Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux Desktop HIGH 7.5
CVE-2018-1054

An out-of-bounds memory read flaw was found in the way 389-ds-base handled certain LDAP search filters, affecting all versions including 1.4.x. A rem…

Fix: after 1.4.0.6
Fix from $1,950 2018-03-07
Enterprise Linux Desktop MEDIUM 6.5
CVE-2018-7727

An issue was discovered in ZZIPlib 0.13.68. There is a memory leak triggered in the function zzip_mem_disk_new in memdisk.c, which will lead to a den…

No fix yet
Fix from $1,600 2018-03-06
Ovirt Engine MEDIUM 5.3
CVE-2018-1062

A vulnerability was discovered in oVirt 4.1.x before 4.1.9, where the combination of Enable Discard and Wipe After Delete flags for VM disks managed …

Fix: 4.1.9+
Fix from $1,600 2018-03-06
Enterprise Linux Desktop HIGH 7.8
CVE-2018-7643

The display_debug_ranges function in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (integer overflow and applicat…

Mitigation only
Fix from $1,950 2018-03-02
Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-7642

The swap_std_reloc_in function in aoutx.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remot…

Mitigation only
Fix from $1,600 2018-03-02
Enterprise Linux HIGH 7.5
CVE-2017-15134

A stack buffer overflow flaw was found in the way 389-ds-base 1.3.6.x before 1.3.6.13, 1.3.7.x before 1.3.7.9, 1.4.x before 1.4.0.5 handled certain L…

Fix: 1.3.6.13 / 1.3.7.9+
Fix from $1,950 2018-03-01
Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-7568

The parse_die function in dwarf1.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attac…

Patch available
Fix from $1,600 2018-02-28
Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-7569

dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of …

Patch available
Fix from $1,600 2018-02-28
Cloudforms HIGH 7.4
CVE-2017-12191

A flaw was found in the CloudForms account configuration when using VMware. By default, a shared account is used that has privileged access to VMRC (…

Patch available
Fix from $1,950 2018-02-28
Enterprise Linux Desktop HIGH 7.5
CVE-2018-7549

In params.c in zsh through 5.4.2, there is a crash during a copy of an empty hash table, as demonstrated by typeset -p.

Fix: after 5.4.2
Fix from $1,950 2018-02-27
Libvirt HIGH 7.8
CVE-2018-6764

util/virlog.c in libvirt does not properly determine the hostname on LXC container startup, which allows local guest OS users to bypass an intended c…

Patch available
Fix from $1,950 2018-02-23
Openstack HIGH 7.5
CVE-2017-18191

An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker …

Fix: after 16.1.1
Fix from $1,950 2018-02-19
Enterprise Linux Desktop HIGH 7.8
CVE-2018-7208

In the coff_pointerize_aux function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, an in…

Mitigation only
Fix from $1,950 2018-02-18
Enterprise Linux MEDIUM 5.9
CVE-2018-1049EPSS 7%

In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by s…

Patch available
Fix from $1,600 2018-02-16
Jboss Enterprise Application Platform HIGH 7.5
CVE-2018-1041EPSS 16%

A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker coul…

No fix yet
Fix from $1,950 2018-02-15
Satellite MEDIUM 6.5
CVE-2017-10690

In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from.…

Fix: 5.3.4 / 2017.3.4+
Fix from $1,600 2018-02-09
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-4877EPSS 8%

A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Pri…

Fix: 28.0.0.161+
Fix from $2,300 2018-02-06
Enterprise Linux Desktop HIGH 7.8
CVE-2018-4878 KEVEPSS 90%

A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Pri…

Fix: 28.0.0.161+
Fix from $1,950 2018-02-06
Enterprise Linux Desktop HIGH 8.8
CVE-2018-6560

In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break ou…

Fix: 0.8.9 / 0.10.3+
Fix from $1,950 2018-02-02
Virtualization Host CRITICAL 9.8
CVE-2018-6485

An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier coul…

Fix: after 2.26
Fix from $2,300 2018-02-01
Resteasy HIGH 8.1
CVE-2018-1051

It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yam…

Mitigation only
Fix from $1,950 2018-01-25
Libvirt HIGH 7.5
CVE-2018-5748

qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply.

Patch available
Fix from $1,950 2018-01-25
Jboss Enterprise Application Platform HIGH 7.5
CVE-2018-1048

It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the…

Mitigation only
Fix from $1,950 2018-01-24
Jboss Wildfly Application Server MEDIUM 5.5
CVE-2018-1047

A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResou…

Mitigation only
Fix from $1,600 2018-01-24
Satellite MEDIUM 5.3
CVE-2018-2657EPSS 8%

Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u…

Patch available
Fix from $1,600 2018-01-18
Satellite HIGH 8.3
CVE-2018-2633EPSS 6%

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Ja…

Patch available
Fix from $1,950 2018-01-18
Satellite HIGH 8.3
CVE-2018-2638

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u152 and 9.0.…

Patch available
Fix from $1,950 2018-01-18
Satellite HIGH 8.3
CVE-2018-2639

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u152 and 9.0.…

Patch available
Fix from $1,950 2018-01-18
Satellite HIGH 7.5
CVE-2018-2627

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Installer). Supported versions that are affected are Java SE: 8u152 and 9.0.1…

Fix: after 11.70.1
Fix from $1,950 2018-01-18
Satellite HIGH 7.4
CVE-2018-2637

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JMX). Supported versions that are affected are Jav…

Patch available
Fix from $1,950 2018-01-18