Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-9635EPSS 9%

Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a…

Fix: after 1.10.1
Fix from $2,300 2017-01-27
Enterprise Linux Desktop HIGH 7.5
CVE-2016-9446

The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrate…

Fix: 1.11.1+
Fix from $1,950 2017-01-23
Enterprise Linux HIGH 7.8
CVE-2016-9675

openjpeg: A heap-based buffer overflow flaw was found in the patch for CVE-2013-6045. A crafted j2k image could cause the application to crash, or po…

Fix: 1.5.2+
Fix from $1,950 2016-12-22
Enterprise Linux Desktop CRITICAL 9.8
CVE-2014-8241

XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return …

Mitigation only
Fix from $2,300 2016-12-14
Enterprise Virtualization MEDIUM 5.5
CVE-2016-4443

Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by r…

Patch available
Fix from $1,600 2016-12-14
Openstack MEDIUM 6.0
CVE-2016-7466

Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator), when the xhci uses msix, allows local guest OS administr…

Fix: after 2.7.1
Fix from $1,600 2016-12-10
Openstack MEDIUM 6.0
CVE-2016-7422

The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service …

Fix: after 2.7.1
Fix from $1,600 2016-12-10
Virtualization MEDIUM 6.0
CVE-2016-6835

The vmxnet_tx_pkt_parse_headers function in hw/net/vmxnet_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denia…

Fix: 2.6.0+
Fix from $1,600 2016-12-10
Enterprise Linux Desktop HIGH 8.8
CVE-2016-7865EPSS 7%

Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitatio…

Fix: after 23.0.0.205
Fix from $1,950 2016-11-08
Enterprise Linux Desktop HIGH 8.8
CVE-2016-7864EPSS 7%

Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitatio…

Fix: after 23.0.0.205
Fix from $1,950 2016-11-08
Enterprise Linux Desktop HIGH 8.8
CVE-2016-7863EPSS 7%

Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitatio…

Fix: after 23.0.0.205
Fix from $1,950 2016-11-08
Enterprise Linux Desktop HIGH 8.8
CVE-2016-7862EPSS 7%

Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitatio…

Fix: after 23.0.0.205
Fix from $1,950 2016-11-08
Enterprise Linux Desktop HIGH 8.8
CVE-2016-7861EPSS 7%

Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitatio…

Fix: after 23.0.0.205
Fix from $1,950 2016-11-08
Enterprise Linux Desktop HIGH 8.8
CVE-2016-7860EPSS 7%

Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitatio…

Fix: after 23.0.0.205
Fix from $1,950 2016-11-08
Enterprise Linux Desktop HIGH 8.8
CVE-2016-7859EPSS 7%

Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitatio…

Fix: after 23.0.0.205
Fix from $1,950 2016-11-08
Enterprise Linux Desktop HIGH 8.8
CVE-2016-7858EPSS 7%

Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitatio…

Fix: after 23.0.0.205
Fix from $1,950 2016-11-08
Enterprise Linux Desktop HIGH 8.8
CVE-2016-7857EPSS 7%

Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitatio…

Fix: after 23.0.0.205
Fix from $1,950 2016-11-08
Openstack MEDIUM 6.0
CVE-2016-8669

The serial_update_parameters function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of serv…

Fix: after 2.7.1
Fix from $1,600 2016-11-04
Openstack MEDIUM 6.0
CVE-2016-8576

The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (inf…

Fix: after 2.7.1
Fix from $1,600 2016-11-04
Enterprise Linux Desktop HIGH 7.5
CVE-2016-8864EPSS 39%

named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (ass…

Fix: 9.9.9 / 9.10.4+
Fix from $1,950 2016-11-02
Enterprise Linux Desktop HIGH 8.8
CVE-2016-7855 KEVEPSS 25%

Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to …

Fix: after 23.0.0.185
Fix from $1,950 2016-11-01
Enterprise Linux Desktop HIGH 8.8
CVE-2016-4286EPSS 6%

Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to…

Fix: after 23.0.0.162
Fix from $1,950 2016-10-13
Enterprise Linux Desktop MEDIUM 5.5
CVE-2016-7796

The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received o…

Patch available
Fix from $1,600 2016-10-13
Jboss Enterprise Application Platform HIGH 8.8
CVE-2016-7065EPSS 12%

The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and pos…

No fix yet
Fix from $1,950 2016-10-13
Pagure MEDIUM 6.1
CVE-2016-1000007

Pagure 2.2.1 XSS in raw file endpoint

Patch available
Fix from $1,600 2016-10-07
Cloudforms Management Engine HIGH 8.8
CVE-2016-7040

Red Hat CloudForms Management Engine 4.1 does not properly handle regular expressions passed to the expression engine via the JSON API and the web-ba…

Mitigation only
Fix from $1,950 2016-10-07
Jboss Enterprise Application Platform MEDIUM 5.9
CVE-2016-7046

Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause …

Mitigation only
Fix from $1,600 2016-10-03
Ceph Storage HIGH 7.5
CVE-2016-7031

The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL.

Fix: after 10.0.0
Fix from $1,950 2016-10-03
Jboss Bpm Suite MEDIUM 5.4
CVE-2016-5398

Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6.3.3 allows remote authenticated users to inje…

Fix: after 6.3.2
Fix from $1,600 2016-10-03
Jboss Operations Network CRITICAL 9.8
CVE-2016-6330EPSS 11%

The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote a…

Mitigation only
Fix from $2,300 2016-09-27