Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2022-0670 A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file syste… Ceph Storage 5.2 / 15.2.17+ Fix from $2,3002022-07-25 MEDIUM 6.5 CVE-2022-1655 An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without … Openstack Mitigation only Fix from $1,6002022-07-22 MEDIUM 5.7 CVE-2022-2393 A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled.… Certificate System after 10.12.4 Fix from $1,6002022-07-14 MEDIUM 6.5 CVE-2022-2211 A vulnerability was found in libguestfs. This issue occurs while calculating the greatest possible number of matching keys in the get_keys() function… Enterprise Linux No fix yet Fix from $1,6002022-07-12 CRITICAL 9.8 CVE-2022-1245 A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid ac… Keycloak 18.0.0+ Fix from $2,3002022-07-08 CRITICAL 9.1 CVE-2014-8164 A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat Cloud… Cloudforms Management Engine Mitigation only Fix from $2,3002022-07-06 HIGH 7.0 CVE-2021-3697 A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to … Developer Tools Mitigation only Fix from $1,9502022-07-06 HIGH 7.5 CVE-2014-3648 The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But this is use… Jboss Aerogear Mitigation only Fix from $1,9502022-07-01 MEDIUM 5.4 CVE-2014-3650 Multiple persistent cross-site scripting (XSS) flaws were found in the way Aerogear handled certain user-supplied content. A remote attacker could us… Jboss Aerogear Mitigation only Fix from $1,6002022-07-01 MEDIUM 5.5 CVE-2014-0068 It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission. Openshift Origin Node Util Mitigation only Fix from $1,6002022-06-30 CRITICAL 9.1 CVE-2013-4561 In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to loss of confidentiality and i… Openshift Patch available Fix from $2,3002022-06-30 HIGH 8.8 CVE-2022-1833 A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has access to the namespace where th… Amq Broker Mitigation only Fix from $1,9502022-06-21 HIGH 8.2 CVE-2022-1665 A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub in Secure Boot mode even tho… Enterprise Linux Mitigation only Fix from $1,9502022-06-21 CRITICAL 9.8 CVE-2021-41411 drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, res… Drools 7.6.0+ Fix from $2,3002022-06-16 HIGH 7.5 CVE-2022-1949 An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progr… 389 Directory Server after 2.0.0 Fix from $1,9502022-06-02 HIGH 7.8 CVE-2021-3717 A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER acces… Jboss Enterprise Application Platform 17.0+ Fix from $1,9502022-05-24 MEDIUM 5.9 CVE-2021-3597 A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The h… Fuse 2.0.35 / 2.2.6+ Fix from $1,6002022-05-24 MEDIUM 5.9 CVE-2021-3629 A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a deni… Integration 2.0.40 / 2.2.11+ Fix from $1,6002022-05-24 MEDIUM 6.5 CVE-2022-1706 A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issu… Ignition 2.14.0+ Fix from $1,6002022-05-17 CRITICAL 9.1 CVE-2022-1587 An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. Th… Enterprise Linux 10.40+ Fix from $2,3002022-05-16 MEDIUM 6.5 CVE-2021-3611 A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use this flaw to crash the QEMU pr… Enterprise Linux 7.0.0+ Fix from $1,6002022-05-11 MEDIUM 5.3 CVE-2022-0866 This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that is configured with a… Jboss Enterprise Application Platform 26.1.1+ Fix from $1,6002022-05-10 HIGH 8.2 CVE-2021-3750 A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO regi… Enterprise Linux 7.0.0+ Fix from $1,9502022-05-02 HIGH 8.2 CVE-2021-4206 A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a smal… Enterprise Linux 7.0.0+ Fix from $1,9502022-04-29 HIGH 8.2 CVE-2021-4207 A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.he… Enterprise Linux 7.0.0+ Fix from $1,9502022-04-29 HIGH 7.5 CVE-2021-3523 A flaw was found in 3Scale APICast in versions prior to 2.11.0, where it incorrectly identified connections for reuse. This flaw allows an attacker t… Apicast 2.11.0+ Fix from $1,9502022-04-27 MEDIUM 6.5 CVE-2022-1466 Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was po… Keycloak 17.0.1+ Fix from $1,6002022-04-26 MEDIUM 5.5 CVE-2021-3681 A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly ex… Ansible Automation Platform Mitigation only Fix from $1,6002022-04-18 HIGH 7.8 CVE-2022-1304 An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code executi… Enterprise Linux Mitigation only Fix from $1,9502022-04-14 HIGH 7.5 CVE-2021-4047 The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only aff… Openshift Mitigation only Fix from $1,9502022-04-11