Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cman MEDIUM 6.9
CVE-2008-4192

The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack…

Mitigation only
Fix from $1,600 2008-09-29
Adminutil HIGH 7.5
CVE-2008-2932

Heap-based buffer overflow in Red Hat adminutil 1.1.6 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitra…

Mitigation only
Fix from $1,950 2008-09-12
Enterprise Ipa MEDIUM 5.0
CVE-2008-3274

The default configuration of Red Hat Enterprise IPA 1.0.0 and FreeIPA before 1.1.1 places ldap:///anyone on the read ACL for the krbMKey attribute, w…

Fix: after 1.1.0
Fix from $1,600 2008-09-12
Directory Server HIGH 10.0
CVE-2008-2928EPSS 7%

Multiple buffer overflows in the adminutil library in CGI applications in Red Hat Directory Server 7.1 before SP7 allow remote attackers to cause a d…

Patch available
Fix from $1,950 2008-08-29
Satellite CRITICAL 9.1
CVE-2008-2369

manzier.pxt in Red Hat Network Satellite Server before 5.1.1 has a hard-coded authentication key, which allows remote attackers to connect to the ser…

Fix: 5.1.1+
Fix from $2,300 2008-08-14
Nfs Utils HIGH 7.5
CVE-2008-1376

A certain Red Hat build script for nfs-utils before 1.0.9-35z.el5_2 on Red Hat Enterprise Linux (RHEL) 5 omits TCP wrappers support, which might allo…

Mitigation only
Fix from $1,950 2008-08-01
Cygwin HIGH 7.6
CVE-2008-3323

setup.exe before 2.573.2.3 in Cygwin does not properly verify the authenticity of packages, which allows remote Cygwin mirror servers or man-in-the-m…

Fix: after 1.7
Fix from $1,950 2008-07-28
Vsftpd HIGH 7.1
CVE-2008-2375

Memory leak in a certain Red Hat deployment of vsftpd before 2.0.5 on Red Hat Enterprise Linux (RHEL) 3 and 4, when PAM is used, allows remote attack…

No fix yet
Fix from $1,950 2008-07-09
Fedora 8 HIGH 7.2
CVE-2008-2359

The default configuration of consolehelper in system-config-network before 1.5.10-1 on Fedora 8 lacks the USER=root directive, which allows local use…

Mitigation only
Fix from $1,950 2008-06-02
Desktop HIGH 7.5
CVE-2008-1767EPSS 13%

Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent attackers to cause a denial of service (crash) and possibly execute ar…

No fix yet
Fix from $1,950 2008-05-23
Enterprise Linux HIGH 7.1
CVE-2007-5962EPSS 12%

Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux a…

Patch available
Fix from $1,950 2008-05-22
Directory Server HIGH 7.5
CVE-2008-1677

Buffer overflow in the regular expression handler in Red Hat Directory Server 8.0 and 7.1 before SP6 allows remote attackers to cause a denial of ser…

Mitigation only
Fix from $1,950 2008-05-12
Enterprise Linux HIGH 7.1
CVE-2007-6282

The IPsec implementation in Linux kernel before 2.6.25 allows remote routers to cause a denial of service (crash) via a fragmented ESP packet in whic…

No fix yet
Fix from $1,950 2008-05-08
Directory Server HIGH 9.0
CVE-2008-0892EPSS 14%

The replication monitor CGI script (repl-monitor-cgi.pl) in Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, allow…

Mitigation only
Fix from $1,950 2008-04-16
Directory Server HIGH 7.5
CVE-2008-0893

Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, does not properly restrict access to CGI scripts, which allows re…

Patch available
Fix from $1,950 2008-04-16
Enterprise Linux HIGH 7.2
CVE-2007-4130

The Linux kernel 2.6.9 before 2.6.9-67 in Red Hat Enterprise Linux (RHEL) 4 on Itanium (ia64) does not properly handle page faults during NUMA memory…

Patch available
Fix from $1,950 2008-02-05
Cairo MEDIUM 6.8
CVE-2007-5503EPSS 5%

Multiple integer overflows in Cairo before 1.4.12 might allow remote attackers to execute arbitrary code, as demonstrated using a crafted PNG image w…

Fix: after 1.4.10
Fix from $1,600 2007-11-30
Cygwin HIGH 8.5
CVE-2007-6181EPSS 6%

Heap-based buffer overflow in cygwin1.dll in Cygwin 1.5.7 and earlier allows context-dependent attackers to execute arbitrary code via a filename wit…

Fix: after 1.5.19
Fix from $1,950 2007-11-30
Conga MEDIUM 5.0
CVE-2007-4136

The ricci daemon in Red Hat Conga 0.10.0 allows remote attackers to cause a denial of service (loss of new connections) by repeatedly sending data or…

Patch available
Fix from $1,600 2007-11-14
Certificate Server HIGH 7.5
CVE-2007-4994

Certificate Server 7.2 in Red Hat Certificate System (RHCS) does not properly handle new revocations that occur while a Certificate Revocation List (…

Mitigation only
Fix from $1,950 2007-11-06
Linux MEDIUM 6.0
CVE-2007-5079

Red Hat Enterprise Linux 4 does not properly compile and link gdm with tcp_wrappers on x86_64 platforms, which might allow remote attackers to bypass…

Mitigation only
Fix from $1,600 2007-09-25
Fedora MEDIUM 6.8
CVE-2007-4134

Directory traversal vulnerability in extract.c in star before 1.5a84 allows user-assisted remote attackers to overwrite arbitrary files via certain /…

Patch available
Fix from $1,600 2007-08-30
Network Satelite Server MEDIUM 6.5
CVE-2007-4132

Unspecified vulnerability in Red Hat Network Satellite Server 5.0.0 allows remote authenticated users to execute arbitrary code via unknown vectors i…

Patch available
Fix from $1,600 2007-08-30
Fedora Core MEDIUM 5.8
CVE-2007-2874

Buffer overflow in the wpa_printf function in the debugging code in wpa_supplicant in the Fedora NetworkManager package before 0.6.5-3.fc7 allows use…

Fix: after 0.6.5-3.fc7
Fix from $1,600 2007-07-27
Enterprise Linux MEDIUM 6.2
CVE-2007-3103

The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the permissions of arbitrary fil…

Patch available
Fix from $1,600 2007-07-15
Cluster Suite MEDIUM 5.0
CVE-2007-3373

daemon.c in cman (redhat-cluster-suite) before 20070622 does not clear a buffer for reading requests, which might allow local users to obtain sensiti…

Patch available
Fix from $1,600 2007-06-25
Enterprise Linux HIGH 10.0
CVE-2007-1007EPSS 7%

Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbit…

Patch available
Fix from $1,950 2007-02-20
Enterprise Linux HIGH 10.0
CVE-2006-6235EPSS 6%

A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary c…

Patch available
Fix from $1,950 2006-12-07
Kdelibs MEDIUM 6.8
CVE-2006-4811

Integer overflow in Qt 3.3 before 3.3.7, 4.1 before 4.1.5, and 4.2 before 4.2.1, as used in the KDE khtml library, kdelibs 3.1.3, and possibly other …

Patch available
Fix from $1,600 2006-10-18
Enterprise Linux HIGH 7.5
CVE-2006-5170

pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition wh…

Patch available
Fix from $1,950 2006-10-10