Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux Desktop HIGH 10.0
CVE-2013-3331EPSS 5%

Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux,…

Fix: 3.7.0.1860 / 10.3.183.86+
Fix from $1,950 2013-05-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-3332EPSS 5%

Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux,…

Fix: 3.7.0.1860 / 10.3.183.86+
Fix from $1,950 2013-05-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-3333EPSS 5%

Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux,…

Fix: 3.7.0.1860 / 10.3.183.86+
Fix from $1,950 2013-05-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-3334EPSS 5%

Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux,…

Fix: 3.7.0.1860 / 10.3.183.86+
Fix from $1,950 2013-05-16
Enterprise Linux Desktop HIGH 10.0
CVE-2013-3335EPSS 5%

Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux,…

Fix: 3.7.0.1860 / 10.3.183.86+
Fix from $1,950 2013-05-16
Enterprise Linux Desktop CRITICAL 9.8
CVE-2013-2729 KEVEPSS 67%

Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code…

Fix: 9.5.5 / 10.1.7+
Fix from $2,300 2013-05-16
Icedtea Web MEDIUM 6.8
CVE-2013-1927

The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 allows remote attackers to execute arbitrary code via a crafted file that validates as bot…

Fix: after 1.2.2
Fix from $1,600 2013-04-29
Icedtea Web MEDIUM 5.8
CVE-2013-1926

The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different doma…

Fix: after 1.2.2
Fix from $1,600 2013-04-29
Jboss Enterprise Portal Platform HIGH 7.5
CVE-2013-0314

The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 does not properly check authentication when importing Zip files, whi…

Mitigation only
Fix from $1,950 2013-04-12
Jboss Enterprise Portal Platform MEDIUM 5.0
CVE-2013-0315

The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 allows remote attackers to read arbitrary files via a crafted extern…

Mitigation only
Fix from $1,600 2013-04-12
Jboss Enterprise Portal Platform MEDIUM 6.8
CVE-2012-3532

Cross-site request forgery (CSRF) vulnerability in the GateIn Portal component in JBoss Enterprise Portal Platform 5.2.2 and earlier allows remote at…

Fix: after 5.2.2
Fix from $1,600 2013-04-12
Openstack Essex MEDIUM 6.1
CVE-2013-1815

A flaw was found in PackStack. This vulnerability allows a local user to modify deployed systems by changing the answer file, which is created in ins…

No fix yet
Fix from $1,600 2013-04-10
Jboss Enterprise Application Platform HIGH 7.5
CVE-2012-5629

The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.…

Mitigation only
Fix from $1,950 2013-03-12
Automatic Bug Reporting Tool MEDIUM 6.9
CVE-2012-5660

abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbit…

Fix: after 2.0.9
Fix from $1,600 2013-03-12
Aeolus Conductor MEDIUM 5.5
CVE-2012-6118

The Administer tab in Aeolus Conductor allows remote authenticated users to bypass intended quota restrictions by updating the Maximum Running Instan…

No fix yet
Fix from $1,600 2013-03-12
Enterprise Linux Desktop HIGH 10.0
CVE-2013-2555EPSS 8%

Integer overflow in Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11…

Fix: 10.3.183.75+
Fix from $1,950 2013-03-11
Enterprise Linux Desktop MEDIUM 5.0
CVE-2012-3411EPSS 5%

Dnsmasq before 2.63test1, when used with certain libvirt configurations, replies to requests from prohibited interfaces, which allows remote attacker…

Fix: after 2.62
Fix from $1,600 2013-03-05
Enterprise Linux Desktop HIGH 8.8
CVE-2013-0643 KEVEPSS 11%

The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x be…

Fix: 10.3.183.67 / 11.2.202.273+
Fix from $1,950 2013-02-27
Enterprise Linux Desktop HIGH 8.8
CVE-2013-0648 KEVEPSS 11%

Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 o…

Fix: 10.3.183.67 / 11.2.202.273+
Fix from $1,950 2013-02-27
Openshift MEDIUM 5.8
CVE-2012-5647

Open redirect vulnerability in node-util/www/html/restorer.php in Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to redirect users t…

Fix: after 1.0.5
Fix from $1,600 2013-02-24
Openshift HIGH 7.5
CVE-2012-5646

node-util/www/html/restorer.php in the Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to execute arbitrary commands via a crafted uu…

Fix: after 1.0.5
Fix from $1,950 2013-02-24
Enterprise Linux MEDIUM 6.2
CVE-2012-5536

A certain Red Hat build of the pam_ssh_agent_auth module on Red Hat Enterprise Linux (RHEL) 6 and Fedora Rawhide calls the glibc error function inste…

Patch available
Fix from $1,600 2013-02-22
Enterprise Linux Desktop HIGH 7.8
CVE-2013-0640 KEVEPSS 87%

Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a de…

Fix: 9.5.4 / 10.1.6+
Fix from $1,950 2013-02-14
Enterprise Linux Desktop HIGH 7.8
CVE-2013-0641 KEVEPSS 32%

Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute arbitrar…

Fix: 9.5.4 / 10.1.6+
Fix from $1,950 2013-02-14
Libvirt MEDIUM 6.8
CVE-2013-0170EPSS 6%

Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9…

Fix: 0.9.6.4 / 0.9.11.9+
Fix from $1,600 2013-02-08
Jboss Enterprise Application Platform MEDIUM 6.8
CVE-2012-0874EPSS 14%

The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (E…

Fix: after 5.3.0
Fix from $1,600 2013-02-05
Jboss Enterprise Application Platform MEDIUM 5.8
CVE-2012-3370

The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platf…

Fix: after 5.3.0
Fix from $1,600 2013-02-05
Enterprise Virtualization CRITICAL 9.8
CVE-2013-1591

Stack-based buffer overflow in libpixman, as used in Pale Moon before 15.4 and possibly other products, has unspecified impact and context-dependent …

Fix: 15.4+
Fix from $2,300 2013-01-31
Freeipa HIGH 7.9
CVE-2012-5484

The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows ma…

Mitigation only
Fix from $1,950 2013-01-27
Enterprise Linux Desktop HIGH 7.1
CVE-2012-5689EPSS 12%

ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA …

Mitigation only
Fix from $1,950 2013-01-25