Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2013-1820 tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service. Tuned 2.0.2+ Fix from $1,6002019-11-08 MEDIUM 5.5 CVE-2019-3866 An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world… Openstack Mistral Mitigation only Fix from $1,6002019-11-08 MEDIUM 6.5 CVE-2008-5083 In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBoss ON. Jboss Operations Network 2.1.2+ Fix from $1,6002019-11-08 HIGH 7.8 CVE-2008-3278 frysk packages through 2008-08-05 as shipped in Red Hat Enterprise Linux 5 are built with an insecure RPATH set in the ELF header of multiple binarie… Frysk after 2008-08-05 Fix from $1,9502019-11-07 MEDIUM 6.1 CVE-2016-1000037 Pagure: XSS possible in file attachment endpoint Pagure 2.3.4+ Fix from $1,6002019-11-06 MEDIUM 5.5 CVE-2014-8181 The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace. Enterprise Linux Mitigation only Fix from $1,6002019-11-06 HIGH 7.5 CVE-2010-2222 The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a denial of service (NULL pointe… Directory Server Patch available Fix from $1,9502019-11-05 MEDIUM 5.9 CVE-2013-5661 Cache Poisoning issue exists in DNS Response Rate Limiting. Enterprise Linux 1.3.0+ Fix from $1,6002019-11-05 HIGH 7.1 CVE-2013-4374 An insecurity temporary file vulnerability exists in RHQ Mongo DB Drift Server through 2013-09-25 when unpacking zipped files. Rhq Mongo Db Drift Server after 2013-09-25 Fix from $1,9502019-11-04 CRITICAL 9.8 CVE-2015-8980EPSS 7% The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code. Enterprise Linux 1.0.12+ Fix from $2,3002019-11-04 HIGH 7.8 CVE-2017-5332 The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cau… Enterprise Linux Patch available Fix from $1,9502019-11-04 HIGH 7.8 CVE-2017-5333 Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a d… Enterprise Linux Patch available Fix from $1,9502019-11-04 MEDIUM 5.5 CVE-2013-4280 Insecure temporary file vulnerability in RedHat vsdm 4.9.6. Virtual Desktop Server Manager No fix yet Fix from $1,6002019-11-04 MEDIUM 6.1 CVE-2014-3649 JBoss AeroGear has reflected XSS via the password field Jboss Aerogear after 2014-09-19 Fix from $1,6002019-11-04 MEDIUM 5.5 CVE-2013-4423 CloudForms stores user passwords in recoverable format Cloudforms Mitigation only Fix from $1,6002019-11-04 MEDIUM 5.5 CVE-2013-4518 RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates Update Infrastructure No fix yet Fix from $1,6002019-11-04 HIGH 7.5 CVE-2019-6470EPSS 9% There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in … Enterprise Linux No fix yet Fix from $1,9502019-11-01 HIGH 7.3 CVE-2013-0165 cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp. Openshift Mitigation only Fix from $1,9502019-11-01 MEDIUM 6.1 CVE-2013-0186 Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspecified ve… Cloudforms Mitigation only Fix from $1,6002019-11-01 MEDIUM 5.9 CVE-2013-2255 HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL cert… Openstack Mitigation only Fix from $1,6002019-11-01 CRITICAL 9.1 CVE-2010-2548 IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files. Icedtea6 1.7.4+ Fix from $2,3002019-10-31 CRITICAL 9.1 CVE-2010-2783 IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services. Icedtea6 1.7.4+ Fix from $2,3002019-10-31 HIGH 8.0 CVE-2010-0737 A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON u… Jboss Operations Network 2.3.1+ Fix from $1,9502019-10-30 CRITICAL 9.1 CVE-2019-17631 From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privil… Satellite after 0.16.0 Fix from $2,3002019-10-17 MEDIUM 6.8 CVE-2019-2989 Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7… Enterprise Linux Desktop after 11.50.2 Fix from $1,6002019-10-16 HIGH 7.5 CVE-2019-14832 A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authent… Keycloak 7.0.1+ Fix from $1,9502019-10-15 HIGH 7.4 CVE-2019-14823 A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly tru… Enterprise Linux after 4.6.2 Fix from $1,9502019-10-14 MEDIUM 5.5 CVE-2019-14858 A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters mar… Ansible Engine after 3.5.0 Fix from $1,6002019-10-14 MEDIUM 5.3 CVE-2019-6465 Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 … Enterprise Linux after 9.13.6 Fix from $1,6002019-10-09 HIGH 7.8 CVE-2019-14846 In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level whi… Ansible Engine 2.6.20 / 2.7.14+ Fix from $1,9502019-10-08