Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2014-0233 Red Hat OpenShift Enterprise 2.0 and 2.1 and OpenShift Origin allow remote authenticated users to execute arbitrary commands via shell metacharacters… Openshift No fix yet Fix from $1,6002014-11-16 HIGH 9.4 CVE-2014-8567 The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request … Enterprise Linux Desktop 0.8.1+ Fix from $1,9502014-11-14 MEDIUM 5.0 CVE-2014-8564 The _gnutls_ecc_ansi_x963_export function in gnutls_ecc.c in GnuTLS 3.x before 3.1.28, 3.2.x before 3.2.20, and 3.3.x before 3.3.10 allows remote att… Enterprise Linux Desktop Patch available Fix from $1,6002014-11-13 MEDIUM 5.0 CVE-2014-7823 The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE … Libvirt after 1.2.10 Fix from $1,6002014-11-13 HIGH 7.5 CVE-2014-3674 Red Hat OpenShift Enterprise before 2.2 does not properly restrict access to gears, which allows remote attackers to access the network resources of … Openshift after 2.1.8 Fix from $1,9502014-11-13 HIGH 7.5 CVE-2014-3693 Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote attackers t… Enterprise Linux Desktop Patch available Fix from $1,9502014-11-07 MEDIUM 5.0 CVE-2013-0336 The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_extop.c in the directory server (dirsrv) in FreeIPA before 3.2.0 allows… Freeipa after 3.1.5 Fix from $1,6002014-11-03 MEDIUM 5.0 CVE-2014-0136 The (1) get and (2) log methods in the AgentController in Red Hat CloudForms 3.0 Management Engine (CFME) 5.x allow remote attackers to insert arbitr… Cloudforms 3.0 Management Engine after 5.2.5.3 Fix from $1,6002014-10-27 MEDIUM 6.8 CVE-2014-5075 The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify that the server hostname match… Jboss Fuse after 6.1.0 Fix from $1,6002014-10-25 MEDIUM 5.0 CVE-2014-7968 VDSM allows remote attackers to cause a denial of service (connection blocking) by keeping an SSL connection open. Virtual Desktop Service Manager Mitigation only Fix from $1,6002014-10-22 HIGH 7.5 CVE-2014-3676EPSS 5% Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related to the "tftp:// DHCPv6 boot … Shim 0.8+ Fix from $1,9502014-10-22 HIGH 7.5 CVE-2014-3677 Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption. Shim 0.8+ Fix from $1,9502014-10-22 MEDIUM 5.0 CVE-2014-3675 Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet. Shim 0.8+ Fix from $1,6002014-10-22 MEDIUM 6.5 CVE-2014-3573 The oVirt Engine backend module, as used in Red Hat Enterprise Virtualization Manager before 3.4.2, uses an "insecure DocumentBuilderFactory," which … Enterprise Virtualization Manager after 3.4.1 Fix from $1,6002014-10-18 HIGH 7.5 CVE-2014-3666 Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to execute arbitrary code via a crafted packet to the CLI channel. Openshift after 3.1 Fix from $1,9502014-10-16 MEDIUM 5.0 CVE-2014-3661 Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to cause a denial of service (thread consumption) via vectors related to a CLI ha… Openshift after 3.1 Fix from $1,6002014-10-16 HIGH 7.5 CVE-2014-3192 Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation … Enterprise Linux Desktop Supplementary after 38.0.2125.7 Fix from $1,9502014-10-08 HIGH 7.5 CVE-2014-3193 The SessionService::GetLastSession function in browser/sessions/session_service.cc in Google Chrome before 38.0.2125.101 allows remote attackers to c… Enterprise Linux Desktop Supplementary after 38.0.2125.7 Fix from $1,9502014-10-08 HIGH 7.5 CVE-2014-3194 Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of ser… Enterprise Linux Desktop Supplementary after 38.0.2125.7 Fix from $1,9502014-10-08 MEDIUM 5.0 CVE-2014-3199 The wrap function in bindings/core/v8/custom/V8EventCustom.cpp in the V8 bindings in Blink, as used in Google Chrome before 38.0.2125.101, has an err… Enterprise Linux Desktop Supplementary after 38.0.2125.7 Fix from $1,6002014-10-08 MEDIUM 6.5 CVE-2014-3642 vmdb/app/controllers/application_controller/performance.rb in Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated … Cloudforms 3.0.1 Management Engine after 5.2.5 Fix from $1,6002014-10-06 MEDIUM 5.5 CVE-2014-3521 The component in (1) /luci/homebase and (2) /luci/cluster menu in Red Hat Conga 0.12.2 allows remote authenticated users to bypass intended access re… Conga Mitigation only Fix from $1,6002014-10-06 MEDIUM 5.0 CVE-2013-6496 Red Hat Conga 0.12.2 allows remote attackers to obtain sensitive information via a crafted request to the (1) homebase, (2) cluster, (3) storage, (4)… Conga Mitigation only Fix from $1,6002014-10-06 HIGH 7.5 CVE-2014-6051EPSS 8% Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of se… Enterprise Linux Server Aus after 0.9.9 Fix from $1,9502014-09-30 MEDIUM 5.0 CVE-2014-3558 ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 … Hibernate Validator 4.3.2 / 5.1.2+ Fix from $1,6002014-09-30 HIGH 7.8 CVE-2014-7145 The SMB2_tcon function in fs/cifs/smb2pdu.c in the Linux kernel before 3.16.3 allows remote CIFS servers to cause a denial of service (NULL pointer d… Enterprise Linux Desktop 3.10.55 / 3.12.29+ Fix from $1,9502014-09-28 MEDIUM 6.8 CVE-2014-0152 Session fixation vulnerability in the web admin interface in oVirt 3.4.0 and earlier allows remote attackers to hijack web sessions via unspecified v… Ovirt Engine after 3.4.0 Fix from $1,6002014-09-08 MEDIUM 5.0 CVE-2014-3562 Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by se… Directory Server Mitigation only Fix from $1,6002014-08-21 HIGH 7.5 CVE-2014-3490 RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external… Jboss Enterprise Application Platform 3.0.9+ Fix from $1,9502014-08-19 MEDIUM 5.0 CVE-2014-4615 The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014… Openstack after 0.5.0 Fix from $1,6002014-08-19