Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2012-1094 JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched… Jboss Application Server 7.1.1+ Fix from $1,9502020-03-10 HIGH 7.8 CVE-2020-1737 A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as t… Ansible Engine 2.7.17 / 2.8.9+ Fix from $1,9502020-03-09 HIGH 7.0 CVE-2020-1706 It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, multiple containers modify th… Openshift Container Platform Mitigation only Fix from $1,9502020-03-09 MEDIUM 6.5 CVE-2019-14886 A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context… Decision Manager Mitigation only Fix from $1,6002020-03-05 HIGH 7.5 CVE-2020-8659 CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e. 1 byte) chunks. Openshift Service Mesh after 1.13.0 Fix from $1,9502020-03-04 HIGH 7.5 CVE-2020-8661 CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests. Openshift Service Mesh after 1.13.0 Fix from $1,9502020-03-04 HIGH 7.4 CVE-2020-1734 A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=… Ansible Engine after 3.3.4 Fix from $1,9502020-03-03 CRITICAL 9.8 CVE-2020-1731 A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password… Keycloak Operator 8.0.2+ Fix from $2,3002020-03-02 CRITICAL 9.8 CVE-2019-14892EPSS 6% A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a mal… Decision Manager 2.6.7.3 / 2.8.11.5+ Fix from $2,3002020-03-02 HIGH 7.5 CVE-2015-5201 VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as pack… Enterprise Virtualization 3.5.6 / 6-6.7-20151117.0+ Fix from $1,9502020-02-25 CRITICAL 9.8 CVE-2014-4657 The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code vi… Ansible 1.5.4+ Fix from $2,3002020-02-20 MEDIUM 5.5 CVE-2014-4658 The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtai… Ansible 1.5.5+ Fix from $1,6002020-02-20 MEDIUM 5.5 CVE-2014-4659 Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunisti… Ansible 1.5.5+ Fix from $1,6002020-02-20 CRITICAL 9.8 CVE-2014-4678EPSS 5% The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code vi… Ansible 1.6.4+ Fix from $2,3002020-02-20 MEDIUM 5.5 CVE-2014-4660 Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local user… Ansible 1.5.5+ Fix from $1,6002020-02-20 HIGH 7.5 CVE-2012-6685 Nokogiri before 1.5.4 is vulnerable to XXE attacks Cloudforms Management Engine 1.5.4+ Fix from $1,9502020-02-19 CRITICAL 9.8 CVE-2014-4966 Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which … Ansible 1.6.7+ Fix from $2,3002020-02-18 CRITICAL 9.8 CVE-2014-4967 Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansib… Ansible 1.6.7+ Fix from $2,3002020-02-18 CRITICAL 9.8 CVE-2014-8089 SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows … Enterprise Linux 1.12.9 / 2.2.8+ Fix from $2,3002020-02-17 CRITICAL 9.8 CVE-2020-1693 A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An unauthenticated … Spacewalk 2.9+ Fix from $2,3002020-02-17 HIGH 7.8 CVE-2020-1704 An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1.0.8 in the opens… Openshift Service Mesh 1.0.8+ Fix from $1,9502020-02-17 HIGH 8.8 CVE-2020-3757EPSS 10% Adobe Flash Player versions 32.0.0.321 and earlier, 32.0.0.314 and earlier, 32.0.0.321 and earlier, and 32.0.0.255 and earlier have a type confusion … Enterprise Linux Desktop 32.0.0.314 / 32.0.0.321+ Fix from $1,9502020-02-13 HIGH 7.3 CVE-2020-8595 Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact… Openshift Service Mesh after 1.4.3 Fix from $1,9502020-02-12 CRITICAL 9.8 CVE-2014-0234 The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows re… Openshift 2.1+ Fix from $2,3002020-02-12 MEDIUM 5.9 CVE-2020-1726 A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted … Openshift Container Platform Patch available Fix from $1,6002020-02-11 MEDIUM 6.0 CVE-2020-1711 An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming f… Openstack 4.2.1+ Fix from $1,6002020-02-11 HIGH 8.8 CVE-2013-4535 The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm imag… Virtualization 1.7.2+ Fix from $1,9502020-02-11 MEDIUM 5.4 CVE-2020-1697 It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated pro… Keycloak 9.0.0+ Fix from $1,6002020-02-10 HIGH 8.8 CVE-2012-4512EPSS 12% The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read mem… Enterprise Linux No fix yet Fix from $1,9502020-02-08 HIGH 7.0 CVE-2020-1708 It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers mod… Openshift Container Platform Mitigation only Fix from $1,9502020-02-07