Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Satellite HIGH 7.0
CVE-2016-4996

discovery-debug in Foreman before 6.2 when the ssh service has been enabled on discovered nodes displays the root password in plaintext in the system…

Mitigation only
Fix from $1,950 2017-07-17
Networkmanager MEDIUM 6.2
CVE-2016-0764

Race condition in Network Manager before 1.0.12 as packaged in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enter…

Fix: after 1.0.8
Fix from $1,600 2017-07-17
3scale Api Management Platform CRITICAL 9.8
CVE-2017-7512

Red Hat 3scale (aka RH-3scale) API Management Platform (AMP) before 2.0.0 would permit creation of an access token without a client secret. An attack…

Mitigation only
Fix from $2,300 2017-07-07
Gluster Storage HIGH 7.8
CVE-2015-1795

Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root.

Mitigation only
Fix from $1,950 2017-06-27
Storage Console HIGH 7.8
CVE-2016-7062

rhscon-ceph in Red Hat Storage Console 2 x86_64 and Red Hat Storage Console Node 2 x86_64 allows local users to obtain the password as cleartext.

Mitigation only
Fix from $1,950 2017-06-27
Enterprise Linux HIGH 7.5
CVE-2017-9953

There is an invalid free in Image::printIFDStructure that leads to a Segmentation fault in Exiv2 0.26. A crafted input will lead to a remote denial o…

No fix yet
Fix from $1,950 2017-06-26
Automatic Bug Reporting Tool HIGH 7.8
CVE-2015-3315

Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impact on arbitrary files via a sy…

Patch available
Fix from $1,950 2017-06-26
Virtio Win HIGH 7.5
CVE-2015-3215

The NetKVM Windows Virtio driver allows remote attackers to cause a denial of service (guest crash) via a crafted length value in an IP packet, as de…

Patch available
Fix from $1,950 2017-06-26
Automatic Bug Reporting Tool MEDIUM 5.5
CVE-2015-1870

The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which all…

Fix: after 2.1.11
Fix from $1,600 2017-06-26
Enterprise Linux HIGH 7.8
CVE-2017-1000366

glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially …

Patch available
Fix from $1,950 2017-06-19
Enterprise Virtualization Server HIGH 7.0
CVE-2017-1000376

libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting the stack. Please note that lib…

Fix: 3.2+
Fix from $1,950 2017-06-19
Quickstart Cloud Installer CRITICAL 9.8
CVE-2016-5411

/var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created world readable and contains the …

Mitigation only
Fix from $2,300 2017-06-13
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-5405

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server …

Mitigation only
Fix from $2,300 2017-06-08
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-7050EPSS 5%

SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and R…

Mitigation only
Fix from $2,300 2017-06-08
Enterprise Linux Desktop HIGH 7.5
CVE-2016-3099

mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Wo…

Mitigation only
Fix from $1,950 2017-06-08
Enterprise Linux Desktop HIGH 7.5
CVE-2016-4992

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server …

Patch available
Fix from $1,950 2017-06-08
Enterprise Linux Desktop HIGH 7.5
CVE-2016-5416

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server …

Mitigation only
Fix from $1,950 2017-06-08
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2016-3690EPSS 5%

The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.

Mitigation only
Fix from $2,300 2017-06-08
Ansible HIGH 8.8
CVE-2014-3498

The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands.

Fix: after 1.6.5
Fix from $1,950 2017-06-08
Cloudforms HIGH 8.8
CVE-2016-4471

ManageIQ in CloudForms before 4.1 allows remote authenticated users to execute arbitrary code.

Fix: after 4.0
Fix from $1,950 2017-06-08
Cloudforms Management Engine HIGH 7.5
CVE-2016-4457

CloudForms Management Engine before 5.8 includes a default SSL/TLS certificate.

No fix yet
Fix from $1,950 2017-06-08
Ansible HIGH 7.8
CVE-2015-6240

The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow local users to escape a restricted environment via a symlink attack.

Fix: after 1.9.1
Fix from $1,950 2017-06-07
Enterprise Linux Desktop MEDIUM 6.5
CVE-2017-9461

smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory…

Fix: after 4.4.9
Fix from $1,600 2017-06-06
Ovirt Engine MEDIUM 6.5
CVE-2016-3077

The VersionMapper.fromKernelVersionString method in oVirt Engine allows remote authenticated users to cause a denial of service (process crash) for a…

Mitigation only
Fix from $1,600 2017-06-06
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-7504EPSS 29%

HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Se…

Fix: after 4.0
Fix from $2,300 2017-05-19
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-7503

It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use th…

Mitigation only
Fix from $2,300 2017-05-18
Enterprise Linux HIGH 8.8
CVE-2017-3068EPSS 20%

Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Advanced Video Coding engine. Successfu…

Fix: after 25.0.0.163
Fix from $1,950 2017-05-09
Enterprise Linux HIGH 8.8
CVE-2017-3069

Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the BlendMode class. Successful exploitatio…

Fix: after 25.0.0.163
Fix from $1,950 2017-05-09
Enterprise Linux HIGH 8.8
CVE-2017-3070

Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the ConvolutionFilter class. Successful exp…

Fix: after 25.0.0.163
Fix from $1,950 2017-05-09
Enterprise Linux HIGH 8.8
CVE-2017-3071EPSS 6%

Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability when masking display objects. Successful exploita…

Fix: after 25.0.0.163
Fix from $1,950 2017-05-09