Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux Desktop HIGH 8.8
CVE-2016-4132

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11…

Fix: after 21.0.0.242
Fix from $1,950 2016-06-16
Enterprise Linux Desktop HIGH 8.8
CVE-2016-4131

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11…

Fix: after 21.0.0.242
Fix from $1,950 2016-06-16
Enterprise Linux Desktop HIGH 8.8
CVE-2016-4130

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11…

Fix: after 21.0.0.242
Fix from $1,950 2016-06-16
Enterprise Linux Desktop HIGH 8.8
CVE-2016-4129

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11…

Fix: after 21.0.0.242
Fix from $1,950 2016-06-16
Enterprise Linux Desktop HIGH 8.8
CVE-2016-4128

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11…

Fix: after 21.0.0.242
Fix from $1,950 2016-06-16
Enterprise Linux Desktop HIGH 8.8
CVE-2016-4127

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11…

Fix: after 21.0.0.242
Fix from $1,950 2016-06-16
Enterprise Linux Desktop HIGH 8.8
CVE-2016-4125

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11…

Fix: after 21.0.0.242
Fix from $1,950 2016-06-16
Enterprise Linux Desktop HIGH 8.8
CVE-2016-4124

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11…

Fix: after 21.0.0.242
Fix from $1,950 2016-06-16
Enterprise Linux Desktop HIGH 8.8
CVE-2016-4123

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11…

Fix: after 21.0.0.242
Fix from $1,950 2016-06-16
Enterprise Linux Desktop HIGH 8.8
CVE-2016-4122

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11…

Fix: after 21.0.0.242
Fix from $1,950 2016-06-16
Enterprise Linux Desktop HIGH 8.1
CVE-2016-3698

libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remot…

Patch available
Fix from $1,950 2016-06-13
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-4448EPSS 7%

Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.

Mitigation only
Fix from $2,300 2016-06-09
Enterprise Linux HIGH 7.1
CVE-2016-2150

SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to…

Mitigation only
Fix from $1,950 2016-06-09
Openshift HIGH 8.8
CVE-2016-3738

Red Hat OpenShift Enterprise 3.2 does not properly restrict access to STI builds, which allows remote authenticated users to access the Docker socket…

Mitigation only
Fix from $1,950 2016-06-08
Openshift HIGH 7.1
CVE-2016-3708

Red Hat OpenShift Enterprise 3.2, when multi-tenant SDN is enabled and a build is run in a namespace that would normally be isolated from pods in oth…

Mitigation only
Fix from $1,950 2016-06-08
Openshift MEDIUM 5.3
CVE-2016-3703

Red Hat OpenShift Enterprise 3.2 and 3.1 do not properly validate the origin of a request when anonymous access is granted to a service/proxy or pod/…

Mitigation only
Fix from $1,600 2016-06-08
Openshift Origin HIGH 8.8
CVE-2016-2160

Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allow remote authenticated users to execute commands with root privileges by changing the root …

Patch available
Fix from $1,950 2016-06-08
Openshift MEDIUM 6.5
CVE-2016-2149

Red Hat OpenShift Enterprise 3.2 allows remote authenticated users to read log files from another namespace by using the same name as a previously de…

Mitigation only
Fix from $1,600 2016-06-08
Openshift MEDIUM 5.5
CVE-2016-2142

Red Hat OpenShift Enterprise 3.1 uses world-readable permissions on the /etc/origin/master/master-config.yaml configuration file, which allows local …

Mitigation only
Fix from $1,600 2016-06-08
Satellite HIGH 8.8
CVE-2016-3072

Multiple SQL injection vulnerabilities in the scoped_search function in app/controllers/katello/api/v2/api_controller.rb in Katello allow remote auth…

Patch available
Fix from $1,950 2016-06-07
Enterprise Linux Desktop HIGH 7.8
CVE-2015-5260

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash…

Mitigation only
Fix from $1,950 2016-06-07
Gluster Storage Management Console MEDIUM 6.5
CVE-2014-8177

The Red Hat gluster-swift package, as used in Red Hat Gluster Storage (formerly Red Hat Storage Server), allows remote authenticated users to bypass …

Mitigation only
Fix from $1,600 2016-06-07
Satellite CRITICAL 9.1
CVE-2015-5041

The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote at…

Fix: 6.0.16.20 / 6.1.8.20+
Fix from $2,300 2016-06-06
Satellite HIGH 8.1
CVE-2016-0376EPSS 6%

The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), …

Mitigation only
Fix from $1,950 2016-06-03
Satellite HIGH 8.1
CVE-2016-0363

The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 be…

Mitigation only
Fix from $1,950 2016-06-03
Libvirt MEDIUM 6.5
CVE-2014-3672

The qemu implementation in libvirt before 1.3.0 and Xen allows local guest OS users to cause a denial of service (host disk consumption) by writing t…

Fix: after 1.2.21
Fix from $1,600 2016-05-25
Satellite MEDIUM 5.6
CVE-2016-0264

Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25)…

Mitigation only
Fix from $1,600 2016-05-24
Enterprise Linux HIGH 7.8
CVE-2016-4805

Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memor…

Fix: 3.2.80 / 3.10.102+
Fix from $1,950 2016-05-23
Openshift MEDIUM 6.5
CVE-2016-3724

Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with extended read access to obtain sensitive password information by read…

Fix: after 1.651.1
Fix from $1,600 2016-05-17
Jboss Middleware HIGH 7.5
CVE-2016-3674EPSS 8%

Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) Stand…

Fix: 1.4.9+
Fix from $1,950 2016-05-17