Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2020-35497 A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal information, including name, email an… Virtualization after 4.4.3 Fix from $1,6002020-12-21 HIGH 7.1 CVE-2020-27781 User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open S… Ceph 14.2.16 / 15.2.8+ Fix from $1,9502020-12-18 MEDIUM 5.3 CVE-2020-10770EPSS 70% A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_u… Keycloak 12.0.2+ Fix from $1,6002020-12-15 HIGH 7.8 CVE-2020-25712 A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The … Enterprise Linux 1.20.10+ Fix from $1,9502020-12-15 HIGH 7.8 CVE-2020-17159 Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability Language Support For Java Patch available Fix from $1,9502020-12-10 HIGH 7.5 CVE-2020-25692 A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An unauthenticated atta… Enterprise Linux 2.4.55+ Fix from $1,9502020-12-08 MEDIUM 5.9 CVE-2020-27822 A flaw was found in Wildfly affecting versions 19.0.0.Final, 19.1.0.Final, 20.0.0.Final, 20.0.1.Final, and 21.0.0.Final. When an application uses the… Wildfly Mitigation only Fix from $1,6002020-12-08 MEDIUM 5.5 CVE-2020-25677 A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any use… Ceph Storage Patch available Fix from $1,6002020-12-08 HIGH 7.5 CVE-2020-29573 sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on x86 targets has a stack-based buffer overflow if the input to any of… Enterprise Linux 2.23+ Fix from $1,9502020-12-06 HIGH 7.5 CVE-2020-27778 A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious… Enterprise Linux 0.76.0+ Fix from $1,9502020-12-03 MEDIUM 6.1 CVE-2020-27783 A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behavi… Software Collections 4.6.2+ Fix from $1,6002020-12-03 HIGH 8.8 CVE-2020-14339 A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privi… Libvirt 6.7.0+ Fix from $1,9502020-12-03 MEDIUM 6.5 CVE-2020-25711 A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When … Data Grid 11.0.6+ Fix from $1,6002020-12-03 MEDIUM 6.3 CVE-2020-14369 This release fixes a Cross Site Request Forgery vulnerability was found in Red Hat CloudForms which forces end users to execute unwanted actions on a… Cloudforms after 5.11 Fix from $1,6002020-12-02 MEDIUM 6.5 CVE-2020-14383 A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC server, which also serves prot… Enterprise Linux 4.11.15 / 4.12.9+ Fix from $1,6002020-12-02 HIGH 7.5 CVE-2020-25708 A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this flaw to send a specially crafted message that, wh… Enterprise Linux Patch available Fix from $1,9502020-11-27 MEDIUM 5.3 CVE-2020-25640 A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inser… Wildfly 21.0.0+ Fix from $1,6002020-11-24 MEDIUM 5.5 CVE-2020-10762 An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes … Gluster Block 0.5.1+ Fix from $1,6002020-11-24 MEDIUM 5.5 CVE-2020-10763 An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access t… Gluster Storage 10.1.0+ Fix from $1,6002020-11-24 HIGH 8.8 CVE-2020-25660 A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly a… Ceph 14.2.14 / 15.2.6+ Fix from $1,9502020-11-23 HIGH 8.1 CVE-2020-14389 It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, … Keycloak 12.0.0+ Fix from $1,9502020-11-17 MEDIUM 5.9 CVE-2020-25658 It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt part… Openstack Platform 4.7+ Fix from $1,6002020-11-12 HIGH 7.5 CVE-2020-14366 A vulnerability was found in keycloak, where path traversal using URL-encoded path segments in the request is possible because the resources endpoint… Keycloak 12.0.0+ Fix from $1,9502020-11-09 MEDIUM 6.5 CVE-2020-25655 An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created f… Advanced Cluster Management For Kubernetes Mitigation only Fix from $1,6002020-11-09 HIGH 8.8 CVE-2020-25661 A Red Hat only CVE-2020-12351 regression issue was found in the way the Linux kernel's Bluetooth implementation handled L2CAP packets with A2MP CID. … Enterprise Linux Mitigation only Fix from $1,9502020-11-05 MEDIUM 6.5 CVE-2020-25662 A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of s… Enterprise Linux Mitigation only Fix from $1,6002020-11-05 MEDIUM 6.5 CVE-2020-25689 A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connec… Wildfly after 21.0.0 Fix from $1,6002020-11-02 HIGH 7.8 CVE-2020-10721 A flaw was found in the fabric8-maven-plugin 4.0.0 and later. When using a wildfly-swarm or thorntail custom configuration, a malicious YAML configur… Fabric8 Maven after 4.4.1 Fix from $1,9502020-10-22 HIGH 7.5 CVE-2020-25648 A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages,… Enterprise Linux 3.58 / 9.2.6.0+ Fix from $1,9502020-10-20 MEDIUM 6.5 CVE-2020-14299 A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox Secur… Jboss Enterprise Application Platform 5.0.3+ Fix from $1,6002020-10-16