Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux Desktop MEDIUM 5.5
CVE-2011-2519

Xen in the Linux kernel, when running a guest on a host without hardware assisted paging (HAP), allows guest users to cause a denial of service (inva…

Fix: 3.3.0+
Fix from $1,600 2013-12-27
Enterprise Virtualization Hypervisor HIGH 7.4
CVE-2010-0430

libspice, as used in QEMU-KVM in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 and possibly other produ…

Fix: after 5.4-2.1
Fix from $1,950 2013-12-27
Subscription Asset Manager HIGH 9.3
CVE-2013-6439

Candlepin in Red Hat Subscription Asset Manager 1.0 through 1.3 uses a weak authentication scheme when the configuration file does not specify a sche…

No fix yet
Fix from $1,950 2013-12-23
Enterprise Mrg HIGH 7.5
CVE-2013-4461

SQL injection vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to execute arbitrary SQL comman…

Mitigation only
Fix from $1,950 2013-12-23
Enterprise Mrg MEDIUM 6.8
CVE-2013-4405

Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allow remote attackers t…

Mitigation only
Fix from $1,600 2013-12-23
Enterprise Mrg MEDIUM 6.5
CVE-2013-4404

cumin in Red Hat Enterprise MRG Grid 2.4 does not properly enforce user roles, which allows remote authenticated users to bypass intended role restri…

Mitigation only
Fix from $1,600 2013-12-23
Enterprise Linux MEDIUM 6.8
CVE-2013-1913

Integer overflow in the load_image function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier, when used with glib before 2.…

Fix: after 2.6.9
Fix from $1,600 2013-12-12
Enterprise Linux MEDIUM 6.8
CVE-2013-1978

Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier allows remote att…

Fix: after 2.6.9
Fix from $1,600 2013-12-12
Libvirt HIGH 7.2
CVE-2013-4400

virt-login-shell in libvirt 1.1.2 through 1.1.3 allows local users to overwrite arbitrary files and possibly gain privileges via unspecified environm…

Patch available
Fix from $1,950 2013-12-09
Jboss Enterprise Application Platform MEDIUM 5.5
CVE-2013-2133

The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly …

Fix: after 6.1.0
Fix from $1,600 2013-12-06
Enterprise Linux MEDIUM 6.3
CVE-2013-2561

OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet…

No fix yet
Fix from $1,600 2013-11-23
Openstack MEDIUM 6.3
CVE-2013-2029

nagios.upgrade_to_v3.sh, as distributed by Red Hat and possibly others for Nagios Core 3.4.4, 3.5.1, and earlier, allows local users to overwrite arb…

Mitigation only
Fix from $1,600 2013-11-23
Openstack MEDIUM 6.3
CVE-2013-4214

rss-newsfeed.php in Nagios Core 3.4.4, 3.5.1, and earlier, when MAGPIE_CACHE_ON is set to 1, allows local users to overwrite arbitrary files via a sy…

Fix: after 3.5.1
Fix from $1,600 2013-11-23
Enterprise Linux HIGH 7.2
CVE-2013-1813

util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows lo…

Fix: after 1.20.2
Fix from $1,950 2013-11-23
Enterprise Linux MEDIUM 6.2
CVE-2013-4482

Untrusted search path vulnerability in python-paste-script (aka paster) in Luci 0.26.0, when started using the initscript, allows local users to gain…

Mitigation only
Fix from $1,600 2013-11-23
Openstack HIGH 7.5
CVE-2013-4386

Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL …

Fix: after 1.2.2
Fix from $1,950 2013-11-20
Network Satellite HIGH 7.5
CVE-2013-4480

Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satellite, which allows remote attac…

Fix: after 5.6
Fix from $1,950 2013-11-18
Enterprise Virtualization MEDIUM 5.0
CVE-2013-4282

Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service …

Patch available
Fix from $1,600 2013-11-02
Libvirt HIGH 8.5
CVE-2013-4401

The virConnectDomainXMLToNative API function in libvirt 1.1.0 through 1.1.3 checks for the connect:read permission instead of the connect:write permi…

Patch available
Fix from $1,950 2013-11-02
Jboss Enterprise Brms Platform HIGH 7.5
CVE-2013-2186EPSS 13%

The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss …

Fix: after 3.1
Fix from $1,950 2013-10-28
Enterprise Linux MEDIUM 6.8
CVE-2013-4397EPSS 5%

Multiple integer overflows in the th_read function in lib/block.c in libtar before 1.2.20 allow remote attackers to cause a denial of service (crash)…

Fix: after 1.2.19
Fix from $1,600 2013-10-17
Enterprise Linux Desktop HIGH 10.0
CVE-2013-5842EPSS 18%

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and ear…

Mitigation only
Fix from $1,950 2013-10-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-5843EPSS 6%

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JavaFX 2.2.40 and earlier, and Ja…

Fix: after 2.2.40
Fix from $1,950 2013-10-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-5829EPSS 7%

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and ear…

Mitigation only
Fix from $1,950 2013-10-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-5830EPSS 7%

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRoc…

Mitigation only
Fix from $1,950 2013-10-16
Enterprise Linux HIGH 7.6
CVE-2013-4342EPSS 6%

xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it e…

Patch available
Fix from $1,950 2013-10-10
Enterprise Mrg MEDIUM 5.0
CVE-2013-4284

Cumin, as used in Red Hat Enterprise MRG 2.4, allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted Ajax up…

Mitigation only
Fix from $1,600 2013-10-09
Enterprise Linux Desktop HIGH 7.2
CVE-2013-4344

Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to …

Fix: after 1.6.2
Fix from $1,950 2013-10-04
Enterprise Linux HIGH 7.2
CVE-2013-2231

Unquoted Windows search path vulnerability in the QEMU Guest Agent service for Red Hat Enterprise Linux Desktop 6, HPC Node 6, Server 6, Workstation …

Mitigation only
Fix from $1,950 2013-10-01
Jboss Enterprise Application Platform MEDIUM 5.0
CVE-2013-4210

The org.jboss.remoting.transport.socket.ServerThread class in Red Hat JBoss Remoting for Red Hat JBoss SOA Platform 5.3.1 GA, Web Platform 5.2.0, Ent…

Mitigation only
Fix from $1,600 2013-10-01