Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.9 CVE-2022-0552 A flaw was found in the original fix for the netty-codec-http CVE-2021-21409, where the OpenShift Logging openshift-logging/elasticsearch6-rhel8 cont… Origin Aggregated Logging Patch available Fix from $1,6002022-04-11 HIGH 7.5 CVE-2022-27649 A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker E… Developer Tools Patch available Fix from $1,9502022-04-04 HIGH 7.1 CVE-2021-3461 A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Prin… Keycloak Patch available Fix from $1,9502022-04-01 HIGH 7.5 CVE-2019-14839 It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercep… Business Central after 7.48.0 Fix from $1,9502022-04-01 HIGH 8.1 CVE-2022-0759 A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeco… Kubeclient 4.9.3+ Fix from $1,9502022-03-25 HIGH 7.5 CVE-2021-3814 It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably b… 3scale 2.11.0+ Fix from $1,9502022-03-25 MEDIUM 6.5 CVE-2021-3941 In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations such as `float Z = (1 - chroma.white.x - chroma.white.y) * Y / chroma… Enterprise Linux Patch available Fix from $1,6002022-03-25 MEDIUM 6.5 CVE-2021-4147 A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash,… Libvirt 2.33.0+ Fix from $1,6002022-03-25 MEDIUM 6.1 CVE-2021-20323EPSS 37% A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak. Keycloak 17.0.0+ Fix from $1,6002022-03-25 MEDIUM 6.5 CVE-2022-0996 A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication. 389 Directory Server No fix yet Fix from $1,6002022-03-23 HIGH 8.0 CVE-2021-3589 An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access host… Satellite 7.1.0+ Fix from $1,9502022-03-23 HIGH 7.5 CVE-2022-0918EPSS 6% A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a de… Enterprise Linux Patch available Fix from $1,9502022-03-16 MEDIUM 5.5 CVE-2021-20180 A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using… Ansible 2.9.18+ Fix from $1,6002022-03-16 HIGH 7.5 CVE-2022-0853 A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and l… Descision Manager No fix yet Fix from $1,9502022-03-11 HIGH 7.5 CVE-2021-3698 A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Dae… Enterprise Linux 260+ Fix from $1,9502022-03-10 HIGH 7.8 CVE-2021-20319 An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image sign… Coreos Installer 0.10.1+ Fix from $1,9502022-03-04 HIGH 7.8 CVE-2021-3575 A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use … Enterprise Linux after 2.4.0 Fix from $1,9502022-03-04 CRITICAL 9.8 CVE-2021-3762 A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image w… Clair 0.4.8 / 0.5.5+ Fix from $2,3002022-03-03 MEDIUM 5.5 CVE-2021-3602 An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Doc… Enterprise Linux 1.16.8 / 1.17.2+ Fix from $1,6002022-03-03 MEDIUM 5.5 CVE-2021-3620 A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by defa… Ansible Automation Platform Early Access 2.9.27+ Fix from $1,6002022-03-03 MEDIUM 6.5 CVE-2021-3667 An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function w… Libvirt after 7.5.0 Fix from $1,6002022-03-02 MEDIUM 6.3 CVE-2021-3631 A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access fil… Libvirt 7.5.0+ Fix from $1,6002022-03-02 MEDIUM 6.1 CVE-2021-3623 A flaw was found in libtpms. The flaw can be triggered by specially-crafted TPM 2 command packets containing illegal values and may lead to an out-of… Enterprise Linux 0.6.5 / 0.7.8+ Fix from $1,6002022-03-02 MEDIUM 6.1 CVE-2021-3654EPSS 27% A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL. Openstack Platform 21.2.3 / 22.2.3+ Fix from $1,6002022-03-02 HIGH 7.5 CVE-2022-0711EPSS 17% A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted H… Openshift Container Platform 2.2.21 / 2.3.18+ Fix from $1,9502022-03-02 HIGH 7.8 CVE-2021-26252 A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of s… Enterprise Linux Patch available Fix from $1,9502022-02-24 MEDIUM 6.5 CVE-2021-3596 A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not c… Enterprise Linux 7.0.10-31+ Fix from $1,6002022-02-24 MEDIUM 6.4 CVE-2021-3700 A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c… Enterprise Linux 0.11.0+ Fix from $1,6002022-02-24 MEDIUM 5.5 CVE-2021-4115 There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threa… Enterprise Linux Patch available Fix from $1,6002022-02-21 MEDIUM 5.5 CVE-2022-23645 swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerab… Enterprise Linux 0.5.3 / 0.6.2+ Fix from $1,6002022-02-18