Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jboss Enterprise Application Platform HIGH 8.8
CVE-2016-5406

The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by…

Fix: after 7.0.1
Fix from $1,950 2016-09-26
Jboss Enterprise Application Platform MEDIUM 6.1
CVE-2016-4993

CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before …

Fix: after 7.0.1
Fix from $1,600 2016-09-26
Jboss Enterprise Application Platform HIGH 7.5
CVE-2016-3110

mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP mes…

Mitigation only
Fix from $1,950 2016-09-26
Quickstart Cloud Installer HIGH 8.4
CVE-2016-6340

The kickstart file in Red Hat QuickStart Cloud Installer (QCI) forces use of MD5 passwords on deployed systems, which makes it easier for attackers t…

Mitigation only
Fix from $1,950 2016-09-22
Quickstart Cloud Installer HIGH 8.4
CVE-2016-6322

Red Hat QuickStart Cloud Installer (QCI) uses world-readable permissions for /etc/qci/answers, which allows local users to obtain the root password f…

Mitigation only
Fix from $1,950 2016-09-22
Enterprise Linux Desktop MEDIUM 5.5
CVE-2016-7166

libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory con…

Patch available
Fix from $1,600 2016-09-21
Enterprise Linux Desktop MEDIUM 6.5
CVE-2016-5844

Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a crafted …

Patch available
Fix from $1,600 2016-09-21
Enterprise Linux Desktop HIGH 7.5
CVE-2016-5418

The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to …

Patch available
Fix from $1,950 2016-09-21
Enterprise Linux Desktop HIGH 7.5
CVE-2016-4809

The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a…

Patch available
Fix from $1,950 2016-09-21
Enterprise Linux Desktop HIGH 7.8
CVE-2016-4302

Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to exe…

Fix: after 3.2.0
Fix from $1,950 2016-09-21
Enterprise Linux Desktop HIGH 7.8
CVE-2016-4300

Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to exec…

Fix: after 3.2.0
Fix from $1,950 2016-09-21
Jboss Operations Network HIGH 8.8
CVE-2016-5422

The web console in Red Hat JBoss Operations Network (JON) before 3.3.7 does not properly authorize requests to add users with the super user role, wh…

Fix: after 3.3.6
Fix from $1,950 2016-09-07
Jboss Bpm Suite HIGH 8.8
CVE-2016-7034

The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session and includes them in query s…

Mitigation only
Fix from $1,950 2016-09-07
Jboss Bpm Suite MEDIUM 6.1
CVE-2016-7033

Multiple cross-site scripting (XSS) vulnerabilities in the admin pages in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 allow remote attackers to inje…

Mitigation only
Fix from $1,600 2016-09-07
Resteasy HIGH 7.5
CVE-2016-6346EPSS 6%

RESTEasy enables GZIPInterceptor, which allows remote attackers to cause a denial of service via unspecified vectors.

Mitigation only
Fix from $1,950 2016-09-07
Resteasy MEDIUM 6.5
CVE-2016-6345

RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.

Mitigation only
Fix from $1,600 2016-09-07
Jboss Bpm Suite MEDIUM 5.3
CVE-2016-6344

Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attacke…

Mitigation only
Fix from $1,600 2016-09-07
Jboss Enterprise Application Platform HIGH 7.5
CVE-2016-2183EPSS 96%

The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately…

Fix: 0.10.47 / 0.12.16+
Fix from $1,950 2016-09-01
Cloudforms HIGH 8.8
CVE-2016-5383

The web UI in Red Hat CloudForms 4.1 allows remote authenticated users to execute arbitrary code via vectors involving "Lack of field filters."

Mitigation only
Fix from $1,950 2016-08-26
Openshift HIGH 8.8
CVE-2016-5766EPSS 7%

Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x b…

Patch available
Fix from $1,950 2016-08-07
Openshift MEDIUM 6.5
CVE-2016-5392

The API server in Kubernetes, as used in Red Hat OpenShift Enterprise 3.2, in a multi tenant environment allows remote authenticated users with knowl…

Mitigation only
Fix from $1,600 2016-08-05
Dashbuilder CRITICAL 9.8
CVE-2016-4999

SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuil…

Fix: after 0.5.0
Fix from $2,300 2016-08-05
Satellite MEDIUM 6.1
CVE-2016-3097

Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML vi…

Mitigation only
Fix from $1,600 2016-08-05
Satellite MEDIUM 6.1
CVE-2016-3080

Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML vi…

Mitigation only
Fix from $1,600 2016-08-05
Jboss Operations Network CRITICAL 9.8
CVE-2016-3737EPSS 7%

The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, relat…

Fix: after 3.3.5
Fix from $2,300 2016-08-02
Enterprise Linux Desktop HIGH 8.1
CVE-2016-5388EPSS 51%

Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not prote…

Patch available
Fix from $1,950 2016-07-19
Libvirt CRITICAL 9.8
CVE-2016-5008

libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers…

Fix: after 1.3.5
Fix from $2,300 2016-07-13
Ceph Storage Mon MEDIUM 6.5
CVE-2016-5009

The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph mon…

Fix: after 0.94.6
Fix from $1,600 2016-07-12
Openstack HIGH 7.5
CVE-2016-4985

The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive informati…

Fix: after 4.2.4
Fix from $1,950 2016-07-12
Openstack MEDIUM 5.4
CVE-2016-4428

Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allows remote authenticated users…

Fix: after 8.0.1
Fix from $1,600 2016-07-12