Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-11281EPSS 34%

Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploitation could lead to arbitrary …

Fix: after 26.0.0.151
Fix from $2,300 2017-12-01
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-11282EPSS 35%

Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code ex…

Fix: after 26.0.0.151
Fix from $2,300 2017-12-01
Openstack Platform HIGH 8.1
CVE-2017-15114

When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all no…

Patch available
Fix from $1,950 2017-11-27
Satellite MEDIUM 6.1
CVE-2017-15100

An attacker submitting facts to the Foreman server containing HTML can cause a stored XSS on certain pages: (1) Facts page, when clicking on the "cha…

Fix: 1.16.0+
Fix from $1,600 2017-11-27
Ansible CRITICAL 9.8
CVE-2017-7550

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attac…

Fix: 2.3.3 / 2.4.1+
Fix from $2,300 2017-11-21
Data Grid CRITICAL 9.8
CVE-2015-7501EPSS 86%

Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Pl…

Mitigation only
Fix from $2,300 2017-11-09
Gluster Storage HIGH 7.5
CVE-2017-15087

It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.

Mitigation only
Fix from $1,950 2017-11-08
Gluster Storage HIGH 7.4
CVE-2017-15086

It was discovered that the fix for CVE-2017-12151 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.

Mitigation only
Fix from $1,950 2017-11-08
Gluster Storage MEDIUM 5.9
CVE-2017-15085

It was discovered that the fix for CVE-2017-12150 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.

Mitigation only
Fix from $1,600 2017-11-08
Enterprise Linux Desktop MEDIUM 6.5
CVE-2017-16541

Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vec…

Fix: 7.0.9+
Fix from $1,600 2017-11-04
Libvirt HIGH 8.1
CVE-2017-1000256

libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to …

Fix: 3.9.0+
Fix from $1,950 2017-10-31
Single Sign On HIGH 7.5
CVE-2017-12159

It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to a…

Mitigation only
Fix from $1,950 2017-10-26
Keycloak HIGH 7.2
CVE-2017-12160

It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permit…

Mitigation only
Fix from $1,950 2017-10-26
Single Sign On MEDIUM 5.4
CVE-2017-12158

It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use …

Mitigation only
Fix from $1,600 2017-10-26
Jboss Application Server MEDIUM 6.6
CVE-2013-3734

The Embedded Jopr component in JBoss Application Server includes the cleartext datasource password in unspecified HTML responses, which might allow (…

Fix: after 1.2
Fix from $1,600 2017-10-24
Enterprise Linux Desktop HIGH 8.8
CVE-2017-11292 KEVEPSS 12%

Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the…

Fix: after 27.0.0.159
Fix from $1,950 2017-10-22
Satellite HIGH 7.5
CVE-2017-10388

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java S…

Patch available
Fix from $1,950 2017-10-19
Satellite CRITICAL 9.6
CVE-2017-10346

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE:…

Patch available
Fix from $2,300 2017-10-19
Satellite MEDIUM 6.2
CVE-2017-10356

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected ar…

Patch available
Fix from $1,600 2017-10-19
Satellite MEDIUM 5.3
CVE-2017-10348

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java S…

Patch available
Fix from $1,600 2017-10-19
Satellite MEDIUM 5.3
CVE-2017-10349

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 6u…

Patch available
Fix from $1,600 2017-10-19
Satellite MEDIUM 5.3
CVE-2017-10350

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAX-WS). Supported versions that are affected are Java SE: …

Patch available
Fix from $1,600 2017-10-19
Satellite MEDIUM 5.3
CVE-2017-10355EPSS 16%

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected …

Patch available
Fix from $1,600 2017-10-19
Satellite MEDIUM 5.3
CVE-2017-10357

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Ja…

Patch available
Fix from $1,600 2017-10-19
Satellite HIGH 7.1
CVE-2017-10309EPSS 9%

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u144 and 9. E…

Patch available
Fix from $1,950 2017-10-19
Cloudforms 3.0 Management Engine MEDIUM 6.5
CVE-2014-7813

Red Hat CloudForms 3 Management Engine (CFME) allows remote authenticated users to cause a denial of service (resource consumption) via vectors invol…

Mitigation only
Fix from $1,600 2017-10-18
Enterprise Mrg MEDIUM 5.9
CVE-2014-3706

ovirt-engine, as used in Red Hat MRG 3, allows man-in-the-middle attackers to spoof servers by leveraging failure to verify key attributes in vdsm X.…

Mitigation only
Fix from $1,600 2017-10-18
Edeploy CRITICAL 9.1
CVE-2014-3702

Directory traversal vulnerability in eNovance eDeploy allows remote attackers to create arbitrary directories and files and consequently cause a deni…

Mitigation only
Fix from $2,300 2017-10-16
Ovirt Engine HIGH 7.5
CVE-2014-7851

oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowle…

Mitigation only
Fix from $1,950 2017-10-16
Subscription Asset Manager MEDIUM 6.1
CVE-2014-0029

Multiple cross-site scripting (XSS) vulnerabilities in the SAM web application in Red Hat katello-headpin allow remote attackers to inject arbitrary …

Mitigation only
Fix from $1,600 2017-10-16