Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2022-38065 A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functio… Openstack No fix yet Fix from $1,9502022-12-21 HIGH 7.1 CVE-2022-3775 When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and height is constrained within bi… Enterprise Linux after 2.06 Fix from $1,9502022-12-19 HIGH 7.4 CVE-2022-3259 Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks. Openshift Mitigation only Fix from $1,9502022-12-09 HIGH 8.1 CVE-2022-3262 A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw a… Openshift Mitigation only Fix from $1,9502022-12-08 CRITICAL 9.8 CVE-2022-4116EPSS 33% A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to… Build Of Quarkus 2.13.5 / 2.14.2+ Fix from $2,3002022-11-22 MEDIUM 5.1 CVE-2022-3500 A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the … Enterprise Linux 6.5.1+ Fix from $1,6002022-11-22 MEDIUM 5.5 CVE-2022-3821 An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time a… Enterprise Linux after 251 Fix from $1,6002022-11-08 MEDIUM 5.5 CVE-2022-3675 Fedora CoreOS supports setting a GRUB bootloader password using a Butane config. When this feature is enabled, GRUB requires a password to access the… Fedora Coreos 37.20221031.1.0+ Fix from $1,6002022-11-03 HIGH 7.5 CVE-2022-3697 A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw a… Ansible 2.0.0 / 2.10.0+ Fix from $1,9502022-10-28 MEDIUM 5.5 CVE-2022-3644 The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the… Ansible Automation Platform No fix yet Fix from $1,6002022-10-25 MEDIUM 6.5 CVE-2022-2805 A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-style. This flaw allows an attac… Virtualization Mitigation only Fix from $1,6002022-10-19 HIGH 8.8 CVE-2022-1414 3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An authenticated user could use this flaw to inject s… 3scale Api Management Mitigation only Fix from $1,9502022-10-19 HIGH 7.5 CVE-2013-4253 The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root … Openshift Patch available Fix from $1,9502022-10-19 MEDIUM 5.5 CVE-2013-4281 In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users… Openshift Patch available Fix from $1,6002022-10-19 HIGH 8.8 CVE-2019-14841 A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to … Decision Manager Mitigation only Fix from $1,9502022-10-17 HIGH 7.5 CVE-2019-14840 A flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to leak of credentials. Decision Manager No fix yet Fix from $1,9502022-10-17 MEDIUM 6.5 CVE-2022-2850 A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using… Directory Server after 2.4.1 Fix from $1,6002022-10-14 MEDIUM 6.1 CVE-2020-15855 Two cross-site scripting vulnerabilities were fixed in Bodhi 5.6.1. Bodhi 5.6.1+ Fix from $1,6002022-10-07 HIGH 8.6 CVE-2014-0144 QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions, integer/bu… Virtualization Patch available Fix from $1,9502022-09-29 MEDIUM 5.5 CVE-2014-0148 Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to … Virtualization Patch available Fix from $1,6002022-09-29 MEDIUM 5.5 CVE-2015-1931 IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 b… Satellite 5.0.16.13 / 6.0.16.7+ Fix from $1,6002022-09-29 MEDIUM 6.1 CVE-2022-3205 Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS inje… Ansible Automation Platform Mitigation only Fix from $1,6002022-09-13 HIGH 7.5 CVE-2022-1278 A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain. Wildfly 27.0.0+ Fix from $1,9502022-09-13 HIGH 7.1 CVE-2022-2989 An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data … Openshift Container Platform Patch available Fix from $1,9502022-09-13 HIGH 7.1 CVE-2022-2990 An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data… Openshift Container Platform 1.27.1+ Fix from $1,9502022-09-13 HIGH 7.8 CVE-2022-25308 A stack-based buffer overflow flaw was found in the Fribidi package. This flaw allows an attacker to pass a specially crafted file to the Fribidi app… Enterprise Linux 1.0.12+ Fix from $1,9502022-09-06 MEDIUM 5.5 CVE-2022-25309 A heap-based buffer overflow flaw was found in the Fribidi package and affects the fribidi_cap_rtl_to_unicode() function of the fribidi-char-sets-cap… Enterprise Linux 1.0.12+ Fix from $1,6002022-09-06 MEDIUM 5.5 CVE-2022-25310 A segmentation fault (SEGV) flaw was found in the Fribidi package and affects the fribidi_remove_bidi_marks() function of the lib/fribidi.c file. Thi… Enterprise Linux 1.0.12+ Fix from $1,6002022-09-06 HIGH 8.1 CVE-2022-23451 An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, mo… Openstack Platform 14.0.0+ Fix from $1,9502022-09-06 HIGH 8.8 CVE-2022-1902 A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw … Advanced Cluster Security Patch available Fix from $1,9502022-09-01