Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2017-7465 It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw … Jboss Enterprise Application Platform Mitigation only Fix from $2,3002018-06-27 HIGH 7.5 CVE-2018-3760EPSS 27% There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially craft… Cloudforms after 3.7.1 Fix from $1,9502018-06-26 CRITICAL 9.8 CVE-2018-1072 ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the option… Enterprise Virtualization Manager 4.2.2+ Fix from $2,3002018-06-26 HIGH 8.0 CVE-2017-7466 Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An attacker with control over a cl… Ansible 2.3+ Fix from $1,9502018-06-22 MEDIUM 6.5 CVE-2017-2668 389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote… Enterprise Linux Desktop 1.3.5.17 / 1.3.6.10+ Fix from $1,6002018-06-22 HIGH 8.8 CVE-2017-2672 A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file woul… Satellite 1.15+ Fix from $1,9502018-06-21 CRITICAL 9.8 CVE-2018-1117 ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/Clou… Enterprise Virtualization 1.0.6+ Fix from $2,3002018-06-20 MEDIUM 5.3 CVE-2018-1073 The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an a… Virtualization 4.2.3+ Fix from $1,6002018-06-19 CRITICAL 9.8 CVE-2018-12532EPSS 7% JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and exec… Richfaces after 4.5.17 Fix from $2,3002018-06-18 CRITICAL 9.8 CVE-2018-12533EPSS 19% JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java… Richfaces after 3.3.4 Fix from $2,3002018-06-18 CRITICAL 9.8 CVE-2018-1085 openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificate authentication to be disabl… Openshift Container Platform 3.9.31+ Fix from $2,3002018-06-15 HIGH 7.8 CVE-2018-5848 In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_le… Virtualization Host Patch available Fix from $1,9502018-06-12 MEDIUM 6.5 CVE-2018-1103 Openshift Enterprise source-to-image before version 1.1.10 is vulnerable to an improper validation of user input. An attacker who could trick a user … Source To Image 1.1.10+ Fix from $1,6002018-06-12 HIGH 7.5 CVE-2018-1070 routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which can cause an entire shard to b… Openshift Container Platform 3.10+ Fix from $1,9502018-06-12 CRITICAL 9.8 CVE-2018-5183 Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and… Enterprise Linux Desktop Mitigation only Fix from $2,3002018-06-11 MEDIUM 6.5 CVE-2018-5185 Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird… Enterprise Linux Desktop Mitigation only Fix from $1,6002018-06-11 HIGH 7.5 CVE-2018-5157 Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow th… Enterprise Linux Desktop Mitigation only Fix from $1,9502018-06-11 HIGH 7.5 CVE-2018-5162 Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Th… Enterprise Linux Desktop Mitigation only Fix from $1,9502018-06-11 HIGH 8.8 CVE-2018-5146EPSS 12% An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.… Enterprise Linux Desktop Mitigation only Fix from $1,9502018-06-11 HIGH 7.3 CVE-2018-5144 An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affec… Enterprise Linux Desktop 52.7.0+ Fix from $1,9502018-06-11 HIGH 8.8 CVE-2018-5127EPSS 8% A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentially exploitable crash. This vul… Enterprise Linux Desktop 52.7.0 / 59.0+ Fix from $1,9502018-06-11 HIGH 8.8 CVE-2017-7846 It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in th… Enterprise Linux Desktop 52.5.2+ Fix from $1,9502018-06-11 MEDIUM 5.3 CVE-2017-7848 RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2. Enterprise Linux 52.5.2+ Fix from $1,6002018-06-11 CRITICAL 9.8 CVE-2017-7824 A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. This is due to an incorrect va… Enterprise Linux Aus 52.4.0 / 56.0+ Fix from $2,3002018-06-11 MEDIUM 5.4 CVE-2017-7823 The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-ori… Enterprise Linux Desktop 52.4.0 / 56.0+ Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7829 It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not d… Enterprise Linux Aus 52.5.2+ Fix from $1,6002018-06-11 CRITICAL 9.8 CVE-2017-7818 A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applications (ARIA) elements within containers through … Enterprise Linux Desktop 52.4.0 / 56.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-7819 A use-after-free vulnerability can occur in design mode when image objects are resized if objects referenced during the resizing have been freed from… Enterprise Linux Desktop 52.4.0 / 56.0+ Fix from $2,3002018-06-11 HIGH 7.8 CVE-2017-7814 File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature … Enterprise Linux Desktop 52.4.0 / 56.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-7803 When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This results in the incorrect enforc… Enterprise Linux Desktop 52.3.0 / 55.0+ Fix from $1,9502018-06-11