Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jboss Enterprise Application Platform MEDIUM 5.5
CVE-2014-3464

The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not proper…

Mitigation only
Fix from $1,600 2014-08-19
Jboss Enterprise Application Platform HIGH 7.5
CVE-2014-3530

The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform …

Mitigation only
Fix from $1,950 2014-07-22
Jboss Enterprise Application Platform MEDIUM 6.8
CVE-2014-3518

jmx-remoting.sar in JBoss Remoting, as used in Red Hat JBoss Enterprise Application Platform (JEAP) 5.2.0, Red Hat JBoss BRMS 5.3.1, Red Hat JBoss Po…

Mitigation only
Fix from $1,600 2014-07-22
Enterprise Linux Desktop MEDIUM 5.0
CVE-2014-4341EPSS 7%

MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting in…

Patch available
Fix from $1,600 2014-07-20
Enterprise Mrg MEDIUM 5.0
CVE-2012-2682

Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, allows attackers with certain database privileges to cause a denial of ser…

Mitigation only
Fix from $1,600 2014-07-19
Cloudforms 3.0 Management Engine MEDIUM 6.9
CVE-2014-3486

The (1) shell_exec function in lib/util/MiqSshUtilV1.rb and (2) temp_cmd_file function in lib/util/MiqSshUtilV2.rb in Red Hat CloudForms 3.0 Manageme…

Fix: after 5.2.4
Fix from $1,600 2014-07-07
Jboss Enterprise Application Platform MEDIUM 6.8
CVE-2014-0248

org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Ente…

Mitigation only
Fix from $1,600 2014-07-07
Cloudforms 3.0 Management Engine MEDIUM 5.0
CVE-2014-0180

The wait_for_task function in app/controllers/application_controller.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allows remo…

Fix: after 5.2.4
Fix from $1,600 2014-07-07
Jboss Enterprise Application Platform MEDIUM 5.0
CVE-2014-3481

org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion…

Fix: after 6.2.3
Fix from $1,600 2014-07-07
Openshift HIGH 10.0
CVE-2014-3496EPSS 5%

cartridge_repository.rb in OpenShift Origin and Enterprise 1.2.8 through 2.1.1 allows remote attackers to execute arbitrary commands via shell metach…

Patch available
Fix from $1,950 2014-06-20
Virtualization HIGH 7.5
CVE-2014-3468

The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows con…

Patch available
Fix from $1,950 2014-06-05
Virtualization MEDIUM 5.0
CVE-2014-3467EPSS 7%

Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of se…

Patch available
Fix from $1,600 2014-06-05
Virtualization MEDIUM 5.0
CVE-2014-3469

The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of ser…

Patch available
Fix from $1,600 2014-06-05
Openstack MEDIUM 5.0
CVE-2013-6470

The default configuration in the standalone controller quickstack manifest in openstack-foreman-installer, as used in Red Hat Enterprise Linux OpenSt…

Mitigation only
Fix from $1,600 2014-06-02
Freeipa MEDIUM 5.0
CVE-2013-0199

The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes,…

Patch available
Fix from $1,600 2014-05-29
Cloudforms 3.0 Management Engine MEDIUM 6.5
CVE-2014-0137

SQL injection vulnerability in the saved_report_delete action in the ReportController in Red Hat CloudForms Management Engine (CFME) before 5.2.3.2 a…

Fix: after 5.2.3
Fix from $1,600 2014-05-14
Icedtea Web MEDIUM 6.8
CVE-2011-2514

The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and bef…

Fix: after 1.8.8
Fix from $1,600 2014-05-14
Icedtea Web MEDIUM 5.0
CVE-2011-2513

The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and bef…

Fix: after 1.8.8
Fix from $1,600 2014-05-14
Subscription Asset Manager HIGH 7.5
CVE-2014-0130 KEVEPSS 54%

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18,…

Fix: 3.2.18 / 4.0.5+
Fix from $1,950 2014-05-07
Enterprise Mrg MEDIUM 5.0
CVE-2013-6445

Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, uses the DES-based crypt function to hash passwords, which makes it easier…

Mitigation only
Fix from $1,600 2014-04-30
Openshift HIGH 7.5
CVE-2014-0188

The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remot…

Fix: after 2.0.5
Fix from $1,950 2014-04-24
Jboss Fuse Service Works MEDIUM 6.5
CVE-2013-6469

JBoss Overlord Run Time Governance (RTGov) 1.0 for JBossAS allows remote authenticated users to execute arbitrary Java code via an MVFLEX Expression …

Mitigation only
Fix from $1,600 2014-04-22
Openstack MEDIUM 6.4
CVE-2014-0071

PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass int…

Mitigation only
Fix from $1,600 2014-04-17
Network Satellite MEDIUM 6.5
CVE-2013-2143EPSS 48%

The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows r…

Fix: after 1.5.0-14
Fix from $1,600 2014-04-17
Libvirt MEDIUM 5.8
CVE-2013-6456

The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDetta…

Mitigation only
Fix from $1,600 2014-04-15
Network Proxy MEDIUM 6.0
CVE-2010-2236

The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and …

Fix: after 2.1.147-1
Fix from $1,600 2014-04-15
Jboss Bpm Suite MEDIUM 6.5
CVE-2013-6468

JBoss Drools, Red Hat JBoss BRMS before 6.0.1, and Red Hat JBoss BPM Suite before 6.0.1 allows remote authenticated users to execute arbitrary Java c…

Mitigation only
Fix from $1,600 2014-04-10
Jboss Enterprise Application Platform MEDIUM 5.8
CVE-2014-0093

Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by…

Mitigation only
Fix from $1,600 2014-04-03
Cloudforms HIGH 7.5
CVE-2014-0057

The x_button method in the ServiceController (vmdb/app/controllers/service_controller.rb) in Red Hat CloudForms 3.0 Management Engine 5.2 allows remo…

Mitigation only
Fix from $1,950 2014-03-18
Enterprise Linux MEDIUM 6.8
CVE-2011-4111

Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote…

Fix: after 0.15.1
Fix from $1,600 2014-02-26