Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2019-3891 It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin da… Satellite No fix yet Fix from $1,9502019-04-15 HIGH 8.0 CVE-2019-3845 A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite… Satellite 6.2+ Fix from $1,9502019-04-11 HIGH 7.0 CVE-2019-3842 In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is p… Enterprise Linux after 241 Fix from $1,9502019-04-09 HIGH 7.5 CVE-2017-3139 A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly w… Enterprise Linux Server Aus Mitigation only Fix from $1,9502019-04-09 MEDIUM 6.5 CVE-2019-0757 A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package'… Enterprise Linux Patch available Fix from $1,6002019-04-09 MEDIUM 6.5 CVE-2019-10876 An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with sep… Openstack 11.0.7 / 12.0.6+ Fix from $1,6002019-04-05 MEDIUM 5.4 CVE-2019-3886 An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest a… Libvirt 5.3.0+ Fix from $1,6002019-04-04 MEDIUM 6.3 CVE-2019-3876 A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X… Openshift Container Platform after 3.11 Fix from $1,6002019-04-01 HIGH 7.2 CVE-2019-3869 When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A mal… Ansible Tower 3.3.5 / 3.4.3+ Fix from $1,9502019-03-28 MEDIUM 6.3 CVE-2019-3840 A NULL pointer dereference flaw was discovered in libvirt before version 5.0.0 in the way it gets interface information through the QEMU agent. An at… Libvirt 5.0.0+ Fix from $1,6002019-03-27 MEDIUM 5.4 CVE-2018-10934 A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can c… Jboss Enterprise Application Platform Mitigation only Fix from $1,6002019-03-27 HIGH 7.8 CVE-2019-3830 A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data t… Openstack after 2015.1.4 Fix from $1,9502019-03-26 HIGH 7.5 CVE-2018-16856 In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.… Openstack 2.0.2-5 / 3.0.1-0.20181009115732+ Fix from $1,9502019-03-26 HIGH 8.1 CVE-2019-3879 It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission … Virtualization 4.3.2.1+ Fix from $1,9502019-03-25 MEDIUM 5.5 CVE-2019-3835 It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file cou… Ansible Tower No fix yet Fix from $1,6002019-03-25 MEDIUM 5.5 CVE-2019-3838 It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript … Ansible Tower Patch available Fix from $1,6002019-03-25 HIGH 8.8 CVE-2017-7510 In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface. Ovirt Engine Mitigation only Fix from $1,9502019-03-25 MEDIUM 6.7 CVE-2019-3831 A vulnerability was discovered in vdsm, version 4.19 through 4.30.3 and 4.30.5 through 4.30.8. The systemd_run function exposed to the vdsm system us… Gluster Storage after 4.30.8 Fix from $1,6002019-03-25 MEDIUM 5.4 CVE-2018-16838 A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the ser… Enterprise Linux Mitigation only Fix from $1,6002019-03-25 HIGH 7.5 CVE-2019-3816EPSS 15% Openwsman, versions up to and including 2.6.9, are vulnerable to arbitrary file disclosure because the working directory of openwsmand daemon was set… Enterprise Linux Mitigation only Fix from $1,9502019-03-14 MEDIUM 6.5 CVE-2019-9735 An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 1… Openstack 10.0.8 / 11.0.7+ Fix from $1,6002019-03-13 CRITICAL 9.8 CVE-2018-12547 In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects exis… Satellite 0.12.0+ Fix from $2,3002019-02-11 CRITICAL 9.8 CVE-2018-12549 In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when acceleratin… Satellite Mitigation only Fix from $2,3002019-02-11 MEDIUM 5.5 CVE-2019-7664 In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check. Crafted elf in… Enterprise Linux No fix yet Fix from $1,6002019-02-09 MEDIUM 5.9 CVE-2019-7628 Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for man-in-the-middle attackers to … Pagure Patch available Fix from $1,6002019-02-08 HIGH 7.5 CVE-2019-3818 The kube-rbac-proxy container before version 0.4.1 as used in Red Hat OpenShift Container Platform does not honor TLS configurations, allowing for us… Openshift Container Platform 0.4.1+ Fix from $1,9502019-02-05 HIGH 7.5 CVE-2019-3813 Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a deni… Enterprise Linux Desktop Mitigation only Fix from $1,9502019-02-04 HIGH 7.5 CVE-2018-16889 Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files … Ceph after 13.2.4 Fix from $1,9502019-01-28 HIGH 7.5 CVE-2018-16881 A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket,… Virtualization Manager Patch available Fix from $1,9502019-01-25 HIGH 7.2 CVE-2018-14666 An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered… Satellite after 6.4 Fix from $1,9502019-01-22