Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux HIGH 7.8
CVE-2017-1000253 KEVEPSS 11%

Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committ…

Fix: 3.2.70 / 3.4.109+
Fix from $1,950 2017-10-05
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-12149 KEVEPSS 91%

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessF…

Mitigation only
Fix from $2,300 2017-10-04
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-14491EPSS 85%

Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafte…

Fix: after 2.77
Fix from $2,300 2017-10-04
Mobile Application Platform CRITICAL 9.8
CVE-2017-7552

A flaw was discovered in the file editor of millicore, affecting versions before 3.19.0 and 4.x before 4.5.0, which allows files to be executed as we…

Fix: after 4.4.3
Fix from $2,300 2017-09-29
Mobile Application Platform MEDIUM 6.3
CVE-2017-7553

The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the netwo…

Fix: after 4.4.3
Fix from $1,600 2017-09-29
Mobile Application Platform MEDIUM 6.1
CVE-2017-7554

It was found that the App Studio component of RHMAP 4.4 executes javascript provided by a user. An attacker could use this flaw to execute a stored X…

Patch available
Fix from $1,600 2017-09-29
Enterprise Virtualization Manager CRITICAL 9.1
CVE-2015-7544

redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the Supe…

Mitigation only
Fix from $2,300 2017-09-25
Amq HIGH 8.8
CVE-2015-5182

Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ.

Mitigation only
Fix from $1,950 2017-09-25
Amq HIGH 7.5
CVE-2015-5183

Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ.

Fix: 6.3+
Fix from $1,950 2017-09-25
Amq HIGH 7.5
CVE-2015-5184

Console: CORS headers set to allow all in Red Hat AMQ.

Fix: 6.2.1+
Fix from $1,950 2017-09-25
Jboss A Mq MEDIUM 5.4
CVE-2015-5181

The JBoss console in A-MQ allows remote attackers to execute arbitrary JavaScript.

Fix: after 6.0
Fix from $1,600 2017-09-25
Feedhenry Enterprise Mobile Application Platform MEDIUM 6.5
CVE-2015-5248

Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform.

No fix yet
Fix from $1,600 2017-09-20
Jboss Enterprise Application Platform MEDIUM 5.9
CVE-2015-1849

AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vect…

Fix: after 6.4.0
Fix from $1,600 2017-09-19
Enterprise Linux MEDIUM 5.5
CVE-2015-7837

The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local …

Patch available
Fix from $1,600 2017-09-19
Edeploy CRITICAL 9.8
CVE-2014-8174

eDeploy makes it easier for remote attackers to execute arbitrary code by leveraging use of HTTP to download files.

Fix: after 1.11.0
Fix from $2,300 2017-09-19
Pagure HIGH 7.5
CVE-2017-1002151

Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization

Fix: after 3.3
Fix from $1,950 2017-09-14
Jboss Enterprise Application Platform HIGH 7.5
CVE-2017-7561

Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component re…

Patch available
Fix from $1,950 2017-09-13
Rhnsd MEDIUM 5.5
CVE-2017-7560

It was found that rhnsd PID files are created as world-writable that allows local attackers to fill the disks or to kill selected processes.

Mitigation only
Fix from $1,600 2017-09-13
Satellite MEDIUM 6.5
CVE-2014-8163

Directory traversal vulnerability in the XMLRPC interface in Red Hat Satellite 5.

No fix yet
Fix from $1,600 2017-08-28
Satellite MEDIUM 6.1
CVE-2014-0141

Cross-site scripting (XSS) vulnerability in Red Hat Satellite 6.0.3.

No fix yet
Fix from $1,600 2017-08-28
Satellite MEDIUM 6.1
CVE-2014-8168

Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.

Mitigation only
Fix from $1,600 2017-08-28
Enterprise Virtualization Manager MEDIUM 5.9
CVE-2015-5293

Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which m…

Fix: after 3.6.0
Fix from $1,600 2017-08-24
Enterprise Virtualization MEDIUM 5.5
CVE-2016-6310

oVirt Engine discloses the ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD in /var/log/ovirt-engine/engine.log file in RHEV before 4.0.

Fix: after 3.6
Fix from $1,600 2017-08-22
Jboss Enterprise Application Platform MEDIUM 5.3
CVE-2016-6311

Get requests in JBoss Enterprise Application Platform (EAP) 7 disclose internal IP addresses to remote attackers.

Mitigation only
Fix from $1,600 2017-08-22
Enterprise Linux HIGH 8.8
CVE-2017-3106EPSS 22%

Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful exploitation c…

Fix: after 26.0.0.137
Fix from $1,950 2017-08-11
Enterprise Linux HIGH 7.4
CVE-2017-3085

Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redi…

Fix: after 26.0.0.137
Fix from $1,950 2017-08-11
Enterprise Linux HIGH 7.0
CVE-2014-0143

Multiple integer overflows in the block drivers in QEMU, possibly before 2.0.0, allow local users to cause a denial of service (crash) via a crafted …

Fix: after 1.7.1
Fix from $1,950 2017-08-10
Ovirt Engine MEDIUM 6.1
CVE-2016-3113

Cross-site scripting (XSS) vulnerability in ovirt-engine allows remote attackers to inject arbitrary web script or HTML.

Mitigation only
Fix from $1,600 2017-08-07
Enterprise Linux Desktop MEDIUM 5.5
CVE-2015-3149

The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitrary files via a symlink attack.

Mitigation only
Fix from $1,600 2017-07-25
Jboss Wildfly Application Server HIGH 7.5
CVE-2015-3198

The Undertow module of WildFly 9.x before 9.0.0.CR2 and 10.x before 10.0.0.Alpha1 allows remote attackers to obtain the source code of a JSP page via…

Mitigation only
Fix from $1,950 2017-07-21