Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.9 CVE-2014-0245 It was found that the implementation of the GTNSubjectCreatingInterceptor class in gatein-wsrp was not thread safe. For a specific WSRP endpoint, und… Jboss Portal Mitigation only Fix from $1,6002020-01-02 MEDIUM 6.5 CVE-2014-0169 In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could all… Jboss Enterprise Application Platform Mitigation only Fix from $1,6002020-01-02 MEDIUM 6.3 CVE-2019-10205 A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay … Quay Mitigation only Fix from $1,6002020-01-02 MEDIUM 6.5 CVE-2019-14864 Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True w… Ansible 2.7.15 / 2.8.7+ Fix from $1,6002020-01-02 MEDIUM 6.1 CVE-2019-14862 There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers… Decision Manager after 3.4.2 Fix from $1,6002020-01-02 MEDIUM 6.1 CVE-2019-14863 There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application de… Decision Manager after 1.4.14 Fix from $1,6002020-01-02 CRITICAL 9.8 CVE-2019-10158 A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session inte… Jboss Data Grid after 9.4.14 Fix from $2,3002020-01-02 CRITICAL 9.1 CVE-2019-14859 A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this ver… Ceph Storage 0.13.3+ Fix from $2,3002020-01-02 HIGH 7.5 CVE-2013-0264 An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary … Mrg Management Console Patch available Fix from $1,9502019-12-30 MEDIUM 6.5 CVE-2013-0196 A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection me… Openshift No fix yet Fix from $1,6002019-12-30 MEDIUM 5.5 CVE-2012-5474 The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2… Openstack 2012.1.1+ Fix from $1,6002019-12-30 MEDIUM 6.5 CVE-2019-19337 A flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An authenticated attacker can abuse … Ceph Storage Mitigation only Fix from $1,6002019-12-23 HIGH 7.8 CVE-2019-18389 A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS use… Enterprise Linux after 0.8.0 Fix from $1,9502019-12-23 HIGH 7.1 CVE-2019-18390 An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a den… Enterprise Linux after 0.8.0 Fix from $1,9502019-12-23 MEDIUM 5.5 CVE-2019-18391 A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS use… Enterprise Linux after 0.8.0 Fix from $1,6002019-12-23 MEDIUM 6.1 CVE-2016-1000229 swagger-ui has XSS in key names Jboss Fuse Mitigation only Fix from $1,6002019-12-20 MEDIUM 5.5 CVE-2019-19341 A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' are left world-readable. These files include both … Ansible Tower 3.6.2+ Fix from $1,6002019-12-19 MEDIUM 5.3 CVE-2019-19342 A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and the password contains the '#'… Ansible Tower 3.5.4 / 3.6.2+ Fix from $1,6002019-12-19 HIGH 8.2 CVE-2019-19340 A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e rabbitm… Ansible Tower 3.5.3 / 3.6.2+ Fix from $1,9502019-12-19 HIGH 7.8 CVE-2012-2312 An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat … Jboss Application Server Mitigation only Fix from $1,9502019-12-18 CRITICAL 9.8 CVE-2014-3699 eDeploy has RCE via cPickle deserialization of untrusted data Edeploy No fix yet Fix from $2,3002019-12-15 HIGH 8.1 CVE-2014-3701 eDeploy has tmp file race condition flaws Edeploy No fix yet Fix from $1,9502019-12-15 MEDIUM 6.1 CVE-2014-3652 JBoss KeyCloak: Open redirect vulnerability via failure to validate the redirect URL. Keycloak Patch available Fix from $1,6002019-12-15 MEDIUM 5.5 CVE-2014-3536 CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration Cloudforms Management Engine Mitigation only Fix from $1,6002019-12-15 MEDIUM 5.5 CVE-2014-0241 rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable Satellite Mitigation only Fix from $1,6002019-12-13 CRITICAL 9.8 CVE-2014-0175 mcollective has a default password set at install Openshift Mitigation only Fix from $2,3002019-12-13 HIGH 8.8 CVE-2014-0197 CFME: CSRF protection vulnerability via permissive check of the referrer header Cloudforms after 5.9.3.1 Fix from $1,9502019-12-13 MEDIUM 6.5 CVE-2019-16775 Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of… Enterprise Linux 6.13.3+ Fix from $1,6002019-12-13 MEDIUM 5.4 CVE-2019-14849 A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to … 3scale 2.6+ Fix from $1,6002019-12-12 HIGH 8.8 CVE-2014-0163 Openshift has shell command injection flaws due to unsanitized data being passed into shell commands. Openshift Mitigation only Fix from $1,9502019-12-11