Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Evince HIGH 7.6
CVE-2010-2642EPSS 14%

Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possibly other…

Fix: after 2.32
Fix from $1,950 2011-01-07
Evince HIGH 7.6
CVE-2010-2643EPSS 6%

Integer overflow in the TFM font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to execute arbitrary code via…

Patch available
Fix from $1,950 2011-01-07
Jboss Enterprise Application Platform HIGH 7.5
CVE-2010-3708

The serialization implementation in JBoss Drools in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 and …

Mitigation only
Fix from $1,950 2010-12-30
Icedtea MEDIUM 5.0
CVE-2010-3860

IcedTea 1.7.x before 1.7.6, 1.8.x before 1.8.3, and 1.9.x before 1.9.2, as based on OpenJDK 6, declares multiple sensitive variables as public, which…

Fix: after 1.9.1
Fix from $1,600 2010-12-08
Spice Activex MEDIUM 6.8
CVE-2010-2793

Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows…

Fix: after 2.2.3
Fix from $1,600 2010-12-08
Enterprise Mrg HIGH 7.5
CVE-2010-4179

The installation documentation for Red Hat Enterprise Messaging, Realtime and Grid (MRG) 1.3 recommends that Condor should be configured so that the …

Mitigation only
Fix from $1,950 2010-12-07
Certificate System MEDIUM 5.8
CVE-2010-3868

Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, w…

Patch available
Fix from $1,600 2010-11-17
Luci MEDIUM 6.4
CVE-2010-3852

The default configuration of Luci 0.22.4 and earlier in Red Hat Conga uses "[INSERT SECRET HERE]" as its secret key for cookies, which makes it easie…

Fix: after 0.22.4
Fix from $1,600 2010-11-06
Enterprise Virtualization MEDIUM 6.6
CVE-2010-2784

The subpage MMIO initialization functionality in the subpage_register function in exec.c in QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor)…

Patch available
Fix from $1,600 2010-08-24
Enterprise Virtualization MEDIUM 5.7
CVE-2010-2811

Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization (RHEV) 2.2 does not properly accept TCP connections for SSL sessions, whic…

Patch available
Fix from $1,600 2010-08-24
Enterprise Virtualization MEDIUM 6.6
CVE-2010-0431

QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and KVM 83, does not properly validate gues…

Patch available
Fix from $1,600 2010-08-24
Enterprise Virtualization MEDIUM 6.6
CVE-2010-0429

libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and qspice 0.3.0, does not prop…

Patch available
Fix from $1,600 2010-08-24
Enterprise Virtualization MEDIUM 6.6
CVE-2010-0428

libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and qspice 0.3.0, does not prop…

Patch available
Fix from $1,600 2010-08-24
Jboss Enterprise Soa Platform MEDIUM 5.0
CVE-2010-2493

The default configuration of the deployment descriptor (aka web.xml) in picketlink-sts.war in (1) the security_saml quickstart, (2) the webservice_pr…

Fix: after 5.0.1
Fix from $1,600 2010-08-10
Jboss Enterprise Application Platform HIGH 8.8
CVE-2010-1871 KEVEPSS 83%

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Exp…

Mitigation only
Fix from $1,950 2010-08-05
Jboss Enterprise Application Platform HIGH 7.5
CVE-2010-1428 KEVEPSS 62%

The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 …

Mitigation only
Fix from $1,950 2010-04-28
Jboss Enterprise Application Platform MEDIUM 5.3
CVE-2010-0738 KEVEPSS 79%

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 be…

Mitigation only
Fix from $1,600 2010-04-28
Jboss Enterprise Application Platform MEDIUM 5.0
CVE-2010-1429EPSS 54%

Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 allows remote attackers to obt…

Fix: after 4.3.0
Fix from $1,600 2010-04-28
Enterprise Mrg MEDIUM 6.5
CVE-2009-4133

Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and Grid Execute Node for MRG, allows remote authenticated users to queue…

Mitigation only
Fix from $1,600 2009-12-23
Enterprise Linux Server CRITICAL 9.9
CVE-2009-3616

Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitrary code on…

Fix: after 0.10.6
Fix from $2,300 2009-10-23
Enterprise Linux MEDIUM 6.9
CVE-2009-1893

The configtest function in the Red Hat dhcpd init script for DHCP 3.0.1 in Red Hat Enterprise Linux (RHEL) 3 allows local users to overwrite arbitrar…

Mitigation only
Fix from $1,600 2009-07-17
Certificate System MEDIUM 6.5
CVE-2009-0588

agent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remot…

Patch available
Fix from $1,600 2009-05-27
Cman HIGH 7.8
CVE-2008-6560

Buffer overflow in CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9 and Red Hat Enterprise Linux (RHEL) 5 allows attackers to cause a denial o…

Fix: after 2.03.08-1
Fix from $1,950 2009-03-31
Cluster Project MEDIUM 6.9
CVE-2008-6552

Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified com…

Mitigation only
Fix from $1,600 2009-03-30
Jboss Enterprise Application Platform MEDIUM 5.0
CVE-2009-0027

The request handler in JBossWS in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP06 and 4.3 before 4.3.0.CP04 does…

Patch available
Fix from $1,600 2009-03-09
Enterprise Linux MEDIUM 5.0
CVE-2008-6123

The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does …

Fix: after 5.4.2.1
Fix from $1,600 2009-02-12
Dogtag Certificate System MEDIUM 6.0
CVE-2008-5082

The verifyProof function in the Token Processing System (TPS) component in Red Hat Certificate System (RHCS) 7.1 through 7.3 and Dogtag Certificate S…

Mitigation only
Fix from $1,600 2009-01-30
Enterprise Linux MEDIUM 6.8
CVE-2008-4315

tog-pegasus in OpenGroup Pegasus 2.7.0 on Red Hat Enterprise Linux (RHEL) 5, Fedora 9, and Fedora 10 does not log failed authentication attempts to t…

Mitigation only
Fix from $1,600 2008-11-27
Enterprise Linux MEDIUM 6.0
CVE-2008-4313

A certain Red Hat patch for tog-pegasus in OpenGroup Pegasus 2.7.0 does not properly configure the PAM tty name, which allows remote authenticated us…

Patch available
Fix from $1,600 2008-11-27
Enterprise Virtualization HIGH 10.0
CVE-2008-3522

Buffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c in JasPer 1.900.1 might allow context-dependent attackers to have an…

No fix yet
Fix from $1,950 2008-10-02