Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux MEDIUM 6.5
CVE-2015-8553

Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and I/O decodi…

Patch available
Fix from $1,600 2016-04-13
Openstack HIGH 8.8
CVE-2016-1568

Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service…

Fix: after 2.5.1.1
Fix from $1,950 2016-04-12
Cloudforms Management Engine MEDIUM 5.1
CVE-2015-7502

Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.5.0 do not properly encrypt data in the backend P…

Mitigation only
Fix from $1,600 2016-04-11
Openstack HIGH 7.3
CVE-2015-5329

The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 7.0, do not properly use the configured R…

Mitigation only
Fix from $1,950 2016-04-11
Enterprise Linux HIGH 7.5
CVE-2015-5229

The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 and 7.2 does not properly initialize memory areas, which might allow …

Mitigation only
Fix from $1,950 2016-04-08
Openshift CRITICAL 9.8
CVE-2016-0791

Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to…

Fix: after 1.649
Fix from $2,300 2016-04-07
Openstack HIGH 8.1
CVE-2016-1714EPSS 6%

The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware Configuration device emulati…

Fix: after 2.3.0
Fix from $1,950 2016-04-07
Jboss Wildfly Application Server HIGH 7.5
CVE-2016-0793EPSS 16%

Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Server) before 10.0.0.Final on …

No fix yet
Fix from $1,950 2016-04-01
Enterprise Linux Desktop HIGH 8.1
CVE-2016-0636EPSS 6%

Unspecified vulnerability in Oracle Java SE 7u97, 8u73, and 8u74 allows remote attackers to affect confidentiality, integrity, and availability via u…

Fix: after 2.6.6
Fix from $1,950 2016-03-24
Openshift HIGH 8.8
CVE-2015-7537

Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication o…

Fix: after 3.1
Fix from $1,950 2016-02-03
Enterprise Linux Desktop MEDIUM 6.8
CVE-2016-0505EPSS 8%

Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.…

Fix: after 5.7.9
Fix from $1,600 2016-01-21
Openstack MEDIUM 5.4
CVE-2015-5295

The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticat…

Fix: 5.0.1 / 2015.1.3+
Fix from $1,600 2016-01-20
Enterprise Linux Desktop CRITICAL 9.0
CVE-2015-7512EPSS 8%

Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial…

Mitigation only
Fix from $2,300 2016-01-08
Openshift CRITICAL 9.8
CVE-2015-5254EPSS 38%

Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitr…

Mitigation only
Fix from $2,300 2016-01-08
Enterprise Linux Desktop HIGH 8.8
CVE-2015-8651 KEVEPSS 68%

Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Ad…

Fix: 11.2.202.559 / 18.0.0.324+
Fix from $1,950 2015-12-28
Enterprise Linux Desktop HIGH 7.5
CVE-2015-8327EPSS 10%

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows rem…

Mitigation only
Fix from $1,950 2015-12-17
Enterprise Linux Desktop HIGH 7.2
CVE-2015-5277

The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow loc…

Fix: after 2.19
Fix from $1,950 2015-12-17
Libreport MEDIUM 5.0
CVE-2015-5302

libreport 2.0.7 before 2.6.3 only saves changes to the first file when editing a crash report, which allows remote attackers to obtain sensitive info…

Patch available
Fix from $1,600 2015-12-07
Automatic Bug Reporting Tool MEDIUM 6.9
CVE-2015-5287

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges vi…

Fix: after 2.7.0
Fix from $1,600 2015-12-07
Openshift Container Platform CRITICAL 9.8
CVE-2015-8103EPSS 87%

The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized J…

Fix: 1.625.2 / 1.638+
Fix from $2,300 2015-11-25
Openshift HIGH 7.5
CVE-2015-5325

Jenkins before 1.638 and LTS before 1.625.2 allow attackers to bypass intended slave-to-master access restrictions by leveraging a JNLP slave. NOTE: …

Fix: after 3.1
Fix from $1,950 2015-11-25
Openshift MEDIUM 6.5
CVE-2015-5323

Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges …

Fix: after 3.1
Fix from $1,600 2015-11-25
Openshift MEDIUM 5.0
CVE-2015-5322

Directory traversal vulnerability in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to list directory contents and read arbitrar…

Fix: after 3.1
Fix from $1,600 2015-11-25
Openshift MEDIUM 5.0
CVE-2015-5321

The sidepanel widgets in the CLI command overview and help pages in Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sens…

Fix: after 3.1
Fix from $1,600 2015-11-25
Openshift MEDIUM 5.0
CVE-2015-5320

Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, which allows remote attackers to…

Fix: after 3.1
Fix from $1,600 2015-11-25
Openshift MEDIUM 5.0
CVE-2015-5319

XML external entity (XXE) vulnerability in the create-job CLI command in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to read …

Fix: after 3.1
Fix from $1,600 2015-11-25
Gluster Storage MEDIUM 6.0
CVE-2015-5242

OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authe…

Mitigation only
Fix from $1,600 2015-11-25
Openstack HIGH 7.2
CVE-2015-5225

Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of s…

Fix: after 2.4.0
Fix from $1,950 2015-11-06
Openshift MEDIUM 6.4
CVE-2015-5305

Directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift Enterprise 3.0, allows attackers to write to arbitrary files via a craf…

Mitigation only
Fix from $1,600 2015-11-06
Jboss Enterprise Application Platform MEDIUM 5.0
CVE-2015-5220

The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers…

Fix: after 6.4.3
Fix from $1,600 2015-10-27