Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Libvirt MEDIUM 6.9
CVE-2013-4291

The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the domain has read an uid:gid label, does not properly …

Patch available
Fix from $1,600 2013-09-30
Libvirt MEDIUM 5.0
CVE-2013-4153

Double free vulnerability in the qemuAgentGetVCPUs function in qemu/qemu_agent.c in libvirt 1.0.6 through 1.1.0 allows remote attackers to cause a de…

Patch available
Fix from $1,600 2013-09-30
Libvirt MEDIUM 5.0
CVE-2013-5651

The virBitmapParse function in util/virbitmap.c in libvirt before 1.1.2 allows context-dependent attackers to cause a denial of service (out-of-bound…

Fix: after 1.1.1
Fix from $1,600 2013-09-30
Libvirt MEDIUM 5.0
CVE-2013-2218EPSS 8%

Double free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_netcf.c in libvirt 1.0.6 allows remote attackers t…

Patch available
Fix from $1,600 2013-09-30
Jboss Enterprise Application Platform MEDIUM 5.4
CVE-2013-4112

The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (di…

Mitigation only
Fix from $1,600 2013-09-28
Cloudforms Management Engine HIGH 9.4
CVE-2013-2068EPSS 59%

Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow remote attackers to create and …

No fix yet
Fix from $1,950 2013-09-28
Openstack HIGH 7.5
CVE-2013-4182

app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to acces…

Fix: after 1.2.1
Fix from $1,950 2013-09-16
Openstack MEDIUM 5.0
CVE-2013-4180

The (1) power and (2) ipmi_boot actions in the HostController in Foreman before 1.2.2 allow remote attackers to cause a denial of service (memory con…

Fix: after 1.2.1
Fix from $1,600 2013-09-16
Enterprise Virtualization HIGH 7.2
CVE-2013-2176

Unquoted Windows search path vulnerability in the Red Hat Enterprise Virtualization Application Provisioning Tool (RHEV-APT) in the rhev-guest-tools-…

Mitigation only
Fix from $1,950 2013-08-28
Cloudforms Management Engine HIGH 8.5
CVE-2013-4172

The Red Hat CloudForms Management Engine 5.1 allow remote administrators to execute arbitrary Ruby code via unspecified vectors.

Mitigation only
Fix from $1,950 2013-08-23
Enterprise Mrg MEDIUM 5.8
CVE-2013-1909

The Python client in Apache Qpid before 2.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subje…

Fix: after 0.20
Fix from $1,600 2013-08-23
Jboss Enterprise Application Platform MEDIUM 6.4
CVE-2013-4213

Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attacker…

Mitigation only
Fix from $1,600 2013-08-16
Jboss Enterprise Application Platform MEDIUM 6.4
CVE-2013-4128

Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by remote-naming, which allows remote attackers to …

Mitigation only
Fix from $1,600 2013-08-16
Openstack MEDIUM 6.0
CVE-2013-2113EPSS 21%

The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or …

Fix: after 1.2.0
Fix from $1,600 2013-07-31
Openstack MEDIUM 6.0
CVE-2013-2121EPSS 25%

Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with perm…

Fix: after 1.2.0
Fix from $1,600 2013-07-31
Satellite MEDIUM 5.0
CVE-2013-2056

The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5.3, 5.4, and 5.5 does not properly check client "authenticity," which al…

Mitigation only
Fix from $1,600 2013-07-31
Jboss Communications Platform MEDIUM 5.0
CVE-2011-1483

wsf/common/DOMUtils.java in JBossWS Native in Red Hat JBoss Enterprise Application Platform 4.2.0.CP09, 4.3, and 5.1.1; JBoss Enterprise Portal Platf…

Patch available
Fix from $1,600 2013-07-29
Jboss Enterprise Application Platform HIGH 7.5
CVE-2013-2165EPSS 13%

ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform …

Fix: after 2.2.0
Fix from $1,950 2013-07-23
Jboss Enterprise Web Server MEDIUM 6.9
CVE-2013-1976

The (1) tomcat5, (2) tomcat6, and (3) tomcat7 init scripts, as used in the RPM distribution of Tomcat for JBoss Enterprise Web Server 1.0.2 and 2.0.0…

Mitigation only
Fix from $1,600 2013-07-09
Enterprise Virtualization Manager MEDIUM 5.0
CVE-2013-2144

Red Hat Enterprise Virtualization Manager (RHEVM) before 3.2 does not properly check permissions for the target storage domain, which allows attacker…

Fix: after 3.1
Fix from $1,600 2013-07-03
Livecd Tools HIGH 7.2
CVE-2013-2069

Red Hat livecd-tools before 13.4.4, 17.x before 17.17, 18.x before 18.16, and 19.x before 19.3, when a rootpw directive is not set in a Kickstart fil…

Fix: 13.4.4 / 17.17+
Fix from $1,950 2013-05-29
Libvirt MEDIUM 5.0
CVE-2013-1962

The remoteDispatchStoragePoolListAllVolumes function in the storage pool manager in libvirt 1.0.5 allows remote attackers to cause a denial of servic…

Mitigation only
Fix from $1,600 2013-05-29
Enterprise Linux Desktop HIGH 10.0
CVE-2013-2728EPSS 5%

Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux,…

Fix: 3.7.0.1860 / 10.3.183.86+
Fix from $1,950 2013-05-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-3324EPSS 5%

Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux,…

Fix: 3.7.0.1860 / 10.3.183.86+
Fix from $1,950 2013-05-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-3325EPSS 5%

Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux,…

Fix: 3.7.0.1860 / 10.3.183.86+
Fix from $1,950 2013-05-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-3326EPSS 5%

Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux,…

Fix: 3.7.0.1860 / 10.3.183.86+
Fix from $1,950 2013-05-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-3327EPSS 5%

Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux,…

Fix: 3.7.0.1860 / 10.3.183.86+
Fix from $1,950 2013-05-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-3328EPSS 5%

Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux,…

Fix: 3.7.0.1860 / 10.3.183.86+
Fix from $1,950 2013-05-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-3329EPSS 5%

Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux,…

Fix: 3.7.0.1860 / 10.3.183.86+
Fix from $1,950 2013-05-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-3330EPSS 5%

Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux,…

Fix: 3.7.0.1860 / 10.3.183.86+
Fix from $1,950 2013-05-16