Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jboss Data Grid HIGH 8.8
CVE-2018-1131

Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticat…

Mitigation only
Fix from $1,950 2018-05-15
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2016-8627

admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be available via …

Mitigation only
Fix from $1,600 2018-05-11
Enterprise Linux Desktop HIGH 7.5
CVE-2018-1089

389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading …

Fix: 1.3.6.15 / 1.4.0.9+
Fix from $1,950 2018-05-09
Wildfly CRITICAL 9.8
CVE-2018-10683

An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successful…

No fix yet
Fix from $2,300 2018-05-09
Enterprise Linux HIGH 7.5
CVE-2018-10184EPSS 8%

An issue was discovered in HAProxy before 1.8.8. The incoming H2 frame length was checked against the max_frame_size setting instead of being checked…

Fix: 1.8.8+
Fix from $1,950 2018-05-09
Ansible Tower MEDIUM 6.5
CVE-2018-10767

There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 beca…

Fix: after 0.3.0
Fix from $1,600 2018-05-06
Ansible HIGH 7.4
CVE-2013-2233

Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-middle attacks by leveraging failure to cache SSH host keys.

Fix: 1.2.1+
Fix from $1,950 2018-05-04
Ansible Tower MEDIUM 6.5
CVE-2018-10733

There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a rem…

Fix: after 0.3.0
Fix from $1,600 2018-05-04
Ansible Tower HIGH 8.8
CVE-2018-1104

Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrar…

Fix: after 3.2.3
Fix from $1,950 2018-05-02
Ansible Tower HIGH 7.2
CVE-2018-1101

Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. Syste…

Fix: 3.2.4+
Fix from $1,950 2018-05-02
Manageiq Enterprise Virtualization Manager HIGH 8.8
CVE-2013-0185

Cross-site request forgery (CSRF) vulnerability in ManageIQ Enterprise Virtualization Manager (EVM) allows remote attackers to hijack the authenticat…

No fix yet
Fix from $1,950 2018-05-01
Cloudforms Management Engine HIGH 7.5
CVE-2013-2049

Red Hat CloudForms 2 Management Engine (CFME) allows remote attackers to conduct session tampering attacks by leveraging use of a static secret_token…

Mitigation only
Fix from $1,950 2018-05-01
Openshift HIGH 8.8
CVE-2018-1102

A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFr…

Patch available
Fix from $1,950 2018-04-30
Enterprise Linux HIGH 7.5
CVE-2017-2591

389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniqueness_entry_to_config() function in the "attribute …

Fix: 1.3.6+
Fix from $1,950 2018-04-30
Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-10534

The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU B…

Mitigation only
Fix from $1,600 2018-04-29
Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-10535

The ignore_section_sym function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, does not vali…

Mitigation only
Fix from $1,600 2018-04-29
Openshift Container Platform MEDIUM 5.9
CVE-2018-10237EPSS 5%

Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against serv…

Fix: 24.1.1+
Fix from $1,600 2018-04-26
Enterprise Virtualization HIGH 7.2
CVE-2018-1074

ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, includ…

Fix: after 4.1.11.1
Fix from $1,950 2018-04-26
Openstack MEDIUM 6.5
CVE-2016-9590

puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object …

Fix: 8.2.1 / 9.4.4+
Fix from $1,600 2018-04-26
Enterprise Linux Desktop MEDIUM 6.5
CVE-2018-10373

concat_filename in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to…

Mitigation only
Fix from $1,600 2018-04-25
Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-10372

process_cu_tu_index in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (heap-based buffer over-read and application…

No fix yet
Fix from $1,600 2018-04-25
Ansible HIGH 8.1
CVE-2016-9587EPSS 18%

Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacke…

Fix: 2.1.4 / 2.2.1+
Fix from $1,950 2018-04-24
Openstack HIGH 7.5
CVE-2016-9599

puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of T…

Mitigation only
Fix from $1,950 2018-04-24
Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-1106

An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed package…

Mitigation only
Fix from $1,600 2018-04-23
Enterprise Linux Desktop HIGH 8.3
CVE-2018-2814

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE:…

Patch available
Fix from $1,950 2018-04-19
Enterprise Linux Server HIGH 7.7
CVE-2018-2811

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Install). Supported versions that are affected are Java SE: 8u162 and 10. Dif…

Fix: 7.6.0+
Fix from $1,950 2018-04-19
Enterprise Linux Desktop MEDIUM 5.3
CVE-2018-2815

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affect…

Patch available
Fix from $1,600 2018-04-19
Satellite HIGH 7.7
CVE-2018-2794

Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, …

Patch available
Fix from $1,950 2018-04-19
Satellite HIGH 7.4
CVE-2018-2783

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected ar…

Patch available
Fix from $1,950 2018-04-19
Satellite MEDIUM 5.3
CVE-2018-2795EPSS 8%

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected ar…

Patch available
Fix from $1,600 2018-04-19