Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2018-11307EPSS 6% An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows… Openshift Container Platform 2.6.7.3 / 2.7.9.4+ Fix from $2,3002019-07-09 HIGH 7.8 CVE-2019-13314 virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password… Virt Bootstrap No fix yet Fix from $1,9502019-07-05 CRITICAL 9.8 CVE-2019-10137 A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthen… Satellite after 2.9 Fix from $2,3002019-07-02 MEDIUM 6.5 CVE-2019-10177 A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user input is no… Cloudforms Management Engine Mitigation only Fix from $1,6002019-06-27 HIGH 7.8 CVE-2012-6711 A heap-based buffer overflow exists in GNU Bash before 4.3 when wide characters, not supported by the current locale set in the LC_CTYPE environment … Enterprise Linux after 4.3 Fix from $1,9502019-06-18 HIGH 8.8 CVE-2019-7845EPSS 6% Adobe Flash Player versions 32.0.0.192 and earlier, 32.0.0.192 and earlier, and 32.0.0.192 and earlier have an use after free vulnerability. Successf… Enterprise Linux Desktop after 32.0.0.192 Fix from $1,9502019-06-12 CRITICAL 9.8 CVE-2019-3888 A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connector… Undertow 2.0.21+ Fix from $2,3002019-06-12 CRITICAL 9.0 CVE-2019-3873 It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An att… Jboss Enterprise Application Platform Mitigation only Fix from $2,3002019-06-12 MEDIUM 5.4 CVE-2019-3872 It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. … Jboss Enterprise Application Platform Mitigation only Fix from $1,6002019-06-12 MEDIUM 5.9 CVE-2019-10150 It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during… Openshift Container Platform after 4.1 Fix from $1,6002019-06-12 MEDIUM 5.5 CVE-2019-10157 It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel l… Keycloak 4.8.3 / 7.3.2+ Fix from $1,6002019-06-12 MEDIUM 5.3 CVE-2017-15123 A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users onl… Cloudforms Management Engine after 5.10 Fix from $1,6002019-06-12 HIGH 7.0 CVE-2019-9755 An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafte… Enterprise Linux Mitigation only Fix from $1,9502019-06-05 HIGH 8.0 CVE-2019-3895 An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker c… Openstack 0.9.0+ Fix from $1,9502019-06-03 HIGH 7.7 CVE-2019-10144 rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are given all capab… Rkt after 1.30.0 Fix from $1,9502019-06-03 HIGH 7.7 CVE-2019-10145 rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` do not have seccomp… Rkt after 1.30.0 Fix from $1,9502019-06-03 HIGH 7.7 CVE-2019-10147 rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are not limited by … Rkt after 1.30.0 Fix from $1,9502019-06-03 HIGH 8.8 CVE-2019-7837EPSS 10% Adobe Flash Player versions 32.0.0.171 and earlier, 32.0.0.171 and earlier, and 32.0.0.171 and earlier have a use after free vulnerability. Successfu… Enterprise Linux Desktop after 32.0.0.171 Fix from $1,9502019-05-22 HIGH 8.8 CVE-2019-10132 A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configurati… Libvirt after 4.1.0 Fix from $1,9502019-05-22 HIGH 7.5 CVE-2019-0820EPSS 6% A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial… Enterprise Linux Patch available Fix from $1,9502019-05-16 CRITICAL 9.8 CVE-2016-7043 It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any… Kie Server 7.21.0+ Fix from $2,3002019-05-15 HIGH 8.8 CVE-2019-3894 It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread … Wildfly after 16.0.0 Fix from $1,9502019-05-03 HIGH 7.1 CVE-2019-10131 An off-by-one read vulnerability was discovered in ImageMagick before version 7.0.7-28 in the formatIPTCfromBuffer function in coders/meta.c. A local… Enterprise Linux 6.9.9-40 / 7.0.7-28+ Fix from $1,9502019-04-30 HIGH 8.3 CVE-2019-9900 When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers c… Openshift Service Mesh after 1.9.0 Fix from $1,9502019-04-25 HIGH 8.1 CVE-2019-2698EPSS 12% Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Diffi… Openshift Container Platform Patch available Fix from $1,9502019-04-23 MEDIUM 5.9 CVE-2019-2684EPSS 38% Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u2… Openshift Container Platform Patch available Fix from $1,6002019-04-23 HIGH 7.5 CVE-2019-2602 Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java S… Openshift Container Platform Patch available Fix from $1,9502019-04-23 CRITICAL 9.8 CVE-2019-3899 It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This i… Openshift Container Platform Mitigation only Fix from $2,3002019-04-22 HIGH 7.5 CVE-2019-10245 In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causi… Satellite 0.14.0+ Fix from $1,9502019-04-19 HIGH 7.5 CVE-2016-10746 libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was … Libvirt 1.3.1+ Fix from $1,9502019-04-18