Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2023-5367 A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data s… Enterprise Linux Patch available Fix from $1,9502023-10-25 HIGH 7.0 CVE-2023-5574 A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setu… Enterprise Linux Patch available Fix from $1,9502023-10-25 HIGH 7.8 CVE-2023-4692 An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesys… Enterprise Linux 2.12+ Fix from $1,9502023-10-25 HIGH 7.7 CVE-2023-5557 A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if th… Enterprise Linux 3.3.2 / 3.4.5+ Fix from $1,9502023-10-13 MEDIUM 5.5 CVE-2023-43789 A vulnerability was found in libXpm where a vulnerability exists due to a boundary condition, a local user can trigger an out-of-bounds read error an… Enterprise Linux 3.5.17+ Fix from $1,6002023-10-12 HIGH 7.8 CVE-2023-43787 A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an intege… Enterprise Linux 1.8.7+ Fix from $1,9502023-10-10 MEDIUM 5.5 CVE-2023-43786 A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to consume all available… Enterprise Linux 1.8.7+ Fix from $1,6002023-10-10 MEDIUM 5.5 CVE-2023-43785 A vulnerability was found in libX11 due to a boundary condition within the _XkbReadKeySyms() function. This flaw allows a local user to trigger an ou… Enterprise Linux 1.8.7+ Fix from $1,6002023-10-10 MEDIUM 5.5 CVE-2023-5366 A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may … Openshift Container Platform 2023-02-28+ Fix from $1,6002023-10-06 HIGH 7.5 CVE-2022-3248 A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the bo… Advanced Cluster Management For Kubernetes Mitigation only Fix from $1,9502023-10-05 MEDIUM 5.3 CVE-2022-4145 A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, e… Openshift Container Platform Mitigation only Fix from $1,6002023-10-05 HIGH 7.8 CVE-2023-4237 A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the stand… Ansible Automation Platform Mitigation only Fix from $1,9502023-10-04 MEDIUM 6.3 CVE-2023-4380 A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. T… Ansible Automation Platform Mitigation only Fix from $1,6002023-10-04 MEDIUM 5.4 CVE-2023-3971 An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a cust… Ansible Automation Controller 4.3.11+ Fix from $1,6002023-10-04 HIGH 8.1 CVE-2023-1832 An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of… Satellite 4.3.7-3+ Fix from $1,9502023-10-04 HIGH 7.5 CVE-2023-3361 A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads… Openshift Data Science 1.28.1+ Fix from $1,9502023-10-04 MEDIUM 5.9 CVE-2022-4132 A flaw was found in JSS. A memory leak in JSS requires non-standard configuration but is a low-effort DoS vector if configured that way (repeatedly h… Enterprise Linux 5.5.0+ Fix from $1,6002023-10-04 MEDIUM 5.3 CVE-2023-3153 A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could allow an attacker to cause a de… Openshift Container Platform 22.03.3 / 22.09.2+ Fix from $1,6002023-10-04 HIGH 7.4 CVE-2023-4586 A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS,… Data Grid Mitigation only Fix from $1,9502023-10-04 HIGH 7.1 CVE-2023-2422 A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the clien… Keycloak Mitigation only Fix from $1,9502023-10-04 HIGH 7.5 CVE-2023-44488 VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding. Enterprise Linux 1.13.1+ Fix from $1,9502023-09-30 MEDIUM 6.5 CVE-2023-5215 A flaw was found in libnbd. A server can reply with a block size larger than 2^63 (the NBD spec states the size is a 64-bit unsigned value). This iss… Libnbd 1.18.0+ Fix from $1,6002023-09-28 MEDIUM 5.5 CVE-2023-4066 A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecur… Jboss A Mq Mitigation only Fix from $1,6002023-09-27 MEDIUM 5.5 CVE-2023-4065 A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Opera… Jboss A Mq Mitigation only Fix from $1,6002023-09-27 HIGH 7.5 CVE-2023-3223 A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow u… Undertow 2.2.24+ Fix from $1,9502023-09-27 HIGH 7.5 CVE-2023-0456 A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token from a separate realm. This coul… Apicast 2.12.2 / 2.13.2+ Fix from $1,9502023-09-27 MEDIUM 5.5 CVE-2023-0833 A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception trigger… A Mq Streams 2.2.1 / 2.4.0+ Fix from $1,6002023-09-27 HIGH 7.5 CVE-2022-4244 A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outsid… Integration Camel K 1.10.1 / 3.0.24+ Fix from $1,9502023-09-25 MEDIUM 6.1 CVE-2022-4137 A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte handling. This issue allows a m… Keycloak Mitigation only Fix from $1,6002023-09-25 HIGH 7.1 CVE-2023-4156 A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive informa… Enterprise Linux 5.1.1+ Fix from $1,9502023-09-25