Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2016-5406 The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by… Jboss Enterprise Application Platform after 7.0.1 Fix from $1,9502016-09-26 MEDIUM 6.1 CVE-2016-4993 CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before … Jboss Enterprise Application Platform after 7.0.1 Fix from $1,6002016-09-26 HIGH 7.5 CVE-2016-3110 mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP mes… Jboss Enterprise Application Platform Mitigation only Fix from $1,9502016-09-26 HIGH 8.4 CVE-2016-6340 The kickstart file in Red Hat QuickStart Cloud Installer (QCI) forces use of MD5 passwords on deployed systems, which makes it easier for attackers t… Quickstart Cloud Installer Mitigation only Fix from $1,9502016-09-22 HIGH 8.4 CVE-2016-6322 Red Hat QuickStart Cloud Installer (QCI) uses world-readable permissions for /etc/qci/answers, which allows local users to obtain the root password f… Quickstart Cloud Installer Mitigation only Fix from $1,9502016-09-22 MEDIUM 5.5 CVE-2016-7166 libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory con… Enterprise Linux Desktop Patch available Fix from $1,6002016-09-21 MEDIUM 6.5 CVE-2016-5844 Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a crafted … Enterprise Linux Desktop Patch available Fix from $1,6002016-09-21 HIGH 7.5 CVE-2016-5418 The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to … Enterprise Linux Desktop Patch available Fix from $1,9502016-09-21 HIGH 7.5 CVE-2016-4809 The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a… Enterprise Linux Desktop Patch available Fix from $1,9502016-09-21 HIGH 7.8 CVE-2016-4302 Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to exe… Enterprise Linux Desktop after 3.2.0 Fix from $1,9502016-09-21 HIGH 7.8 CVE-2016-4300 Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to exec… Enterprise Linux Desktop after 3.2.0 Fix from $1,9502016-09-21 HIGH 8.8 CVE-2016-5422 The web console in Red Hat JBoss Operations Network (JON) before 3.3.7 does not properly authorize requests to add users with the super user role, wh… Jboss Operations Network after 3.3.6 Fix from $1,9502016-09-07 HIGH 8.8 CVE-2016-7034 The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session and includes them in query s… Jboss Bpm Suite Mitigation only Fix from $1,9502016-09-07 MEDIUM 6.1 CVE-2016-7033 Multiple cross-site scripting (XSS) vulnerabilities in the admin pages in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 allow remote attackers to inje… Jboss Bpm Suite Mitigation only Fix from $1,6002016-09-07 HIGH 7.5 CVE-2016-6346EPSS 6% RESTEasy enables GZIPInterceptor, which allows remote attackers to cause a denial of service via unspecified vectors. Resteasy Mitigation only Fix from $1,9502016-09-07 MEDIUM 6.5 CVE-2016-6345 RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs. Resteasy Mitigation only Fix from $1,6002016-09-07 MEDIUM 5.3 CVE-2016-6344 Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attacke… Jboss Bpm Suite Mitigation only Fix from $1,6002016-09-07 HIGH 7.5 CVE-2016-2183EPSS 96% The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately… Jboss Enterprise Application Platform 0.10.47 / 0.12.16+ Fix from $1,9502016-09-01 HIGH 8.8 CVE-2016-5383 The web UI in Red Hat CloudForms 4.1 allows remote authenticated users to execute arbitrary code via vectors involving "Lack of field filters." Cloudforms Mitigation only Fix from $1,9502016-08-26 HIGH 8.8 CVE-2016-5766EPSS 7% Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x b… Openshift Patch available Fix from $1,9502016-08-07 MEDIUM 6.5 CVE-2016-5392 The API server in Kubernetes, as used in Red Hat OpenShift Enterprise 3.2, in a multi tenant environment allows remote authenticated users with knowl… Openshift Mitigation only Fix from $1,6002016-08-05 CRITICAL 9.8 CVE-2016-4999 SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuil… Dashbuilder after 0.5.0 Fix from $2,3002016-08-05 MEDIUM 6.1 CVE-2016-3097 Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML vi… Satellite Mitigation only Fix from $1,6002016-08-05 MEDIUM 6.1 CVE-2016-3080 Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML vi… Satellite Mitigation only Fix from $1,6002016-08-05 CRITICAL 9.8 CVE-2016-3737EPSS 7% The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, relat… Jboss Operations Network after 3.3.5 Fix from $2,3002016-08-02 HIGH 8.1 CVE-2016-5388EPSS 51% Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not prote… Enterprise Linux Desktop Patch available Fix from $1,9502016-07-19 CRITICAL 9.8 CVE-2016-5008 libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers… Libvirt after 1.3.5 Fix from $2,3002016-07-13 MEDIUM 6.5 CVE-2016-5009 The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph mon… Ceph Storage Mon after 0.94.6 Fix from $1,6002016-07-12 HIGH 7.5 CVE-2016-4985 The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive informati… Openstack after 4.2.4 Fix from $1,9502016-07-12 MEDIUM 5.4 CVE-2016-4428 Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allows remote authenticated users… Openstack after 8.0.1 Fix from $1,6002016-07-12