Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux HIGH 8.8
CVE-2017-3072

Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the BitmapData class. Successful exploitati…

Fix: after 25.0.0.163
Fix from $1,950 2017-05-09
Enterprise Linux HIGH 8.8
CVE-2017-3073

Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability when handling multiple mask properties of display…

Fix: after 25.0.0.163
Fix from $1,950 2017-05-09
Enterprise Linux HIGH 8.8
CVE-2017-3074

Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Graphics class. Successful exploitation…

Fix: after 25.0.0.163
Fix from $1,950 2017-05-09
Fuse HIGH 7.5
CVE-2017-7957

XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during…

Fix: after 1.4.9
Fix from $1,950 2017-04-29
Icedtea HIGH 8.3
CVE-2017-3512

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 7u131 and 8u121. Diff…

Fix: 3.4.0+
Fix from $1,950 2017-04-24
Cloudforms Management Engine MEDIUM 5.3
CVE-2016-3702

Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext information.

Mitigation only
Fix from $1,600 2017-04-21
Openstack MEDIUM 5.4
CVE-2016-6519

Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authenticated users to inject arbitr…

Fix: after 2.5
Fix from $1,600 2017-04-21
Jboss Bpm Suite HIGH 8.8
CVE-2016-5401

Cross-site request forgery (CSRF) vulnerability in Red Hat JBoss BRMS and BPMS 6 allows remote attackers to hijack the authentication of users for re…

Mitigation only
Fix from $1,950 2017-04-20
Resteasy MEDIUM 6.1
CVE-2016-6347

Cross-site scripting (XSS) vulnerability in the default exception handler in RESTEasy allows remote attackers to inject arbitrary web script or HTML …

Mitigation only
Fix from $1,600 2017-04-20
Openshift HIGH 7.5
CVE-2016-5409

Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which makes it easier for remote atta…

Mitigation only
Fix from $1,950 2017-04-20
Enterprise Virtualization MEDIUM 6.8
CVE-2016-6338

ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate atta…

No fix yet
Fix from $1,600 2017-04-20
Enterprise Linux Desktop MEDIUM 5.5
CVE-2016-5410

firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations via the (1) addPassthrough, (…

Fix: after 0.4.3.2
Fix from $1,600 2017-04-19
Enterprise Linux Desktop HIGH 7.5
CVE-2016-6489EPSS 5%

The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack.

Fix: 3.3+
Fix from $1,950 2017-04-14
Jboss Data Grid HIGH 7.5
CVE-2016-4970EPSS 11%

handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (…

Fix: 4.0.37 / 4.1.1+
Fix from $1,950 2017-04-13
Satellite MEDIUM 6.1
CVE-2016-2104

Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the …

Mitigation only
Fix from $1,600 2017-04-13
Resteasy MEDIUM 6.1
CVE-2016-6348

JacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack.

Mitigation only
Fix from $1,600 2017-04-12
Mod Cluster HIGH 7.5
CVE-2016-4459

Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9.

Mitigation only
Fix from $1,950 2017-04-12
Enterprise Linux Desktop HIGH 7.0
CVE-2016-4444

The allow_execmod plugin for setroubleshoot before 3.2.23 allows local users to execute arbitrary commands by triggering an execmod SELinux denial wi…

Fix: after 3.2.22
Fix from $1,950 2017-04-11
Enterprise Linux Desktop HIGH 7.0
CVE-2016-4445

The fix_lookup_id function in sealert in setroubleshoot before 3.2.23 allows local users to execute arbitrary commands as root by triggering an SELin…

Fix: after 3.2.22
Fix from $1,950 2017-04-11
Enterprise Linux Desktop HIGH 7.0
CVE-2016-4446

The allow_execstack plugin for setroubleshoot allows local users to execute arbitrary commands by triggering an execstack SELinux denial with a craft…

Patch available
Fix from $1,950 2017-04-11
Enterprise Linux Desktop HIGH 7.0
CVE-2016-4989

setroubleshoot allows local users to bypass an intended container protection mechanism and execute arbitrary commands by (1) triggering an SELinux de…

Patch available
Fix from $1,950 2017-04-11
Openstack CRITICAL 9.8
CVE-2008-7313

The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CV…

Fix: after 4.2.3
Fix from $2,300 2017-03-31
Openstack CRITICAL 9.8
CVE-2014-5008

Snoopy allows remote attackers to execute arbitrary commands.

Patch available
Fix from $2,300 2017-03-31
Openstack CRITICAL 9.8
CVE-2014-5009

Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.

Fix: after 4.2.3
Fix from $2,300 2017-03-31
Enterprise Linux High Availability HIGH 7.5
CVE-2016-7797

Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthent…

Fix: after 1.1.14
Fix from $1,950 2017-03-24
Satellite CRITICAL 9.8
CVE-2017-5929EPSS 8%

QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.

Fix: 1.2.0+
Fix from $2,300 2017-03-13
Enterprise Linux HIGH 8.8
CVE-2016-3616

The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitra…

Mitigation only
Fix from $1,950 2017-02-13
Enterprise Linux HIGH 7.8
CVE-2016-2568

pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters t…

Mitigation only
Fix from $1,950 2017-02-13
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-9636EPSS 9%

Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a…

Fix: after 1.10.1
Fix from $2,300 2017-01-27
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-9634EPSS 9%

Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a…

Fix: after 1.10.1
Fix from $2,300 2017-01-27