Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2021-20232 A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potentia… Enterprise Linux 3.7.1+ Fix from $2,3002021-03-12 MEDIUM 5.5 CVE-2020-35521 A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of servi… Enterprise Linux 4.2.0+ Fix from $1,6002021-03-09 MEDIUM 5.5 CVE-2021-20244 A flaw was found in ImageMagick in MagickCore/visual-effects.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger… Enterprise Linux 7.0.10-62+ Fix from $1,6002021-03-09 MEDIUM 5.5 CVE-2021-20245 A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined beh… Enterprise Linux 6.9.11-62 / 7.0.10-62+ Fix from $1,6002021-03-09 MEDIUM 5.5 CVE-2021-20246 A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undef… Enterprise Linux 6.9.11-62 / 7.0.10-62+ Fix from $1,6002021-03-09 MEDIUM 6.8 CVE-2021-20262 A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows an attacker to take over an … Keycloak Mitigation only Fix from $1,6002021-03-09 MEDIUM 6.7 CVE-2021-20253 A flaw was found in ansible-tower. The default installation is vulnerable to Job Isolation escape allowing an attacker to elevate the privilege from … Ansible Tower 3.6.7 / 3.7.5+ Fix from $1,6002021-03-09 MEDIUM 6.5 CVE-2020-27838EPSS 18% A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like cli… Keycloak 13.0.0+ Fix from $1,6002021-03-08 HIGH 7.8 CVE-2021-3403 In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) … Enterprise Linux No fix yet Fix from $1,9502021-03-04 HIGH 7.8 CVE-2021-3404 In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a h… Enterprise Linux No fix yet Fix from $1,9502021-03-04 HIGH 8.2 CVE-2021-20233 A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption tha… Enterprise Linux 2.06+ Fix from $1,9502021-03-03 HIGH 8.2 CVE-2020-25632 A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking … Enterprise Linux 2.06+ Fix from $1,9502021-03-03 HIGH 7.6 CVE-2020-25647 A flaw was found in grub2 in versions prior to 2.06. During USB device initialization, descriptors are read with very little bounds checking and assu… Enterprise Linux 2.06+ Fix from $1,9502021-03-03 HIGH 7.5 CVE-2020-14372 A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the ACPI command when Secure Boot is enabled. This fla… Enterprise Linux 2.06+ Fix from $1,9502021-03-03 HIGH 7.5 CVE-2020-27779 A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove … Enterprise Linux 2.06+ Fix from $1,9502021-03-03 MEDIUM 6.7 CVE-2020-27749 A flaw was found in grub2 in versions prior to 2.06. Variable names present are expanded in the supplied command line into their corresponding variab… Enterprise Linux 2.06+ Fix from $1,6002021-03-03 MEDIUM 6.7 CVE-2021-20225 A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-allocated buffer by calling… Enterprise Linux 2.06+ Fix from $1,6002021-03-03 MEDIUM 6.5 CVE-2021-20252 A flaw was found in Red Hat 3scale API Management Platform 2. The 3scale backend does not perform preventive handling on user-requested date ranges i… 3scale Api Management Mitigation only Fix from $1,6002021-02-23 MEDIUM 5.3 CVE-2021-20256 A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local attacker with view_hosts perm… Satellite Mitigation only Fix from $1,6002021-02-23 HIGH 8.8 CVE-2021-20182 A privilege escalation flaw was found in openshift4/ose-docker-builder. The build container runs with high privileges using a chrooted environment in… Openshift Container Platform 4.4.33 / 4.5.30+ Fix from $1,9502021-02-23 HIGH 7.5 CVE-2020-27782 A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings… Jboss Fuse Mitigation only Fix from $1,9502021-02-23 HIGH 8.1 CVE-2021-20198 A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installation of OpenShift Container Pl… Openshift Installer 0.9.0-master.0.20210125200451-95101da940b0+ Fix from $1,9502021-02-23 HIGH 7.3 CVE-2020-14359 A vulnerability was found in all versions of Keycloak Gatekeeper, where on using lower case HTTP headers (via cURL) an attacker can bypass our Gateke… Louketo Proxy Mitigation only Fix from $1,9502021-02-23 HIGH 7.0 CVE-2021-20188 A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not correctly checked. This flaw c… Openshift Container Platform 1.7.0+ Fix from $1,9502021-02-11 MEDIUM 6.5 CVE-2019-25014 A NULL pointer dereference was found in pkg/proxy/envoy/v2/debug.go getResourceVersion in Istio pilot before 1.5.0-alpha.0. If a particular HTTP GET … Openshift Service Mesh after 1.4.9 Fix from $1,6002021-01-29 MEDIUM 6.1 CVE-2020-1723 A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected ver… Mobile Application Platform Mitigation only Fix from $1,6002021-01-28 MEDIUM 5.4 CVE-2020-1725 A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycl… Keycloak 13.0.0+ Fix from $1,6002021-01-28 MEDIUM 5.9 CVE-2020-25657 A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the t… Virtualization Mitigation only Fix from $1,6002021-01-12 MEDIUM 5.4 CVE-2020-25680 A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The v… Jboss Core Services Httpd Mitigation only Fix from $1,6002021-01-07 MEDIUM 5.5 CVE-2020-35507 There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit… Enterprise Linux 2.34+ Fix from $1,6002021-01-04