Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Satellite MEDIUM 5.3
CVE-2018-2796EPSS 7%

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Supported versions that are affected…

Patch available
Fix from $1,600 2018-04-19
Satellite MEDIUM 5.3
CVE-2018-2797EPSS 8%

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JMX). Supported versions that are affected are Jav…

Patch available
Fix from $1,600 2018-04-19
Satellite MEDIUM 5.3
CVE-2018-2798EPSS 8%

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Jav…

Patch available
Fix from $1,600 2018-04-19
Satellite MEDIUM 5.3
CVE-2018-2799EPSS 15%

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Ja…

Patch available
Fix from $1,600 2018-04-19
Gluster Storage HIGH 8.1
CVE-2018-1088EPSS 6%

A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared …

Fix: after 3.13.2
Fix from $1,950 2018-04-18
Undertow MEDIUM 5.9
CVE-2017-12196

undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that…

Fix: after 1.4.18
Fix from $1,600 2018-04-18
Satellite HIGH 8.8
CVE-2016-9593

foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file would be able…

Fix: 1.15.0+
Fix from $1,950 2018-04-16
Enterprise Linux MEDIUM 6.5
CVE-2018-1079

pcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call. The REST interface of the pcsd s…

Fix: after 0.9.164
Fix from $1,600 2018-04-12
Rhn Client Tools MEDIUM 5.9
CVE-2015-1777

rhnreg_ks in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Gluster Storage 2.1 and Enterprise Linux (RHEL) 5, 6, and 7 does not prop…

Mitigation only
Fix from $1,600 2018-04-12
Openshift MEDIUM 5.4
CVE-2017-7534

OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, spec…

Mitigation only
Fix from $1,600 2018-04-11
Satellite MEDIUM 6.5
CVE-2018-1096

An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could use this flaw to perform an S…

Fix: 1.16.1+
Fix from $1,600 2018-04-05
Satellite HIGH 8.8
CVE-2018-1097

A flaw was found in foreman before 1.16.1. The issue allows users with limited permissions for powering oVirt/RHV hosts on and off to discover the us…

Fix: 1.6.1+
Fix from $1,950 2018-04-04
Etcd HIGH 8.8
CVE-2018-1098

A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd…

Fix: after 3.3.1
Fix from $1,950 2018-04-03
Etcd MEDIUM 5.5
CVE-2018-1099

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser in…

Fix: after 3.3.1
Fix from $1,600 2018-04-03
Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-8945

The bfd_section_from_shdr function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows rem…

Patch available
Fix from $1,600 2018-03-22
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2018-8088EPSS 15%

org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via…

Patch available
Fix from $2,300 2018-03-20
Ceph HIGH 7.5
CVE-2018-7262

In Ceph before 12.2.3 and 13.x through 13.0.1, the rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesn't handle malformed HTTP headers pr…

Fix: 12.2.3+
Fix from $1,950 2018-03-19
Spacewalk HIGH 7.5
CVE-2018-1077

Spacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensitive information from the server.

Mitigation only
Fix from $1,950 2018-03-14
Ansible Engine CRITICAL 9.8
CVE-2018-7750EPSS 27%

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2…

Patch available
Fix from $2,300 2018-03-13
Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-7858

Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of ser…

Fix: after 2.11.2
Fix from $1,600 2018-03-12
Satellite HIGH 8.1
CVE-2017-2667

Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by defau…

Fix: 0.10.0+
Fix from $1,950 2018-03-12
Jboss Wildfly Application Server HIGH 7.5
CVE-2016-9589

Undertow in Red Hat wildfly before version 11.0.0.Beta1 is vulnerable to a resource exhaustion resulting in a denial of service. Undertow keeps a cac…

Fix: after 10.1.0
Fix from $1,950 2018-03-12
Keycloak MEDIUM 6.5
CVE-2016-8629

Red Hat Keycloak before version 2.4.0 did not correctly check permissions when handling service account user deletion requests sent to the rest serve…

Fix: 2.4.0+
Fix from $1,600 2018-03-12
Keycloak MEDIUM 5.9
CVE-2017-2585

Red Hat Keycloak before version 2.5.1 has an implementation of HMAC verification for JWS tokens that uses a method that runs in non-constant time, po…

Fix: 2.5.1+
Fix from $1,600 2018-03-12
Enterprise Linux HIGH 8.8
CVE-2016-5314

Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (a…

Fix: after 4.0.6
Fix from $1,950 2018-03-12
Enterprise Linux Desktop MEDIUM 6.5
CVE-2014-8130

The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divi…

Patch available
Fix from $1,600 2018-03-12
Resteasy HIGH 8.1
CVE-2016-9606EPSS 6%

JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted dat…

Fix: after 3.1.1
Fix from $1,950 2018-03-09
Enterprise Linux Desktop MEDIUM 5.5
CVE-2016-9591

JasPer before version 2.0.12 is vulnerable to a use-after-free in the way it decodes certain JPEG 2000 image files resulting in a crash on the applic…

Fix: 2.0.12+
Fix from $1,600 2018-03-09
Jboss Enterprise Application Platform MEDIUM 5.3
CVE-2016-9585

Red Hat JBoss EAP version 5 is vulnerable to a deserialization of untrusted data in the JMX endpoint when deserializes the credentials passed to it. …

Mitigation only
Fix from $1,600 2018-03-09
Openshift HIGH 7.1
CVE-2018-1069

Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the U…

Mitigation only
Fix from $1,950 2018-03-09