Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-7465

It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw …

Mitigation only
Fix from $2,300 2018-06-27
Cloudforms HIGH 7.5
CVE-2018-3760EPSS 27%

There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially craft…

Fix: after 3.7.1
Fix from $1,950 2018-06-26
Enterprise Virtualization Manager CRITICAL 9.8
CVE-2018-1072

ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the option…

Fix: 4.2.2+
Fix from $2,300 2018-06-26
Ansible HIGH 8.0
CVE-2017-7466

Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An attacker with control over a cl…

Fix: 2.3+
Fix from $1,950 2018-06-22
Enterprise Linux Desktop MEDIUM 6.5
CVE-2017-2668

389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote…

Fix: 1.3.5.17 / 1.3.6.10+
Fix from $1,600 2018-06-22
Satellite HIGH 8.8
CVE-2017-2672

A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file woul…

Fix: 1.15+
Fix from $1,950 2018-06-21
Enterprise Virtualization CRITICAL 9.8
CVE-2018-1117

ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/Clou…

Fix: 1.0.6+
Fix from $2,300 2018-06-20
Virtualization MEDIUM 5.3
CVE-2018-1073

The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an a…

Fix: 4.2.3+
Fix from $1,600 2018-06-19
Richfaces CRITICAL 9.8
CVE-2018-12532EPSS 7%

JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and exec…

Fix: after 4.5.17
Fix from $2,300 2018-06-18
Richfaces CRITICAL 9.8
CVE-2018-12533EPSS 19%

JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java…

Fix: after 3.3.4
Fix from $2,300 2018-06-18
Openshift Container Platform CRITICAL 9.8
CVE-2018-1085

openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificate authentication to be disabl…

Fix: 3.9.31+
Fix from $2,300 2018-06-15
Virtualization Host HIGH 7.8
CVE-2018-5848

In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_le…

Patch available
Fix from $1,950 2018-06-12
Source To Image MEDIUM 6.5
CVE-2018-1103

Openshift Enterprise source-to-image before version 1.1.10 is vulnerable to an improper validation of user input. An attacker who could trick a user …

Fix: 1.1.10+
Fix from $1,600 2018-06-12
Openshift Container Platform HIGH 7.5
CVE-2018-1070

routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which can cause an entire shard to b…

Fix: 3.10+
Fix from $1,950 2018-06-12
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-5183

Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and…

Mitigation only
Fix from $2,300 2018-06-11
Enterprise Linux Desktop MEDIUM 6.5
CVE-2018-5185

Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird…

Mitigation only
Fix from $1,600 2018-06-11
Enterprise Linux Desktop HIGH 7.5
CVE-2018-5157

Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow th…

Mitigation only
Fix from $1,950 2018-06-11
Enterprise Linux Desktop HIGH 7.5
CVE-2018-5162

Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Th…

Mitigation only
Fix from $1,950 2018-06-11
Enterprise Linux Desktop HIGH 8.8
CVE-2018-5146EPSS 12%

An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.…

Mitigation only
Fix from $1,950 2018-06-11
Enterprise Linux Desktop HIGH 7.3
CVE-2018-5144

An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affec…

Fix: 52.7.0+
Fix from $1,950 2018-06-11
Enterprise Linux Desktop HIGH 8.8
CVE-2018-5127EPSS 8%

A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentially exploitable crash. This vul…

Fix: 52.7.0 / 59.0+
Fix from $1,950 2018-06-11
Enterprise Linux Desktop HIGH 8.8
CVE-2017-7846

It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in th…

Fix: 52.5.2+
Fix from $1,950 2018-06-11
Enterprise Linux MEDIUM 5.3
CVE-2017-7848

RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2.

Fix: 52.5.2+
Fix from $1,600 2018-06-11
Enterprise Linux Aus CRITICAL 9.8
CVE-2017-7824

A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. This is due to an incorrect va…

Fix: 52.4.0 / 56.0+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop MEDIUM 5.4
CVE-2017-7823

The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-ori…

Fix: 52.4.0 / 56.0+
Fix from $1,600 2018-06-11
Enterprise Linux Aus MEDIUM 5.3
CVE-2017-7829

It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not d…

Fix: 52.5.2+
Fix from $1,600 2018-06-11
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-7818

A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applications (ARIA) elements within containers through …

Fix: 52.4.0 / 56.0+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-7819

A use-after-free vulnerability can occur in design mode when image objects are resized if objects referenced during the resizing have been freed from…

Fix: 52.4.0 / 56.0+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop HIGH 7.8
CVE-2017-7814

File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature …

Fix: 52.4.0 / 56.0+
Fix from $1,950 2018-06-11
Enterprise Linux Desktop HIGH 7.5
CVE-2017-7803

When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This results in the incorrect enforc…

Fix: 52.3.0 / 55.0+
Fix from $1,950 2018-06-11