Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2018-10865 It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated use… Certification Mitigation only Fix from $1,9502021-05-26 HIGH 7.5 CVE-2018-10868 redhat-certification 7 does not properly restrict the number of recursive definitions of entities in XML documents, allowing an unauthenticated user … Certification Mitigation only Fix from $1,9502021-05-26 MEDIUM 5.5 CVE-2021-20178 A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using… Ansible 2.9.18+ Fix from $1,6002021-05-26 HIGH 8.8 CVE-2019-14836 A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to… 3scale Mitigation only Fix from $1,9502021-05-26 MEDIUM 6.5 CVE-2021-3559 A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with a PCI device and driver that… Libvirt 7.0.0+ Fix from $1,6002021-05-24 CRITICAL 9.8 CVE-2018-25011 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16(). Enterprise Linux 1.0.1+ Fix from $2,3002021-05-21 CRITICAL 9.8 CVE-2018-25014 A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol(). Enterprise Linux 1.0.1+ Fix from $2,3002021-05-21 CRITICAL 9.8 CVE-2020-36328 A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check … Enterprise Linux 1.0.1+ Fix from $2,3002021-05-21 CRITICAL 9.8 CVE-2020-36329 A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this… Enterprise Linux 1.0.1 / 14.7+ Fix from $2,3002021-05-21 CRITICAL 9.1 CVE-2018-25009 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16(). Enterprise Linux 1.0.1+ Fix from $2,3002021-05-21 CRITICAL 9.1 CVE-2018-25010 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter(). Enterprise Linux 1.0.1+ Fix from $2,3002021-05-21 CRITICAL 9.1 CVE-2018-25012 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24(). Enterprise Linux 1.0.1+ Fix from $2,3002021-05-21 CRITICAL 9.1 CVE-2018-25013 A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes(). Enterprise Linux 1.0.1+ Fix from $2,3002021-05-21 CRITICAL 9.1 CVE-2020-36331 A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulne… Enterprise Linux 1.0.1 / 14.7+ Fix from $2,3002021-05-21 HIGH 7.5 CVE-2020-36332 A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from th… Enterprise Linux 1.0.1+ Fix from $1,9502021-05-21 HIGH 8.6 CVE-2021-3517EPSS 8% There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be… Jboss Core Services 2.9.11+ Fix from $1,9502021-05-19 MEDIUM 5.5 CVE-2021-3421 A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiab… Enterprise Linux 4.16.1.3+ Fix from $1,6002021-05-19 MEDIUM 5.3 CVE-2021-3531 A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift URL that ends with two slashes… Ceph 14.2.21+ Fix from $1,6002021-05-18 MEDIUM 6.5 CVE-2021-3524 A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection … Ceph 14.2.21+ Fix from $1,6002021-05-17 HIGH 7.1 CVE-2020-27833 A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by using a specially crafted raw c… Openshift Container Platform after 4.7 Fix from $1,9502021-05-14 MEDIUM 5.9 CVE-2021-3537 A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL der… Jboss Core Services 2.9.11+ Fix from $1,6002021-05-14 MEDIUM 6.0 CVE-2021-20221 An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt Controller emulator of QEMU up to and including qemu 4.2.0on aarch64… Enterprise Linux after 4.2.0 Fix from $1,6002021-05-13 HIGH 8.8 CVE-2021-3528 A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator and the noobaa core are leake… Noobaa Operator 5.7.0+ Fix from $1,9502021-05-13 MEDIUM 5.5 CVE-2020-27824 A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input t… Enterprise Linux 2.4.0+ Fix from $1,6002021-05-13 HIGH 7.3 CVE-2021-20202 A flaw was found in keycloak. Directories can be created prior to the Java process creating them in the temporary directory, but with wider user perm… Keycloak 13.0.0+ Fix from $1,9502021-05-12 MEDIUM 5.4 CVE-2021-3504 A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the hivex_open function. An attack… Hivex 1.3.20+ Fix from $1,6002021-05-11 HIGH 7.5 CVE-2021-31918 A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update a… Openstack Mitigation only Fix from $1,9502021-05-06 HIGH 7.5 CVE-2021-20228 A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using th… Ansible Engine Patch available Fix from $1,9502021-04-29 MEDIUM 6.1 CVE-2021-20208 A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credent… Enterprise Linux 6.13+ Fix from $1,6002021-04-19 MEDIUM 5.5 CVE-2021-3505 A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG … Enterprise Linux 0.8.0+ Fix from $1,6002021-04-19