Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2018-15982 KEVEPSS 82% Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to a… Enterprise Linux Desktop after 31.0.0.153 Fix from $1,9502019-01-18 HIGH 7.5 CVE-2018-5740EPSS 60% "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potenti… Enterprise Linux Desktop 9.8.8 / 9.9.13+ Fix from $1,9502019-01-16 HIGH 7.5 CVE-2017-3137EPSS 9% Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a sit… Enterprise Linux Desktop Mitigation only Fix from $1,9502019-01-16 HIGH 7.5 CVE-2017-3144EPSS 73% A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors availabl… Enterprise Linux Desktop Mitigation only Fix from $1,9502019-01-16 HIGH 7.5 CVE-2017-3145EPSS 28% BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trig… Enterprise Linux Desktop after 9.11.2 Fix from $1,9502019-01-16 HIGH 7.5 CVE-2018-5733EPSS 20% A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit ref… Enterprise Linux Desktop after 4.3.6 Fix from $1,9502019-01-16 MEDIUM 5.9 CVE-2017-3135EPSS 17% Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to eithe… Enterprise Linux Desktop Mitigation only Fix from $1,6002019-01-16 MEDIUM 5.9 CVE-2017-3136EPSS 11% A query with a specific set of characteristics could cause a server using DNS64 to encounter an assertion failure and terminate. An attacker could de… Enterprise Linux Desktop after 9.10.4 Fix from $1,6002019-01-16 MEDIUM 5.9 CVE-2017-3143EPSS 18% An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and s… Enterprise Linux Desktop after 9.11.1 Fix from $1,6002019-01-16 MEDIUM 5.7 CVE-2018-14662 It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph d… Ceph 13.2.4+ Fix from $1,6002019-01-15 MEDIUM 6.5 CVE-2018-16846 It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices. Ceph 13.2.4+ Fix from $1,6002019-01-15 HIGH 8.1 CVE-2018-16886 etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is… Enterprise Linux Desktop 3.2.26 / 3.3.11+ Fix from $1,9502019-01-14 MEDIUM 5.4 CVE-2018-16887 A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/edit organizations and locati… Satellite 3.9.0+ Fix from $1,6002019-01-13 HIGH 7.8 CVE-2018-16865 An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when m… Enterprise Linux Desktop Patch available Fix from $1,9502019-01-11 HIGH 7.8 CVE-2018-16864 An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a… Enterprise Linux Desktop Patch available Fix from $1,9502019-01-11 CRITICAL 9.8 CVE-2017-1002157 modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution. Modulemd after 1.3.1 Fix from $2,3002019-01-10 MEDIUM 6.1 CVE-2017-1002152 Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles. Bodhi after 2.9.0 Fix from $1,6002019-01-10 HIGH 8.8 CVE-2019-0542 A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerabi… Openshift Container Platform 3.9.99 / 3.10.163+ Fix from $1,9502019-01-09 MEDIUM 5.3 CVE-2018-16876 ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of … Ansible 2.5.14 / 2.6.11+ Fix from $1,6002019-01-03 CRITICAL 9.8 CVE-2018-16879 Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging cel… Ansible Tower 3.3.3+ Fix from $2,3002019-01-03 HIGH 8.8 CVE-2018-5802 An error within the "kodak_radc_load_raw()" function (internal/dcraw_common.cpp) related to the "buf" variable in LibRaw versions prior to 0.18.7 can… Enterprise Linux Desktop 0.18.7+ Fix from $1,9502018-12-07 HIGH 8.8 CVE-2018-5805 A boundary error within the "quicktake_100_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to ca… Enterprise Linux Desktop 0.18.8+ Fix from $1,9502018-12-07 MEDIUM 6.5 CVE-2018-5800 An off-by-one error within the "LibRaw::kodak_ycbcr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.7 can be exploi… Enterprise Linux Desktop 0.18.7+ Fix from $1,6002018-12-07 MEDIUM 6.5 CVE-2018-5801 An error within the "LibRaw::unpack()" function (src/libraw_cxx.cpp) in LibRaw versions prior to 0.18.7 can be exploited to trigger a NULL pointer de… Enterprise Linux Desktop 0.18.7+ Fix from $1,6002018-12-07 MEDIUM 6.5 CVE-2018-5806 An error within the "leaf_hdr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a NULL … Enterprise Linux Desktop 0.18.8+ Fix from $1,6002018-12-07 HIGH 7.5 CVE-2018-6101 A lack of host validation in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML … Linux Desktop 66.0.3359.117+ Fix from $1,9502018-12-04 MEDIUM 6.5 CVE-2018-6095 Inappropriate dismissal of file picker on keyboard events in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to read local fi… Linux Desktop 66.0.3359.117+ Fix from $1,6002018-12-04 MEDIUM 6.5 CVE-2018-6098 Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoo… Linux Desktop 66.0.3359.117+ Fix from $1,6002018-12-04 MEDIUM 6.5 CVE-2018-6099 A lack of CORS checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML… Linux Desktop 66.0.3359.117+ Fix from $1,6002018-12-04 MEDIUM 6.5 CVE-2018-6103 A stagnant permission prompt in Prompts in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass permission policy via a crafted H… Linux Desktop 66.0.3359.117+ Fix from $1,6002018-12-04