Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openshift MEDIUM 6.5
CVE-2014-0233

Red Hat OpenShift Enterprise 2.0 and 2.1 and OpenShift Origin allow remote authenticated users to execute arbitrary commands via shell metacharacters…

No fix yet
Fix from $1,600 2014-11-16
Enterprise Linux Desktop HIGH 9.4
CVE-2014-8567

The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request …

Fix: 0.8.1+
Fix from $1,950 2014-11-14
Enterprise Linux Desktop MEDIUM 5.0
CVE-2014-8564

The _gnutls_ecc_ansi_x963_export function in gnutls_ecc.c in GnuTLS 3.x before 3.1.28, 3.2.x before 3.2.20, and 3.3.x before 3.3.10 allows remote att…

Patch available
Fix from $1,600 2014-11-13
Libvirt MEDIUM 5.0
CVE-2014-7823

The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE …

Fix: after 1.2.10
Fix from $1,600 2014-11-13
Openshift HIGH 7.5
CVE-2014-3674

Red Hat OpenShift Enterprise before 2.2 does not properly restrict access to gears, which allows remote attackers to access the network resources of …

Fix: after 2.1.8
Fix from $1,950 2014-11-13
Enterprise Linux Desktop HIGH 7.5
CVE-2014-3693

Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote attackers t…

Patch available
Fix from $1,950 2014-11-07
Freeipa MEDIUM 5.0
CVE-2013-0336

The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_extop.c in the directory server (dirsrv) in FreeIPA before 3.2.0 allows…

Fix: after 3.1.5
Fix from $1,600 2014-11-03
Cloudforms 3.0 Management Engine MEDIUM 5.0
CVE-2014-0136

The (1) get and (2) log methods in the AgentController in Red Hat CloudForms 3.0 Management Engine (CFME) 5.x allow remote attackers to insert arbitr…

Fix: after 5.2.5.3
Fix from $1,600 2014-10-27
Jboss Fuse MEDIUM 6.8
CVE-2014-5075

The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify that the server hostname match…

Fix: after 6.1.0
Fix from $1,600 2014-10-25
Virtual Desktop Service Manager MEDIUM 5.0
CVE-2014-7968

VDSM allows remote attackers to cause a denial of service (connection blocking) by keeping an SSL connection open.

Mitigation only
Fix from $1,600 2014-10-22
Shim HIGH 7.5
CVE-2014-3676EPSS 5%

Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related to the "tftp:// DHCPv6 boot …

Fix: 0.8+
Fix from $1,950 2014-10-22
Shim HIGH 7.5
CVE-2014-3677

Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption.

Fix: 0.8+
Fix from $1,950 2014-10-22
Shim MEDIUM 5.0
CVE-2014-3675

Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet.

Fix: 0.8+
Fix from $1,600 2014-10-22
Enterprise Virtualization Manager MEDIUM 6.5
CVE-2014-3573

The oVirt Engine backend module, as used in Red Hat Enterprise Virtualization Manager before 3.4.2, uses an "insecure DocumentBuilderFactory," which …

Fix: after 3.4.1
Fix from $1,600 2014-10-18
Openshift HIGH 7.5
CVE-2014-3666

Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to execute arbitrary code via a crafted packet to the CLI channel.

Fix: after 3.1
Fix from $1,950 2014-10-16
Openshift MEDIUM 5.0
CVE-2014-3661

Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to cause a denial of service (thread consumption) via vectors related to a CLI ha…

Fix: after 3.1
Fix from $1,600 2014-10-16
Enterprise Linux Desktop Supplementary HIGH 7.5
CVE-2014-3192

Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation …

Fix: after 38.0.2125.7
Fix from $1,950 2014-10-08
Enterprise Linux Desktop Supplementary HIGH 7.5
CVE-2014-3193

The SessionService::GetLastSession function in browser/sessions/session_service.cc in Google Chrome before 38.0.2125.101 allows remote attackers to c…

Fix: after 38.0.2125.7
Fix from $1,950 2014-10-08
Enterprise Linux Desktop Supplementary HIGH 7.5
CVE-2014-3194

Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of ser…

Fix: after 38.0.2125.7
Fix from $1,950 2014-10-08
Enterprise Linux Desktop Supplementary MEDIUM 5.0
CVE-2014-3199

The wrap function in bindings/core/v8/custom/V8EventCustom.cpp in the V8 bindings in Blink, as used in Google Chrome before 38.0.2125.101, has an err…

Fix: after 38.0.2125.7
Fix from $1,600 2014-10-08
Cloudforms 3.0.1 Management Engine MEDIUM 6.5
CVE-2014-3642

vmdb/app/controllers/application_controller/performance.rb in Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated …

Fix: after 5.2.5
Fix from $1,600 2014-10-06
Conga MEDIUM 5.5
CVE-2014-3521

The component in (1) /luci/homebase and (2) /luci/cluster menu in Red Hat Conga 0.12.2 allows remote authenticated users to bypass intended access re…

Mitigation only
Fix from $1,600 2014-10-06
Conga MEDIUM 5.0
CVE-2013-6496

Red Hat Conga 0.12.2 allows remote attackers to obtain sensitive information via a crafted request to the (1) homebase, (2) cluster, (3) storage, (4)…

Mitigation only
Fix from $1,600 2014-10-06
Enterprise Linux Server Aus HIGH 7.5
CVE-2014-6051EPSS 8%

Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of se…

Fix: after 0.9.9
Fix from $1,950 2014-09-30
Hibernate Validator MEDIUM 5.0
CVE-2014-3558

ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 …

Fix: 4.3.2 / 5.1.2+
Fix from $1,600 2014-09-30
Enterprise Linux Desktop HIGH 7.8
CVE-2014-7145

The SMB2_tcon function in fs/cifs/smb2pdu.c in the Linux kernel before 3.16.3 allows remote CIFS servers to cause a denial of service (NULL pointer d…

Fix: 3.10.55 / 3.12.29+
Fix from $1,950 2014-09-28
Ovirt Engine MEDIUM 6.8
CVE-2014-0152

Session fixation vulnerability in the web admin interface in oVirt 3.4.0 and earlier allows remote attackers to hijack web sessions via unspecified v…

Fix: after 3.4.0
Fix from $1,600 2014-09-08
Directory Server MEDIUM 5.0
CVE-2014-3562

Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by se…

Mitigation only
Fix from $1,600 2014-08-21
Jboss Enterprise Application Platform HIGH 7.5
CVE-2014-3490

RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external…

Fix: 3.0.9+
Fix from $1,950 2014-08-19
Openstack MEDIUM 5.0
CVE-2014-4615

The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014…

Fix: after 0.5.0
Fix from $1,600 2014-08-19