Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2017-3072 Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the BitmapData class. Successful exploitati… Enterprise Linux after 25.0.0.163 Fix from $1,9502017-05-09 HIGH 8.8 CVE-2017-3073 Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability when handling multiple mask properties of display… Enterprise Linux after 25.0.0.163 Fix from $1,9502017-05-09 HIGH 8.8 CVE-2017-3074 Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Graphics class. Successful exploitation… Enterprise Linux after 25.0.0.163 Fix from $1,9502017-05-09 HIGH 7.5 CVE-2017-7957 XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during… Fuse after 1.4.9 Fix from $1,9502017-04-29 HIGH 8.3 CVE-2017-3512 Vulnerability in the Java SE component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 7u131 and 8u121. Diff… Icedtea 3.4.0+ Fix from $1,9502017-04-24 MEDIUM 5.3 CVE-2016-3702 Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext information. Cloudforms Management Engine Mitigation only Fix from $1,6002017-04-21 MEDIUM 5.4 CVE-2016-6519 Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authenticated users to inject arbitr… Openstack after 2.5 Fix from $1,6002017-04-21 HIGH 8.8 CVE-2016-5401 Cross-site request forgery (CSRF) vulnerability in Red Hat JBoss BRMS and BPMS 6 allows remote attackers to hijack the authentication of users for re… Jboss Bpm Suite Mitigation only Fix from $1,9502017-04-20 MEDIUM 6.1 CVE-2016-6347 Cross-site scripting (XSS) vulnerability in the default exception handler in RESTEasy allows remote attackers to inject arbitrary web script or HTML … Resteasy Mitigation only Fix from $1,6002017-04-20 HIGH 7.5 CVE-2016-5409 Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which makes it easier for remote atta… Openshift Mitigation only Fix from $1,9502017-04-20 MEDIUM 6.8 CVE-2016-6338 ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate atta… Enterprise Virtualization No fix yet Fix from $1,6002017-04-20 MEDIUM 5.5 CVE-2016-5410 firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations via the (1) addPassthrough, (… Enterprise Linux Desktop after 0.4.3.2 Fix from $1,6002017-04-19 HIGH 7.5 CVE-2016-6489EPSS 5% The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack. Enterprise Linux Desktop 3.3+ Fix from $1,9502017-04-14 HIGH 7.5 CVE-2016-4970EPSS 11% handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (… Jboss Data Grid 4.0.37 / 4.1.1+ Fix from $1,9502017-04-13 MEDIUM 6.1 CVE-2016-2104 Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the … Satellite Mitigation only Fix from $1,6002017-04-13 MEDIUM 6.1 CVE-2016-6348 JacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack. Resteasy Mitigation only Fix from $1,6002017-04-12 HIGH 7.5 CVE-2016-4459 Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9. Mod Cluster Mitigation only Fix from $1,9502017-04-12 HIGH 7.0 CVE-2016-4444 The allow_execmod plugin for setroubleshoot before 3.2.23 allows local users to execute arbitrary commands by triggering an execmod SELinux denial wi… Enterprise Linux Desktop after 3.2.22 Fix from $1,9502017-04-11 HIGH 7.0 CVE-2016-4445 The fix_lookup_id function in sealert in setroubleshoot before 3.2.23 allows local users to execute arbitrary commands as root by triggering an SELin… Enterprise Linux Desktop after 3.2.22 Fix from $1,9502017-04-11 HIGH 7.0 CVE-2016-4446 The allow_execstack plugin for setroubleshoot allows local users to execute arbitrary commands by triggering an execstack SELinux denial with a craft… Enterprise Linux Desktop Patch available Fix from $1,9502017-04-11 HIGH 7.0 CVE-2016-4989 setroubleshoot allows local users to bypass an intended container protection mechanism and execute arbitrary commands by (1) triggering an SELinux de… Enterprise Linux Desktop Patch available Fix from $1,9502017-04-11 CRITICAL 9.8 CVE-2008-7313 The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CV… Openstack after 4.2.3 Fix from $2,3002017-03-31 CRITICAL 9.8 CVE-2014-5008 Snoopy allows remote attackers to execute arbitrary commands. Openstack Patch available Fix from $2,3002017-03-31 CRITICAL 9.8 CVE-2014-5009 Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008. Openstack after 4.2.3 Fix from $2,3002017-03-31 HIGH 7.5 CVE-2016-7797 Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthent… Enterprise Linux High Availability after 1.1.14 Fix from $1,9502017-03-24 CRITICAL 9.8 CVE-2017-5929EPSS 8% QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components. Satellite 1.2.0+ Fix from $2,3002017-03-13 HIGH 8.8 CVE-2016-3616 The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitra… Enterprise Linux Mitigation only Fix from $1,9502017-02-13 HIGH 7.8 CVE-2016-2568 pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters t… Enterprise Linux Mitigation only Fix from $1,9502017-02-13 CRITICAL 9.8 CVE-2016-9636EPSS 9% Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a… Enterprise Linux Desktop after 1.10.1 Fix from $2,3002017-01-27 CRITICAL 9.8 CVE-2016-9634EPSS 9% Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a… Enterprise Linux Desktop after 1.10.1 Fix from $2,3002017-01-27