Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux Desktop HIGH 9.3
CVE-2012-2035EPSS 6%

Stack-based buffer overflow in Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.…

Fix: after 11.2.202.235
Fix from $1,950 2012-06-09
Enterprise Linux Desktop HIGH 9.3
CVE-2012-2036

Integer overflow in Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11…

Fix: after 11.2.202.235
Fix from $1,950 2012-06-09
Enterprise Linux Desktop HIGH 9.3
CVE-2012-2037

Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux;…

Fix: after 11.2.202.235
Fix from $1,950 2012-06-09
Enterprise Linux Desktop HIGH 9.3
CVE-2012-2039

Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux;…

Fix: after 11.2.202.235
Fix from $1,950 2012-06-09
Enterprise Linux Desktop HIGH 7.5
CVE-2012-2034 KEVEPSS 8%

Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux;…

Fix: after 11.2.202.235
Fix from $1,950 2012-06-09
Jboss Enterprise Application Platform HIGH 7.5
CVE-2011-4608

mod_cluster in JBoss Enterprise Application Platform 5.1.2 for Red Hat Linux allows worker nodes to register with arbitrary virtual hosts, which allo…

Mitigation only
Fix from $1,950 2012-01-27
Jboss Enterprise Application Platform MEDIUM 5.8
CVE-2011-4314

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework …

Fix: after 1.0.1
Fix from $1,600 2012-01-27
Freeipa MEDIUM 6.8
CVE-2011-3636

Cross-site request forgery (CSRF) vulnerability in the management interface in FreeIPA before 2.1.4 allows remote attackers to hijack the authenticat…

Fix: after 2.1.3
Fix from $1,600 2011-12-08
System Config Printer MEDIUM 5.1
CVE-2011-2899

pysmb.py in system-config-printer 0.6.x and 0.7.x, as used in foomatic-gui and possibly other products, allows remote SMB servers to execute arbitrar…

Patch available
Fix from $1,600 2011-08-31
Network Satellite Server MEDIUM 6.8
CVE-2009-4139

A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authent…

Patch available
Fix from $1,600 2011-07-27
Jboss Enterprise Application Platform MEDIUM 6.8
CVE-2011-2196

jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP05 and 5.1.0; JBoss E…

Fix: after 2.2.2
Fix from $1,600 2011-07-27
Jboss Enterprise Application Platform MEDIUM 6.8
CVE-2011-1484

jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP04 and 5.1.0 and JBos…

Fix: after 2.2.2
Fix from $1,600 2011-07-27
System Config Firewall HIGH 7.8
CVE-2011-2520

fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the bac…

Fix: after 1.2.29
Fix from $1,950 2011-07-21
Policykit MEDIUM 6.9
CVE-2011-1485EPSS 5%

Race condition in the pkexec utility and polkitd daemon in PolicyKit (aka polkit) 0.96 allows local users to gain privileges by executing a setuid pr…

Patch available
Fix from $1,600 2011-05-31
Spice Xpi MEDIUM 5.1
CVE-2011-1179

The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows remote attackers to cause a denial of service (crash) and pos…

Patch available
Fix from $1,600 2011-04-18
Network Satellite Server MEDIUM 6.4
CVE-2009-0788

Red Hat Network (RHN) Satellite Server 5.3 and 5.4 does not properly rewrite unspecified URLs, which allows remote attackers to (1) obtain unspecifie…

No fix yet
Fix from $1,600 2011-04-18
Satellite MEDIUM 5.5
CVE-2010-1171

Red Hat Network (RHN) Satellite 5.3 and 5.4 exposes a dangerous, obsolete XML-RPC API, which allows remote authenticated users to access arbitrary fi…

Mitigation only
Fix from $1,600 2011-04-18
Enterprise Linux MEDIUM 6.9
CVE-2011-0536

Multiple untrusted search path vulnerabilities in elf/dl-object.c in certain modified versions of the GNU C Library (aka glibc or libc6), including g…

Patch available
Fix from $1,600 2011-04-08
Libvirt MEDIUM 6.9
CVE-2011-1146

libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only connection, which allows remote attackers to cause…

Patch available
Fix from $1,600 2011-03-15
Network Satellite Server MEDIUM 5.8
CVE-2011-0717

Session fixation vulnerability in Red Hat Network (RHN) Satellite Server 5.4 allows remote attackers to hijack web sessions via unspecified vectors r…

Mitigation only
Fix from $1,600 2011-02-25
Network Satellite Server MEDIUM 5.8
CVE-2011-0718

Red Hat Network (RHN) Satellite Server 5.4 does not use a time delay after a failed login attempt, which makes it easier for remote attackers to cond…

Mitigation only
Fix from $1,600 2011-02-25
Policycoreutils MEDIUM 6.9
CVE-2011-1011

The seunshare_mount function in sandbox/seunshare.c in seunshare in certain Red Hat packages of policycoreutils 2.0.83 and earlier in Red Hat Enterpr…

Fix: after 2.0.83
Fix from $1,600 2011-02-24
Directory Server HIGH 7.5
CVE-2011-0019

slapd (aka ns-slapd) in 389 Directory Server 1.2.7.5 (aka Red Hat Directory Server 8.2.x or dirsrv) does not properly handle simple paged result sear…

Mitigation only
Fix from $1,950 2011-02-23
Directory Server MEDIUM 6.2
CVE-2011-0532

The (1) backup and restore scripts, (2) main initialization script, and (3) ldap-agent script in 389 Directory Server 1.2.x (aka Red Hat Directory Se…

Mitigation only
Fix from $1,600 2011-02-23
Icedtea Web HIGH 7.5
CVE-2011-0706

The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via u…

Patch available
Fix from $1,950 2011-02-19
Icedtea MEDIUM 6.8
CVE-2011-0025

IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or…

Patch available
Fix from $1,600 2011-02-04
Conga HIGH 7.5
CVE-2011-0720

Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain administra…

Mitigation only
Fix from $1,950 2011-02-03
Icedtea MEDIUM 6.8
CVE-2010-4351

The JNLP SecurityManager in IcedTea (IcedTea.so) 1.7 before 1.7.7, 1.8 before 1.8.4, and 1.9 before 1.9.4 for Java OpenJDK returns from the checkPerm…

Patch available
Fix from $1,600 2011-01-20
Evince HIGH 7.6
CVE-2010-2640

Array index error in the PK font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to cause a denial of service …

Fix: after 2.32
Fix from $1,950 2011-01-07
Evince HIGH 7.6
CVE-2010-2641

Array index error in the VF font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to cause a denial of service …

Fix: after 2.32
Fix from $1,950 2011-01-07