Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2023-6478 A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow wh… Enterprise Linux Eus 21.1.10 / 23.2.3+ Fix from $1,9502023-12-13 HIGH 7.8 CVE-2023-6377 A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory… Enterprise Linux Eus 21.1.10 / 23.2.3+ Fix from $1,9502023-12-13 HIGH 7.8 CVE-2023-5764 A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from templa… Ansible 2.14.12 / 2.15.7+ Fix from $1,9502023-12-12 HIGH 7.5 CVE-2023-5379 A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error… Jboss Enterprise Application Platform Mitigation only Fix from $1,9502023-12-12 MEDIUM 5.4 CVE-2023-6710 A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the… Enterprise Linux Mitigation only Fix from $1,6002023-12-12 MEDIUM 6.1 CVE-2023-4958 In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this… Advanced Cluster Security Patch available Fix from $1,6002023-12-12 CRITICAL 9.1 CVE-2023-6394 A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operati… Build Of Quarkus 3.6.0+ Fix from $2,3002023-12-09 MEDIUM 5.3 CVE-2023-6393 A flaw was found in the Quarkus Cache Runtime. When request processing utilizes a Uni cached using @CacheResult and the cached Uni reuses the initial… Build Of Quarkus Mitigation only Fix from $1,6002023-12-06 MEDIUM 5.3 CVE-2023-5871 A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network. … Libnbd 1.18.2+ Fix from $1,6002023-11-27 MEDIUM 6.5 CVE-2023-5189 A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy … Ansible Automation Platform No fix yet Fix from $1,6002023-11-14 MEDIUM 6.5 CVE-2023-4061 A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from… Jboss Enterprise Application Platform 15.0.30+ Fix from $1,6002023-11-08 MEDIUM 6.6 CVE-2023-40660 A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographi… Enterprise Linux after 0.23.0 Fix from $1,6002023-11-06 MEDIUM 6.4 CVE-2023-40661 Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user … Enterprise Linux after 0.23.0 Fix from $1,6002023-11-06 MEDIUM 5.5 CVE-2023-4910 A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the browser, the tokens… 3scale Api Management Mitigation only Fix from $1,6002023-11-06 MEDIUM 6.5 CVE-2023-42669 A vulnerability was found in Samba's "rpcecho" development server, a non-Windows RPC server used to test Samba's DCE/RPC stack elements. This vulnera… Storage 4.17.12 / 4.18.8+ Fix from $1,6002023-11-06 HIGH 7.0 CVE-2023-5088 A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead (potentially overw… Enterprise Linux 8.2.0+ Fix from $1,9502023-11-03 CRITICAL 9.8 CVE-2023-3961 A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory… Storage 4.17.12 / 4.18.8+ Fix from $2,3002023-11-03 HIGH 7.5 CVE-2023-46847EPSS 88% Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to he… Enterprise Linux Mitigation only Fix from $1,9502023-11-03 HIGH 7.5 CVE-2023-46848EPSS 10% Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ft… Enterprise Linux 6.4+ Fix from $1,9502023-11-03 HIGH 7.5 CVE-2023-5824EPSS 5% A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HT… Enterprise Linux 6.4+ Fix from $1,9502023-11-03 MEDIUM 5.3 CVE-2023-46846EPSS 6% SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling pas… Enterprise Linux 6.4+ Fix from $1,6002023-11-03 MEDIUM 5.5 CVE-2023-38473 A vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name() function. Enterprise Linux 0.9+ Fix from $1,6002023-11-02 MEDIUM 5.5 CVE-2023-38469 A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record. Enterprise Linux 0.9+ Fix from $1,6002023-11-02 MEDIUM 5.5 CVE-2023-38470 A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function. Enterprise Linux 0.9+ Fix from $1,6002023-11-02 MEDIUM 5.5 CVE-2023-38471 A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function. Enterprise Linux 0.9+ Fix from $1,6002023-11-02 MEDIUM 5.5 CVE-2023-38472 A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function. Enterprise Linux 0.9+ Fix from $1,6002023-11-02 MEDIUM 5.5 CVE-2023-3164 A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/tiffcrop.c:7801. This flaw all… Enterprise Linux 4.6.0+ Fix from $1,6002023-11-02 HIGH 7.2 CVE-2023-5408 A privilege escalation flaw was found in the node restriction admission plugin of the kubernetes api server of OpenShift. A remote attacker who modif… Openshift Container Platform Patch available Fix from $1,9502023-11-02 HIGH 7.8 CVE-2023-3972 A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files an… Insights Client 3.2.2+ Fix from $1,9502023-11-01 HIGH 7.5 CVE-2023-5625 A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2… Openshift Container Platform For Arm64 Patch available Fix from $1,9502023-11-01