Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.8 CVE-2015-5188 Cross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platform before 6.4.4 and WildFly … Jboss Enterprise Application Platform after 6.4.3 Fix from $1,6002015-10-27 MEDIUM 5.3 CVE-2015-4902 KEVEPSS 13% Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployme… Satellite Patch available Fix from $1,6002015-10-22 HIGH 7.8 CVE-2015-7645 KEVEPSS 68% Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attac… Enterprise Linux Desktop after 18.0.0.252 Fix from $1,9502015-10-15 MEDIUM 6.8 CVE-2015-5234 IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .app… Enterprise Linux Desktop after 1.5.2 Fix from $1,6002015-10-09 MEDIUM 6.8 CVE-2014-9751 The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP addr… Enterprise Linux Desktop 4.2.8+ Fix from $1,6002015-10-06 MEDIUM 5.8 CVE-2014-9750EPSS 6% ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtain sensitive information from … Enterprise Linux Desktop 4.2.8+ Fix from $1,6002015-10-06 MEDIUM 6.5 CVE-2015-5274 rubygem-openshift-origin-console in Red Hat OpenShift 2.2 allows remote authenticated users to execute arbitrary commands via a crafted request to th… Openshift Mitigation only Fix from $1,6002015-09-18 MEDIUM 6.9 CVE-2015-3247 Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (h… Enterprise Linux Mitigation only Fix from $1,6002015-09-08 HIGH 7.2 CVE-2015-5157 arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform mishandles IRET faults in processing NMIs that occurred during user… Enterprise Linux Desktop 3.12.47 / 3.14.54+ Fix from $1,9502015-08-31 HIGH 8.5 CVE-2015-5222 Red Hat OpenShift Enterprise 3.0.0.0 does not properly check permissions, which allows remote authenticated users with build permissions to execute a… Openshift Mitigation only Fix from $1,9502015-08-24 HIGH 7.5 CVE-2015-1867 Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command. Enterprise Linux High Availability after 1.1.12 Fix from $1,9502015-08-12 MEDIUM 5.8 CVE-2015-5176 The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets,… Jboss Portal Mitigation only Fix from $1,6002015-08-11 HIGH 7.2 CVE-2015-3246EPSS 7% libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allo… Libuser after 0.56.13-5 Fix from $1,9502015-08-11 HIGH 7.5 CVE-2015-1818 XML external entity (XXE) vulnerability in the dashbuilder import facility (DocumentBuilders in org.jboss.dashboard.export.ImportManagerImpl) in Red … Jboss Bpm Suite after 6.1.0 Fix from $1,9502015-08-11 MEDIUM 5.0 CVE-2015-1285 The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, d… Enterprise Linux Desktop Supplementary after 43.0.2357.134 Fix from $1,6002015-07-23 HIGH 7.5 CVE-2015-1279 Integer overflow in the CJBig2_Image::expand function in fxcodec/jbig2/JBig2_Image.cpp in PDFium, as used in Google Chrome before 44.0.2403.89, allow… Enterprise Linux Desktop Supplementary after 43.0.2357.134 Fix from $1,9502015-07-23 MEDIUM 6.8 CVE-2015-1273 Heap-based buffer overflow in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 44.0.2403.89, allows remote attackers to caus… Enterprise Linux Desktop Supplementary after 43.0.2357.134 Fix from $1,6002015-07-23 CRITICAL 9.8 CVE-2015-5123 KEVEPSS 18% Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Wind… Enterprise Linux Desktop after 18.0.0.203 Fix from $2,3002015-07-14 CRITICAL 9.8 CVE-2015-5122 KEVEPSS 94% Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on W… Enterprise Linux Desktop after 18.0.0.204 Fix from $2,3002015-07-14 MEDIUM 6.0 CVE-2014-8175 Red Hat JBoss Fuse before 6.2.0 allows remote authenticated users to bypass intended restrictions and access the HawtIO console by leveraging an acco… Jboss Fuse after 6.1.0 Fix from $1,6002015-07-08 CRITICAL 9.8 CVE-2015-5119 KEVEPSS 99% Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x… Enterprise Linux Desktop after 18.0.0.194 Fix from $2,3002015-07-08 CRITICAL 9.8 CVE-2015-0192 Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 F… Enterprise Linux Desktop 5.0.16.10 / 6.1.8.4+ Fix from $2,3002015-07-02 CRITICAL 9.8 CVE-2015-3113 KEVEPSS 100% Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.46… Enterprise Linux Desktop 11.2.202.468 / 13.0.0.296+ Fix from $2,3002015-06-23 MEDIUM 5.0 CVE-2015-4148EPSS 20% The do_soap_call function in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that the uri property … Enterprise Linux Desktop after 10.10.4 Fix from $1,6002015-06-09 HIGH 7.5 CVE-2015-4147EPSS 12% The SoapClient::__call method in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that __default_hea… Enterprise Linux Desktop after 10.10.4 Fix from $1,9502015-06-09 HIGH 7.5 CVE-2015-4026EPSS 20% The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 charact… Enterprise Linux after 5.4.40 Fix from $1,9502015-06-09 MEDIUM 5.0 CVE-2015-4024EPSS 50% Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x … Enterprise Linux after 5.4.40 Fix from $1,6002015-06-09 HIGH 7.5 CVE-2015-4022EPSS 21% Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote FTP ser… Enterprise Linux Desktop after 5.4.40 Fix from $1,9502015-06-09 MEDIUM 5.0 CVE-2015-4021EPSS 21% The phar_parse_tarfile function in ext/phar/tar.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 does not verify that the first ch… Enterprise Linux Desktop after 5.4.40 Fix from $1,6002015-06-09 HIGH 7.5 CVE-2015-3329EPSS 38% Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5… Enterprise Linux Desktop after 5.4.39 Fix from $1,9502015-06-09