Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux MEDIUM 5.0
CVE-2012-2124

functions/imap_general.php in SquirrelMail, as used in Red Hat Enterprise Linux (RHEL) 4 and 5, does not properly handle 8-bit characters in password…

Mitigation only
Fix from $1,600 2013-01-18
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2012-4549

A flaw was found in JBoss Enterprise Application Platform. The `processInvocation` function within the `org.jboss.as.ejb3.security.AuthorizationInter…

Fix: after 6.0.0
Fix from $1,600 2013-01-05
Jboss Enterprise Application Platform MEDIUM 5.3
CVE-2012-4550

A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system d…

Mitigation only
Fix from $1,600 2013-01-05
Cloudforms MEDIUM 5.5
CVE-2012-5603

proxies_controller.rb in Katello in Red Hat CloudForms before 1.1 does not properly check permissions, which allows remote authenticated users to rea…

Fix: after 1.0
Fix from $1,600 2013-01-04
Enterprise Virtualization Manager MEDIUM 6.8
CVE-2012-0861

The vds_installer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, uses the -k curl parameter when downloading d…

Fix: after 3.0
Fix from $1,600 2013-01-04
Enterprise Virtualization Manager MEDIUM 6.2
CVE-2012-0860

Multiple untrusted search path vulnerabilities in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, allow local user…

Fix: after 3.0
Fix from $1,600 2013-01-04
Openshift MEDIUM 6.8
CVE-2012-5622

Cross-site request forgery (CSRF) vulnerability in the management console (openshift-console/app/controllers/application_controller.rb) in OpenShift …

Patch available
Fix from $1,600 2012-12-18
Virtualization HIGH 7.2
CVE-2012-3515

Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users…

Fix: 1.2.0+
Fix from $1,950 2012-11-23
Resteasy MEDIUM 5.0
CVE-2011-5245

The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external …

Fix: after 2.3.1
Fix from $1,600 2012-11-23
Resteasy MEDIUM 5.0
CVE-2012-0818

RESTEasy before 2.3.1 allows remote attackers to read arbitrary files via an external entity reference in a DOM document, aka an XML external entity …

Fix: after 2.3.0
Fix from $1,600 2012-11-23
Jboss Enterprise Application Platform HIGH 7.5
CVE-2011-4605

The (1) JNDI service, (2) HA-JNDI service, and (3) HAJNDIFactory invoker servlet in JBoss Enterprise Application Platform 4.3.0 CP10 and 5.1.2, Web P…

Fix: after 5.2.0
Fix from $1,950 2012-11-23
Jboss Enterprise Application Platform MEDIUM 6.8
CVE-2011-4085

The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, …

Fix: after 5.2.0
Fix from $1,600 2012-11-23
Jboss Enterprise Brms Platform MEDIUM 6.0
CVE-2011-2908

Cross-site request forgery (CSRF) vulnerability in the JMX Console (jmx-console) in JBoss Enterprise Portal Platform before 5.2.2, BRMS Platform 5.3.…

Fix: after 5.2.1
Fix from $1,600 2012-11-23
Jboss Enterprise Portal Platform MEDIUM 5.0
CVE-2011-1096

The W3C XML Encryption Standard, as used in the JBoss Web Services (JBossWS) component in JBoss Enterprise Portal Platform before 5.2.2 and other pro…

Fix: after 5.2.1
Fix from $1,600 2012-11-23
Libvirt MEDIUM 5.0
CVE-2012-4423

The virNetServerProgramDispatchCall function in libvirt before 0.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference …

Fix: after 0.10.1
Fix from $1,600 2012-11-19
Icedtea Web MEDIUM 6.8
CVE-2012-4540

Off-by-one error in the invoke function in IcedTeaScriptablePluginObject.cc in IcedTea-Web 1.1.x before 1.1.7, 1.2.x before 1.2.2, 1.3.x before 1.3.1…

Mitigation only
Fix from $1,600 2012-11-11
Enterprise Mrg MEDIUM 6.8
CVE-2012-2734

Multiple cross-site request forgery (CSRF) vulnerabilities in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG…

Fix: after 0.1.5192-4
Fix from $1,600 2012-09-28
Enterprise Mrg HIGH 7.5
CVE-2012-2684

Multiple SQL injection vulnerabilities in the get_sample_filters_by_signature function in Cumin before 0.1.5444, as used in Red Hat Enterprise Messag…

Fix: after 0.1.5192-4
Fix from $1,950 2012-09-28
Enterprise Mrg MEDIUM 5.8
CVE-2012-2681

Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, uses predictable random numbers to generate session key…

Fix: after 0.1.5192-4
Fix from $1,600 2012-09-28
Enterprise Mrg MEDIUM 5.0
CVE-2012-2680

Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, does not properly restrict access to resources, which a…

Fix: after 0.1.5192-4
Fix from $1,600 2012-09-28
Enterprise Linux Desktop CRITICAL 9.8
CVE-2012-4681 KEVEPSS 99%

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute a…

Mitigation only
Fix from $2,300 2012-08-28
Enterprise Linux Server CRITICAL 9.8
CVE-2012-3503

The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default in…

Fix: after 1.0
Fix from $2,300 2012-08-25
Enterprise Linux Desktop HIGH 7.8
CVE-2012-1535 KEVEPSS 70%

Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers …

Fix: 11.2.202.238 / 11.3.300.271+
Fix from $1,950 2012-08-15
Certificate System MEDIUM 5.5
CVE-2012-3367

Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System does not properly check certificate revocation requests made through the…

Fix: after 8.1
Fix from $1,600 2012-08-13
Enterprise Linux MEDIUM 5.6
CVE-2012-3440

A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary files via a symlink attack on …

No fix yet
Fix from $1,600 2012-08-08
Icedtea Web HIGH 7.5
CVE-2012-3423EPSS 6%

The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a de…

Fix: after 1.2
Fix from $1,950 2012-08-07
Icedtea Web MEDIUM 6.8
CVE-2012-3422

The getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 returns an uninitialized pointer when the instance_to_id_map hash is empt…

Fix: after 1.2
Fix from $1,600 2012-08-07
Enterprise Linux Optional Productivity Applications HIGH 7.5
CVE-2012-2149EPSS 14%

The WPXContentListener::_closeTableRow function in WPXContentListener.cpp in libwpd 0.8.8, as used by OpenOffice.org (OOo) before 3.4, allows remote …

Fix: after 3.4
Fix from $1,950 2012-06-21
Icedtea6 CRITICAL 9.8
CVE-2012-1723 KEVEPSS 94%

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update…

Fix: 1.10.8 / 1.11.3+
Fix from $2,300 2012-06-16
Satellite MEDIUM 5.0
CVE-2012-1145

spacewalk-backend in Red Hat Network Satellite 5.4 on Red Hat Enterprise Linux 6 does not properly authorize or authenticate uploads to the NULL orga…

Mitigation only
Fix from $1,600 2012-06-16