Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2018-12827EPSS 32% Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. Enterprise Linux Desktop after 30.0.0.154 Fix from $1,9502018-08-29 MEDIUM 5.9 CVE-2018-12824EPSS 11% Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. Enterprise Linux Desktop after 30.0.0.154 Fix from $1,6002018-08-29 MEDIUM 6.5 CVE-2017-15419 Insufficient policy enforcement in Resource Timing API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to infer browsing history by … Enterprise Linux Desktop 63.0.3239.84+ Fix from $1,6002018-08-28 MEDIUM 6.5 CVE-2017-15416 Heap buffer overflow in Blob API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafte… Enterprise Linux Desktop 63.0.3239.84+ Fix from $1,6002018-08-28 HIGH 8.8 CVE-2017-15413 Type confusion in WebAssembly in V8 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a cra… Enterprise Linux Desktop 63.0.3239.84+ Fix from $1,9502018-08-28 HIGH 8.8 CVE-2017-15412 Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potentially e… Enterprise Linux Desktop 2.9.5 / 63.0.3239.84+ Fix from $1,9502018-08-28 HIGH 7.5 CVE-2017-15139 A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configura… Openstack after 12.0.4-7 Fix from $1,9502018-08-27 MEDIUM 6.5 CVE-2017-2635 A NULL pointer deference flaw was found in the way libvirt from 2.5.0 to 3.0.0 handled empty drives. A remote authenticated attacker could use this f… Libvirt after 3.0.0 Fix from $1,6002018-08-22 HIGH 8.2 CVE-2017-2627 A flaw was found in openstack-tripleo-common as shipped with Red Hat Openstack Enterprise 10 and 11. The sudoers file as installed with OSP's opensta… Openstack Mitigation only Fix from $1,9502018-08-22 MEDIUM 6.5 CVE-2017-7528 Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection. It was found that X-Forwarded-For header allows… Ansible Tower Mitigation only Fix from $1,6002018-08-22 MEDIUM 5.4 CVE-2017-7513 It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fiel… Satellite Mitigation only Fix from $1,6002018-08-22 HIGH 8.8 CVE-2018-10884 Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could expl… Ansible Tower after 3.2.6 Fix from $1,9502018-08-22 MEDIUM 5.9 CVE-2018-10844 It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to … Enterprise Linux Desktop 3.6.12+ Fix from $1,6002018-08-22 MEDIUM 5.9 CVE-2018-10845 It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to … Enterprise Linux Desktop 3.6.12+ Fix from $1,6002018-08-22 MEDIUM 5.6 CVE-2018-10846 A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a c… Enterprise Linux Desktop 3.6.12+ Fix from $1,6002018-08-22 HIGH 7.5 CVE-2018-1517 A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack w… Satellite Mitigation only Fix from $1,9502018-08-20 MEDIUM 6.5 CVE-2018-1656 The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Technology Edition 6.0 , 7.0, and 8.0) does not protec… Satellite Patch available Fix from $1,6002018-08-20 MEDIUM 5.5 CVE-2015-5160 libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sen… Virtualization Mitigation only Fix from $1,6002018-08-20 MEDIUM 6.5 CVE-2016-9596 libxml2, as used in Red Hat JBoss Core Services and when in recovery mode, allows context-dependent attackers to cause a denial of service (stack con… Jboss Core Services 2.9.4+ Fix from $1,6002018-08-16 MEDIUM 6.5 CVE-2016-9598 libxml2, as used in Red Hat JBoss Core Services, allows context-dependent attackers to cause a denial of service (out-of-bounds read and application … Jboss Core Services 2.9.4+ Fix from $1,6002018-08-16 MEDIUM 6.2 CVE-2018-10864 An uncontrolled resource consumption flaw has been discovered in redhat-certification in the way documents are loaded. A remote attacker may provide … Certification Mitigation only Fix from $1,6002018-08-13 MEDIUM 5.0 CVE-2017-15138 The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook… Openshift Container Platform Patch available Fix from $1,6002018-08-13 CRITICAL 9.8 CVE-2018-10931EPSS 68% It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use… Satellite after 2.6.11 Fix from $2,3002018-08-09 HIGH 7.5 CVE-2018-10915EPSS 5% A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections… Openstack Patch available Fix from $1,9502018-08-09 MEDIUM 6.3 CVE-2018-10908 It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By uploading a specially crafted image… Virtualization 4.20.37+ Fix from $1,6002018-08-09 HIGH 7.5 CVE-2018-5390EPSS 74% Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet… Virtualization 4.18+ Fix from $1,9502018-08-06 HIGH 8.1 CVE-2016-8609 It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing … Keycloak 2.3.0+ Fix from $1,9502018-08-01 HIGH 8.1 CVE-2018-10897EPSS 6% A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration fil… Virtualization after 1.1.31 Fix from $1,9502018-08-01 HIGH 7.8 CVE-2016-9583 An out-of-bounds heap read vulnerability was found in the jpc_pi_nextpcrl() function of jasper before 2.0.6 when processing crafted input. Enterprise Linux Desktop 2.0.6+ Fix from $1,9502018-08-01 MEDIUM 5.4 CVE-2018-10894 It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to acce… Keycloak Patch available Fix from $1,6002018-08-01