Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2022-0671 A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large file. Vscode Xml 0.19.0+ Fix from $2,3002022-02-18 HIGH 7.5 CVE-2021-4091 A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search r… Enterprise Linux Desktop 1.3.10.2+ Fix from $1,9502022-02-18 CRITICAL 9.8 CVE-2021-20325 Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regress… Enterprise Linux Mitigation only Fix from $2,3002022-02-18 MEDIUM 6.5 CVE-2021-3930 An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the … Codeready Linux Builder Patch available Fix from $1,6002022-02-18 MEDIUM 6.3 CVE-2021-3948 An incorrect default permissions vulnerability was found in the mig-controller. Due to an incorrect cluster namespaces handling an attacker may be ab… Migration Toolkit 1.5.2 / 1.6.3+ Fix from $1,6002022-02-18 MEDIUM 6.5 CVE-2021-3557 A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-serve… Openshift Gitops 1.1.1+ Fix from $1,6002022-02-16 MEDIUM 5.5 CVE-2022-0561 Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 … Enterprise Linux after 4.3.0 Fix from $1,6002022-02-11 MEDIUM 5.5 CVE-2022-0529 A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound wri… Enterprise Linux No fix yet Fix from $1,6002022-02-09 MEDIUM 5.5 CVE-2022-0530 A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound wri… Enterprise Linux 10.15.7 / 11.6.6+ Fix from $1,6002022-02-09 HIGH 7.8 CVE-2021-4034 KEVEPSS 95% A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileg… Enterprise Linux Server Update Services For Sap Solutions Patch available Fix from $1,9502022-01-28 HIGH 8.8 CVE-2021-4133 A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default … Keycloak 15.1.1+ Fix from $1,9502022-01-25 MEDIUM 6.5 CVE-2021-4145 A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in mirror… Enterprise Linux Patch available Fix from $1,6002022-01-25 HIGH 7.8 CVE-2021-45417 AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of… Ovirt Node after 0.17.3 Fix from $1,9502022-01-20 HIGH 7.1 CVE-2021-4166 vim is vulnerable to Out-of-bounds Read Enterprise Linux 8.2.3884 / 11.6.6+ Fix from $1,9502021-12-25 HIGH 8.8 CVE-2021-3621 A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This fl… Virtualization Patch available Fix from $1,9502021-12-23 HIGH 7.2 CVE-2021-3584 A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to … Satellite 2.4.1 / 2.5.1+ Fix from $1,9502021-12-23 HIGH 7.2 CVE-2021-20318 The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary … Jboss Enterprise Application Platform Mitigation only Fix from $1,9502021-12-23 HIGH 7.8 CVE-2021-45463 load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by u… Enterprise Linux 0.4.34 / 2.10.30+ Fix from $1,9502021-12-23 MEDIUM 6.6 CVE-2021-42550 In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configurat… Satellite 1.0.3+ Fix from $1,6002021-12-16 CRITICAL 9.1 CVE-2021-4048 An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS b… Ceph Storage 0.3.18+ Fix from $2,3002021-12-08 HIGH 8.1 CVE-2021-3935 When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first e… Enterprise Linux 1.16.1+ Fix from $1,9502021-11-22 HIGH 7.1 CVE-2021-3583 A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template i… Ansible Automation Platform 2.9.23 / 3.7.0+ Fix from $1,9502021-09-22 CRITICAL 9.8 CVE-2021-31917 A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authenticat… Data Grid 11.0.12 / 12.1.4+ Fix from $2,3002021-09-21 CRITICAL 9.0 CVE-2021-40438 KEVEPSS 100% A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP … Enterprise Linux Patch available Fix from $2,3002021-09-16 HIGH 7.8 CVE-2021-33285 In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, a heap buffer overflow… Enterprise Linux 2021.8.22+ Fix from $1,9502021-09-07 MEDIUM 6.5 CVE-2021-3634 A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during the lifetime of the session. On… Virtualization 0.9.6+ Fix from $1,6002021-08-31 MEDIUM 5.5 CVE-2021-3605 There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an applicatio… Enterprise Linux 3.0.5+ Fix from $1,6002021-08-25 CRITICAL 9.8 CVE-2021-20314 Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code executio… Enterprise Linux 1.2.11+ Fix from $2,3002021-08-12 MEDIUM 5.3 CVE-2021-3642 A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susc… Wildfly Elytron 1.10.14 / 1.15.5+ Fix from $1,6002021-08-05 HIGH 7.5 CVE-2021-3580 A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a mani… Enterprise Linux 3.7.3+ Fix from $1,9502021-08-05