Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cloudforms HIGH 8.8
CVE-2017-7530

In CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1, it was found that privilege check is missing when invoking arbitrary meth…

Fix: 5.7.3 / 5.8.1+
Fix from $1,950 2018-07-26
Enterprise Linux Desktop HIGH 7.5
CVE-2017-7537

It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package before 10.6.4.…

Fix: 10.6.4+
Fix from $1,950 2018-07-26
Openstack CRITICAL 10.0
CVE-2017-2637

A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed…

Mitigation only
Fix from $2,300 2018-07-26
Package Manager HIGH 8.2
CVE-2017-3224

Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNum…

No fix yet
Fix from $1,950 2018-07-24
Cloudforms HIGH 7.8
CVE-2018-10905

CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with access to an…

Mitigation only
Fix from $1,950 2018-07-24
Enterprise Linux Desktop HIGH 8.8
CVE-2018-5007EPSS 18%

Adobe Flash Player 30.0.0.113 and earlier versions have a Type Confusion vulnerability. Successful exploitation could lead to arbitrary code executio…

Fix: after 30.0.0.113
Fix from $1,950 2018-07-20
Enterprise Linux Desktop HIGH 7.5
CVE-2018-5008EPSS 7%

Adobe Flash Player 30.0.0.113 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclo…

Fix: after 30.0.0.113
Fix from $1,950 2018-07-20
Certification CRITICAL 9.8
CVE-2018-10870EPSS 6%

redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any fil…

Mitigation only
Fix from $2,300 2018-07-19
Certification HIGH 7.5
CVE-2018-10869

redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file access…

Mitigation only
Fix from $1,950 2018-07-19
Openshift Container Platform CRITICAL 9.8
CVE-2017-7481

Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of looku…

Fix: 2.3.1.0 / 2.4.0.0+
Fix from $2,300 2018-07-19
Openstack HIGH 7.2
CVE-2017-2673

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user…

Patch available
Fix from $1,950 2018-07-19
Satellite MEDIUM 5.9
CVE-2018-2973

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JSSE). Supported versions that are affected are Java SE: 6u…

Patch available
Fix from $1,600 2018-07-18
Openshift MEDIUM 5.3
CVE-2017-15137

The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a…

Mitigation only
Fix from $1,600 2018-07-16
Jboss Data Grid MEDIUM 6.5
CVE-2017-2638

It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability…

Fix: 9.0.0+
Fix from $1,600 2018-07-16
Ansible Engine HIGH 7.8
CVE-2018-10875

A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module pat…

Mitigation only
Fix from $1,950 2018-07-13
Enterprise Linux MEDIUM 5.6
CVE-2018-3693EPSS 8%

Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker wi…

Patch available
Fix from $1,600 2018-07-10
Enterprise Linux MEDIUM 5.5
CVE-2018-10872

A flaw was found in the way the Linux kernel handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. During th…

Patch available
Fix from $1,600 2018-07-10
Ceph Storage HIGH 8.1
CVE-2018-10861

A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage po…

Patch available
Fix from $1,950 2018-07-10
Ceph Storage HIGH 7.5
CVE-2018-1128

It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access…

Fix: after 13.2.1
Fix from $1,950 2018-07-10
Ceph Storage MEDIUM 6.5
CVE-2018-1129

A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who…

Patch available
Fix from $1,600 2018-07-10
Enterprise Linux Desktop HIGH 7.8
CVE-2018-5002 KEVEPSS 25%

Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary …

Fix: after 29.0.0.171
Fix from $1,950 2018-07-09
Enterprise Linux Desktop MEDIUM 6.5
CVE-2018-5000EPSS 14%

Adobe Flash Player versions 29.0.0.171 and earlier have an Integer Overflow vulnerability. Successful exploitation could lead to information disclosu…

Fix: after 29.0.0.171
Fix from $1,600 2018-07-09
Enterprise Linux Desktop MEDIUM 6.5
CVE-2018-5001EPSS 13%

Adobe Flash Player versions 29.0.0.171 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclo…

Fix: after 29.0.0.171
Fix from $1,600 2018-07-09
Enterprise Linux Desktop HIGH 8.8
CVE-2018-4945EPSS 7%

Adobe Flash Player versions 29.0.0.171 and earlier have a Type Confusion vulnerability. Successful exploitation could lead to arbitrary code executio…

Fix: after 29.0.0.171
Fix from $1,950 2018-07-09
Openshift HIGH 7.5
CVE-2018-10885

In atomic-openshift before version 3.10.9 a malicious network-policy configuration can cause Openshift Routing to crash when using ovs-networkpolicy …

Fix: 3.10.9+
Fix from $1,950 2018-07-05
Ansible Engine MEDIUM 5.9
CVE-2018-10855

Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect…

Fix: 2.4.5+
Fix from $1,600 2018-07-03
Setup MEDIUM 5.3
CVE-2018-1113

setup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /etc/shells. This violates sec…

Fix: 2.11.4+
Fix from $1,600 2018-07-03
Openshift Container Platform HIGH 8.8
CVE-2018-10843

source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privile…

Fix: 3.7.53+
Fix from $1,950 2018-07-02
Ansible Engine HIGH 7.8
CVE-2018-10874

In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's con…

Mitigation only
Fix from $1,950 2018-07-02
Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-13033

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (exc…

Patch available
Fix from $1,600 2018-07-01