Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2023-7216 A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a… Enterprise Linux No fix yet Fix from $1,6002024-02-05 MEDIUM 5.9 CVE-2023-5992 A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in th… Enterprise Linux No fix yet Fix from $1,6002024-01-31 MEDIUM 5.9 CVE-2024-0914 A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw co… Enterprise Linux 3.23.0+ Fix from $1,6002024-01-31 MEDIUM 5.5 CVE-2023-40546 A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it tries to print an err… Shim 15.8+ Fix from $1,6002024-01-29 MEDIUM 5.5 CVE-2023-40549 An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw allows an atta… Shim 15.8+ Fix from $1,6002024-01-29 MEDIUM 5.5 CVE-2023-40550 An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensitive data during the system's… Shim 15.8+ Fix from $1,6002024-01-29 MEDIUM 5.1 CVE-2023-40551 A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during t… Shim 15.8+ Fix from $1,6002024-01-29 HIGH 7.4 CVE-2023-40548 A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a user-controlled value parsed … Shim 15.8+ Fix from $1,9502024-01-29 HIGH 7.1 CVE-2023-6291 A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful … Keycloak 22.0.7+ Fix from $1,9502024-01-26 HIGH 7.5 CVE-2023-52356 A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw a… Enterprise Linux Patch available Fix from $1,9502024-01-25 HIGH 7.5 CVE-2023-52355 An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw al… Enterprise Linux 4.6.0+ Fix from $1,9502024-01-25 HIGH 8.3 CVE-2023-40547 A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This … Shim 15.8+ Fix from $1,9502024-01-25 MEDIUM 6.8 CVE-2023-4001 An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains… Enterprise Linux Mitigation only Fix from $1,6002024-01-15 MEDIUM 5.5 CVE-2024-23301 Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to syst… Enterprise Linux after 2.7 Fix from $1,6002024-01-12 MEDIUM 6.5 CVE-2023-6683 A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before… Enterprise Linux 8.2.2+ Fix from $1,6002024-01-12 HIGH 7.5 CVE-2023-6476 A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get a… Openshift Container Platform Mitigation only Fix from $1,9502024-01-09 MEDIUM 5.7 CVE-2023-6944 A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded … Red Hat Developer Hub 1.21.0+ Fix from $1,6002024-01-04 MEDIUM 6.7 CVE-2024-0193 A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is r… Codeready Linux Builder For Eus Patch available Fix from $1,6002024-01-02 MEDIUM 5.3 CVE-2023-6693 A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virtio_net_flush_tx function if g… Enterprise Linux 8.2.1+ Fix from $1,6002024-01-02 HIGH 7.5 CVE-2023-3171 A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources… Jboss Enterprise Application Platform Mitigation only Fix from $1,9502023-12-27 MEDIUM 5.5 CVE-2023-4641 A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, … Codeready Linux Builder Mitigation only Fix from $1,6002023-12-27 HIGH 8.1 CVE-2023-2585 Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validatio… Single Sign On Mitigation only Fix from $1,9502023-12-21 MEDIUM 6.1 CVE-2023-6927 A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM respo… Keycloak Mitigation only Fix from $1,6002023-12-18 MEDIUM 6.5 CVE-2023-5236 A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permis… Data Grid 8.4.4+ Fix from $1,6002023-12-18 MEDIUM 6.3 CVE-2023-5115 An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make … Ansible Automation Platform Mitigation only Fix from $1,6002023-12-18 HIGH 7.5 CVE-2023-4320 An arithmetic overflow flaw was found in Satellite when creating a new personal access token. This flaw allows an attacker who uses this arithmetic o… Satellite 6.13+ Fix from $1,9502023-12-18 MEDIUM 6.5 CVE-2023-3628 A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation. This issue could allow an aut… Jboss Data Grid 8.4.4+ Fix from $1,6002023-12-18 MEDIUM 6.5 CVE-2023-3629 A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This iss… Data Grid 8.4.4+ Fix from $1,6002023-12-18 MEDIUM 5.4 CVE-2023-6134 A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could al… Single Sign On 7.6 / 22.0.7+ Fix from $1,6002023-12-14 HIGH 7.7 CVE-2023-6563 An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline toke… Keycloak 21.0.0+ Fix from $1,9502023-12-14