Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.8 CVE-2018-2634 Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JGSS). Supported versions that are affected are Java SE: 7u… Satellite Patch available Fix from $1,6002018-01-18 MEDIUM 6.1 CVE-2018-2641EPSS 5% Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u1… Satellite Patch available Fix from $1,6002018-01-18 MEDIUM 5.3 CVE-2018-2629 Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JGSS). Supported versions that are affected are Ja… Satellite Patch available Fix from $1,6002018-01-18 MEDIUM 5.9 CVE-2018-2618 Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Jav… Satellite Patch available Fix from $1,6002018-01-18 MEDIUM 5.3 CVE-2018-2603EPSS 7% Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected a… Satellite Patch available Fix from $1,6002018-01-18 MEDIUM 6.5 CVE-2018-2582 Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE:… Satellite Patch available Fix from $1,6002018-01-18 HIGH 8.8 CVE-2014-0087 The check_privileges method in vmdb/app/controllers/application_controller.rb in ManageIQ, as used in Red Hat CloudForms Management Engine (CFME), al… Cloudforms Management Engine 5.3+ Fix from $1,9502018-01-11 HIGH 7.8 CVE-2017-12189 It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handling which c… Jboss Enterprise Application Platform Patch available Fix from $1,9502018-01-10 HIGH 7.0 CVE-2017-7536 In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows… Hibernate Validator 5.2.5 / 5.3.6+ Fix from $1,9502018-01-10 MEDIUM 6.1 CVE-2017-7559 In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before 1.3.31.Final, it was found that the fix for CVE-2017-2666 was incomp… Undertow 1.3.31 / 1.4.17+ Fix from $1,6002018-01-10 HIGH 7.8 CVE-2017-15131 It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting… Enterprise Linux 0.15.5+ Fix from $1,9502018-01-09 HIGH 7.5 CVE-2018-4871EPSS 6% An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28.0.0.137. This vulnerability occurs because of computation that reads data … Enterprise Linux Desktop after 28.0.0.126 Fix from $1,9502018-01-09 HIGH 7.8 CVE-2013-4364 (1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local u… Openshift Mitigation only Fix from $1,9502018-01-08 CRITICAL 9.8 CVE-2014-0121 The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter. Jboss Fuse after 1.2.2 Fix from $2,3002017-12-29 HIGH 8.8 CVE-2014-0120 Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary us… Jboss Fuse after 1.2.2 Fix from $1,9502017-12-29 MEDIUM 6.5 CVE-2017-16818 RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) b… Ceph after 12.2.1 Fix from $1,6002017-12-20 MEDIUM 5.4 CVE-2013-6465 Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 6.0.x allow remote authenticated users to inject arbitrary web script or HT… Jbpm Patch available Fix from $1,6002017-12-19 HIGH 8.8 CVE-2017-15103EPSS 5% A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted r… Enterprise Linux Patch available Fix from $1,9502017-12-18 HIGH 7.8 CVE-2017-15104 An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi serv… Enterprise Linux Mitigation only Fix from $1,9502017-12-18 HIGH 7.8 CVE-2017-16997 elf/dl-load.c in the GNU C Library (aka glibc or libc6) 2.19 through 2.26 mishandles RPATH and RUNPATH containing $ORIGIN for a privileged (setuid or… Enterprise Linux Desktop Patch available Fix from $1,9502017-12-18 MEDIUM 6.5 CVE-2017-11305 A regression affecting Adobe Flash Player version 27.0.0.187 (and earlier versions) causes the unintended reset of the global settings preference fil… Enterprise Linux Desktop after 27.0.0.187 Fix from $1,6002017-12-13 HIGH 7.4 CVE-2017-1000407 The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to … Virtualization Host 4.15+ Fix from $1,9502017-12-11 MEDIUM 6.5 CVE-2014-3250 The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers t… Linux 3.6.2+ Fix from $1,6002017-12-11 CRITICAL 9.8 CVE-2017-3112EPSS 6% An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data… Enterprise Linux Desktop after 27.0.0.183 Fix from $2,3002017-12-09 CRITICAL 9.8 CVE-2017-3114EPSS 6% An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data… Enterprise Linux Desktop after 27.0.0.183 Fix from $2,3002017-12-09 CRITICAL 9.8 CVE-2017-11213EPSS 7% An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data… Enterprise Linux Desktop after 27.0.0.183 Fix from $2,3002017-12-09 CRITICAL 9.8 CVE-2017-11215EPSS 6% An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in… Enterprise Linux Desktop after 27.0.0.183 Fix from $2,3002017-12-09 CRITICAL 9.8 CVE-2017-11225EPSS 6% An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in… Enterprise Linux Desktop after 27.0.0.183 Fix from $2,3002017-12-09 CRITICAL 9.8 CVE-2017-10906 Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitr… Openstack Patch available Fix from $2,3002017-12-08 MEDIUM 5.5 CVE-2017-15121 A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not e… Enterprise Linux Mitigation only Fix from $1,6002017-12-07