 / 5.8.1+
Fix from $1,600 2018-07-26
Openstack MEDIUM 5.9
CVE-2017-7543

A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1,…

Fix: 7.2.0-12.1 / 8.3.0-11.1+
Fix from $1,600 2018-07-26