Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jboss Enterprise Application Platform MEDIUM 6.8
CVE-2015-5188

Cross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platform before 6.4.4 and WildFly …

Fix: after 6.4.3
Fix from $1,600 2015-10-27
Satellite MEDIUM 5.3
CVE-2015-4902 KEVEPSS 13%

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployme…

Patch available
Fix from $1,600 2015-10-22
Enterprise Linux Desktop HIGH 7.8
CVE-2015-7645 KEVEPSS 68%

Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attac…

Fix: after 18.0.0.252
Fix from $1,950 2015-10-15
Enterprise Linux Desktop MEDIUM 6.8
CVE-2015-5234

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .app…

Fix: after 1.5.2
Fix from $1,600 2015-10-09
Enterprise Linux Desktop MEDIUM 6.8
CVE-2014-9751

The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP addr…

Fix: 4.2.8+
Fix from $1,600 2015-10-06
Enterprise Linux Desktop MEDIUM 5.8
CVE-2014-9750EPSS 6%

ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtain sensitive information from …

Fix: 4.2.8+
Fix from $1,600 2015-10-06
Openshift MEDIUM 6.5
CVE-2015-5274

rubygem-openshift-origin-console in Red Hat OpenShift 2.2 allows remote authenticated users to execute arbitrary commands via a crafted request to th…

Mitigation only
Fix from $1,600 2015-09-18
Enterprise Linux MEDIUM 6.9
CVE-2015-3247

Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (h…

Mitigation only
Fix from $1,600 2015-09-08
Enterprise Linux Desktop HIGH 7.2
CVE-2015-5157

arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform mishandles IRET faults in processing NMIs that occurred during user…

Fix: 3.12.47 / 3.14.54+
Fix from $1,950 2015-08-31
Openshift HIGH 8.5
CVE-2015-5222

Red Hat OpenShift Enterprise 3.0.0.0 does not properly check permissions, which allows remote authenticated users with build permissions to execute a…

Mitigation only
Fix from $1,950 2015-08-24
Enterprise Linux High Availability HIGH 7.5
CVE-2015-1867

Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.

Fix: after 1.1.12
Fix from $1,950 2015-08-12
Jboss Portal MEDIUM 5.8
CVE-2015-5176

The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets,…

Mitigation only
Fix from $1,600 2015-08-11
Libuser HIGH 7.2
CVE-2015-3246EPSS 7%

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allo…

Fix: after 0.56.13-5
Fix from $1,950 2015-08-11
Jboss Bpm Suite HIGH 7.5
CVE-2015-1818

XML external entity (XXE) vulnerability in the dashbuilder import facility (DocumentBuilders in org.jboss.dashboard.export.ImportManagerImpl) in Red …

Fix: after 6.1.0
Fix from $1,950 2015-08-11
Enterprise Linux Desktop Supplementary MEDIUM 5.0
CVE-2015-1285

The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, d…

Fix: after 43.0.2357.134
Fix from $1,600 2015-07-23
Enterprise Linux Desktop Supplementary HIGH 7.5
CVE-2015-1279

Integer overflow in the CJBig2_Image::expand function in fxcodec/jbig2/JBig2_Image.cpp in PDFium, as used in Google Chrome before 44.0.2403.89, allow…

Fix: after 43.0.2357.134
Fix from $1,950 2015-07-23
Enterprise Linux Desktop Supplementary MEDIUM 6.8
CVE-2015-1273

Heap-based buffer overflow in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 44.0.2403.89, allows remote attackers to caus…

Fix: after 43.0.2357.134
Fix from $1,600 2015-07-23
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-5123 KEVEPSS 18%

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Wind…

Fix: after 18.0.0.203
Fix from $2,300 2015-07-14
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-5122 KEVEPSS 94%

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on W…

Fix: after 18.0.0.204
Fix from $2,300 2015-07-14
Jboss Fuse MEDIUM 6.0
CVE-2014-8175

Red Hat JBoss Fuse before 6.2.0 allows remote authenticated users to bypass intended restrictions and access the HawtIO console by leveraging an acco…

Fix: after 6.1.0
Fix from $1,600 2015-07-08
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-5119 KEVEPSS 99%

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x…

Fix: after 18.0.0.194
Fix from $2,300 2015-07-08
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-0192

Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 F…

Fix: 5.0.16.10 / 6.1.8.4+
Fix from $2,300 2015-07-02
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-3113 KEVEPSS 100%

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.46…

Fix: 11.2.202.468 / 13.0.0.296+
Fix from $2,300 2015-06-23
Enterprise Linux Desktop MEDIUM 5.0
CVE-2015-4148EPSS 20%

The do_soap_call function in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that the uri property …

Fix: after 10.10.4
Fix from $1,600 2015-06-09
Enterprise Linux Desktop HIGH 7.5
CVE-2015-4147EPSS 12%

The SoapClient::__call method in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that __default_hea…

Fix: after 10.10.4
Fix from $1,950 2015-06-09
Enterprise Linux HIGH 7.5
CVE-2015-4026EPSS 20%

The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 charact…

Fix: after 5.4.40
Fix from $1,950 2015-06-09
Enterprise Linux MEDIUM 5.0
CVE-2015-4024EPSS 50%

Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x …

Fix: after 5.4.40
Fix from $1,600 2015-06-09
Enterprise Linux Desktop HIGH 7.5
CVE-2015-4022EPSS 21%

Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote FTP ser…

Fix: after 5.4.40
Fix from $1,950 2015-06-09
Enterprise Linux Desktop MEDIUM 5.0
CVE-2015-4021EPSS 21%

The phar_parse_tarfile function in ext/phar/tar.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 does not verify that the first ch…

Fix: after 5.4.40
Fix from $1,600 2015-06-09
Enterprise Linux Desktop HIGH 7.5
CVE-2015-3329EPSS 38%

Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5…

Fix: after 5.4.39
Fix from $1,950 2015-06-09