Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2018-6104 Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoo… Linux Desktop 66.0.3359.117+ Fix from $1,6002018-12-04 MEDIUM 6.5 CVE-2018-6105 Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing v… Linux Desktop 66.0.3359.117+ Fix from $1,6002018-12-04 MEDIUM 6.5 CVE-2018-6107 Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoo… Linux Desktop 66.0.3359.117+ Fix from $1,6002018-12-04 MEDIUM 6.5 CVE-2018-6108 Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoo… Linux Desktop 66.0.3359.117+ Fix from $1,6002018-12-04 HIGH 7.8 CVE-2018-16863 It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSA… Enterprise Linux Desktop Patch available Fix from $1,9502018-12-03 HIGH 8.1 CVE-2018-14637 The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit th… Keycloak 4.6.0+ Fix from $1,9502018-11-30 CRITICAL 9.8 CVE-2018-15981EPSS 12% Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution. Enterprise Linux Desktop after 31.0.0.148 Fix from $2,3002018-11-29 HIGH 7.5 CVE-2018-15978EPSS 7% Flash Player versions 31.0.0.122 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. Enterprise Linux Desktop after 31.0.0.122 Fix from $1,9502018-11-29 HIGH 8.1 CVE-2018-14657 A flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force detection algorithm will not … Keycloak Mitigation only Fix from $1,9502018-11-13 MEDIUM 6.1 CVE-2018-14658 A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.Red… Keycloak Mitigation only Fix from $1,6002018-11-13 MEDIUM 5.4 CVE-2018-14655 A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible to inject arbitrary Javascrip… Keycloak Mitigation only Fix from $1,6002018-11-13 HIGH 7.8 CVE-2018-19214 Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for insufficient input. Enterprise Linux Patch available Fix from $1,9502018-11-12 HIGH 7.8 CVE-2018-19215 Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for the special cases of the % and $ and !… Enterprise Linux No fix yet Fix from $1,9502018-11-12 MEDIUM 6.5 CVE-2018-19208 In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a d… Enterprise Linux No fix yet Fix from $1,6002018-11-12 MEDIUM 5.5 CVE-2018-19139 An issue has been found in JasPer 2.0.14. There is a memory leak in jas_malloc.c when called from jpc_unk_getparms in jpc_cs.c. Fedora No fix yet Fix from $1,6002018-11-09 CRITICAL 9.8 CVE-2018-14667 KEVEPSS 74% The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticate… Richfaces after 3.3.4 Fix from $2,3002018-11-06 HIGH 7.5 CVE-2018-16849 A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbit… Openstack Mistral 7.0.1+ Fix from $1,9502018-11-02 MEDIUM 6.5 CVE-2018-14660 A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated… Virtualization Host after 4.1.4 Fix from $1,6002018-11-01 MEDIUM 6.5 CVE-2016-2125EPSS 9% It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to wh… Gluster Storage 4.3.13 / 4.4.8+ Fix from $1,6002018-10-31 HIGH 8.8 CVE-2018-14653 The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the '__server_getspec' function via the 'gf_… Gluster Storage after 4.1.4 Fix from $1,9502018-10-31 MEDIUM 6.5 CVE-2018-14652 The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' translator via the code handling t… Gluster Storage after 4.1.8 Fix from $1,6002018-10-31 MEDIUM 6.5 CVE-2018-14654 The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attacker with access to mount volum… Gluster Storage after 4.1.4 Fix from $1,6002018-10-31 MEDIUM 6.5 CVE-2018-14659 The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_XATTR_IOSTATS_DUMP_KEY' xattr… Gluster File System after 4.1.4 Fix from $1,6002018-10-31 HIGH 8.8 CVE-2016-5402EPSS 6% A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with acces… Cloudforms Mitigation only Fix from $1,9502018-10-31 MEDIUM 5.5 CVE-2016-2121 A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitive informat… Openstack Mitigation only Fix from $1,6002018-10-31 MEDIUM 5.4 CVE-2016-6343 JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that have privileges to access da… Jboss Bpm Suite 6.4.2+ Fix from $1,6002018-10-31 MEDIUM 6.6 CVE-2018-14665EPSS 27% A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server al… Enterprise Linux Desktop Patch available Fix from $1,6002018-10-25 HIGH 7.8 CVE-2016-10729 An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binar… Enterprise Linux No fix yet Fix from $1,9502018-10-24 HIGH 7.8 CVE-2016-10730 An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Applicatio… Enterprise Linux No fix yet Fix from $1,9502018-10-24 HIGH 7.8 CVE-2018-16837 Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases c… Ansible Engine Mitigation only Fix from $1,9502018-10-23