Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.5 CVE-2021-3682 A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfe… Enterprise Linux 6.1.0+ Fix from $1,9502021-08-05 MEDIUM 6.5 CVE-2021-3541 A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of s… Jboss Core Services 2.9.11+ Fix from $1,6002021-07-09 HIGH 7.5 CVE-2021-3637 A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity … Keycloak 14.0.0+ Fix from $1,9502021-07-09 HIGH 8.8 CVE-2021-3570 A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote att… Enterprise Linux 1.5.1 / 1.6.1+ Fix from $1,9502021-07-09 HIGH 7.1 CVE-2021-3571 A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a … Enterprise Linux 2.0.1 / 3.1.1+ Fix from $1,9502021-07-09 MEDIUM 5.5 CVE-2021-3598 There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an… Enterprise Linux 3.0.5+ Fix from $1,6002021-07-06 MEDIUM 6.1 CVE-2021-20293 A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where it did not properly handle URL… Resteasy after 4.6.0 Fix from $1,6002021-06-10 MEDIUM 5.7 CVE-2021-0129 Improper access control in BlueZ may allow an authenticated user to potentially enable information disclosure via adjacent access. Enterprise Linux 5.57+ Fix from $1,6002021-06-09 HIGH 8.1 CVE-2020-25716 A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is possible. An attacker with a… Cloudforms 5.11.10.1+ Fix from $1,9502021-06-07 MEDIUM 6.5 CVE-2020-1750 A flaw was found in the machine-config-operator that causes an OpenShift node to become unresponsive when a container consumes a large amount of memo… Machine Config Operator 4.2.36 / 4.3.25+ Fix from $1,6002021-06-07 HIGH 7.0 CVE-2020-1742 An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the containe… Openshift Virtualization 2.3.0+ Fix from $1,9502021-06-07 MEDIUM 6.5 CVE-2020-1690 An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root user in a container from pri… Openstack Selinux 0.8.24+ Fix from $1,6002021-06-07 MEDIUM 5.4 CVE-2020-1719 A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Security Domain. The highest th… Wildfly 20.0.0+ Fix from $1,6002021-06-07 MEDIUM 5.9 CVE-2021-3565 A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed AES key for the inner wrapper, potentially allowin… Enterprise Linux 4.3.2 / 5.1.1+ Fix from $1,6002021-06-04 MEDIUM 5.5 CVE-2021-3569 A stack corruption bug was found in libtpms in versions before 0.7.2 and before 0.8.0 while decrypting data using RSA. This flaw could result in a SI… Enterprise Linux 0.7.2 / 0.8.0+ Fix from $1,6002021-06-03 HIGH 7.1 CVE-2021-3529 A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as p… Noobaa Operator 5.7.0+ Fix from $1,9502021-06-02 HIGH 7.0 CVE-2020-35514 An insecure modification flaw in the /etc/kubernetes/kubeconfig file was found in OpenShift. This flaw allows an attacker with access to a running co… Openshift 4.7.0+ Fix from $1,9502021-06-02 MEDIUM 5.9 CVE-2020-35510 A flaw was found in jboss-remoting in versions before 5.0.20.SP1-redhat-00001. A malicious attacker could cause threads to hold up forever in the EJB… Jboss Remoting 5.0.20+ Fix from $1,6002021-06-02 MEDIUM 6.3 CVE-2020-14388 A flaw was found in the Red Hat 3scale API Management Platform, where member permissions for an API's admin portal were not properly enforced. This f… 3scale Api Management Mitigation only Fix from $1,6002021-06-02 HIGH 7.5 CVE-2020-14380 An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authen… Satellite Mitigation only Fix from $1,9502021-06-02 MEDIUM 6.5 CVE-2020-14371 A credential leak vulnerability was found in Red Hat Satellite. This flaw exposes the compute resources credentials through VMs that are running on t… Satellite Mitigation only Fix from $1,6002021-06-02 MEDIUM 5.9 CVE-2020-14340 A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection c… Xnio 3.7.9 / 3.8.2+ Fix from $1,6002021-06-02 HIGH 7.5 CVE-2020-14326 A vulnerability was found in RESTEasy, where RootNode incorrectly caches routes. This issue results in hash flooding, leading to slower requests with… Integration Camel K 4.5.6+ Fix from $1,9502021-06-02 MEDIUM 6.5 CVE-2020-14336 A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets. This flaw allows an atta… Openshift Container Platform Mitigation only Fix from $1,6002021-06-02 MEDIUM 5.5 CVE-2020-14317 It was found that the issue for security flaw CVE-2019-3805 appeared again in a further version of JBoss Enterprise Application Platform - Continuous… Jboss Enterprise Application Platform Mitigation only Fix from $1,6002021-06-02 MEDIUM 5.5 CVE-2020-14335 A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets through the ISC DHCP of Smart-Proxy. This flaw allows… Satellite Mitigation only Fix from $1,6002021-06-02 HIGH 7.1 CVE-2020-10771 A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw… Data Grid Mitigation only Fix from $1,9502021-06-02 MEDIUM 5.3 CVE-2021-3424 A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can register himself… Single Sign On Mitigation only Fix from $1,6002021-06-01 HIGH 8.8 CVE-2021-3495 An incorrect access control flaw was found in the kiali-operator in versions before 1.33.0 and before 1.24.7. This flaw allows an attacker with a bas… Openshift Service Mesh 1.24.7 / 1.33.0+ Fix from $1,9502021-06-01 HIGH 7.3 CVE-2021-3412 It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, an… 3scale Mitigation only Fix from $1,9502021-06-01