Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2017-1000253 KEVEPSS 11% Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committ… Enterprise Linux 3.2.70 / 3.4.109+ Fix from $1,9502017-10-05 CRITICAL 9.8 CVE-2017-12149 KEVEPSS 91% In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessF… Jboss Enterprise Application Platform Mitigation only Fix from $2,3002017-10-04 CRITICAL 9.8 CVE-2017-14491EPSS 85% Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafte… Enterprise Linux Desktop after 2.77 Fix from $2,3002017-10-04 CRITICAL 9.8 CVE-2017-7552 A flaw was discovered in the file editor of millicore, affecting versions before 3.19.0 and 4.x before 4.5.0, which allows files to be executed as we… Mobile Application Platform after 4.4.3 Fix from $2,3002017-09-29 MEDIUM 6.3 CVE-2017-7553 The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the netwo… Mobile Application Platform after 4.4.3 Fix from $1,6002017-09-29 MEDIUM 6.1 CVE-2017-7554 It was found that the App Studio component of RHMAP 4.4 executes javascript provided by a user. An attacker could use this flaw to execute a stored X… Mobile Application Platform Patch available Fix from $1,6002017-09-29 CRITICAL 9.1 CVE-2015-7544 redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the Supe… Enterprise Virtualization Manager Mitigation only Fix from $2,3002017-09-25 HIGH 8.8 CVE-2015-5182 Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ. Amq Mitigation only Fix from $1,9502017-09-25 HIGH 7.5 CVE-2015-5183 Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ. Amq 6.3+ Fix from $1,9502017-09-25 HIGH 7.5 CVE-2015-5184 Console: CORS headers set to allow all in Red Hat AMQ. Amq 6.2.1+ Fix from $1,9502017-09-25 MEDIUM 5.4 CVE-2015-5181 The JBoss console in A-MQ allows remote attackers to execute arbitrary JavaScript. Jboss A Mq after 6.0 Fix from $1,6002017-09-25 MEDIUM 6.5 CVE-2015-5248 Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform. Feedhenry Enterprise Mobile Application Platform No fix yet Fix from $1,6002017-09-20 MEDIUM 5.9 CVE-2015-1849 AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vect… Jboss Enterprise Application Platform after 6.4.0 Fix from $1,6002017-09-19 MEDIUM 5.5 CVE-2015-7837 The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local … Enterprise Linux Patch available Fix from $1,6002017-09-19 CRITICAL 9.8 CVE-2014-8174 eDeploy makes it easier for remote attackers to execute arbitrary code by leveraging use of HTTP to download files. Edeploy after 1.11.0 Fix from $2,3002017-09-19 HIGH 7.5 CVE-2017-1002151 Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization Pagure after 3.3 Fix from $1,9502017-09-14 HIGH 7.5 CVE-2017-7561 Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component re… Jboss Enterprise Application Platform Patch available Fix from $1,9502017-09-13 MEDIUM 5.5 CVE-2017-7560 It was found that rhnsd PID files are created as world-writable that allows local attackers to fill the disks or to kill selected processes. Rhnsd Mitigation only Fix from $1,6002017-09-13 MEDIUM 6.5 CVE-2014-8163 Directory traversal vulnerability in the XMLRPC interface in Red Hat Satellite 5. Satellite No fix yet Fix from $1,6002017-08-28 MEDIUM 6.1 CVE-2014-0141 Cross-site scripting (XSS) vulnerability in Red Hat Satellite 6.0.3. Satellite No fix yet Fix from $1,6002017-08-28 MEDIUM 6.1 CVE-2014-8168 Red Hat Satellite 6 allows local users to access mongod and delete pulp_database. Satellite Mitigation only Fix from $1,6002017-08-28 MEDIUM 5.9 CVE-2015-5293 Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which m… Enterprise Virtualization Manager after 3.6.0 Fix from $1,6002017-08-24 MEDIUM 5.5 CVE-2016-6310 oVirt Engine discloses the ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD in /var/log/ovirt-engine/engine.log file in RHEV before 4.0. Enterprise Virtualization after 3.6 Fix from $1,6002017-08-22 MEDIUM 5.3 CVE-2016-6311 Get requests in JBoss Enterprise Application Platform (EAP) 7 disclose internal IP addresses to remote attackers. Jboss Enterprise Application Platform Mitigation only Fix from $1,6002017-08-22 HIGH 8.8 CVE-2017-3106EPSS 22% Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful exploitation c… Enterprise Linux after 26.0.0.137 Fix from $1,9502017-08-11 HIGH 7.4 CVE-2017-3085 Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redi… Enterprise Linux after 26.0.0.137 Fix from $1,9502017-08-11 HIGH 7.0 CVE-2014-0143 Multiple integer overflows in the block drivers in QEMU, possibly before 2.0.0, allow local users to cause a denial of service (crash) via a crafted … Enterprise Linux after 1.7.1 Fix from $1,9502017-08-10 MEDIUM 6.1 CVE-2016-3113 Cross-site scripting (XSS) vulnerability in ovirt-engine allows remote attackers to inject arbitrary web script or HTML. Ovirt Engine Mitigation only Fix from $1,6002017-08-07 MEDIUM 5.5 CVE-2015-3149 The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitrary files via a symlink attack. Enterprise Linux Desktop Mitigation only Fix from $1,6002017-07-25 HIGH 7.5 CVE-2015-3198 The Undertow module of WildFly 9.x before 9.0.0.CR2 and 10.x before 10.0.0.Alpha1 allows remote attackers to obtain the source code of a JSP page via… Jboss Wildfly Application Server Mitigation only Fix from $1,9502017-07-21