Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Satellite MEDIUM 6.8
CVE-2018-2634

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JGSS). Supported versions that are affected are Java SE: 7u…

Patch available
Fix from $1,600 2018-01-18
Satellite MEDIUM 6.1
CVE-2018-2641EPSS 5%

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u1…

Patch available
Fix from $1,600 2018-01-18
Satellite MEDIUM 5.3
CVE-2018-2629

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JGSS). Supported versions that are affected are Ja…

Patch available
Fix from $1,600 2018-01-18
Satellite MEDIUM 5.9
CVE-2018-2618

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Jav…

Patch available
Fix from $1,600 2018-01-18
Satellite MEDIUM 5.3
CVE-2018-2603EPSS 7%

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected a…

Patch available
Fix from $1,600 2018-01-18
Satellite MEDIUM 6.5
CVE-2018-2582

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE:…

Patch available
Fix from $1,600 2018-01-18
Cloudforms Management Engine HIGH 8.8
CVE-2014-0087

The check_privileges method in vmdb/app/controllers/application_controller.rb in ManageIQ, as used in Red Hat CloudForms Management Engine (CFME), al…

Fix: 5.3+
Fix from $1,950 2018-01-11
Jboss Enterprise Application Platform HIGH 7.8
CVE-2017-12189

It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handling which c…

Patch available
Fix from $1,950 2018-01-10
Hibernate Validator HIGH 7.0
CVE-2017-7536

In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows…

Fix: 5.2.5 / 5.3.6+
Fix from $1,950 2018-01-10
Undertow MEDIUM 6.1
CVE-2017-7559

In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before 1.3.31.Final, it was found that the fix for CVE-2017-2666 was incomp…

Fix: 1.3.31 / 1.4.17+
Fix from $1,600 2018-01-10
Enterprise Linux HIGH 7.8
CVE-2017-15131

It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting…

Fix: 0.15.5+
Fix from $1,950 2018-01-09
Enterprise Linux Desktop HIGH 7.5
CVE-2018-4871EPSS 6%

An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28.0.0.137. This vulnerability occurs because of computation that reads data …

Fix: after 28.0.0.126
Fix from $1,950 2018-01-09
Openshift HIGH 7.8
CVE-2013-4364

(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local u…

Mitigation only
Fix from $1,950 2018-01-08
Jboss Fuse CRITICAL 9.8
CVE-2014-0121

The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.

Fix: after 1.2.2
Fix from $2,300 2017-12-29
Jboss Fuse HIGH 8.8
CVE-2014-0120

Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary us…

Fix: after 1.2.2
Fix from $1,950 2017-12-29
Ceph MEDIUM 6.5
CVE-2017-16818

RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) b…

Fix: after 12.2.1
Fix from $1,600 2017-12-20
Jbpm MEDIUM 5.4
CVE-2013-6465

Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 6.0.x allow remote authenticated users to inject arbitrary web script or HT…

Patch available
Fix from $1,600 2017-12-19
Enterprise Linux HIGH 8.8
CVE-2017-15103EPSS 5%

A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted r…

Patch available
Fix from $1,950 2017-12-18
Enterprise Linux HIGH 7.8
CVE-2017-15104

An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi serv…

Mitigation only
Fix from $1,950 2017-12-18
Enterprise Linux Desktop HIGH 7.8
CVE-2017-16997

elf/dl-load.c in the GNU C Library (aka glibc or libc6) 2.19 through 2.26 mishandles RPATH and RUNPATH containing $ORIGIN for a privileged (setuid or…

Patch available
Fix from $1,950 2017-12-18
Enterprise Linux Desktop MEDIUM 6.5
CVE-2017-11305

A regression affecting Adobe Flash Player version 27.0.0.187 (and earlier versions) causes the unintended reset of the global settings preference fil…

Fix: after 27.0.0.187
Fix from $1,600 2017-12-13
Virtualization Host HIGH 7.4
CVE-2017-1000407

The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to …

Fix: 4.15+
Fix from $1,950 2017-12-11
Linux MEDIUM 6.5
CVE-2014-3250

The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers t…

Fix: 3.6.2+
Fix from $1,600 2017-12-11
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-3112EPSS 6%

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data…

Fix: after 27.0.0.183
Fix from $2,300 2017-12-09
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-3114EPSS 6%

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data…

Fix: after 27.0.0.183
Fix from $2,300 2017-12-09
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-11213EPSS 7%

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data…

Fix: after 27.0.0.183
Fix from $2,300 2017-12-09
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-11215EPSS 6%

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in…

Fix: after 27.0.0.183
Fix from $2,300 2017-12-09
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-11225EPSS 6%

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in…

Fix: after 27.0.0.183
Fix from $2,300 2017-12-09
Openstack CRITICAL 9.8
CVE-2017-10906

Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitr…

Patch available
Fix from $2,300 2017-12-08
Enterprise Linux MEDIUM 5.5
CVE-2017-15121

A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not e…

Mitigation only
Fix from $1,600 2017-12-07