Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux Desktop HIGH 7.5
CVE-2015-3307EPSS 8%

The phar_parse_metadata function in ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to caus…

Fix: after 5.4.39
Fix from $1,950 2015-06-09
Network Satellite HIGH 7.5
CVE-2014-8162

XML external entity (XXE) in the RPC interface in Spacewalk and Red Hat Network (RHN) Satellite 5.7 and earlier allows remote attackers to read arbit…

Fix: after 5.7
Fix from $1,950 2015-05-14
Enterprise Virtualization HIGH 7.7
CVE-2015-3456EPSS 15%

The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bou…

Fix: after 2.3.0
Fix from $1,950 2015-05-13
Enterprise Virtualization Manager MEDIUM 6.8
CVE-2015-0237

Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 ignores the permission to deny snapshot creation during live storage migration between …

Fix: after 3.5.0
Fix from $1,600 2015-05-01
Jboss Operations Network HIGH 9.0
CVE-2015-0297

Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java met…

Mitigation only
Fix from $1,950 2015-04-24
Drools HIGH 7.5
CVE-2014-8125

XML external entity (XXE) vulnerability in Drools and jBPM before 6.2.0 allows remote attackers to read arbitrary files or possibly have other unspec…

Fix: after 6.1.0
Fix from $1,950 2015-04-21
Enterprise Linux Desktop Supplementary MEDIUM 5.0
CVE-2015-3044EPSS 9%

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to…

Patch available
Fix from $1,600 2015-04-14
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-3043 KEVEPSS 74%

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to…

Fix: 11.2.202.457 / 13.0.0.281+
Fix from $2,300 2015-04-14
Enterprise Linux Desktop Supplementary HIGH 10.0
CVE-2015-3042EPSS 37%

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to…

Fix: after 13.0.0.264
Fix from $1,950 2015-04-14
Enterprise Linux Desktop Supplementary HIGH 10.0
CVE-2015-3041EPSS 6%

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to…

Fix: after 13.0.0.264
Fix from $1,950 2015-04-14
Enterprise Linux Desktop Supplementary MEDIUM 5.0
CVE-2015-3040

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux does not properly r…

Fix: after 13.0.0.264
Fix from $1,600 2015-04-14
Enterprise Linux Desktop Supplementary HIGH 10.0
CVE-2015-3039EPSS 8%

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.…

Fix: after 13.0.0.264
Fix from $1,950 2015-04-14
Enterprise Linux Desktop Supplementary HIGH 10.0
CVE-2015-3038EPSS 7%

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to…

Fix: after 13.0.0.264
Fix from $1,950 2015-04-14
Enterprise Linux Desktop Supplementary HIGH 10.0
CVE-2015-0360EPSS 6%

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to…

Fix: after 13.0.0.264
Fix from $1,950 2015-04-14
Enterprise Linux Desktop Supplementary HIGH 10.0
CVE-2015-0358EPSS 10%

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.…

Fix: after 13.0.0.264
Fix from $1,950 2015-04-14
Enterprise Linux Desktop Supplementary HIGH 10.0
CVE-2015-0354EPSS 6%

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to…

Fix: after 13.0.0.264
Fix from $1,950 2015-04-14
Enterprise Linux Desktop Supplementary HIGH 10.0
CVE-2015-0355EPSS 6%

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to…

Fix: after 13.0.0.264
Fix from $1,950 2015-04-14
Enterprise Linux Desktop Supplementary HIGH 10.0
CVE-2015-0353EPSS 6%

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to…

Fix: after 13.0.0.264
Fix from $1,950 2015-04-14
Enterprise Linux Desktop Supplementary HIGH 10.0
CVE-2015-0352EPSS 6%

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to…

Fix: after 13.0.0.264
Fix from $1,950 2015-04-14
Enterprise Linux Desktop Supplementary HIGH 10.0
CVE-2015-0351EPSS 8%

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.…

Fix: after 13.0.0.264
Fix from $1,950 2015-04-14
Enterprise Linux Desktop Supplementary HIGH 10.0
CVE-2015-0350EPSS 6%

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to…

Fix: after 13.0.0.264
Fix from $1,950 2015-04-14
Enterprise Linux Desktop Supplementary HIGH 10.0
CVE-2015-0349EPSS 8%

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.…

Fix: after 13.0.0.264
Fix from $1,950 2015-04-14
Enterprise Linux Desktop Supplementary HIGH 10.0
CVE-2015-0348EPSS 9%

Buffer overflow in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux …

Fix: after 13.0.0.264
Fix from $1,950 2015-04-14
Enterprise Linux Desktop Supplementary HIGH 10.0
CVE-2015-0347EPSS 6%

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to…

Fix: after 13.0.0.264
Fix from $1,950 2015-04-14
Enterprise Linux Desktop Supplementary HIGH 10.0
CVE-2015-0346EPSS 10%

Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457…

Fix: after 13.0.0.264
Fix from $1,950 2015-04-14
Openstack HIGH 10.0
CVE-2015-1842EPSS 5%

The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a default password of CHANGEME for the pcsd daemon, whic…

Fix: after 6.0
Fix from $1,950 2015-04-10
Slapi Nis HIGH 7.8
CVE-2015-0283

The slapi-nis plug-in before 0.54.2 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denia…

Fix: after 0.54.1
Fix from $1,950 2015-03-30
Enterprise Linux Desktop MEDIUM 5.0
CVE-2015-2348EPSS 9%

The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a…

Fix: after 10.10.5
Fix from $1,600 2015-03-30
Richfaces MEDIUM 6.8
CVE-2015-0279

JBoss RichFaces before 4.5.4 allows remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via the do parame…

Fix: after 4.5.4
Fix from $1,600 2015-03-26
Openstack HIGH 7.5
CVE-2014-3691

Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which allows remot…

Fix: after 1.5.3
Fix from $1,950 2015-03-09