Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jboss Enterprise Portal Platform MEDIUM 5.8
CVE-2011-2941

Open redirect vulnerability in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allows remote attackers to redirect users to arbitrary web sites…

Fix: after 5.1.1
Fix from $1,600 2014-02-26
Enterprise Linux Desktop HIGH 8.8
CVE-2014-0502 KEVEPSS 24%

Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.…

Fix: 4.0.0.1628 / 11.2.202.341+
Fix from $1,950 2014-02-21
Kexec Tools MEDIUM 5.7
CVE-2011-3588

The SSH configuration in the Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-…

Fix: after 2.0.0-188
Fix from $1,600 2014-02-15
Kexec Tools MEDIUM 5.7
CVE-2011-3589

The Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-209 packages in Red Hat E…

Fix: after 2.0.0-188
Fix from $1,600 2014-02-15
Kexec Tools MEDIUM 5.7
CVE-2011-3590

The Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-209 packages in Red Hat E…

Fix: after 2.0.0-188
Fix from $1,600 2014-02-15
Jboss Operations Network MEDIUM 5.8
CVE-2012-0052

Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 does not check the JON agent key, which allows remote attackers to spoof t…

Fix: after 2.4.1
Fix from $1,600 2014-02-14
Jboss Operations Network MEDIUM 5.8
CVE-2012-0062

Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 allows remote attackers to hijack agent sessions via an agent registration…

Fix: after 2.4.1
Fix from $1,600 2014-02-14
Jboss Operations Network MEDIUM 5.8
CVE-2012-1100

Red Hat JBoss Operations Network (JON) 3.0.x before 3.0.1, 2.4.2, and earlier, when LDAP authentication is enabled and the LDAP bind account credenti…

Fix: after 2.4.1
Fix from $1,600 2014-02-14
Jboss Communications Platform MEDIUM 5.0
CVE-2011-4610

JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1.3, Enterprise Web Platform before 5.1.2, Enterprise Application Platform befor…

Fix: after 5.1.2
Fix from $1,600 2014-02-10
Enterprise Virtualization MEDIUM 6.8
CVE-2012-3406

The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the …

Mitigation only
Fix from $1,600 2014-02-10
Enterprise Virtualization MEDIUM 5.0
CVE-2012-3404

The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other versions does not properly calculate a buffer le…

Patch available
Fix from $1,600 2014-02-10
Enterprise Virtualization MEDIUM 5.0
CVE-2012-3405

The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer le…

Mitigation only
Fix from $1,600 2014-02-10
Network Satellite MEDIUM 5.4
CVE-2011-3344

A flaw was found in Spacewalk. A remote attacker can exploit a cross-site scripting (XSS) vulnerability in the Lookup Login/Password form by injectin…

Patch available
Fix from $1,600 2014-02-05
Network Satellite MEDIUM 5.5
CVE-2011-2920

A flaw was found in Spacewalk and Red Hat Network Satellite. This cross-site scripting (XSS) vulnerability allows a remote attacker to inject arbitra…

Patch available
Fix from $1,600 2014-02-05
Network Satellite MEDIUM 5.4
CVE-2011-2927

A flaw was found in Spacewalk and Red Hat Network Satellite. This vulnerability, known as cross-site scripting (XSS), allows remote attackers to inje…

Patch available
Fix from $1,600 2014-02-05
Network Satellite MEDIUM 6.5
CVE-2011-1594

A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to ar…

Patch available
Fix from $1,600 2014-02-05
Libvirt MEDIUM 6.8
CVE-2013-6458

Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functi…

Fix: after 1.2.0
Fix from $1,600 2014-01-24
Libvirt MEDIUM 5.2
CVE-2013-6457

The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver.c) in libvirt before 1.2.1 does not properly initialize the nodemap…

Fix: after 1.2.0
Fix from $1,600 2014-01-24
Certificate System HIGH 7.5
CVE-2013-1886

Format string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System …

Mitigation only
Fix from $1,950 2014-01-24
Cloudforms MEDIUM 6.8
CVE-2013-6443

CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protect_from_forgery mechanism and conduct cross-…

Fix: after 5.2.1
Fix from $1,600 2014-01-23
Jboss Seam 2 Framework MEDIUM 5.0
CVE-2013-6447

Multiple XML External Entity (XXE) vulnerabilities in the (1) ExecutionHandler, (2) PollHandler, and (3) SubscriptionHandler classes in JBoss Seam Re…

Fix: after 2.3.1
Fix from $1,600 2014-01-23
Jboss Seam 2 Framework MEDIUM 5.0
CVE-2013-6448

The InterfaceGenerator handler in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allows remote …

Fix: after 2.3.1
Fix from $1,600 2014-01-23
Enterprise Virtualization HIGH 7.2
CVE-2013-2151

Unquoted Windows search path vulnerability in Red Hat Enterprise Virtualization (RHEV) 3 and 3.2 allows local users to gain privileges via a crafted …

Mitigation only
Fix from $1,950 2014-01-21
Enterprise Virtualization HIGH 7.2
CVE-2013-2152

Unquoted Windows search path vulnerability in the SPICE service, as used in Red Hat Enterprise Virtualization (RHEV) 3.2, allows local users to gain …

Mitigation only
Fix from $1,950 2014-01-21
Enterprise Linux Desktop Supplementary MEDIUM 6.8
CVE-2013-5870

Unspecified vulnerability in Oracle Java SE 7u45 and JavaFX 2.2.45 allows remote attackers to affect confidentiality, integrity, and availability via…

Fix: after 7.0.08
Fix from $1,600 2014-01-15
Enterprise Linux Desktop Supplementary MEDIUM 5.1
CVE-2014-0418EPSS 6%

Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown …

Mitigation only
Fix from $1,600 2014-01-15
Enterprise Linux Desktop Supplementary MEDIUM 6.8
CVE-2013-5904

Unspecified vulnerability in Oracle Java SE 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors r…

Fix: after 7.0.08
Fix from $1,600 2014-01-15
Enterprise Linux Desktop Supplementary MEDIUM 5.1
CVE-2013-5906EPSS 6%

Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via…

Mitigation only
Fix from $1,600 2014-01-15
Enterprise Linux Desktop Supplementary MEDIUM 5.0
CVE-2013-5895EPSS 6%

Unspecified vulnerability in Oracle Java SE 7u45 and JavaFX 2.2.45 allows remote attackers to affect confidentiality via unknown vectors related to J…

Fix: after 7.0.08
Fix from $1,600 2014-01-15
Cloudforms Management Engine HIGH 7.5
CVE-2013-2050EPSS 16%

SQL injection vulnerability in the miq_policy controller in Red Hat CloudForms 2.0 Management Engine (CFME) 5.1 and ManageIQ Enterprise Virtualizatio…

Fix: after 5.0
Fix from $1,950 2014-01-11