Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2017-2625 It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attack… Enterprise Linux 1.1.2+ Fix from $1,6002018-07-27 MEDIUM 5.3 CVE-2017-2623 It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages… Enterprise Linux 2017.3+ Fix from $1,6002018-07-27 HIGH 8.8 CVE-2017-12173 It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulner… Enterprise Linux Desktop 1.16.0+ Fix from $1,9502018-07-27 HIGH 8.6 CVE-2017-15119 The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a client sen… Virtualization 2.11.0+ Fix from $1,9502018-07-27 HIGH 7.2 CVE-2017-12148 A flaw was found in Ansible Tower's interface before 3.1.5 and 3.2.0 with SCM repositories. If a Tower project (SCM repository) definition does not h… Ansible Tower 3.1.5 / 3.2.0+ Fix from $1,9502018-07-27 MEDIUM 6.6 CVE-2017-15113 ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change th… Virtualization 4.1.7.6+ Fix from $1,6002018-07-27 HIGH 7.5 CVE-2017-12165 It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http… Undertow 1.3.31 / 1.4.17+ Fix from $1,9502018-07-27 HIGH 7.5 CVE-2017-2670 It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively ca… Undertow 1.3.28+ Fix from $1,9502018-07-27 MEDIUM 6.5 CVE-2017-2595 It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path trave… Jboss Enterprise Application Platform Mitigation only Fix from $1,6002018-07-27 MEDIUM 5.4 CVE-2017-15125 A flaw was found in CloudForms before 5.9.0.22 in the self-service UI snapshot feature where the name field is not properly sanitized for HTML and Ja… Cloudforms Management Engine 5.9.0.22+ Fix from $1,6002018-07-27 MEDIUM 6.5 CVE-2017-2666 It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction w… Undertow Mitigation only Fix from $1,6002018-07-27 MEDIUM 5.5 CVE-2018-10862 WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives… Virtualization after 5.0.0 Fix from $1,6002018-07-27 CRITICAL 9.8 CVE-2017-7470 It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorizati… Spacewalk Mitigation only Fix from $2,3002018-07-27 HIGH 7.5 CVE-2017-2639 It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communica… Cloudforms Mitigation only Fix from $1,9502018-07-27 MEDIUM 5.5 CVE-2017-2622 An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malic… Openstack Mitigation only Fix from $1,6002018-07-27 CRITICAL 9.8 CVE-2017-7464 It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use thi… Jboss Enterprise Application Platform Mitigation only Fix from $2,3002018-07-27 HIGH 7.4 CVE-2017-12150EPSS 13% It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options w… Enterprise Linux Desktop 4.4.16 / 4.5.14+ Fix from $1,9502018-07-26 MEDIUM 6.5 CVE-2017-12171EPSS 8% A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines… Enterprise Linux Mitigation only Fix from $1,6002018-07-26 MEDIUM 6.5 CVE-2017-2582 It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute … Keycloak 2.5.1+ Fix from $1,6002018-07-26 MEDIUM 5.5 CVE-2017-12167 It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role ma… Jboss Enterprise Application Platform 7.0.9+ Fix from $1,6002018-07-26 MEDIUM 5.4 CVE-2017-12175 Red Hat Satellite before 6.5 is vulnerable to a XSS in discovery rule when you are entering filter and you use autocomplete functionality. Satellite 6.5+ Fix from $1,6002018-07-26 HIGH 7.1 CVE-2017-12163EPSS 8% An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A ma… Enterprise Linux Desktop 4.4.16 / 4.5.14+ Fix from $1,9502018-07-26 MEDIUM 6.5 CVE-2017-7509 An input validation error was found in Red Hat Certificate System's handling of client provided certificates before 8.1.20-1. If the certreq field is… Certificate System 8.1.20-1+ Fix from $1,6002018-07-26 CRITICAL 9.0 CVE-2017-2589 It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored … Jboss Fuse Mitigation only Fix from $2,3002018-07-26 MEDIUM 6.5 CVE-2017-7545 It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote a… Decision Manager Patch available Fix from $1,6002018-07-26 MEDIUM 6.5 CVE-2017-7562 An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A remote at… Enterprise Linux 1.16.1+ Fix from $1,6002018-07-26 MEDIUM 5.4 CVE-2017-7538 A cross-site scripting (XSS) flaw was found in how an organization name is displayed in Satellite 5, before 5.8. A user able to change an organizatio… Satellite 5.8+ Fix from $1,6002018-07-26 HIGH 7.5 CVE-2017-7539EPSS 6% An assertion-failure flaw was found in Qemu before 2.10.1, in the Network Block Device (NBD) server's initial connection negotiation, where the I/O c… Openstack 2.10.1+ Fix from $1,9502018-07-26 MEDIUM 6.5 CVE-2017-2664 CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the rails application portion of Cl… Cloudforms 5.7.3 / 5.8.1+ Fix from $1,6002018-07-26 MEDIUM 5.9 CVE-2017-7543 A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1,… Openstack 7.2.0-12.1 / 8.3.0-11.1+ Fix from $1,6002018-07-26